Nile
Legal · Privacy Policy

Privacy Policy

Effective date: 9 September 2026

Nile Commerce (Pty) Ltd, registration number 2022/770381/07 (“Nile”, “we”, “us” or “our”), a private company incorporated in the Republic of South Africa and headquartered in Cape Town, is committed to protecting your privacy. This Privacy Policy explains how we handle personal information. Nile provides social commerce infrastructure to brands. We are not a shop and we do not sell goods. onnile.shop is a business website for brands and partners, not a place where consumers shop.

This Policy is prepared with reference to the Protection of Personal Information Act 4 of 2013 (“POPIA”) and should be read together with our PAIA Manual, which sets out how to request access to information we hold. Where we process personal information of people in the European Union or the United Kingdom on behalf of a merchant, we do so in a manner consistent with the General Data Protection Regulation.

This Policy covers all of our services, including onnile.shop, the Social Commerce Studio, the Sales Assistant technology, and the Nile Commerce app for Shopify.

1. Who we are, and the capacity in which we act

Nile acts in two different capacities depending on whose information is being processed. This distinction matters because it determines who is accountable to you.

Responsible party
Brand and Studio user accounts, including the people who administer a brand's Social Commerce Studio. Visitors to onnile.shop, including analytics and cookie data. Our own marketing, waitlist and enquiry data. Creator, supplier and employee records held for our own business.
Operator
Shopper personal information processed inside a brand's Sales Assistant conversation, including chat content and order details. Shopper contact details collected in the course of completing an order for a brand. Merchant store, order, product and customer data accessed through the Nile Commerce app for Shopify. Any other shopper or customer information we process on a brand's or merchant's documented instructions.

Where we are the responsible party, we determine why and how personal information is processed, and we are accountable to you directly under POPIA.

Where we are an operator, the brand or merchant is the responsible party, described in some jurisdictions as the data controller. They determine why and how the information is processed, and we process it only on their documented instructions under a written Data Processing Agreement. If you wish to exercise your rights in relation to information held in a brand's Sales Assistant or a merchant's Shopify store, your request is best directed to that brand or merchant. We will assist them in responding, and you may contact us and we will pass the request on.

Our Information Officer is Joy Des Fountain, registered with the Information Regulator, and can be contacted at [email protected].

2. Information we handle

Because we act in two capacities, it is clearest to separate the information we hold for ourselves from the information we process for a brand or merchant.

2.1 Information we hold as responsible party
This is information about brands, merchants, the people who work at them, website visitors, creators, suppliers and our own staff.

  • Name, work email address, telephone number, company name and store URL when you enquire, request a demonstration, request installation or join a waitlist
  • Studio account details for the people a brand authorises to use it, including name, email address and role
  • Creator records a brand loads into the Studio, being name, image, social network, handle and follower count
  • Billing and payment records. Nile does not store full card details.
  • Correspondence with us, and your communication preferences
  • How you use onnile.shop and the Studio, including IP address, device and browser type, pages visited, time on page and referral source

2.2 Information we process for a brand, as operator
When a shopper buys from a brand through that brand's WhatsApp channel, we process the following on that brand's instructions. The brand decides why and how, and the brand is accountable for it.

  • Name, WhatsApp or telephone number, email address and delivery address
  • The content of the shopping conversation with the brand's Sales Assistant
  • Order and transaction records
  • Payment information handled by the payment provider. Neither Nile nor the brand receives full card details from us.

For shoppers: a shopper is dealing with the brand, not with Nile. The brand's own privacy notice governs that relationship. This Policy explains our part in it, and what to do if you want to reach us about it.

2.3 Information we process through the Nile Commerce app for Shopify, as operator
Section 3 sets out in full what the app accesses, why, and how it is governed. The merchant is the responsible party for all of it.

3. The Nile Commerce app for Shopify

This section applies to merchants who install the Nile Commerce app on their Shopify store, and to the customers of those merchants. It is written to meet Shopify's privacy and Protected Customer Data requirements.

3.1 Our role
The merchant is the responsible party, described in Shopify's documentation as the data controller, for all store, order, product and customer data accessed through the app. Nile is the operator, or data processor, and acts only on the merchant's documented instructions under a written Data Processing Agreement entered into on installation. We do not use merchant or customer data for our own purposes.

3.2 Order synchronisation is required
By installing and using the Nile Commerce app, a merchant acknowledges that order information from their Shopify store will be tracked and synchronised with the Nile platform. This synchronisation is required to enable the core functionality of the app, including:

  • Processing orders originating from social commerce channels
  • Updating order fulfilment status between Shopify and the Nile platform
  • Synchronising product and inventory information
  • Providing real-time order status updates to customers

Order synchronisation is a required component of the Nile Commerce service and cannot be disabled while the app is installed and active. A merchant who does not want this synchronisation should uninstall the app.

3.3 What the app accesses, and why
We access only the minimum personal information required to provide the app's functionality, and we process it only for the purposes stated here.

Order status and fulfilment dataWhy we need itTo keep Shopify and the Nile platform in step, and to update customers on their orders
Order identifiers, being the Shopify Order ID and the Nile Order IDWhy we need itTo match an order in Nile to the same order in Shopify
Product, variant, price and inventory dataWhy we need itTo present accurate products and availability in the social commerce channel
Customer name, email address, telephone number and shipping address, received in Shopify order webhooksWhy we need itTo create and fulfil the order, and to communicate about it in the merchant's channel
Store details, being shop domain, shop ID and installation settingsWhy we need itTo identify the store and operate the integration

We do not access Shopify data that the app does not need, and we do not request scopes beyond those required for the functions above.

3.4 Shopify Protected Customer Data
The Nile Commerce app subscribes to Shopify order webhooks that may contain Protected Customer Data as defined by Shopify, including Level 2 fields being customer name, address, telephone number and email address. Nile complies with Shopify's Protected Customer Data requirements. Our safeguards include:

  • Data minimisation. We process only the minimum personal information required to provide the app's functionality.
  • Purpose limitation. We restrict processing to the purposes set out in section 3.3 and use the data for nothing else.
  • Merchant transparency. We tell merchants what personal information we process and why, in this Policy and in our Data Processing Agreement.
  • Consent and opt-out. Where a customer consent decision or opt-out applies, we respect and apply it. We honour a customer's decision to opt out of having their information shared with us, and a merchant can instruct us to stop processing a given customer's information.
  • Data protection agreements. We enter into a written privacy and data protection agreement with every merchant.
  • Retention. We apply the retention periods in section 9 so that personal information is not kept for longer than it is needed.
  • Encryption. We encrypt personal information in transit and at rest, including backups.
  • Access control. Access to Protected Customer Data is limited to the staff who need it, protected by strong authentication, and logged.
  • Separation of environments. Test and production data are kept separate. We do not use real customer data in development or testing.
  • Data loss prevention. We operate data loss prevention controls across the systems that hold protected customer data.
  • Incident response. We maintain a documented security incident response policy, described in section 8.
  • Automated processing. Our Sales Assistant is described in section 6. It does not make decisions that produce legal consequences for a customer or that similarly significantly affect them, and a customer can ask to deal with a person at any point.

Further detail on Shopify's framework is available in Shopify's documentation on Protected Customer Data.

3.5 Data subject requests through Shopify
The app subscribes to Shopify's mandatory compliance webhooks, and we act on each of them within 30 days of receipt unless we are required by law to retain the information:

  • customers/data_request. When a customer asks a merchant for the information held about them, we compile the information the Nile platform holds about that customer and provide it to the merchant so that the merchant can respond.
  • customers/redact. When a merchant asks us to erase a customer's information, we delete or de-identify that customer's personal information in the Nile platform.
  • shop/redact. Shopify sends this 48 hours after the app is uninstalled. On receipt we erase or de-identify the store's data in the Nile platform.

3.6 Uninstallation
When a merchant uninstalls the Nile Commerce app, our access to their Shopify store is revoked immediately and no further data is synchronised.

Data already held is then handled as follows. On receipt of the shop/redact webhook, which Shopify sends 48 hours after uninstallation, we begin erasure and complete it within 30 days. Order and transaction records that we are required to retain under South African law, in particular section 24 of the Companies Act 71 of 2008, are retained for the period set out in section 9 and then securely deleted. Nothing retained for a legal purpose is used for any other purpose.

A merchant may ask us at any time to confirm in writing that erasure is complete, by writing to [email protected].

3.7 Sub-processors used by the app
The app relies on the following categories of sub-processor, each engaged under a written agreement that includes data protection terms: cloud hosting and database providers, the WhatsApp Business Platform operated by Meta, artificial intelligence providers used by the Sales Assistant, payment processors, and error monitoring and analytics providers.

We keep our sub-processors under review and may change or replace a provider within any of these categories as the service develops. Any replacement is held to data protection terms equivalent to those it replaces. A merchant may request the current list of named sub-processors at any time by writing to [email protected].

4. Lawful basis for processing

In accordance with section 11 of POPIA, we only process personal information where at least one of the following applies:

  • you have consented to the processing
  • processing is necessary to perform a contract to which you are a party, such as providing the Services to a brand or merchant, or enabling a brand to fulfil an order you placed with it
  • processing is necessary to comply with a legal obligation
  • processing protects a legitimate interest of yours, or
  • processing is necessary to pursue our legitimate interests, or those of a brand, merchant or third party, and does not unreasonably prejudice your rights

5. How we use your information

  • Provide and maintain the Services, including the Studio, the Sales Assistant technology and the Nile Commerce app for Shopify
  • Enable a brand or merchant to process orders and payments in its own WhatsApp channel, on that brand's or merchant's instructions
  • Synchronise orders, products and fulfilment status between Shopify and the Nile platform
  • Communicate with you about orders, updates and, where you have consented, promotions
  • Improve the Services and the Studio
  • Analyse usage patterns to improve our services
  • Comply with legal obligations and protect our rights

We do not use merchant or customer data obtained through the Nile Commerce app to train general purpose artificial intelligence models, to build profiles for our own commercial purposes, or for advertising.

Direct marketing. Where we send you electronic marketing, we do so in line with section 69 of POPIA. If you are not an existing customer, we will only market to you where you have consented. If you are an existing customer, we may market related products to you, and every message will give you a straightforward way to opt out at no cost. We will not approach you again for consent once you have refused. We do not market to a merchant's customers.

6. Automated processing and our Sales Assistant

Our Sales Assistant is an artificial intelligence system. It reads the messages you send, interprets what you are asking, and generates responses, product recommendations and order information automatically. This is automated processing of your personal information.

The Sales Assistant does not make decisions that produce legal consequences for you or that similarly significantly affect you. It helps you browse, answers questions and assembles an order. A person at the brand remains responsible for fulfilling that order, and you can ask to speak to a person at any point in the conversation. Your rights in relation to automated decision-making are set out in section 11.

7. Information sharing and disclosure

We do not sell or rent your personal information. We do not sell, rent or share merchant or customer data with third parties for marketing or advertising purposes. We may share information with:

  • The brand or merchant you bought from: the brand or merchant operating the channel receives the order and conversation details, because it is the seller and it fulfils the order
  • Service providers: WhatsApp and Meta, Shopify, payment processors, cloud hosting, artificial intelligence and analytics providers who process information on our behalf under written agreements, including their standard data processing terms
  • Legal requirements: where required by law, regulation or a competent authority, or to protect our rights and safety
  • Business transfers: in connection with a merger, acquisition or sale of assets. Where merchant or customer data is affected, we will notify the merchant.
  • Consent: where you have given explicit consent for a specific purpose

8. Data security

We implement appropriate technical and organisational security measures to protect personal information against unauthorised access, alteration, disclosure or destruction. These include:

  • Encryption of personal information in transit and at rest, including backups, using industry-standard protocols
  • Role-based access control, with access to personal information restricted to authorised personnel who need it for their work
  • Strong authentication requirements on staff accounts
  • Logging of access to protected customer data
  • Separation of test and production environments, with no real customer data used in development or testing
  • Data loss prevention controls
  • Staff confidentiality undertakings and privacy training
  • A documented security incident response policy, reviewed annually

No method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security.

Security compromises. If we have reasonable grounds to believe that your personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and you as soon as reasonably possible after discovering the compromise, in accordance with section 22 of POPIA. Where we act as an operator for a brand or merchant, we will notify that brand or merchant without undue delay, and in any event within 72 hours of becoming aware, so that they can meet their own notification obligations.

9. Data retention

We retain personal information only for as long as necessary to fulfil the purpose for which it was collected, to meet contractual or legal obligations, or to resolve disputes. Our standard retention periods are:

Shopper chat recordsRetention period24 months from the last messageReasonDispute resolution and product queries
Order and transaction recordsRetention period7 yearsReasonCompanies Act 71 of 2008, section 24
Shopify store and integration dataRetention periodErased on receipt of the shop/redact webhook, and in any event within 30 days of uninstallationReasonNo longer needed once the app is uninstalled
Studio account dataRetention periodTerm of the agreement plus 3 yearsReasonPrescription period for contractual claims
Marketing preferencesRetention periodUntil withdrawn, plus 3 yearsReasonTo evidence that consent was given and withdrawn
Website analyticsRetention period14 monthsReasonTrend analysis
Support correspondenceRetention period3 yearsReasonPrescription period
Unsuccessful job applicationsRetention period6 monthsReasonRecruitment records

These periods may be shortened on request where we are not required by law to retain the information. After the retention period, information is securely deleted or de-identified.

10. Cookies, tracking and cross-border processing

10.1 Cookies
We use cookies and similar technologies on onnile.shop. These fall into three categories:

Strictly necessaryPurposeSecurity, session management and core site functionalityCan you refuse?No, the site will not work without them
AnalyticsPurposeUnderstanding which pages are used and how the site performsCan you refuse?Yes
MarketingPurposeMeasuring the performance of campaigns that bring people to the siteCan you refuse?Yes

We rely on our legitimate interests under section 11(1)(f) of POPIA for analytics and marketing cookies. South African law does not currently require us to obtain your prior consent before setting them, and we do not currently use a cookie consent banner. You can control or block cookies through your browser settings, and you can opt out of our analytics at any time by contacting [email protected]. Blocking strictly necessary cookies will stop parts of the site working.

If we begin offering services to people in the United Kingdom or the European Union, we will introduce a consent banner and obtain prior consent for non-essential cookies, as those jurisdictions require.

The Nile Commerce app for Shopify does not set cookies or tracking pixels on a merchant's storefront.

10.2 Cross-border processing
Some of our service providers, including the WhatsApp Business Platform, Shopify, and our cloud hosting and artificial intelligence providers, process information outside South Africa. Where this occurs, we take reasonable steps in line with section 72 of POPIA to ensure the recipient is subject to a law, binding corporate rules or a binding agreement that provides an adequate level of protection substantially similar to POPIA, or that you have consented to the transfer.

Where personal information of people in the European Union or the United Kingdom is transferred, we rely on Standard Contractual Clauses or an equivalent transfer mechanism with the relevant provider.

The Services depend on third parties including the WhatsApp Business Platform operated by Meta, Shopify, social media platforms and payment processors. This Policy does not apply to those services, and we encourage you to review their own privacy notices.

11. Your rights

Subject to POPIA, you have the right to:

  • Access: request confirmation of, and access to, the personal information we hold about you
  • Correction: request correction or updating of inaccurate, incomplete or outdated information
  • Deletion: request that we delete or destroy personal information we are no longer authorised to retain
  • Export: request a copy of the personal information you have provided to us, in a commonly used electronic format. You can export or delete your data at any time.
  • Restriction: request that we restrict our processing of your personal information in certain circumstances
  • Objection: object, on reasonable grounds, to the processing of your personal information
  • Withdrawal: withdraw any consent you previously gave, at any time
  • Automated decision-making: not be subject to a decision based solely on automated processing that affects you significantly, without an opportunity to make representations
  • Complain: lodge a complaint with the Information Regulator, as set out in section 13

To exercise these rights, contact our Information Officer at [email protected]. We respond within the timeframes POPIA requires.

Where the information sits inside a brand's channel or a merchant's Shopify store and we act as operator, the brand or merchant is accountable, so we will direct your request to them and assist them in responding. If you are a customer of a Shopify merchant, the quickest route is to ask that merchant directly, and Shopify's own request mechanism will reach us through the webhooks described in section 3.5.

12. Children's personal information

In line with POPIA, a child is any person under the age of 18 who is not legally competent to act on their own behalf. We do not knowingly collect personal information from children without the consent of a parent or legal guardian, being a competent person, except where permitted by law. If you believe a child has provided us with personal information without appropriate consent, please contact us so that we can take steps to delete it.

13. Complaints to the Information Regulator

If you are unhappy with how we have handled your personal information, you may lodge a complaint with the Information Regulator (South Africa):

14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated effective date. Where a change materially affects how we process a merchant's customer data, we will notify affected merchants directly. Your continued use of our services after any update constitutes acceptance of the revised Policy.

15. Contact information

Privacy enquiries and Information Officer
General enquiries
Registered company
Nile Commerce (Pty) Ltd, registration number 2022/770381/07, Cape Town, South Africa

Read alongside our Terms and Conditions and our PAIA Manual.