Wafiscore
Sign up

Privacy policy

Last updated: 8 August 2026

This policy explains how Aegis Technologies ("we"), publisher of the Wafiscore service, processes the personal data of users of its website and application, in compliance with Algerian law no. 18-07 of 10 June 2018 on the protection of natural persons in the processing of personal data.

1. Data controller

The Wafiscore service is published by Aegis Technologies, a company incorporated under Algerian law and established in Algeria, acting as the controller of the data collected through the website and the application.

For any question about your data — or to obtain the company's full legal details — write to us at privacy@wafiscore.com.

2. Data we process

a. Account data (merchant account holder)

Email address, first and last name, the holder's phone number, postal address, shop name and language preference. This information is used to create and manage your account and our commercial relationship with you.

b. Sign-in via a third-party provider (SSO)

If you sign in via Google, Facebook or TikTok, we receive an account identifier and a verified email address. No provider access token is stored; linking to an existing account only happens if the provider asserts that the email is verified.

c. Verification data (your customers' numbers)

When you check a number or record a delivery outcome, the phone number is pseudonymized by cryptographic fingerprint (HMAC) at entry. The number in clear is never stored or logged. We keep only this fingerprint, the delivery outcomes (delivered, refused, unreachable) and any order metadata (wilaya, amount, delivery type).

d. Technical data

Technical and security logs, IP address, timestamps and request identifiers, for operation, security and abuse prevention.

3. Purposes and legal bases

  • Providing the service (scoring, private book, WhatsApp bot, API) — performance of the contract between us.
  • Delivery fraud prevention and pooling of pseudonymized network signals — merchants' legitimate interest in reducing returned parcels.
  • Security of the service and abuse prevention (rate limiting, scraping detection) — legitimate interest.
  • Social sign-in — based on your request to sign in via the chosen provider.
  • Service communications (transactional emails, notifications) — performance of the contract and legitimate interest.

4. Cookies and local storage

Wafiscore uses only strictly necessary cookies and operational data. No advertising cookies, no third-party trackers, no marketing profiling, no data resale.

  • sessionid — authentication session cookie (HttpOnly, SameSite=Strict). Essential to stay signed in.
  • csrftoken — anti-CSRF security cookie. Essential.
  • OAuth state cookie — temporary cookie created during social sign-in to guard against CSRF attacks, then deleted.
  • Browser local storage — remembers your language preference and the state of the onboarding guide. This data never leaves your device.

As these cookies are strictly necessary for the service to work, they do not require prior consent; this page informs you of them.

5. Recipients and sub-processors

We do not sell or rent your data. We use technical providers acting on our behalf and bound by confidentiality:

  • Hosting: OVHcloud.
  • WhatsApp messaging: Meta WhatsApp Business Cloud API or Twilio, depending on configuration, to route the bot's messages.
  • Social sign-in: Google, Facebook (Meta) and TikTok, if you use this option.
  • Transactional email: a technical email-delivery provider.
  • Error monitoring: Sentry, configured to transmit no personal data.

6. Retention periods

  • Network data and verification events: kept for 365 days, then automatically purged.
  • Account data: for the lifetime of the account, then deleted or anonymized on closure, subject to applicable legal periods.
  • Technical and security logs: 12 months.

7. Transfers outside Algeria

Some sub-processors (hosting, messaging, SSO) may process data outside Algerian territory. Where applicable, such transfers are governed by appropriate safeguards and carried out in accordance with law 18-07.

8. Your rights

In accordance with law 18-07, you have the right to access, rectification, erasure, objection, restriction and portability of your data. Anyone whose number has been checked can also review and dispute the data concerning them, via a confirmation code, through the service's verification page.

To exercise these rights, write to us at privacy@wafiscore.com. You may also lodge a complaint with the National Authority for the Protection of Personal Data (ANPDP).

9. Security

Phone numbers are pseudonymized by HMAC at the first entry point, with a secret key ("pepper") stored outside the database. Exchanges are encrypted in transit (TLS), session cookies are HttpOnly, and data access is role-controlled. As no measure is infallible, we cannot however guarantee absolute security.

10. Minors

Wafiscore is a service intended for professionals and is not designed for minors.

11. Changes

We may update this policy. Any substantial change will be indicated on this page, whose last-updated date will be refreshed.

12. Contact

Aegis Technologies — privacy@wafiscore.com.