How MoonStorm handles the customer data you entrust to us.
Version 2026-09-26. This agreement is accepted at registration and forms part of the MoonStorm Terms of Service. Where this agreement and the Terms disagree on the handling of personal data, this agreement prevails.
Your customer list is yours. In the language of the GDPR you are the controller of it, and MoonStorm is your processor: we handle that data on your instructions and for no purpose of our own. Under South Africa's POPIA the same split applies under different names, where you are the responsible party and MoonStorm is your operator.
In practice this means we never market to your customers, never sell or share your list, and never use it to build a product of our own. If you leave, it leaves with you.
Subject matter: providing the MoonStorm service, which is capturing customers who opt in to your list, taking their orders, and sending the messages you choose to send.
Duration: for as long as your account is active, and afterwards only for the retention periods set out in section 7.
Categories of data: a customer's WhatsApp phone number, the name they give you, an email address where you ask for one, the answers they give to your order questions, the content of messages between you and them, their consent record, and delivery and read receipts.
Categories of people: your customers and prospective customers who have opted in, and the people in your business who use MoonStorm.
We do not ask for and do not want special category data as defined in Article 9. Please do not configure order questions that collect health, biometric, religious, political or similar data.
We process personal data only on your documented instructions, which in normal operation means the actions you take in MoonStorm. We will tell you if we believe an instruction breaks data protection law rather than simply carrying it out.
Everyone at MoonStorm with access to your data is bound by confidentiality. Access is limited to those who need it to run and support the service.
We will help you meet your own obligations: responding to a customer who asks what you hold on them, or asks you to delete it; carrying out an impact assessment; and dealing with a regulator.
Data is encrypted in transit. Access to production systems requires authentication and is logged. Merchant and customer data is separated by business, so one merchant cannot reach another's list. Phone numbers used for consent evidence are stored as anonymised hashes rather than in the clear where the full value is not needed.
If personal data is breached we will notify you without undue delay once we become aware, with what we know about what happened, who is affected and what we are doing, so you can meet your own 72-hour obligation to your regulator.
Running MoonStorm requires other companies, and you agree to our using them as sub-processors. Each is bound by terms no weaker than these.
Meta Platforms Ireland Limited delivers your messages over the WhatsApp Business Platform. Twilio provides and maintains your business phone number. Bunq handles your payments to us, and sees your payment details rather than your customers' data. Our hosting provider runs the servers and the database.
We will give you reasonable notice before adding or replacing a sub-processor, and you may object on reasonable data protection grounds.
Data is held in the European Union. Where a sub-processor transfers data outside the EU, that transfer relies on an adequacy decision or on the European Commission's Standard Contractual Clauses. For merchants in South Africa, transfers rely on POPIA section 72.
A customer who opts out is retained as a suppression record, because forgetting them entirely would mean messaging them again by accident. That record holds only what is needed to keep them off your list.
When your account closes you may export your list and your orders. After that we delete or anonymise the personal data we hold for you, except where the law requires us to keep something, such as the financial records behind an invoice.
You can ask us to delete a specific customer's history at any time.
On reasonable notice we will give you the information you need to show your own compliance, and submit to an audit where you are required to carry one out.
You confirm that you have a lawful basis for the customers you add, that every customer on your list opted in knowingly, and that you will not upload a list gathered somewhere else without their consent. MoonStorm's double opt-in exists to help you demonstrate this, and it only works if you use it as intended.
We will tell you before this agreement changes materially and ask you to accept the new version. The version you accepted, and when, is recorded against your account.
For anything in this agreement, write to chris@moonstorm.nl. MoonStorm Marketing, Amsterdam, Netherlands. KvK 42005987. BTW NL005428643B22.