DEDO

Privacy Policy

Effective 31 August 2026 · Last updated: 31 August 2026

This policy explains how Dedo collects, uses, shares, and protects personal data when you use our services to build online stores, process payments, connect domains, and connect advertising and measurement tools. It is drafted to align with globally recognized data-protection principles, including the EU General Data Protection Regulation (GDPR), Egypt’s Personal Data Protection Law No. 151 of 2020, and the California Consumer Privacy Act / CPRA where applicable.

1) Who we are — controller and processor

The service is owned and operated by Long March for Digital Marketing And Programming (“Dedo”, “we”). Website: dedo-go.com. Privacy contact: info@dedo-go.com or our contact page.

Roles. Dedo is a controller of merchant-account and platform-operations data (registration, subscription, security logs). Dedo is a processor of store-customer data (orders, cart, delivery details) on behalf of the merchant, who remains the controller vis-à-vis their customers. We are not a party to the sale between merchant and customer.

2) Categories of data we may collect

We collect only what is needed to provide the service you requested, what the law requires, or what you expressly consent to.

2.1 Merchant account and store

  • Account data: name, email address, account identifier, and sign-in credentials.
  • If you choose “Continue with Google”: Google account identifiers you consent to on Google’s consent screen (such as name, email, and Google user ID).
  • Store, product, and order data needed to operate the service.
  • Basic technical data: operations and security logs, approximate IP address, and browser type, as needed to protect the service and diagnose faults.

2.2 Advertising, measurement, domain, and payments — only if the merchant enables them

  • Facebook / Meta: access tokens and permissions the merchant consents to, plus page, ad-account, and pixel identifiers they choose.
  • TikTok: access tokens and permissions the merchant consents to, plus advertiser and/or pixel identifiers they choose. If server-side events are enabled, the Events API token the merchant enters may be stored.
  • Snapchat: access and refresh tokens and permissions the merchant consents to, plus organization, ad-account, funding-source, and public-profile identifiers they choose. Tokens are stored on the server and are not shown in the merchant’s browser.
  • Google: (a) Google sign-in as in 2.1; (b) when measurement is enabled: Google Analytics Measurement ID (G-) and the optional Measurement Protocol API secret if entered, plus Google Tag Manager container ID (GTM-); (c) when Google Ads conversions are enabled: conversion ID (AW-) and optional conversion label as entered by the merchant — we do not obtain Google Ads Manager OAuth access tokens of the ads-manager type; (d) optional BigQuery project/dataset identifiers if the merchant connects them; (e) platform hosting on Google Cloud / Firebase (hosting, database, storage, and functions); (f) when the in-platform assistant is used: prompts and limited operational context may be sent to Google AI APIs to generate a reply; we do not sell that data.
  • GoDaddy: the domain name, DNS records, and linking permissions needed to point the domain to the store, as consented to by the merchant.
  • Paymob: integration credentials the merchant enters (API key, HMAC, iframe ID, and integration IDs), plus payment-transaction data needed to complete the order and verify the payment webhook.
  • WhatsApp (WhatsApp Business API via Meta): the WhatsApp Business account ID/token and sending permissions the merchant consents to; plus phone numbers of store customers who gave explicit opt-in to receive messages, and message/template content and delivery status. Used only to send the merchant’s messages to their consenting customers; we do not sell it.

We do not collect more from advertising platforms than is required to perform the connection you enabled and consented to on the permissions screen or in settings fields.

3) Legal bases for processing

We process personal data on one or more of the following bases, depending on context:

  • Performance of a contract: creating the account, operating the store, subscription, and related support.
  • Consent: connecting ad accounts, measurement tags, Google sign-in, domain linking, and enabling the payment gateway. You may withdraw consent by disconnecting or emailing us.
  • Legitimate interests: service security, fraud and abuse prevention, and operational stability, balanced against your rights.
  • Legal obligation: where the law requires retention or disclosure (tax, disputes, or binding orders).

4) Purposes of processing

  • To operate the store, dashboard, platform features, and account maintenance.
  • Authentication, including email/OTP or Google sign-in.
  • To connect and manage ads and measurement at the merchant’s request and with their consent.
  • To connect and point a domain to the store when GoDaddy is enabled.
  • To process online payments when Paymob is enabled.
  • To send the merchant’s marketing or service messages to their customers over WhatsApp when enabled — only to customers who gave explicit opt-in, with opt-out available at any time.
  • Technical support, security, abuse prevention, and legal compliance.

We do not use store-customer data to market Dedo’s services to third parties, and we do not sell personal data.

5) Sharing with third parties

We do not sell personal data and do not share it for monetary consideration. Some data may be processed by providers acting as processors or independent controllers, only to the extent needed to fulfil what the merchant requested:

  • Google (including Firebase / Google Cloud; Google Analytics; Google Tag Manager; Google Ads conversions when enabled; and AI APIs when the assistant is used).
  • Meta Platforms when Facebook/Meta connecting is enabled.
  • TikTok when TikTok connecting is enabled.
  • Snap Inc. when Snapchat connecting is enabled.
  • GoDaddy when domain connecting is enabled.
  • Paymob when online payments are enabled.
  • Meta Platforms / WhatsApp Ireland when WhatsApp is enabled — to deliver the messages the merchant sends to their customers’ numbers, subject to the WhatsApp Business Messaging Policy.
  • Email/operations providers needed to send transactional notices.

Your use of those platforms is also subject to their own policies. The merchant is responsible for the legal basis toward store visitors when they enable a pixel or measurement tag on the storefront.

6) International transfers

Data may be processed on servers outside your country (including the United States and other regions used by Google and advertising partners). Where that occurs, we rely on the safeguards available from the provider (such as Standard Contractual Clauses or an approved transfer framework where applicable) and on the transfer being necessary to provide the service you requested.

7) Retention

We retain data while the account is active, or for as long as needed to provide the service, settle charges, meet legal duties, and resolve disputes. Connection data is deleted or disabled when you disconnect or when an accepted deletion request is carried out. Account and connection data are deleted within 30 days at most of disconnecting or of accepting a deletion request, unless retention is required for a legal obligation or an ongoing dispute. Backups may persist for a limited operational cycle and are then removed. For WhatsApp: we keep the customer’s opt-in status and the message data needed while they remain subscribed, and delete them on opt-out or on disconnecting WhatsApp.

8) Data-subject rights

Depending on the law that applies in your region, you may have the right to:

  • Access your personal data and obtain a copy.
  • Rectify inaccurate data.
  • Request erasure (“right to be forgotten”) where applicable.
  • Restrict or object to processing.
  • Data portability where applicable.
  • Withdraw consent at any time without affecting prior lawful processing.
  • Lodge a complaint with a competent data-protection authority.

If you are a visitor to a merchant’s store on Dedo, please direct your request first to that merchant (the controller). We assist the merchant as processor to fulfil reasonable requests relating to data we store.

9) Data deletion and disconnecting integrations

You may disconnect Facebook/Meta, TikTok, Snapchat, GoDaddy, or WhatsApp in platform settings; disable Google measurement/conversion integrations by removing the identifiers in settings; and disable Paymob by removing integration keys. A store customer can opt out of WhatsApp messages at any time. To delete your account, connection data, or other service-linked data, email info@dedo-go.com with the subject “Data deletion request”, and include the account email and store ID if available. We review and fulfil the request, and account and connection data (including WhatsApp data) are deleted within 30 days at most of accepting the deletion request or of disconnecting, and within statutory periods where they apply, unless retention is required for a legal obligation or an ongoing dispute.

10) Cookies

We use cookies and similar technologies for session, security, and cart operation. Merchants may enable third-party measurement and advertising cookies. Details are in our Cookie Policy.

11) Children

The service is intended for merchants and professional use. We do not knowingly direct the platform to anyone under 18, and we do not knowingly collect their data. If we learn of unintentional collection, we will delete it after verification.

12) Security and automated decisions

We apply appropriate technical and organisational measures (store-data isolation, access controls, transport encryption where applicable, and server-side storage of ad tokens where the product is designed that way). No method of transmission or storage over the internet is 100% secure. We do not carry out solely automated decision-making that produces legal or similarly significant effects on individuals within the meaning of the GDPR.

13) Policy updates

We may update this page when the service or legal requirements change. The “Last updated” date above is the reference. Continued use after publication means you should review the version then in force. For material changes we aim to give reasonable notice via the site or the registered email.

14) Contact

Privacy contact: info@dedo-go.com — dedo-go.com — Long March for Digital Marketing And Programming.