MUTADID العربية

Privacy Policy

Last updated: 2026-09-30

Draft for review — not yet approved by the owner or reviewed by counsel. Red markers are decisions required before publication.
This document covers the MUTADID platform and the MUTADID account, and:
  • the متجر متعدد app (com.mutadid.store)

MO7AMI and its app have their own document: mo7ami.site/privacy

1. Who we are

MUTADID is a platform that runs independent systems for businesses — stores and others — each in its own isolated space.

2. Our role and the business's role

Each business owner (for example, a store owner) collects their customers' data in order to sell or serve — orders, addresses, customer records — and decides how it is used. We host, secure and run the service on their behalf. For the MUTADID account itself (how you sign in to the platform), we are responsible.

No business can reach another business's data: each store sees only its own customers and orders.

3. Your MUTADID account (single identity)

One account for everything that is yours on the platform. It holds:

4. Security and operations data

We record what is needed to protect accounts and the service: sign-in attempts and their results, IP address (or a fingerprint derived from it for rate limiting), the browser type when some public forms are submitted, and an audit log of administrative and sensitive actions. The purpose is detecting abuse and intrusion attempts, not tracking people.

5. Messages and notifications

6. Cookies

Strictly necessary cookies only: the sign-in session cookie and the form-forgery protection cookie (CSRF). Our delivery and protection provider (Cloudflare) may set a necessary security cookie. No advertising or analytics cookies.

7. No ads, no tracking

The platform and its apps contain no advertising tools, no usage analytics, no third-party tracking, and we do not currently use an external crash-reporting service — server errors are logged on our own servers. We do not sell your data or share it for marketing or advertising.

8. Who can access data

9. Retention

Temporary technical records are deleted automatically every day:

Account data is kept while the account exists. Security and audit logs, the message log, read notifications and backups: They are kept to protect and document the service and have no automatic deletion today; backups rotate automatically: the last 7 on the server and 14 off-site.

10. Your rights

You can ask to access, correct or delete your data. For deletion use the account deletion page — it opens without signing in. We reply within 7 days and carry out a verified deletion request within 30 days at most.

11. Children

The platform and its apps are not directed to children, and we do not knowingly collect their data. Using them requires the age of majority and the legal capacity to contract under the applicable law.

12. Data transfers

Some data may be processed outside your country by the providers listed above (for example the email provider in the European Union and Cloudflare's global network). The service's data is stored with the hosting provider, whose servers may be outside your country.

13. Changes and contact

We may update this document; the last-updated date is shown at the top. Contact about your data: [email protected].

متجر متعدد app addendum

The متجر متعدد app (com.mutadid.store) is one app with two experiences: the customer browses the platform's stores, orders, uploads payment proof and leaves reviews; the merchant manages their store's orders, payments, products and stock. This addendum also covers the stores' web storefronts.

Customer data

  • Account: sign-in with a code sent to your email, with Google, or with Apple on iOS (section 3).
  • Your record at each store you buy from: name, phone, email, WhatsApp number if you give it, and notes the store may write. Each store has its own separate record and cannot see your record at another store.
  • Orders: your contact details as entered at order time, the products with quantities, prices, discounts and coupons, your notes, and the order's status history. When delivery applies: name, phone, governorate, city, address, landmark and delivery notes.
  • Cart: your cart is linked to your account, or to an anonymous token in your browser if you are not signed in. The store sees the number and total value of abandoned carts; we send you no messages about them.
  • Payment: the platform does not process cards or receive money. You pay the store directly using the method it lists (for example InstaPay, Vodafone Cash, bank transfer, cash). We record what you declare: method, amount, transaction reference, and the store's review status.
  • Payment proof: an image (JPG, PNG or WEBP) or a PDF up to 5 MB that you choose. It is stored in private, unpublished storage under a random internal name, with its fingerprint and original name, and is seen by the store you ordered from so it can review the payment.
  • Reviews: only buyers of a product can review it. We store the rating (1–5), the text and the display name; the review is shown publicly on the product page after the store approves it, and the store may reply publicly.
  • Notifications: email when your order is placed, when payment is confirmed or rejected, and at fulfilment steps; a notifications inbox in your account; and phone notifications once enabled (section 5), which you can turn off in your device settings.

Merchant data

  • Store owner and team: name, email, phone, hashed password, roles and permissions.
  • Store: its name and address on the platform (subdomain or custom domain), branding, products, images and prices — these are public on the storefront.
  • Payment methods you list for your customers (for example a wallet number or InstaPay handle) — shown to your customers at payment.
  • Your store's platform subscription: plan, subscription orders and invoices — payment is confirmed manually.
  • You are responsible for your customers' data: use it to fulfil and serve their orders, under the Terms of Service.

What the app sends from your device

  • A random installation identifier the app generates on first launch to tell its copy apart on your device — not your device ID and not an advertising ID.
  • OS type (Android/iOS), app version, interface language and the app identifier.
  • The device notification token — once notifications are enabled.

The app does not collect your device model, your location or your contacts.

Permissions

  • Android: internet access and showing notifications. Google's sign-in and notification libraries add normal technical permissions that grant no access to your data.
  • Choosing a payment-proof file uses the system file picker: the app receives only the file you pick, with no storage or photos permission.
  • iOS: "Add to Photos" permission only when you choose to save a file you share.
  • No camera, no location, no contacts, no microphone.

What is stored on your phone

Your session token is stored encrypted in the system key store, together with the installation identifier. Backup and device-to-device transfer are disabled in the Android build, and uninstalling the app erases this data from the device. Signing out also revokes the session on the server.

Retention of store data

Orders, payments and payment proofs are the store's sales records and are kept while the store exists; when a store is permanently deleted, they are deleted with it. Deleting a customer account erases the customer's profile at the stores and unlinks their orders from the account, but does not delete these records (account deletion). They have no automatic deletion today and their contact details are not masked after a period: the store needs them as the accounting record of its sales.