Skip to content
Qrenox
  • Product
  • How it works
  • Integrations
  • Pricing
  • Resources
  • Log in
العربية·Français·English
Start free

Privacy Policy

Last updated: September 14, 2026Effective date: September 14, 2026

1. Scope

This policy explains how Qrenox processes personal data when its platform is used to confirm cash-on-delivery orders and organize store operations. The service is currently intended for merchants in Morocco and does not currently target merchants or customers in the European Union.

2. Who we are

Qrenox is provided by StellarFlow LLC, a limited liability company registered in Wyoming, United States.

Address: 30 N Gould St Ste R, Sheridan, WY 82801, USA
Email: contact@qrenox.com

3. Our role and the merchant’s role

3.1 Merchant data

For account, subscription, billing and usage data, Qrenox determines the purposes and means of processing within the limits of applicable law.

3.2 Merchant-customer data

For data sent from the merchant’s store or connected channels, the merchant determines the purpose of the relationship with its customers and Qrenox acts on the merchant’s behalf and under documented instructions. The merchant remains responsible for lawful collection and the notices or permissions required to contact its customers.

4. Data we process

CategoryExamples
AccountName, store, phone, email, access and roles.
SubscriptionPlan, limits, renewal dates, payments and invoices.
OrdersProducts, quantities, amount, address, city, status and delivery details.
CommunicationsPhone number, message content, timestamps and delivery status.
TechnicalServer access logs (IP address, browser, time and path), and session identifiers with their expiry. IP address and browser are not stored in the application database.
DerivedStatus, performance indicators and operational classifications useful to the merchant.

We do not intentionally request card payment data and do not seek to collect special categories of personal data. The merchant should provide only data necessary for the service.

5. Sources

  • The merchant and its team.
  • The connected store platform, such as WooCommerce, Shopify or YouCan.
  • Messaging and delivery services connected to an order.
  • Direct interactions with Qrenox, including support and rights requests.

6. Purposes

  • Operate the account and platform.
  • Confirm orders and organize communications and delivery.
  • Provide support, notifications, billing and subscription management.
  • Protect the platform from abuse, fraud and unwanted messages.
  • Measure performance and improve service quality.
  • Comply with legal obligations and official requests.

7. Service providers

Qrenox uses specialized providers for hosting, infrastructure, messaging, delivery and, where needed, language-model services. They are selected against appropriate operational and security requirements and are bound by their agreements and applicable data-protection obligations.

We share only what is necessary, do not sell personal data and do not use it for targeted advertising. Providers may change as the service develops, with appropriate protections and contractual obligations maintained.

8. Processing outside Morocco

Some data may be processed outside Morocco because of infrastructure or provider locations. Qrenox applies appropriate contractual, organizational and technical safeguards under applicable law and limits processing to the purposes described here.

9. Retention

Data is kept for as long as the account exists. There is no automatic deletion after an account is closed: the data stays until deletion is requested, and we act on that request. We would rather say this than publish a deadline that no code enforces.

Encrypted backups on the server are kept 14 days, and older ones are removed each night. Where an offsite copy is configured, it is not pruned automatically today. Server access logs rotate by size — five files of 10 MiB — rather than on a calendar.

Separately from all of this, a merchant can erase one customer's personal data at any time from the dashboard, and it takes effect immediately. See section 10.

10. Rights

The merchant may request access, correction, deletion, export or restriction of its data under applicable law. For customer data, requests should first be directed to the merchant, and Qrenox provides the technical means rather than only assistance: from the dashboard a merchant can erase a customer's personal data, and export everything held about one customer as JSON, without going through us. Each erasure is recorded, so the merchant keeps its own evidence that the request was met. Contact us at contact@qrenox.com.

11. Security

Passwords are stored as PBKDF2-HMAC-SHA256 and cannot be recovered from the database. Store and messaging credentials are encrypted. A session token is kept only as a hash. Every database query uses bound parameters, every inbound Meta webhook is signature-checked, and every route verifies record ownership before returning anything. Traffic is HTTPS with a one-year HSTS policy, and backups are encrypted to a public key whose private half is never on the server.

What we do not claim. Customer details — name, phone, address and message text — are stored in the database without field-level encryption; what is encrypted is connection credentials and backups. There is no general-purpose audit log; what is recorded is erasures, message history and order events.

Support access. A Qrenox operator can enter a merchant account in order to help. That is recorded on the session itself rather than hidden inside a token, such a session can be opened read-only, and revoking it takes effect on the next request. The security page sets out each measure against the code that implements it.

12. Artificial intelligence

To read a customer's replies and draft an answer, Qrenox sends the conversation to a language-model provider located outside Morocco. What is sent is the customer's name, where the merchant's store supplied one, and the text of the conversation — which is whatever the customer wrote themselves, including an address when they give one. The store name, its products and its delivery terms are sent as context. The customer's phone number is not sent as a field, though a customer can of course type one into a message.

This data is not used to build an advertising profile and is not sold. We do not operate any process that reuses merchant or customer data to train or improve models. A merchant who turns the assistant off stops these transfers for their account.

13. Cookies

The platform uses technologies necessary for sessions, language, account security and essential performance measurement. It does not use advertising-tracking cookies outside the service context.

14. Changes and contact

We may update this policy as the service or legal requirements change. Material changes are communicated through an appropriate channel. Contact: contact@qrenox.com — StellarFlow LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA.

Qrenox

QRENOX brings your store, confirmation, shipping, delivery outcome and profit visibility into one workflow for COD merchants.

Start free↗

Product

  • Product
  • Integrations
  • Pricing

Help

  • Security
  • Contact
  • Log in

Legal

  • Privacy
  • Terms
  • DPA
  • Refund

Languages

  • العربية
  • Français
  • English

StellarFlow LLC · 30 N Gould St Ste R, Sheridan, WY 82801, USA · © 2026 QRENOX