Privacy Policy

ORXTERA PRIVACY POLICY — v2

Effective date: August 14, 2026. Last updated: September 10, 2026.

1. Who We Are

Orxtera is an AI-native commerce operating platform developed and operated by Shohnatex LLC, a technology company established in Egypt.

In this Privacy Policy, “Orxtera,” “Shohnatex,” “we,” “us,” and “our” refer to Shohnatex LLC in its capacity as the operator of Orxtera.

This Privacy Policy explains how information is collected, used, stored, disclosed, protected, and deleted when businesses and their authorized users use Orxtera, our website, Nader, connected integrations, storefront tools, commerce workflows, communication features, and related services.

Egypt has a Personal Data Protection Law, Law No. 151 of 2020, which forms part of the legal framework applicable to personal-data processing in Egypt.

2. Scope

This Policy applies to:

visitors to orxtera.com;

businesses creating or using an Orxtera organization;

owners, administrators and team members using Orxtera;

information processed through supported third-party integrations;

information relating to customers, contacts, suppliers or other persons that a business processes through Orxtera; and

information processed by AI-assisted functionality, including Nader.

Orxtera is primarily a business-to-business platform and is not intended as a consumer social network or general-purpose consumer data service.

3. Our Role and the Business’s Role

The role played by Shohnatex depends on the processing activity.

For personal data that a business submits to or processes through Orxtera about its customers, prospects, contacts or other persons, the business generally determines the business purpose of that processing. In those circumstances, Shohnatex generally processes that information to provide Orxtera to the business.

Shohnatex may independently determine the purposes and means of certain processing necessary to operate and protect Orxtera, including account administration, platform security, fraud and abuse prevention, billing, service reliability, legal compliance and protection of our rights. For those activities, our legal role may differ depending on applicable law.

Businesses using Orxtera remain responsible for ensuring that they are permitted to collect and process the information they provide to Orxtera and for providing any notices or obtaining any permissions required in their relationship with their customers.

4. Information We Process

Depending on how Orxtera is used, we may process:

Account and organization information

This may include:

business name;

business type and country;

account owner information;

team-member names;

email addresses;

telephone numbers;

roles and permissions;

authentication information;

account settings;

organization membership;

subscription and billing metadata.

Business and commerce data

This may include:

products;

catalogs;

prices;

inventory;

branches;

delivery and return rules;

business policies;

orders;

order status;

payment or COD status;

fulfillment information;

returns;

customer-service workflows;

business objectives and KPIs.

Customer and contact information

Where supplied or authorized by a business, this may include:

name;

telephone number;

email address;

delivery or service address;

order contents;

communication history;

order and delivery outcomes;

return reasons;

customer requests;

preferences or information communicated to the business.

Conversation data

Where a business connects a supported communications channel, Orxtera may process:

messages;

message content;

sender and recipient identifiers;

timestamps;

attachments where supported;

conversation metadata;

conversation status;

inferred intent or classification generated for the business.

Connected-platform data

Where a user expressly authorizes a supported integration, Orxtera may receive information permitted by that authorization.

The information available depends on:

the connected provider;

the permissions or scopes granted;

the account connected;

the functionality enabled by the business.

Website and technical data

We may process information such as:

IP address;

browser and device information;

authentication and security events;

error and diagnostic information;

application activity;

logs necessary for security and reliability;

information submitted through contact or early-access forms.

5. Why We Process Information

We process information where reasonably necessary to:

create and administer accounts;

provide Orxtera features;

authenticate users;

apply roles and permissions;

operate authorized integrations;

unify business communications;

assist with conversations and customer service;

manage commerce workflows;

create or manage storefront experiences;

process orders;

support order confirmation and fulfillment;

prepare reports and summaries;

calculate or display business metrics;

organize workflows around configured KPIs;

provide AI-assisted functionality through Nader;

maintain platform security;

prevent abuse and unauthorized access;

troubleshoot and improve service reliability;

provide customer support;

process subscription and billing activity;

comply with applicable legal obligations;

establish, exercise or defend legal rights.

We do not request access to third-party information merely because it may be useful at some future point. Permissions should be limited to those required for the user-facing functionality being provided.

6. Nader and AI-Assisted Processing

Orxtera includes AI-assisted systems, including Nader.

Depending on the business configuration, authorized data and user permissions, Nader may help:

understand and classify conversations;

draft responses;

summarize activity;

identify follow-ups;

detect operational signals;

prepare recommendations;

organize work around business objectives;

prepare storefront content;

analyse commerce performance;

propose actions;

execute configured actions where the business has expressly authorized that level of authority.

AI-generated results may be incomplete, incorrect or inappropriate for a particular situation. Businesses remain responsible for reviewing decisions where human judgment is required.

Enabling AI does not give Nader unrestricted authority over an organization.

AI training and merchant data

Shohnatex does not use a business’s private customer records, conversations, catalog, orders or merchant-specific business memory to train general-purpose or shared AI models for other businesses unless that business has separately and explicitly agreed to such use.

Where information comes from a third-party API, any stricter restrictions imposed by that provider also apply.

7. Merchant Isolation

Orxtera is designed as a multi-tenant platform.

Business-specific information is logically separated between organizations.

This includes, as applicable:

conversations;

customers;

catalog information;

orders;

operational data;

merchant-specific business memory.

Nader is designed to retrieve business context within the organization and authority scope in which it is operating.

We do not intentionally expose one business’s private information to another business.

8. Roles, Permissions and Internal Access

An Orxtera organization may assign users different roles, permissions and access scopes.

The organization is responsible for:

deciding who receives access;

assigning appropriate permissions;

removing access when no longer required;

protecting user credentials.

Orxtera may enforce permissions server-side for sensitive operations.

Authorized personnel working for Shohnatex may access information only where reasonably necessary for purposes such as:

customer support requested by the user;

platform security;

investigation of abuse;

troubleshooting;

legal compliance.

Where third-party platform policies impose stricter human-access restrictions, those restrictions apply.

9. Third-Party Integrations

Businesses may choose to connect supported third-party services, which may include communications, identity, commerce, payment, productivity, advertising or logistics services.

An integration is accessed only after the appropriate user or business authorization has been granted.

When an integration is connected:

Orxtera receives the information allowed by the authorization;

Orxtera uses it to provide the relevant connected feature;

authorization can expire or be revoked;

third-party terms and privacy policies continue to apply to information independently held by the provider.

Disconnecting an integration stops future authorized access once the revocation takes effect, but it does not automatically delete information already lawfully retained in Orxtera or information held independently by the external provider.

The availability of an integration does not imply partnership, endorsement, certification or official status with that provider.

10. Google API and Google Workspace Data

Where Orxtera accesses information through Google API Services, our use of that information will comply with the applicable Google API Services User Data Policy.

Where Google Workspace APIs are used, Orxtera’s use of information received from Google Workspace APIs will adhere to the applicable Google user-data requirements, including Limited Use requirements. Google currently restricts use of Workspace data to the appropriate user-facing use case and imposes strict restrictions on transfers, advertising use, human access and model training.

In particular, Google Workspace-derived user data will not be:

sold;

transferred to advertising platforms for targeting or retargeting;

used for personalized or interest-based advertising;

used to determine creditworthiness;

used to create, train or improve a general-purpose or shared AI model beyond uses permitted by Google’s applicable policy.

Google Workspace information is processed only as needed for the relevant Orxtera user-facing feature.

Users may revoke Orxtera's Google access through applicable Google account controls and, where supported, through available Orxtera controls.

11. Meta and Messaging/Social Platforms

Orxtera’s Meta integrations are in development. The following describes the permitted processing for those integrations where supported and expressly authorized by a client; it does not announce general availability or Meta approval.

Depending on the connected feature and permissions granted, Meta Platform Data may include business asset identifiers, Page and professional-account identifiers, WhatsApp business-account and channel identifiers, customer messages and supported interactions, sender and recipient identifiers, timestamps, conversation status and other message metadata, and attachments where supported.

This information is used to receive and display conversations, associate messages with the relevant business and customer context, enable the client’s authorized staff to assist with responses, and support related orders and follow-up. Where enabled and authorized, Nader may use that client context to classify or summarize messages, prepare responses and assist with replies within the permitted service.

Meta Platform Data is processed only on behalf of and at the direction of the relevant client for permitted service purposes, not for Shohnatex’s own unrelated purposes or another client’s purposes. Our client-separation requirement applies to Meta Platform Data and context derived from it; access is limited to the relevant client context and authorized service purposes.

Meta Platform Data is not sold. Service providers, including AI processing providers, may process it only as necessary for the relevant client’s permitted service and subject to applicable platform restrictions.

Client authorization does not override Meta Platform Terms, Developer Policies or applicable platform restrictions. General AI training, shared-model consent, advertising and campaign provisions in this Policy do not permit any use of Meta Platform Data prohibited by those restrictions, including use for another client’s purposes.

Meta-specific retention and deletion obligations take precedence over general retention language in this Policy. We handle requests from users, clients and Meta as described on our Data Deletion page; general operational reasons do not create an exception to those obligations.

The appearance of Meta, Facebook, WhatsApp, Instagram or Messenger does not represent a partnership, endorsement or certification.

12. Advertising and Campaign Workflows

Orxtera may allow a business to prepare, manage or analyse advertising or campaign workflows where supported.

We do not sell personal information to advertisers.

Where a business explicitly instructs Orxtera to send authorized information to an advertising or communications service in order to execute that business’s campaign, that processing is performed on behalf of the business and within the permitted integration.

Google Workspace user data is excluded from advertising and retargeting workflows where Google’s applicable policies prohibit such use.

We do not use merchant customer data for unrelated advertising on behalf of Shohnatex.

13. Service Providers and Subprocessors

We may use service providers to help operate Orxtera, including providers of:

cloud infrastructure;

databases and storage;

authentication;

communications delivery;

AI processing;

monitoring and security;

email delivery;

billing or payment infrastructure where enabled;

customer support;

development and operational infrastructure.

These providers may process information only to the extent necessary for the services they provide to us and subject to applicable contractual and legal requirements.

We may publish or maintain additional information about significant subprocessors as the product matures.

14. Legal Bases and Lawful Processing

The lawful basis for processing may depend on:

the nature of the information;

the relationship between the individual, business and Shohnatex;

the purpose of processing;

applicable law.

Depending on the situation, processing may be based on:

performance of a contract or steps necessary to provide the service;

user or business authorization;

consent where consent is required;

compliance with legal obligations;

legitimate operational, security or business interests where permitted by applicable law;

other lawful grounds available under applicable legislation.

Nothing in this Policy permits a business to process personal information unlawfully merely because Orxtera provides a technical capability.

15. International Processing

Orxtera may use infrastructure and service providers located outside Egypt.

As a result, information may be processed in jurisdictions other than the user’s own jurisdiction.

Where applicable law requires safeguards, approvals or other measures for international processing or transfers, Shohnatex intends to implement the required measures before relying on the affected processing arrangement.

We do not represent in this Policy that every international transfer mechanism or regulatory approval has already been completed merely because a provider is technically available.

16. Data Retention

We retain information only for as long as reasonably required to:

provide Orxtera;

maintain the relevant business account;

support business operations requested by the customer;

maintain security and audit information;

resolve disputes;

enforce agreements;

comply with legal, tax or accounting obligations.

Retention periods may differ by:

information type;

organization status;

contractual requirements;

connected-provider restrictions;

security requirements;

applicable law.

We do not publish a fixed universal deletion period unless the corresponding technical and operational process supports that commitment.

When information no longer needs to be retained, we may delete or anonymize it, subject to legal and operational requirements.

17. Security

Orxtera uses technical and organizational measures designed to protect information.

Depending on the relevant system, these may include:

authenticated access;

tenant isolation;

role-based access controls;

server-side authorization checks;

encrypted transport;

audit and security logging;

controlled access to infrastructure.

No internet-connected platform can guarantee absolute security.

Orxtera does not claim a security certification unless and until the certification has actually been obtained and its applicable scope can be identified.

18. Business Communications and Marketing

Shohnatex may send communications necessary to operate Orxtera, such as:

security notices;

authentication messages;

service notices;

billing messages;

material platform updates.

Where marketing communications are sent, we will provide applicable choices or unsubscribe mechanisms where required.

Businesses using Orxtera to communicate with their own customers are responsible for complying with applicable communication, consent and anti-spam requirements and relevant channel-provider policies.

19. Your Rights and Choices

Depending on applicable law and the context of processing, individuals may have rights relating to personal information, including rights to request:

access;

correction;

deletion;

restriction;

objection;

withdrawal of consent where applicable;

other rights made available by applicable law.

Where Orxtera processes information on behalf of a business, an individual may need to contact that business first.

Shohnatex may assist the business with a valid request where appropriate.

We may verify the identity or authority of a requester before acting on a request where necessary to protect information from unauthorized access or deletion.

20. Data Deletion

Information about deletion requests is available at:

https://orxtera.com/data-deletion

Depending on the request and technical functionality available, deletion may involve:

deleting specific data;

anonymizing information;

deleting an organization account;

disconnecting integrations;

revoking authorization;

retaining narrowly limited information where legally or operationally required.

Deleting information from Orxtera does not automatically delete independently stored information held by an external provider.

21. Children

Orxtera is intended for business use and is not designed as a service directed to children.

Businesses using Orxtera are responsible for ensuring that their collection and processing of customer information complies with applicable requirements concerning age and consent.

22. Changes to This Policy

We may update this Privacy Policy to reflect:

product changes;

new functionality;

changes in integrations;

changes in service providers;

legal or regulatory requirements;

security or operational changes.

The “Last updated” date will identify the current published version.

Where required, we may provide additional notice of material changes.

23. Contact

Privacy and personal-data requests may be submitted to:

admin@orxtera.com

They may also be submitted through the Privacy & Data route on our Contact page:

https://orxtera.com/contact

General information about Orxtera and Shohnatex LLC is available through the website.

Registered address: 5A Granada St., Heliopolis, Cairo, Egypt.

Orxtera is a product of Shohnatex LLC, Egypt.