Legal

Privacy Policy

How we collect, use, share and protect information when you use Cawoba — and, because Cawoba is a network, exactly what your connected partners can and cannot see.

Last updated: 1 July 2026Effective: 1 July 2026Applies to: cawoba.com, portal.cawoba.com, business.cawoba.com

1. Scope

This policy covers the Cawoba marketing site, the customer portal at portal.cawoba.com, and the business dashboard at business.cawoba.com (together, "the Platform"). It explains what we do with information about you and about the businesses you operate or transact with.

Cawoba is a two-sided network. That means some information is shared with other users by design — for example, a quotation you send is visible to the business you sent it to. Section 4 sets out exactly how that works.

Plain-language summary We collect the information needed to run your account and your trading relationships. We do not sell your data. Your prices and catalog are visible only to the partners you choose, and your outstanding balances are visible only to you and the supplier who issued the invoice.

2. Information we collect

2.1 Information you give us

  • Account details — name, email address, phone number, password (stored only as a salted hash), and your role within a business.
  • Business profile — legal and trading name, business category, addresses, GSTIN or other tax identifiers, logo, and public description.
  • Commercial records — catalog items, price lists, schemes, quotations and RFQs, credit limits, invoice references, and warranty registrations that you or your team enter.
  • Support correspondence — messages, attachments and any details you share when you contact us.

2.2 Information we collect automatically

  • Device and log data — IP address, browser and device type, operating system, referring pages, and timestamps of requests.
  • Usage data — pages and features used, actions taken on records (created, edited, accepted, rejected), and error diagnostics.
  • Cookies — strictly necessary cookies for session management and security, plus optional analytics cookies you can decline.

2.3 Information from connected systems

If you connect an accounting integration such as Zoho Books, we receive the records needed to power the credit dashboard — typically customer records, invoices, payment status and outstanding balances. We request read access scoped as narrowly as the provider allows, and we do not write back to your books unless you explicitly enable that.

3. How we use information

PurposeWhat this means in practice
Providing the PlatformAuthenticating you, rendering your dashboards, routing quotations between parties, and calculating credit and margin figures.
Network discoveryShowing your public business profile and public catalog items to other users searching by category or location.
CommunicationsSending transactional notifications (a quote was received, a connection request is pending, an invoice is overdue) and, if you opt in, product updates.
Security & abuse preventionDetecting suspicious sign-ins, rate-limiting, investigating fraud, and maintaining audit trails on commercial records.
Improving the productAggregated, de-identified analysis of which features are used and where users encounter errors.
Legal complianceMeeting tax, accounting and statutory record-keeping obligations, and responding to lawful requests.

We do not sell personal information, and we do not use your commercial records — your prices, margins, customer lists or balances — to train models for other customers or to build competing products.

4. Visibility on the network

Because Cawoba is a network, it is important to be precise about who sees what:

  • Public — your business name, category, city, logo, description and any catalog items you mark public. This is what makes you discoverable.
  • Connected partners only — price lists and schemes you publish to a specific retailer, quotations exchanged with that party, and warranty records for products they bought.
  • Bilateral only — credit limits and outstanding balances. A customer sees their balance with each supplier; a supplier sees balances owed to them. No supplier can see what a customer owes anyone else, and no customer can see another customer's terms.
  • Your organisation only — internal cost prices, margin configuration, draft records, team member details and integration credentials.

Where a customer's dashboard aggregates balances "across all connected traders", that aggregate is computed for and shown only to that customer.

5. Sharing & disclosure

We share information only in these circumstances:

  • With other users, as described in Section 4 and as directed by your own actions on the Platform.
  • With service providers who process data on our behalf under contract — cloud hosting, email delivery, error monitoring and payment processing. They may use the data only to provide their service to us.
  • For legal reasons, where disclosure is required by law, court order or a valid request from a competent authority, or where necessary to protect rights, safety or the integrity of the Platform.
  • In a corporate transaction, such as a merger, acquisition or asset sale — in which case we will give notice before your information becomes subject to a different policy.

6. Third-party integrations

Integrations are optional and you control them. When you authorise a connection, you grant Cawoba access to specific data in that system, and you can revoke access at any time from your integration settings or from the provider's own console. Revoking access stops future syncing; records already synced remain in your Cawoba account until you delete them.

Data you send to a third party through an integration is then also governed by that provider's own privacy policy.

7. Retention

We keep information for as long as your account is active. After closure, we delete or de-identify personal information within 90 days, except where we must retain records longer to comply with tax, accounting or statutory obligations, or to resolve a dispute. Because commercial records such as quotations and invoices are shared between two parties, closing your account does not remove the counterparty's copy of transactions they were part of.

8. Security

We use industry-standard safeguards including encryption in transit (TLS), encryption at rest for stored data, hashed credentials, role-based access control within business accounts, least-privilege internal access, audit logging on commercial records, and regular dependency and configuration review.

No system is perfectly secure. Please use a strong, unique password, keep your team's roles current, and notify us immediately at security@cawoba.com if you suspect unauthorised access.

9. Your rights

Subject to applicable law, you can:

  • Access the personal information we hold about you.
  • Correct inaccurate details — most of which you can edit directly in your profile.
  • Export your catalog, quotations and credit records in a machine-readable format.
  • Delete your account, subject to the retention exceptions in Section 7.
  • Object or restrict certain processing, and withdraw consent for optional analytics or marketing at any time.

To exercise any of these, email privacy@cawoba.com. We respond within 30 days and may need to verify your identity first.

10. Children

Cawoba is a business platform and is not directed at anyone under 18. We do not knowingly collect information from children. If you believe a minor has created an account, contact us and we will remove it.

11. Changes to this policy

We may update this policy as the Platform evolves. If a change materially affects how we handle your information, we will notify you by email or an in-app notice at least 14 days before it takes effect. The "Last updated" date at the top always reflects the current version.

12. Contact us

Questions, requests or complaints about privacy:

If you are not satisfied with our response, you may have the right to lodge a complaint with your local data protection authority.