This policy explains how the Safqi platform collects, uses and protects data — both merchants' data and the data of their stores' buyers.
The Arabic text of this policy is the authoritative version. This English translation is provided for convenience; in case of conflict, the Arabic prevails.
1. Our role in processing
We handle two distinct kinds of data, and our role differs between them:
| Kind of data | Our role | Merchant's role |
|---|---|---|
| Merchant account, staff, billing and platform-usage data | Controller | Data subject |
| Store buyers' data (the merchant's customers, orders, addresses) | Processor on the merchant's behalf | Controller |
Put plainly: your store's customer data belongs to you. We process it on your behalf and only as far as operating the service requires. You determine the purpose of its use, and you are the one obliged to inform your customers and obtain their consent where required.
2. Data we collect
2.1 Merchant and staff data
Name, email, phone number, password (stored as a one-way hash), passkeys if enabled, roles and permissions, and application access tokens.
2.2 Store and settings data
Store name, logo and domain; business details, address and coordinates; contact numbers and social accounts; shipping, payment and notification settings; and search-engine metadata.
2.3 Store buyers' data
Name, phone number, email, addresses (including city, district and geographic coordinates when picked on the map), order and cart history, loyalty points, memberships, product questions, and device tokens for notifications.
2.4 Billing and payment data
Plan, subscription and its cycle; payment history and references; wallet transactions; manual transfer receipts you upload; and plan credit and referral grants.
We do not store bank card numbers or their security codes; they are entered at the payment gateway directly and never pass through our servers.
2.5 Usage and analytics data
Store and page visits, the administrative activity log (who did what and when), AI usage records, WhatsApp message records, and technical error logs.
2.6 Technical data
IP address, browser and device type, operating system, and request timestamps.
3. Why we process this data
- Operating the service: creating and serving the store, processing orders and carts, managing accounts and permissions.
- Performing the contract: subscriptions, billing, collection of amounts due, and settlement.
- Communication: system notifications, order status, renewal and limit alerts, and answering your enquiries.
- Security and fraud prevention: detecting unlawful use, protecting accounts, and investigating reports.
- Improvement: measuring performance and developing features, using aggregated data wherever possible.
- Legal compliance: responding to competent authorities and meeting accounting requirements.
4. Artificial intelligence
When you use any AI-backed feature, data from your store is sent to an external model provider for processing and return of the result:
- Generating or translating a product description: that product's data.
- Report analysis: aggregated sales and performance figures.
- The smart command assistant: depending on the command you type, it may read customer, order and product data from your store in order to answer you or to propose an action for you to confirm.
- Image analysis: the image you upload.
This happens on your instruction and does not run automatically in the background, except through automation tasks that you enable yourself. Every call is recorded in the usage log.
5. Service providers (sub-processors)
We rely on external providers to run parts of the service, and share with them only what is necessary:
| Provider | Purpose | What is shared |
|---|---|---|
| Cloud hosting provider | Running servers, storage and backups | All service data |
| AI model provider | Delivering AI features | As set out in clause 4 |
| WhatsApp messaging provider | Sending verification, order status and broadcast messages | Recipient phone number and message content |
| Push notification service | Browser and app notifications | Device token and notification content |
| Payment gateways (APS, ZainCash, Qi Card) | Processing payments | Transaction amount and reference, and payer details held at the gateway |
| Geocoding and maps service | Converting an address to coordinates and displaying maps | Address text or coordinates |
| Integrated shipping companies | Creating and tracking shipments | Recipient details, address and collection amount |
| Exchange rate service | Updating currency rates | No personal data shared |
| Code hosting platform | Verifying theme developers' identity | Developer's public account details |
These providers may process data outside Iraq. We contract with them on terms requiring them to protect the data and use it solely for the purpose of the service.
6. When we disclose data
We do not sell, rent or trade your data or your customers' data. We disclose it only:
- to you or someone you authorise;
- to the service providers listed above, to the extent necessary;
- to competent authorities under a court order or legal obligation;
- to protect rights or prevent fraud or imminent harm;
- in a merger or acquisition, with prior notice to you and with this policy continuing to apply to the transferred data.
7. Third-party apps and themes
When you install an app or theme from an independent developer, it may access data from your store according to the permissions disclosed at installation. That developer's processing is then governed by their own policy, and we are not responsible for it. Review an app's permissions before installing it.
We apply a Content Security Policy to the storefront that limits any theme's ability to send data to external parties.
8. Cookies and local storage
We use:
- Session cookies: necessary for signing in and maintaining the session; these cannot be disabled.
- Language preference cookie: stores the display language chosen in the storefront.
- Browser local storage: stores interface preferences and a referral code when arriving via an invitation link.
- CSRF protection: necessary for security.
You can delete these from your browser settings, bearing in mind that deleting essential cookies will break sign-in.
9. Retention
- Account and store data: for as long as the account exists.
- Accounting and payment records: for the period required by Iraqi law after the relationship ends.
- Activity and usage logs: for a reasonable operational period, then summarised or deleted.
- Backups: rotated periodically; deleted content may persist in them until their cycle expires.
Expiry of a subscription alone does not mean your data is deleted.
10. Your rights
You have the right to:
- access the personal data we hold about you;
- correct any inaccurate data (most data is editable directly from the admin panel);
- delete data, to the extent this does not conflict with a legal or accounting obligation;
- obtain a copy of your data;
- object to a particular processing activity or withdraw consent previously given.
Important note: the admin panel does not currently offer a full data-export button or a permanent account-deletion button. These requests are handled manually by writing to [[SUPPORT_EMAIL]]; we respond within a reasonable period after verifying your identity.
If you are a buyer from one of the stores, direct your request to the store itself, as it is the controller of your data; if that does not resolve it, contact us and we will assist as needed.
11. Data security
- Full transport encryption over HTTPS.
- Passwords stored as one-way hashes, with passkeys supported as a stronger alternative.
- Each store's data isolated from every other at the database level, so no store can reach another's data.
- Sellable digital files stored in a private, non-public area, downloadable only through a signed single-use link.
- Fine-grained permissions for team members, and an activity log recording sensitive operations.
- A Content Security Policy on the storefronts.
Even so, no system on the internet can be guaranteed absolutely secure. Protecting your credentials and managing your team's permissions is your responsibility.
12. Breach notification
If a breach occurs that is likely to materially affect your data, we will notify you without undue delay by registered email or through the admin panel, setting out the nature of the breach, the data affected, the steps taken, and what we recommend you do.
13. Children
The platform is aimed at adult merchants and we do not knowingly collect data from anyone under 18. If we learn that such data has been collected, we delete it.
14. Changes to this policy
We may update this policy. The updated version is published here with its version number and effective date, and we notify you of material changes in advance.
15. Contact
For any privacy enquiry or request:
- Email: [[SUPPORT_EMAIL]]
- Address: [[ADDRESS]]