Privacy Policy

How we handle your data

CODBrain helps Moroccan e-commerce sellers run their business. We take the privacy of your data and your customers' data seriously — this page explains exactly what we collect, why, and what control you have.

Effective date: May 7, 2026Last updated: May 7, 2026

1. Who we are

CODBrain (operated under the brand CODBrain, accessible at codbrain.net) is a Software-as-a-Service customer relationship management platform built for cash-on-delivery e-commerce sellers in Morocco and the wider MENA region. We refer to ourselves below as “CODBrain”, “we”, “us”, or “our”.

For the purposes of data protection law, CODBrain acts as a data processor in respect of personal data uploaded by merchants about their end customers (orders, phone numbers, addresses), and as a data controller in respect of account information about merchants themselves (the people who sign up to use CODBrain).

2. What data we collect

2.1 Information about you (the merchant)

  • Account details — full name, email address, hashed password, preferred language, role within your team.
  • Company information — company name, address, phone, contact email, tax identifier (ICE / RC), website, logo and brand assets you upload.
  • Billing information — subscription plan, payment status, manual payment records (we currently use a manual ledger; we do not store card numbers).
  • Operational logs — login timestamps, device IP, user-agent, actions taken in the dashboard for audit and security purposes.

2.2 Information about your customers (uploaded by you)

  • Order data — order references, products, quantities, prices, totals, statuses, timestamps, notes.
  • Customer contact details — full name, phone number, email, delivery address, city.
  • Order channel and source — the platform the order came from (Shopify, YouCan, custom form, manual entry) and any campaign attribution data.
  • Risk signals — internally computed indicators used to flag potentially fraudulent or low-quality orders (e.g. duplicate phone numbers, prior cancellations).

2.3 Information from connected integrations

When you connect a third-party platform (Shopify, YouCan, Meta Ads, delivery carriers such as Sendit / OzonExpress / ForceLog / Cathedis / Amex / BMD / Digylog), we receive data from that platform via OAuth or API tokens you authorize. The scope and content of that data is determined by you when you authorize the integration. We never request access beyond what is needed to operate the integration (typically read access to orders, customers, products, and inventory; write access for delivery push and webhooks).

2.4 Cookies and similar technologies

We use a small number of strictly-necessary cookies to keep you signed in and to remember your interface preferences. We do not use third-party advertising cookies and we do not sell or share data with advertisers.

3. How we use your data

We use your data to:

  • Provide the CODBrain service to you and your team — confirm orders, prevent returns, manage delivery, generate analytics.
  • Send order- and operations-related notifications via email or webhook (we do not send marketing without separate consent).
  • Communicate with you about your account, security alerts, billing, and product changes.
  • Detect and prevent fraud, abuse, and policy violations.
  • Improve CODBrain — diagnose bugs, tune AI risk-scoring, and develop new features. We use only aggregated and de-identified data for model training.
  • Comply with applicable law and respond to lawful requests from authorities.

Legal basis (where GDPR applies):

  • Contract — most processing is necessary to perform our agreement with you.
  • Legitimate interest — fraud prevention, security, product improvement.
  • Consent — for any optional marketing or analytics where it applies.
  • Legal obligation — for tax, fraud, or law-enforcement requirements.

4. Sharing and sub-processors

We do not sell your personal data and we do not share it with third parties for their own marketing purposes. We share data only with vendors who help us run CODBrain, with services you explicitly connect, and where required by law.

4.1 Sub-processors

The following companies help us operate the service and may process personal data on our behalf:

  • DigitalOcean, LLC — application hosting, managed PostgreSQL database, file storage (Spaces). Servers are in the EU region.
  • Resend — transactional email delivery (account, password reset, alerts).
  • Hostinger — domain registration only; no application data is processed by Hostinger.
  • Anthropic / OpenAI — only when you explicitly use AI-assisted features. Inputs sent to model providers are limited to what each feature requires and are not used to train external models.

Each sub-processor is bound by a written data processing agreement and is required to implement appropriate security measures.

4.2 Integrations you connect

When you connect an external platform (Shopify, YouCan, Meta Ads, delivery carriers), we forward the minimum data required by that integration on your behalf — for example, customer name, phone, and address are sent to a delivery carrier when you push an order for fulfilment. You are responsible for ensuring that you have the legal basis to share customer data with the integrations you enable.

4.3 Legal disclosure

We may disclose data when required by Moroccan law, valid court orders, or to protect the rights, property, or safety of CODBrain, our users, or the public. We push back on overbroad requests.

5. Where data is stored

CODBrain primarily stores data on infrastructure operated by DigitalOcean in the European Union. Backups are encrypted at rest. When data is transferred outside Morocco or the EU (for example, to a US-based sub-processor like Resend or a model provider), the transfer relies on appropriate safeguards including the EU Standard Contractual Clauses and equivalent measures.

6. How long we keep data

  • Active accounts — we keep your data for as long as your account is open.
  • Closed accounts — data is retained for up to 90 days after closure to allow for accidental-closure recovery and legal record-keeping, then deleted or anonymized.
  • Audit logs — security-related logs are retained for up to 12 months.
  • Backups — encrypted backups roll out of retention within 30 days.
  • Tax records — invoices and billing records are retained for the period required by Moroccan tax law (currently 10 years) regardless of account closure.

7. How we secure data

  • All connections to and from CODBrain use HTTPS/TLS 1.2+.
  • API credentials and other secrets stored on your behalf (e.g. carrier API keys) are encrypted at rest using authenticated symmetric encryption.
  • Passwords are hashed with bcrypt; we never store plaintext passwords.
  • Access to production systems is restricted to a small number of authorized personnel and requires multi-factor authentication.
  • Every action taken by an administrator is logged for audit.
  • Sessions are protected with cryptographically signed cookies (iron-session) and expire on inactivity.

No system is perfectly secure. If we ever discover a breach affecting your data, we will notify you without undue delay and within the timeframes required by applicable law.

8. Your rights

Depending on where you live, you have rights over your personal data. CODBrain honors these rights regardless of jurisdiction:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data. Most fields are editable directly in the dashboard; for everything else, write to us.
  • Erasure — ask us to delete your data, subject to retention obligations (see Section 6).
  • Portability — receive your data in a machine-readable format.
  • Restriction and objection — limit how we process your data or object to specific processing.
  • Withdraw consent — at any time where processing is based on consent.
  • Lodge a complaint — with the Moroccan Commission Nationale de contrôle de la Protection des Données à Caractère Personnel (CNDP) or your local data protection authority.

To exercise any right, email us at [email protected]. We respond within 30 days.

Note for end customers: if you are a customer of one of our merchants (you ordered from a store that uses CODBrain) and you wish to exercise your rights, the merchant is the controller of your data — please contact them directly. We will assist them in fulfilling your request.

9. Children

CODBrain is a B2B product not directed to children. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with data, contact us and we will delete it.

10. Changes to this policy

We may update this Privacy Policy from time to time. When we make a material change we will notify you by email and post a prominent notice in the dashboard. The “Last updated” date at the top of this page always reflects the most recent revision. Continued use of CODBrain after a change means you accept the updated policy.

11. Contact us

For any privacy question, request, or complaint:

We will work with you in good faith to resolve any concerns. If you remain dissatisfied, you have the right to contact the Moroccan CNDP at cndp.ma.

Privacy Policy · CODBrain | CODBrain