Pelicart

Security guide

Is Pelicart secure?

This page explains Pelicart’s account permissions, stored data, and technical safeguards. It also identifies each service category that processes your data and explains how you can verify these claims.

By Caleb. Last updated 2026-07-22.

1. What Pelicart is

Pelicart is a WhatsApp assistant for your Woolworths or Checkers Sixty60 account. You send a shopping list, and Pelicart fills your store cart. You review the cart and pay in the store’s app with your saved card.

This section explains the account permissions Pelicart needs and the data it stores. It also names each outside service category that processes your data. Read the privacy reference for retention periods and deletion steps. The final section explains how you can verify these claims.

2. What Pelicart can do on your store account

Linking a store gives Pelicart the following account permissions. Pelicart cannot use permissions outside this list:

  • search the store’s catalogue
  • view, add, remove, update, or clear cart items
  • view, select, or add delivery addresses
  • read your order history

Pelicart cannot check out, choose a delivery slot, or pay. Its code contains no checkout operation. When the cart is ready, open the store’s app and review it. You complete the purchase there.

Your order history

Pelicart stores order history from your linked account. This history helps it select products you bought before. It also lets us contact you about substitutions or missing items after delivery.

Your delivery addresses

Pelicart can list and select addresses saved on your store account. It can also save an address you send in chat. Pelicart changes the selected address only after you ask.

3. What Pelicart stores about you

Pelicart stores only the following data. Each item supports shopping, customer support, or product reliability.

Your store session token, not your password

When you link Woolworths, you enter your email and password in the chat’s secure form. Pelicart uses the password once to sign you in. Woolworths returns a temporary session token. Pelicart stores that token instead of your password.

Checkers Sixty60 sends a one-time code instead of requesting a password. The code creates the same type of session token. Pelicart encrypts tokens with 256-bit Advanced Encryption Standard in Galois/Counter Mode (AES-256-GCM) before storage. The decryption key stays outside the database, so a database copy cannot reveal a token.

Your messages

Pelicart keeps one day of recent conversation for context. A separate audit log stores messages while we develop the product. The audit log currently has no automatic deletion date. We will publish any future retention limit here.

Your order history and saved addresses

Pelicart stores your past orders and delivery addresses to shop for you. It does not use this data for another purpose.

4. What Pelicart staff can do

As Pelicart’s operator, I can view messages, generated carts, and stored order history. I use this access for requested support and onboarding fixes. Until a session expires, I can perform the same store actions that Pelicart can. The next section lists the limits on that access.

5. What Pelicart cannot do

These limits come from Pelicart’s architecture, not from a promise. They remain in place even if someone misuses staff access. Pelicart staff cannot perform any action listed below.

  • Bank account: Pelicart never connects to a bank.
  • Payment card: Your store stores the card and does not expose it to Pelicart.
  • Store checkout: The Pelicart codebase has no checkout operation.
  • Subscription payment: Stripe processes your Pelicart Pro subscription on its hosted checkout. Stripe receives your card details, and Pelicart does not. Pelicart cannot send money from your store account.
  • Store password: A store session token cannot reset credentials. A reset requires your password, which Pelicart does not store.

6. Who else handles your data

Pelicart sends specific data to the service categories below. Each entry states the service’s role and data access.

Meta through the WhatsApp Business Application Programming Interface (API)

Meta receives each message you send Pelicart and each reply Pelicart sends. Meta’s privacy policy governs that traffic.

Artificial intelligence (AI) model providers

Pelicart sends your recent conversation when it needs to generate a reply. Pelicart does not set the provider’s retention period.

Our observability service

We record an observability trace for each assistant run. A trace records messages, model decisions, tool calls, and errors for debugging.

Our database

A managed database stores your account, messages, addresses, order history, and encrypted store token. The provider encrypts stored data, a safeguard called encryption at rest. Pelicart adds its own AES-256-GCM layer to each store token. The decryption key remains in deployment configuration outside the database.

Our hosting provider

A cloud provider hosts this website and runs the Pelicart server. It receives request metadata, including the page, time, and originating country.

Stripe

Stripe processes Pelicart Pro subscriptions. It receives your name, email address, and any card details entered in its hosted checkout. Pelicart receives only your subscription status.

Google Maps

Google Maps converts a new delivery address into store coordinates. It receives the address only when you ask Pelicart to add it.

Woolworths and Checkers

Your linked store receives the cart Pelicart builds and the orders you place.

7. How to verify these claims

You can inspect evidence for these claims with me. Book a 30-minute call, and I can show you the relevant source code. Meetings are available through my calendar or at Workshop 17 on Kloof Street in Cape Town.