Privacy Policy
Last updated: August 15, 20261. Overview & Service Operator
Pangora is a WhatsApp-based ordering, product catalog synchronization, and merchant workspace platform designed for restaurants, cafes, and local businesses.
The Pangora platform (“Pangora,” “we,” “us,” “our”) is operated by Anıl Can Dündar(“Operator”) under the jurisdiction of Türkiye.
- Operator & Data Controller (for Platform Accounts): Anıl Can Dündar
- Support & Privacy Inquiries: support@pangora.app
- Operating Jurisdiction: Türkiye / KVKK & International Privacy Standards
2. Roles & Processing Contexts
To ensure full transparency, our processing activities are divided into two distinct operational contexts:
A. Merchant Account & Platform Operations (Pangora as Data Controller)
Pangora determines the purposes and means of processing for merchant account registration, phone-based OTP authentication, login session maintenance, workspace administrative settings, platform security diagnostics, and direct merchant support interactions.
B. Merchant Customer Order Processing (Pangora on Behalf of Merchant)
In the ordinary merchant ordering workflow, the respective Merchant determines the commercial and transactional purposes of customer orders (menus, prices, delivery zones, and customer relations). The Merchant is primarily responsible for its relationship with customers and the lawful collection of customer data. Pangora processes end-customer order details, communication metadata, and delivery information on behalf of the Merchant strictly to provide the ordering, catalog, and messaging workflow.
3. Information We Process
Depending on how Pangora is used, the following categories of information are processed:
A. Account & Platform Data (Processed by Pangora)
- Merchant Account Data: Phone number (E.164), name, and authentication session tokens for verification and access control.
- Business & Branch Configuration: Business name, branch addresses, operating hours, delivery zones, and fulfillment options.
- WhatsApp Integration Metadata: Meta WABA ID, Phone Number ID, display names, and encrypted API credentials required to facilitate WhatsApp connectivity.
- Technical & Diagnostic Data: IP address, request correlation IDs, server logs, and error diagnostics for security and abuse prevention.
B. Customer & Order Data (Processed on Behalf of Merchants)
- Customer Identity: Customer display name and phone number transmitted via WhatsApp.
- Order & Delivery Details: Ordered items, quantities, delivery address, order notes, fulfillment status, and payment method preference.
- Catalog Data: Product titles, descriptions, categories, prices, and availability flags.
Pangora never sells personal information or customer data to third parties for advertising or profiling.
4. Purposes of Processing
We process collected data for the following legitimate purposes:
- To operate and maintain the Pangora merchant mobile app and backend API.
- To authenticate users and enforce rate-limiting, session isolation, and account security.
- To route and process inbound and outbound WhatsApp customer orders on behalf of merchants.
- To synchronize product catalog structures with Meta Commerce and WhatsApp Business platforms.
- To provide customer support and respond to technical or operational inquiries.
- To comply with applicable legal, accounting, tax, and regulatory requirements.
5. Third-Party Service & Infrastructure Providers
To deliver and maintain the platform, we utilize established cloud infrastructure and communications providers:
- Meta Platforms, Inc. (WhatsApp Cloud API): Message transmission, interactive components, and in-chat catalog presentation for WhatsApp ordering.
- Vercel, Inc.: Web application hosting, edge routing, and serverless compute infrastructure.
- Neon, Inc.: Managed PostgreSQL cloud database infrastructure with encryption at rest.
- Ably Realtime: Real-time event streaming for instant order push notifications to merchant devices.
These providers process data strictly to facilitate technical operations, compute execution, storage, and messaging delivery in accordance with their respective service agreements.
6. Data Retention & Deletion
We retain personal information only for as long as necessary to provide the service, fulfill merchant agreements, and satisfy legal or accounting obligations.
When a merchant closes an account or requests data deletion, active authentication sessions and integration credentials are deleted immediately. Historical order and transaction records may be securely archived or anonymized where required to comply with statutory commercial retention requirements.
7. Your Rights & How to Reach Us
Depending on your role and relationship with Pangora, you have the following rights:
- Merchants & Account Users: You can manage or delete your account directly inside the Pangora mobile app via Settings > Delete My Account and Business (Ayarlar > Hesabımı ve İşletmemi Sil), or review our Data Deletion Instructions.
- End Customers: For inquiries or deletion requests regarding specific orders, receipts, or personal data held by a restaurant/merchant, please reach out directly to the respective Merchant. You may also contact us at support@pangora.app if you need assistance identifying the relevant merchant record.
- General Support: For any privacy questions or data requests, contact us at support@pangora.app. Verified requests are handled within 30 days.
8. Contact Information
For any inquiries regarding this Privacy Policy or platform data practices, please contact:
Email: support@pangora.app