Stravax Engage is operated by Stravax Group LLC, a limited liability company licensed by Sharjah Media City Free Zone Authority (Shams), Government of Sharjah, United Arab Emirates (Licence No. 2537844.01). Registered address: Sharjah Media City (Shams), Al Messaned, Al Bataeh, Sharjah, United Arab Emirates.
Stravax Engage is a WhatsApp engagement platform. Our Shopify app sends WhatsApp abandoned-cart and order-recovery messages to a merchant's customers, on the merchant's behalf and on the merchant's instructions.
We act in two roles:
Stravax Engage is used through a web app and an Android and iOS mobile app, and it connects to WhatsApp, Messenger and Instagram as well as to Shopify. This policy covers the whole platform:
Throughout this policy, "workspace" means the business account a team member signs in to, and "workspace administrator" means the person at that business who provisions and removes team members.
When a merchant installs the Stravax Engage Shopify app and enables cart recovery, Shopify sends us abandoned-checkout and order webhooks. From those we store, per abandoned checkout, only:
We do not store the customer's email address, billing address, shipping address, payment details, or order line-item contents. Those fields are not persisted by the app.
The customer name and phone number are the only Shopify Protected Customer Data fields the app requests or retains.
The people who use the apps are team members of a business that has a Stravax Engage workspace. There is no sign-up inside the apps: an account only exists because a workspace administrator created it.
The apps display the conversations, contacts, leads and campaigns belonging to the workspace. That content includes messages and media exchanged with the business's own customers. The business is the controller of that content; we hold and display it on their instruction. A team member sees it because their administrator granted them access to that workspace.
Each item below is handled only when the team member actively chooses to send it, and each is requested at first use behind an in-app explanation. Declining any of them leaves the rest of the app working.
| What | When it is used | What reaches our servers |
|---|---|---|
| Photos and videos | Taking a photo or picking one to send | The image or video, as a message |
| Voice notes | Recording a voice message in a conversation | The audio recording, as a message |
| Documents | Picking a file to send | The file, as a message |
| Location | Choosing "Send location" | The device's current coordinates at that moment |
| A contact card | Choosing to share a contact | The name and phone numbers of the one contact selected |
Two limits are worth stating plainly, because they are enforced in the app rather than merely promised. We never upload the address book: only the single contact the team member picks is read. And location is foreground only, captured at the moment of sending. The apps cannot access location in the background, and no background-location permission is requested.
Account data is processed to operate the service: to authenticate the team member, to keep the account secure, to deliver notifications, and to bill the business. Workspace content is processed only to provide the messaging, CRM and campaign features the business uses the product for, on that business's instruction.
The sole purpose of the Shopify data is to send the merchant's customer a WhatsApp cart-recovery or order-recovery message, and to record whether that message led to a completed order (so the merchant can see recovery performance).
We process this data only on the merchant's instruction. The merchant is responsible for having a lawful basis and the customer consent required to message their customers on WhatsApp. Our app respects the marketing-consent flag on the Shopify checkout: a marketing-category recovery message is only sent to a customer whose checkout indicated marketing opt-in.
We do not use this data to build our own marketing lists, profile customers across merchants, or for any purpose other than delivering the merchant's recovery messaging.
We do not sell customer personal data. We do not share it with third parties for their own purposes, for advertising, or for any purpose beyond operating the recovery service for the merchant. The only third parties that ever receive this data are the infrastructure sub-processors listed in section 7, and only to the extent needed to deliver the message.
We use the following sub-processors. For the Shopify customer name and phone number specifically, only the rows marked (receives Shopify name + phone) are in that data path.
| Sub-processor | Purpose | In the Shopify name+phone path? |
|---|---|---|
| Cloudflare | Hosting, database (D1), object storage (R2), queues, security | Yes (storage) |
| Meta / WhatsApp (WhatsApp Business Platform) | Delivers the recovery message; the customer name is a message template parameter and the phone number is the recipient | Yes (delivery) |
| Shopify | Source of the checkout and order webhooks | Source, not a recipient |
| Stripe | Merchant billing and self-serve wallet top-up | No |
| Google Ads / Meta Ads | Conversion-event receipt for merchants who enable Ad Sync | No |
| Anthropic | Optional AI conversation qualifier (processes WhatsApp conversation message text only, for merchants who enable it) | No |
| Zoho | Two separate uses: (1) the optional Zoho CRM connector, for merchants who connect it, pushes each lead as a Contact/Deal (name, email, phone, company, deal stage and amount) to the merchant's own Zoho CRM account, hosted in whichever Zoho data center that account lives in (US/EU/IN/AU/JP, tenant-controlled); (2) Zoho Mail provides email hosting for Stravax operational mailboxes (@engage.stravax.ai: support, privacy, billing, hello, no-reply), processing email content and sender metadata for support and transactional communications, global region | Yes (CRM connector only, when a merchant connects it and the synced lead originated from a Shopify recovery message; mail is not in this path) |
Anthropic is listed for completeness because a merchant may separately enable an AI conversation feature that sends WhatsApp message content to Anthropic. That optional feature does not receive the Shopify-sourced customer name or phone fields.
Account data is kept for as long as the team member's account exists, and is deleted when the account is deleted (section 9). Workspace content is kept for as long as the workspace exists, because it belongs to the business rather than to any one team member.
Abandoned-checkout records (customer name, phone, and cart metadata) are retained for up to 90 days from the time the checkout was abandoned, and are then deleted. See the accompanying Data Retention Policy for the full rationale. Recovery loses value quickly after a cart is abandoned; we keep records only long enough for the recovery to fire, for a late order to be attributed, and for the merchant to see recent recovery performance.
Records are also deleted earlier when a merchant uninstalls the app or when a deletion request is received (section 9).
Because we process customer personal data as a processor on the merchant's behalf, a customer exercises their rights through the merchant (the controller). We honour the merchant's instructions and Shopify's mandatory privacy webhooks automatically:
customers/redact): on receiving this webhook from
Shopify, we delete that customer's abandoned-checkout records for that store, matched by phone
number.shop/redact): on receiving this webhook (which Shopify sends
after a merchant uninstalls the app), we delete all abandoned-checkout records we hold for that
store.customers/data_request): we log the request to our administrative
audit trail and fulfil it manually, since the only data we hold for a customer is their
abandoned-checkout contact data (name, phone, cart URL) for that store.A customer or merchant may also contact us directly using the details in section 11.
If you use the Stravax Engage web or mobile app and want your personal data deleted, you have two routes. Either works, and neither requires the other.
What we delete. Your name and email address, your password hash, your two-factor secret, your trusted-device records, your push notification tokens, and your personal settings. Deletion is permanent and cannot be undone.
What is kept, and why. Two things do not go away when your personal account does, and it is better to be direct about them.
How long it takes. We action verified deletion requests within 30 days, and usually much sooner.
Deleting an entire workspace. A business that wants everything removed can ask us at privacy@engage.stravax.ai. We then delete the workspace's accounts, conversations, media, contacts, leads and campaigns, subject only to the retained records described above.
Data may be processed outside the UAE through our global infrastructure providers (principally Cloudflare and Meta/WhatsApp). Transfers rely on those providers' own safeguards.
Stravax Group LLC, Sharjah, UAE.
Privacy and data requests: privacy@engage.stravax.ai
Stravax Engage is a business tool and is not directed to children. We do not knowingly process data relating to anyone under 18.
We update this policy as the service evolves. Material changes will be posted here before they take effect.
© 2026 Stravax Group LLC. All rights reserved.