Verification data: one-time passwords (OTP) via WhatsApp/SMS for COD orders in Lebanon/Syria.
Communications: messages sent via email, contact forms, or WhatsApp.
Technical data: IP address, device/browser info, cookies, and similar technologies for security, cart/session, and performance.
Analytics (optional): aggregated usage statistics (e.g., Google Analytics) if enabled.
We do not intentionally collect special category data.
3) How we collect it
Information you provide at checkout, account creation, forms, or support channels.
Automatically via cookies and similar technologies when you use our website.
From third parties we use to process orders, payments, OTP, shipping, and analytics.
4) Why we use your data (purposes)
To create/manage your account and process, fulfill, and deliver your orders.
To verify your identity/phone for COD orders (OTP).
To provide support, handle returns, and manage invoices.
To prevent fraud and ensure site and payment security.
To meet legal and accounting obligations.
With your consent, to send optional offers or updates.
5) Legal bases we rely on
Contract: to process and deliver your order.
Consent: for OTP delivery, marketing messages, and non-essential cookies.
Legitimate interests: fraud prevention, service improvement.
Legal obligation: invoicing, accounting, and compliance.
We follow Lebanese Law No. 81/2018 (E-Transactions & Personal Data). If you are in the EEA/UK, we apply GDPR principles where applicable.
6) Who we share data with
We share the minimum necessary data with:
Payment processors/Banks: [Stripe/Bank/Payment gateway] for online payments.
Delivery partners:Top Speed (Lebanon), Aramex (international), AB Fast Delivery (Beirut) – name, address, phone, order value.
OTP/verification provider: WhatsApp/Firebase for sending verification codes.
Hosting, security, and analytics: [Hostinger], [Cloudflare], [Google Analytics] (if enabled).
Public authorities when required by law.
We do not sell your personal data.
7) International transfers
Some providers may process data outside your country. We use appropriate safeguards and contractual protections where required.
8) Data retention
Customer accounts: up to 3 years of inactivity (or earlier upon request, unless law requires longer).
Orders & invoices: retained for legally required accounting/tax periods.
OTP logs: kept briefly for security/fraud prevention.
Cookies: per lifetimes listed below.
9) Your rights
You may request access, correction, deletion, restriction, portability, or object to processing. You may withdraw consent at any time (this won’t affect prior lawful processing).
If you are in the EEA/UK, you may also complain to your local data protection authority.
10) Security
We use reasonable technical/organizational measures (HTTPS encryption, encrypted passwords, limited access). No method of transmission/storage is 100% secure.
11) Children
Our services are not directed to children under 16. If you believe a child provided data, contact us to delete it.
12) Marketing messages
We send marketing only with your consent. You can unsubscribe anytime via the link in the message or by contacting us.
13) Cookies & similar technologies
We use essential cookies to operate our store and optional cookies (with your consent) for analytics/marketing. You can control cookies via your browser or our cookie banner.
14) Changes to this policy
We may update this policy from time to time. The latest version will always be posted here with the “Last updated” date.
15) Contact us
For any privacy questions or to exercise your rights: