Privacy Policy
Last updated: May 20, 2026
CuraLog ("we", "our", or "us") is a business operations platform that helps organizations manage their inventory, customers, and communications. This Privacy Policy explains how we collect, use, and protect information when you interact with us — including through WhatsApp Business messaging.
1. Information We Collect
We collect information that is necessary to provide our services:
- Contact information — name, email address, phone number (including WhatsApp number), company name, and billing address provided by you or your organization.
- WhatsApp messages — messages sent to or received from our WhatsApp Business number, including message content, timestamps, and delivery status. This is used solely to facilitate business communication.
- Business data — product information, order details, catalog preferences, and other data you enter into the platform.
- Usage data — log data, device information, and interaction data collected automatically when you use our web application.
- Behavioural analytics — first-party analytics covering page visits, scroll depth, time on page, search queries, product impressions and clicks, hover patterns (aggregated 10×10 viewport grid), click positions, form-field interactions (no field values), and signals such as rage clicks or dead clicks. No third-party analytics or advertising services are used.
- Attribution — UTM parameters and referrer headers if you arrive via a marketing link.
- Session identifier — a random, per-tab session ID stored in
sessionStoragethat lets us group activity within a single browsing session. It is not linked to your real-world identity for visitors who are not signed in.
2. How We Use Your Information
We use the information we collect to:
- Deliver and operate the CuraLog platform and its features.
- Send you catalogs, order updates, and business communications via WhatsApp when you have provided consent.
- Respond to your messages and support requests.
- Generate PDF catalogs and price sheets for your business needs.
- Authenticate users and maintain account security.
- Improve and develop our services — understand which features are used, diagnose friction (e.g. broken UI elements detected via rage/dead clicks), and prioritise improvements.
- Provide each organization with insights into how its own customers use the platform (browsed products, searches, engagement). Each organization can only see data scoped to its own customers; cross-organization aggregates are limited to CuraLog system administrators.
2a. Consent for Analytics (EU / EEA Visitors)
If our browser detects that you are visiting from a timezone within the European Union or EEA, we will not record behavioural analytics until you have explicitly accepted via the consent banner shown on your first visit. You can change your preference at any time using the privacy settings button (🍪) at the bottom-left of any page.
Visitors outside the EU/EEA are tracked by default for first-party analytics, but may opt out at any time using the same privacy-settings button. Essential storage required for the site to function (authentication tokens, theme preference) is always active.
3. WhatsApp Business Messaging
We use the WhatsApp Business Platform (provided by Meta Platforms, Inc.) to send and receive business messages. By providing your WhatsApp number and giving consent, you agree that:
- We may send you approved WhatsApp message templates, including catalogs, OTP verification codes, and business notifications.
- Message content and metadata may be processed by Meta in accordance with their WhatsApp Privacy Policy.
- You can opt out of WhatsApp communications at any time by contacting us or replying STOP.
- We do not sell your WhatsApp contact information to third parties.
4. Data Sharing
We do not sell your personal data. We may share information with:
- Meta Platforms — for WhatsApp Business API message delivery.
- Cloud infrastructure providers — for hosting and storage (data remains encrypted at rest).
- Your organization's administrators — authorized users within your organization may access business data you create on the platform.
- Legal authorities — if required by law or to protect our rights.
5. Data Retention
We retain your personal data for as long as your organization's account is active or as needed to provide services. WhatsApp message history is stored to maintain conversation context and may be deleted upon request. You may request deletion of your data by contacting us at the address below.
Behavioural analytics events are retained on the following schedule:
- High-volume signals (hover patterns, click positions, product impressions, dwell time) — retained for 14 days, then automatically deleted by a nightly cleanup job.
- All other events (page views, searches, product views/clicks, form interactions, attribution, etc.) — retained for 90 days, then automatically deleted.
Aggregated, non-identifying statistics (e.g. "total searches this month") may be retained beyond these windows for trend analysis.
6. Data Security
We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, access controls, and regular security reviews. WhatsApp API credentials and sensitive configuration are stored encrypted. No method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Request correction or deletion of your data.
- Withdraw consent for WhatsApp communications at any time.
- Lodge a complaint with your local data protection authority.
To exercise these rights, contact us using the details in Section 9.
8. Cookies and Local Storage
CuraLog does not set HTTP cookies. The platform uses your browser's localStorage and sessionStorage to maintain:
- Essential — authentication tokens, theme preference, view-mode and pagination preferences, sidebar state. These are required for the site to work and cannot be disabled.
- Analytics consent — a single value (
grantedordenied) that records your privacy-banner choice. - Analytics session ID — a random per-tab identifier used only when analytics consent is granted (EU) or has not been declined (non-EU).
- Attribution — UTM parameters from your entry URL, kept for the duration of your browsing session.
We do not use third-party advertising cookies or trackers. You can clear local storage through your browser settings; however, this will log you out and reset your preferences.
9. Contact Us
If you have questions about this Privacy Policy or your data, please contact us:
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date at the top of this page. Continued use of our services after changes constitutes your acceptance of the revised policy.