Privacy Policy
This policy explains what data Coco OS processes, for what purpose, who we share it with, and how you can ask us to delete it. Coco OS is the internal management tool of Coco Style (Córdoba, Argentina) and is the application registered with Meta under the name "CocoOS" (app id 2192308181566193). It is not a service aimed at the general public, nor is it offered to other businesses.
Last updated: July 31, 2026
1. Data controller
The data controller is Coco Style, a jewelry business based in Córdoba, Argentina, and the owner of the cocostylecba.com store. For any privacy question, to exercise your rights, or to request the deletion of your data, write to us at hola@cocostylecba.com.
Coco OS accesses only Coco Style's own assets: our WhatsApp Business account (WABA), our Facebook page, and our Instagram professional account. We do not access the pages, accounts, messages, or data of any other business, and we do not provide software services to third parties.
2. Who this policy covers
Internal users: the business owner and the employees with access to Coco OS.
People who write to us on WhatsApp, Instagram Direct, or Messenger, or who comment on or mention us in our Instagram and Facebook posts. When you contact us through those channels, your conversation is copied into our internal inbox so that we can reply to you from a single place.
Customers of our online store (Tienda Nube), whose orders we manage from Coco OS.
3. Data we process
From internal users: name, email address, encrypted password, second authentication factor (MFA), role and permissions, and the record of the actions they perform inside the tool.
From the Meta platforms (WhatsApp, Instagram, and Messenger), when you write to us or comment: your identifier on that channel (WhatsApp wa_id, Instagram IGSID, Messenger PSID); your WhatsApp phone number; your display name and, on Instagram, your username, exactly as Meta delivers them to us; the content of the messages, including text, images, audio, video, documents, stickers, and reactions; the location you share, if you send a location message; the sent, delivered, and read timestamps; and the text of your comments and mentions on our posts, together with your identifier and your public name.
We also keep a verbatim copy of the technical notification (webhook) that Meta sends us for each event, so that we can reprocess it if the sync fails, and we re-host the attached files with our storage provider, because Meta's original links expire within a few hours.
Internal annotations the team adds about a contact: tags, notes, and a timeline of facts about the commercial relationship (for example, a delayed order or a complaint).
Identity verification: if you write to us from a number we do not have linked to a purchase and you ask about an order, we ask you for the email address used for that purchase and send you a code; we store that email address and, of the code, only an irreversible cryptographic fingerprint (never the code itself). Both are deleted automatically when the code expires.
From Tienda Nube: orders, products, and customers' contact, shipping, and billing details.
Minimal technical data: activity logs, errors, and usage metrics, for security, auditing, and diagnostics.
4. Purpose and legal basis
Replying to your messages and comments and supporting you with products, orders, and shipments. Basis: your own initiative in contacting us through that channel, and the performance of the commercial relationship.
Running the business: catalog, stock, orders, payments, suppliers, and internal reports. Basis: Coco Style's legitimate interest in running its activity, and compliance with its contractual, accounting, and tax obligations.
Sending you commercial communications by WhatsApp or email. Basis: your prior consent. You can unsubscribe at any time, as explained in section 9.
Security, internal auditing, and the prevention of fraud and abuse. Basis: legitimate interest.
We do not use the data we receive from the Meta platforms for any purpose other than those above. In particular: we do not sell it, we do not transfer it to third parties for those third parties' own purposes, we do not use it for targeted advertising, we do not combine it with data bought from other companies, and we do not use it to train artificial intelligence models.
5. Automation and artificial intelligence
Some of the replies in our inbox are written and sent by an automated assistant. To do that, the text of your message and the previous messages in that same conversation are sent to Anthropic's API (the Claude model), which generates the reply. Anthropic acts as a provider and does not use that content to train its models.
The assistant introduces itself as automated at the start of the conversation. You can ask to speak with a person at any time, and the Coco Style team can take over the conversation whenever it considers it necessary.
The assistant does not disclose order data without first verifying your identity, following the procedure described in section 3.
We do not make automated decisions that produce legal effects concerning you or that significantly affect you: the assistant answers questions and hands over to a person when it cannot resolve them.
6. Providers and integrations
Coco OS relies on the following providers, which process data on behalf of and under the instructions of Coco Style: Meta Platforms (WhatsApp Business, Instagram, and Messenger, to receive and send messages); Tienda Nube (store and order data); Railway (infrastructure, database, and job queues); Cloudinary (hosting of the message attachments); Vercel (hosting of the internal interface); Anthropic (the inbox's automated assistant); OpenAI (processing of our internal reference material and of the query the assistant runs against it); Resend (email delivery); and Sentry (error logging and technical monitoring).
Some of these providers process and store data outside the Argentine Republic. When contracting them we require adequate contractual guarantees of confidentiality and security.
We do not sell personal data, we do not transfer it to third parties for purposes unrelated to Coco Style's operation, we do not use it for advertising, and we do not use it to train artificial intelligence models.
7. Retention
We keep each type of data only for as long as the purpose that justifies it requires.
The technical copies of the notifications Meta sends us (webhooks) are deleted automatically after 90 days.
Identity verification codes are deleted when they expire.
Conversations, their attachments, and internal annotations are kept while the commercial relationship remains active and they are necessary in order to serve you; if you ask us to delete them sooner, we proceed as described in section 8.
Order and billing data is kept for the period required by Argentine accounting and tax obligations.
Internal users' data is kept for as long as their access to the tool lasts.
8. How to request the deletion of your data
Anyone whose data Coco OS processes can ask us to delete it, regardless of the channel they contacted us through and without needing an account in the tool.
To request it, write to us at hola@cocostylecba.com with the subject "Data deletion", stating the channel you contacted us through (WhatsApp, Instagram, Messenger, or the store) and the phone number, username, or email address you used. You can also request it by replying "ELIMINAR MIS DATOS" — Spanish for "delete my data" — in the same WhatsApp, Instagram, or Messenger conversation.
The full procedure is detailed at os.cocostylecba.com/data-deletion.
We verify your identity before deleting, so that we do not erase someone else's data at a third party's request.
What we delete: your contact record, your conversations and their full content (text, images, audio, video, documents, locations, and reactions), the files we host with our storage provider, your comments and mentions mirrored from Instagram and Facebook, the associated tags, notes, and internal events, and the corresponding technical copies of Meta's notifications.
What we cannot delete: the billing data and the records of transactions already carried out, which Argentine accounting and tax regulations require us to keep. In that case we explain it to you and restrict the use of that data to that single purpose.
Timeframe: we confirm receipt of the request within 5 business days and carry it out within 30 calendar days. We notify you in writing once it is done.
Deleting your data from Coco OS does not erase the conversation history on your own device, nor the data Meta keeps on its own account. For that, see the privacy tools of WhatsApp, Instagram, and Facebook.
9. Commercial communications and opting out
We only send you commercial messages on WhatsApp if you gave us your number and agreed to receive them from Coco Style, and by email if you subscribed. WhatsApp messages are sent using templates previously approved by Meta.
You can opt out at any time by replying "BAJA" — Spanish for "unsubscribe" — in the same WhatsApp conversation, by using the unsubscribe link in our emails, or by writing to hola@cocostylecba.com. The opt-out applies to all of our campaigns and is permanent until you ask us otherwise.
Opting out of commercial communications does not affect the customer-service messages that reply to a question of yours or to an order in progress.
10. Security
We apply role-based access control, reinforced authentication (MFA), sessions with secure cookies, encryption in transit, and audit logs of sensitive actions. Access is limited to the business's authorized people and is revoked when the relationship ends.
If a security incident affecting your personal data were to occur, we will notify you and inform the supervisory authority where appropriate.
11. Your rights
You can request access to, rectification of, updating of, and deletion of your personal data, and object to its processing, by writing to hola@cocostylecba.com. We handle requests in accordance with Law 25.326 on the Protection of Personal Data of the Argentine Republic.
The Agencia de Acceso a la Información Pública, in its capacity as the supervisory body for Law 25.326, has the power to hear the complaints and claims brought by those whose rights are affected by non-compliance with the personal data protection rules in force.
12. Minors
Coco OS is not directed at people under 18 and we do not intentionally collect minors' data. If we detect that a conversation belongs to a minor without the authorization of whoever holds parental responsibility, we delete that data.
13. Changes to this policy
We may update this policy when our integrations or the way we process data change. The version in force is always the one published on this page, with its last-updated date shown above. If the change is substantial, we will announce it through our usual customer-service channels.
14. Contact
For any question about this policy, write to us at hola@cocostylecba.com.