Platform policy

Privacy Policy

Last updated: 29 July 2026

EFTAH SHOP PLATFORM PRIVACY POLICY

Website: https://eftahshop.com

At Eftah Shop, we respect your privacy and are committed to protecting your Personal Data and Processing it lawfully, fairly, and transparently.

This Privacy Policy explains how we collect, use, store, share, and protect Personal Data when you visit the Eftah Shop website, create a Merchant Account, use the Dashboard, contact us, or use any of the services and features provided through the Platform.

Please read this Policy carefully. By using the Platform, creating an Account, or continuing to use our services, you acknowledge that you have read and understood this Policy.

1. Scope of this Privacy Policy

This Policy applies to Personal Data processed by Eftah Shop relating to the following categories:

Merchants who create Accounts or Stores through the Platform.

Representatives, employees, and authorised users of Merchant Accounts.

Visitors to the Platform website and its informational pages.

Individuals who contact technical support or sales.

Applicants for services or partnerships with the Platform.

Store Customers, to the extent that the Platform processes their data on behalf of a Merchant.

Suppliers, Service Providers, partners, and their representatives.

This Policy does not replace the privacy policy that each Merchant must publish in its Store for its Customers.

2. Definitions

For the purposes of this Policy, the following words and expressions have the meanings set out below:

Platform: The Eftah Shop Platform and all its related websites, systems, Dashboards, and technical services.

Merchant: Any natural or legal person who uses the Platform to create and manage an online Store.

Customer: Any person who visits a Merchant’s Store or submits an Order to purchase a product or receive a service.

Personal Data: Any information relating to an identified natural person or a natural person who can be identified directly or indirectly.

Processing: Any operation performed on Personal Data, including collecting, recording, storing, organising, using, modifying, sharing, or deleting it.

Data Controller: The entity that determines the purposes and means of Processing Personal Data.

Data Processor: The entity that processes Personal Data on behalf of a Data Controller and in accordance with its instructions.

Service Provider: Any external party that assists the Platform in operating its services, including hosting, payment, shipping, messaging, analytics, and technical support providers.

3. Roles of Eftah Shop and the Merchant

3.1 Merchant Account Data

Eftah Shop generally acts as the Data Controller for Personal Data relating to:

Registering the Merchant Account.

Managing the contractual relationship with the Merchant.

Collecting fees and commissions.

Providing technical support.

Protecting the Platform and verifying its use.

Sending service-related notifications.

Managing complaints and legal correspondence.

Complying with legal and regulatory obligations.

3.2 Store Customer Data

When a Merchant uses the Platform to receive Customer Orders and manage Customer Data, the Merchant is generally the Data Controller responsible for determining why the Customer’s Personal Data is collected and how it is used.

In this situation, Eftah Shop generally acts as a Data Processor on behalf of the Merchant and processes Customer Data in accordance with the Merchant’s instructions for the purposes of providing the services and operating the Store.

3.3 Merchant Responsibilities

The Merchant must:

Publish a clear privacy policy within its Store.

Explain what Customer Data it collects and the purposes for which it is used.

Obtain any legally required consent.

Avoid collecting unnecessary Personal Data.

Respond to Customers’ requests concerning their Personal Data.

Protect Customer Data and refrain from using it unlawfully.

Notify the Platform in the event of a security incident or data breach.

Refrain from requesting Sensitive Personal Data unless it is necessary and supported by an appropriate legal basis.

3.4 Independent Processing

The Platform may act as an independent Data Controller for certain Customer Data where the Processing is necessary for independent purposes, including:

Protecting the Platform against fraud or misuse.

Retaining legal or financial records.

Responding to requests from competent authorities.

Protecting the Platform’s legal rights.

Handling complaints relating to Platform security.

4. Personal Data We Collect

We may collect the following categories of data depending on how you use the Platform.

4.1 Identity Data

Full name.

Username.

Account photograph.

Date of birth, where necessary.

Nationality, where required for verification.

National identification number or passport information, where verification is required.

Details of the authorised person or legal representative of an organisation.

4.2 Contact Data

Email address.

Telephone number.

WhatsApp number, where provided.

Correspondence address.

Country and city.

Contact details provided to technical support.

4.3 Business Data

Store name.

Legal or trade name.

Type of business activity.

Country and currency.

Commercial registration information.

Tax number or tax registration information.

Business licences.

Business address.

Details of owners or authorised representatives.

Store logo and brand identity information.

4.4 Account and Usage Data

Login credentials.

Roles and permissions.

Account and Store settings.

Records of actions performed through the Dashboard.

Pages and features used.

Login dates and times.

Successful and unsuccessful login attempts.

Session and device information.

We will not ask you to send your password to us by email or through technical support messages.

4.5 Financial and Billing Data

Records of fees and commissions.

Platform Balance.

Balance top-up requests.

Invoice information.

Currency and country.

Order values and commissions due.

Payment status.

Transaction reference numbers.

Bank account or wallet information where required for collection or refunds.

When an external Payment Provider is used, card or payment-method information may be entered directly into the Payment Provider’s systems.

The information received by the Platform will depend on the nature of the integration and may be limited to the transaction status, reference number, and a limited number of the final digits of the payment method.

4.6 Order and Customer Data

When a Merchant uses the Platform to manage its Store, the Platform may process data such as:

Customer name.

Telephone number.

Email address.

Shipping and billing addresses.

City, region, and country.

Details of the requested products or services.

Order value.

Payment method.

Payment status.

Order and shipping status.

Notes submitted by the Customer.

Communications relating to the Order.

Exchange, return, refund, and complaint information.

This data is generally processed on behalf of the Merchant for the purposes of operating the Store and fulfilling Orders.

4.7 Content and Files

Product images.

Logos and designs.

Product and service descriptions.

Pages, articles, and published content.

Documents uploaded for verification.

Transfer receipts or Platform Balance top-up receipts.

Attachments sent to technical support.

4.8 Support and Communication Data

The content of messages and conversations.

Technical support tickets.

Complaints and enquiries.

Audio recordings, where a call is recorded after the required notice has been provided.

Attachments, images, and screenshots.

Service ratings and user feedback.

4.9 Technical Data

We may automatically collect certain technical information, including:

Internet Protocol address, or IP address.

Device type.

Browser type and version.

Operating system.

Language and time zone.

Device or session identifiers.

Pages visited.

Time and duration of visits.

Source of the visit.

Error and performance logs.

Security logs and records of unusual activity.

4.10 Location Data

We may collect an approximate location based on an IP address, such as the country or city.

We do not collect the precise geographical location of a device unless a feature requiring it is enabled and the required permission has been obtained.

4.11 Data Obtained from External Sources

We may obtain data from:

The Merchant or its authorised representatives.

Store Customers.

Payment Providers.

Shipping companies.

Login and verification services.

Messaging and email providers.

Integration partners.

Public sources and official records, where verification is required.

Fraud-prevention and cybersecurity services.

5. Sensitive Personal Data

The Platform does not normally request Sensitive Personal Data unless such data is necessary and its Processing is permitted by law.

Depending on applicable law, Sensitive Personal Data may include health, biometric, religious, highly sensitive financial, children’s, or other categories of data requiring additional protection.

A Merchant must not use the Platform to collect or store Sensitive Personal Data unless:

The data is necessary for the nature of the Merchant’s activity.

The collection is lawful.

The required notice has been provided to the relevant individual.

Explicit consent has been obtained where required.

Appropriate safeguards have been implemented.

The Platform’s features are suitable for that category of data.

The Platform may restrict or prohibit the storage of certain categories of Sensitive Personal Data where they create legal or security risks.

6. How We Collect Personal Data

We may collect Personal Data through:

Registration and Account creation forms.

Account and Store settings.

Use of the Dashboard.

Creation and management of Orders.

Payment and Platform Balance top-up transactions.

Communications with support or sales.

Cookies and similar technologies.

Integrations with Payment Providers, Shipping Providers, and other services.

Identity or business-verification procedures.

Correspondence, contracts, and commercial offers.

Use of the website and informational pages.

Reports, complaints, and disputes.

7. Purposes for Which We Use Personal Data

We may use Personal Data for the following purposes.

7.1 Account Creation and Service Provision

Creating the Merchant Account.

Activating the Store.

Providing access to the Dashboard.

Operating the features selected by the Merchant.

Saving settings and Content.

Managing users and permissions.

Performing the contractual relationship with the Merchant.

7.2 Operating Stores and Orders

Receiving Orders and displaying them to the Merchant.

Managing Order, payment, and shipping statuses.

Sending Order notifications.

Enabling Customers to track their Orders.

Providing invoices and internal records.

Supporting cancellations, returns, and refunds.

Operating payment and shipping methods.

7.3 Managing Fees and Commissions

Calculating Platform commissions.

Managing the Merchant’s Platform Balance.

Processing Platform Balance top-up requests.

Issuing records and invoices relating to Platform services.

Following up on outstanding amounts.

Handling financial disputes.

7.4 Verification and Compliance

Verifying identity or business activity.

Reviewing documents and licences.

Complying with legal and tax requirements.

Preventing fraud and money laundering.

Cooperating with Payment Providers and competent authorities.

Preventing prohibited products and activities.

7.5 Security and Prevention of Misuse

Protecting Accounts and Stores.

Detecting unauthorised login attempts.

Monitoring unusual behaviour.

Preventing fraud and fake Orders.

Investigating security incidents.

Fixing errors and vulnerabilities.

Protecting the rights of the Platform, Merchants, and Customers.

7.6 Support and Communications

Responding to enquiries.

Handling support tickets.

Sending operational notifications.

Notifying the Merchant of changes to the Account or Platform Balance.

Sending security alerts.

Communicating about outages or maintenance.

Handling complaints and disputes.

7.7 Service Improvement and Development

Analysing the use of Platform features.

Measuring performance and stability.

Identifying technical issues.

Developing new features.

Improving the user experience.

Preparing aggregated statistics and reports.

Testing updates and improvements.

7.8 Marketing

We may use Contact Data to send:

Platform news.

Service updates.

Offers or information about new features.

Educational content relating to e-commerce.

Invitations to events or surveys.

You may unsubscribe from marketing communications at any time.

Unsubscribing from marketing communications will not affect notifications necessary for operating the Account, maintaining security, or performing the contract.

8. Legal Bases for Processing

We process Personal Data on one or more of the following legal bases, depending on applicable law:

Performing a contract to which you are a party or taking steps at your request before entering into a contract.

Complying with a legal or regulatory obligation.

Your consent, where consent is required.

Protecting the legitimate interests and rights of the Platform, Merchants, or users, provided those interests do not unjustifiably override your rights.

Protecting the vital interests of an individual where necessary.

Establishing, exercising, or defending legal claims.

Any other purpose permitted under applicable law.

Where we rely on your consent, you may withdraw it at any time.

Withdrawal of consent does not affect the lawfulness of Processing carried out before the consent was withdrawn.

9. Accuracy of Personal Data

We seek to keep Personal Data accurate and up to date.

The Merchant is responsible for:

Providing accurate information.

Updating business and Contact Data.

Updating bank-account and payment information.

Updating registration documents and licences.

Correcting information relating to employees and Account users.

Ensuring that Customer Data entered or modified by the Merchant is accurate.

We may request additional documents or information to verify the accuracy of Personal Data.

10. Sharing Personal Data

We do not sell Personal Data.

We may share Personal Data, to the extent necessary, with the following categories of recipients.

10.1 Platform Employees and Representatives

Authorised employees and representatives may access Personal Data to the extent required to perform their duties, subject to appropriate access controls and confidentiality obligations.

10.2 Hosting and Infrastructure Providers

We may use providers of hosting, servers, databases, cloud storage, content-delivery networks, and backup services.

10.3 Payment Providers and Banks

Necessary Personal Data may be shared for the purposes of:

Creating a payment transaction.

Confirming the transaction status.

Processing refunds.

Resolving disputes.

Preventing fraud.

Complying with legal requirements.

10.4 Shipping and Delivery Companies

Customer Data necessary to fulfil an Order may be shared, including the Customer’s name, telephone number, address, and shipment details.

10.5 Messaging and Communication Providers

We may share Contact Data with providers of:

Email services.

SMS services.

Mobile notifications.

WhatsApp or other available messaging channels.

Technical support services.

10.6 Analytics and Technical Monitoring Providers

We may use services that analyse performance, errors, and use of the Platform, while minimising or aggregating Personal Data where reasonably possible.

10.7 Professional Advisers

We may share Personal Data with lawyers, accountants, auditors, and consultants to the extent necessary to obtain their services and protect our rights.

10.8 Governmental and Judicial Authorities

We may disclose Personal Data where disclosure is:

Required by law.

Made in response to a court order or binding request.

Necessary to investigate fraud or a criminal offence.

Necessary to protect rights, safety, or security.

Required by a competent regulatory authority.

10.9 Merger or Transfer of Business

If the Platform becomes subject to an acquisition, merger, restructuring, or asset sale, Personal Data may be transferred to a successor entity, subject to appropriate confidentiality and data-protection measures.

10.10 The Merchant

The Merchant may access the Personal Data of its Store Customers and their Orders according to the Account permissions.

The Merchant is responsible for using that Personal Data in accordance with applicable law and the privacy policy published in its Store.

11. Engaging Data Processors

We seek to select Service Providers capable of providing an appropriate level of data protection.

Depending on the nature of the service and applicable law, we may require Service Providers to:

Process Personal Data only for the specified purposes.

Maintain confidentiality.

Implement appropriate security measures.

Restrict employee access.

Notify us of security incidents.

Refrain from engaging additional parties without appropriate safeguards.

Delete or return Personal Data when the service ends.

Cooperate in fulfilling Data Subject requests.

12. Third-Party Links and Services

The Platform or Stores may contain links to or integrations with external websites and services.

Those websites and services are governed by their own privacy policies.

Eftah Shop does not control their practices except to the extent that the external party acts as a contracted Service Provider to the Platform.

You should review the privacy policy and terms of use of each external service before using it.

13. Cookies and Similar Technologies

The Platform uses Cookies and similar technologies to operate and improve the website and services.

The types of Cookies used may include the following.

13.1 Necessary Cookies

These Cookies may be used for:

Logging in.

Protecting the user session.

Saving security settings.

Remembering the selected language.

Operating essential functions.

Preventing fraud.

Certain services may not function properly without these Cookies.

13.2 Preference Cookies

These Cookies help remember:

Language.

Country.

Display settings.

Certain user selections.

13.3 Performance and Analytics Cookies

These Cookies help us understand:

How the Platform is used.

Which pages are visited most frequently.

Technical errors.

Feature performance.

Sources of website traffic.

13.4 Marketing Cookies

Marketing Cookies may be used to measure campaigns or display more relevant marketing content where such tools have been enabled and the required consent has been obtained.

You may manage Cookies through your browser settings or the Cookie-preference tool available on the website.

Disabling Necessary Cookies may prevent certain parts of the Platform from functioning properly.

14. International Transfers of Personal Data

Personal Data may be processed or stored within the country in which it was collected or in other countries in which our hosting, support, or integration providers operate.

When Personal Data is transferred outside the relevant country, we take the measures required under applicable law, which may include:

Ensuring that an appropriate level of protection is available.

Entering into appropriate contractual terms or agreements.

Obtaining any necessary approvals.

Limiting the transferred Personal Data to the minimum necessary.

Applying appropriate encryption and security safeguards.

Verifying the purposes of the transfer and the identity of the recipients.

Complying with the requirements governing transfers of Personal Data outside the Kingdom of Saudi Arabia where applicable.

By using the Platform, you acknowledge that providing cloud-based services may require Personal Data to be processed by Service Providers operating in more than one country, in accordance with applicable legal safeguards.

15. Retention of Personal Data

We retain Personal Data for as long as necessary to fulfil the purposes described in this Policy, for the duration of the contractual relationship, or for any longer period required by law.

The retention period depends on factors including:

The nature of the Personal Data.

The purpose for which it is processed.

The duration of the Account.

The existence of open Orders or transactions.

Financial and tax obligations.

Fraud-prevention requirements.

Legally required record-retention periods.

The existence of a complaint, dispute, or legal claim.

The need to protect the Platform and its users.

We may retain certain categories of Personal Data after an Account is closed, including:

Transaction and invoice records.

Fee and commission records.

Security and login records.

Complaints and disputes.

Verification documents.

Records required to be retained by law.

When Personal Data is no longer required, it may be securely deleted, destroyed, or anonymised.

16. Closure of a Merchant Account and Store Data

When a Merchant Account is closed:

The Merchant must export any required data before the available export period expires.

Access to the Account may be restricted after closure.

Certain data may continue to be retained to comply with legal or financial obligations.

Store Content and operational data may be deleted after the applicable retention or export period expires.

Closing the Account will not result in the deletion of data that must be retained because of a dispute, investigation, or legal obligation.

Backup copies may be retained for a limited period before being automatically deleted as part of the Platform’s backup cycle.

17. Data Security

We implement appropriate technical and organisational measures to protect Personal Data against unauthorised access, use, modification, disclosure, loss, or destruction.

Depending on the nature of the systems and Personal Data, these measures may include:

Encrypting communications during transmission.

Controlling access permissions.

Separating Merchant Accounts and Stores.

Recording and reviewing significant activities.

Protecting Accounts and passwords.

Maintaining backups.

Monitoring errors and unusual activity.

Updating systems and remediating vulnerabilities.

Restricting employee access.

Training personnel on confidentiality and security.

Reviewing Service Providers.

Maintaining procedures for responding to security incidents.

No electronic system can guarantee absolute security.

Users must also take appropriate precautions to protect their Accounts.

18. User Responsibility for Account Security

Users must:

Use a strong and unique password.

Refrain from sharing login credentials.

Enable additional security measures where available.

Log out of shared devices.

Avoid opening suspicious links or files.

Keep Contact Data updated.

Review users and permissions regularly.

Notify us immediately of any unauthorised use.

Protect the devices used to access the Dashboard.

The Merchant is responsible for managing the permissions of its employees and revoking the access of any employee who is no longer authorised to use the Account.

19. Personal Data Incidents and Breaches

If an incident that may affect Personal Data is identified, the Platform will take appropriate measures that may include:

Determining the nature and scope of the incident.

Containing the incident and limiting its effects.

Protecting the affected Accounts and systems.

Investigating the causes of the incident.

Documenting the measures taken.

Notifying competent authorities where required.

Notifying affected individuals where required.

Taking measures to prevent the incident from recurring.

The Merchant must notify the Platform immediately if it discovers a security incident affecting its Account or its Customers’ Personal Data.

20. Data Subject Rights

Depending on applicable law, you may have one or more of the following rights:

The right to be informed about the Personal Data we collect and the purposes for which it is used.

The right to request access to your Personal Data.

The right to obtain a clear and readable copy of your Personal Data.

The right to correct inaccurate Personal Data.

The right to complete incomplete Personal Data or update outdated Personal Data.

The right to request deletion or destruction of Personal Data where permitted by law.

The right to withdraw consent where Processing is based on consent.

The right to object to certain types of Processing.

The right to request restriction of Processing in certain circumstances.

The right to submit a complaint to a competent authority.

The right not to be subject to a solely automated decision having a legal or similarly significant effect where applicable law grants such a right.

Any other rights provided under applicable law.

These rights are not absolute.

We may be unable to fully comply with a request where retaining or Processing Personal Data is necessary to:

Perform a contract.

Comply with a legal obligation.

Protect the rights of others.

Prevent fraud.

Establish, exercise, or defend a legal claim.

Maintain Platform security.

Retain financial or tax records.

21. Exercising Privacy Rights

You may submit a request relating to Personal Data through:

Contact Page: https://eftahshop.com/contact

We may request additional information to verify the identity of the person submitting the request and to protect Personal Data from being disclosed to an unauthorised person.

We will not request more verification information than is reasonably necessary.

We seek to respond within the period required under applicable law and may explain the reasons for any delay or refusal where permitted by law.

22. Requests from Store Customers

If you are a Customer of a Store created using Eftah Shop, the Merchant may be the party primarily responsible for handling your privacy request.

In such a case:

You should first contact the Store with which you interacted.

The Merchant may use Platform tools to fulfil your request.

Eftah Shop will assist the Merchant in fulfilling the request to the extent required by contract and applicable law.

We may request the Store name and Order number to identify the relevant Personal Data.

We cannot delete Personal Data that the Merchant or Platform is legally required to retain.

Where the request concerns Processing independently carried out by Eftah Shop, we will handle the request directly.

23. Marketing Communications

We may send marketing communications to users who have agreed to receive them or where otherwise permitted by law.

You may unsubscribe by:

Using the unsubscribe link included in the message.

Changing your Account settings.

Contacting support.

We may continue to send necessary non-marketing communications, including:

Security alerts.

Verification codes.

Order and payment notifications.

Platform Balance and commission alerts.

Important Account changes.

Maintenance notices.

Legal correspondence.

24. Merchant Use of Customer Data for Marketing

The Merchant is responsible for ensuring that marketing communications sent to its Customers are lawful.

The Merchant may not use Customer Data for:

Spam or unsolicited communications.

Campaigns to which the Customer has not agreed where consent is required.

Selling or renting Customer Data.

Sharing Customer Data with marketing parties without a lawful basis.

Sending misleading or unlawful Content.

Continuing to contact a Customer after consent has been withdrawn unless another lawful basis applies.

The Platform may restrict messaging features or suspend an Account where those features are misused.

25. Aggregated and Anonymised Data

We may create statistical, aggregated, or anonymised data that does not reasonably identify a particular person.

We may use this data to:

Analyse Platform performance.

Develop products and services.

Prepare public reports.

Measure business activity.

Improve security.

Study e-commerce trends.

Support operational decisions.

Anonymised data will not be treated as Personal Data where it cannot reasonably be linked again to an identifiable person.

26. Children’s Privacy

The Platform is intended for commercial use.

A child may not independently create a Merchant Account unless this is legally permitted and completed through a parent, guardian, or legal representative.

We do not knowingly seek to collect children’s Personal Data without an appropriate legal basis.

Where the Merchant’s business targets children or requires the Processing of children’s Personal Data, the Merchant must:

Comply with the applicable age of consent.

Obtain parental or guardian consent where required.

Collect the minimum amount of Personal Data necessary.

Publish an appropriate and clear privacy notice.

Apply additional safeguards.

Refrain from using children’s Personal Data for unlawful marketing.

If you believe that we have unlawfully received a child’s Personal Data, please contact us so that we can delete it or take other appropriate action.

27. Automated Decisions and Fraud Prevention

The Platform may use technical rules or automated tools to assist with:

Detecting suspicious login attempts.

Identifying unusual activity.

Detecting misuse of Platform features.

Monitoring transactions or Orders that may involve fraud.

Protecting the Platform, Merchants, and Customers.

These tools may result in a request for additional verification or a temporary restriction on certain functions.

Where a decision has a significant effect, we seek to provide human review or a means of objection where required by law.

28. We Do Not Sell Personal Data

Eftah Shop does not sell the Personal Data of Merchants, Customers, or users.

We do not share Personal Data with advertisers or other parties for their own independent use unless there is appropriate consent or another clear legal basis.

Where such sharing applies, it will be clearly disclosed.

29. Changes to this Privacy Policy

We may update this Policy where:

New services or features are introduced.

The way Personal Data is processed changes.

New Service Providers are engaged.

Legal requirements change.

Security and privacy procedures are improved.

We will publish the updated version and state the date on which it was last updated.

Where a change is material, we may send a notice through email, the Dashboard, or the website before the change takes effect.

Continued use of the Platform after an updated Policy takes effect constitutes acknowledgement of the updated Policy, without prejudice to situations requiring new consent.

30. Applicable Law

The Processing of Personal Data is subject to the laws and regulations applicable to the Platform operator, the relevant Data Subject, and the location in which the services are provided.

Depending on the circumstances, applicable laws may include:

Personal Data protection laws in the Arab Republic of Egypt.

The Personal Data Protection Law and its implementing regulations in the Kingdom of Saudi Arabia.

E-commerce and consumer-protection laws.

Financial and tax laws.

Requirements imposed by Payment Providers and regulatory authorities.

If any provision of this Policy conflicts with a mandatory legal requirement, that mandatory legal requirement will apply to the extent of the conflict.

31. Contact Us

For enquiries or requests relating to this Policy or your Personal Data, you may contact us through:

Trade Name: Eftah Shop

Contact Page: https://eftahshop.com/contact


Is your store ready for the next step?

Start with an Arabic platform that brings launch, customization, sales, and insights into one clear experience.