Privacy Policy
What Bena’a collects, what we do with it, and who sees it. Written against what the software actually does.
Last updated: 2026-09-18
Who we are, and the two kinds of data here
Bena’a lets a merchant build an online store and sell from it. Two different groups of people have data on the platform, and they are treated differently:
- Merchants — people who open an account and build a store. We are the controller of that data.
- Shoppers — people who buy from a merchant’s store. That data belongs to the merchant; we store and process it on their behalf.
Merchant data
When you open an account we collect your name, your email address, and your phone number if you provide one. If you sign in with Google we receive your name, your email address and your Google account identifier — and nothing else. We never ask for or receive your Google password, and we request no permission to read anything from your Google account.
Passwords are stored hashed with argon2, which cannot be reversed. Nobody here can read yours, and that is deliberate: if you forget it we send you a link to set a new one, because we cannot tell you the old one.
We use this to sign you in, to notify you about your store and its orders, and to answer you when you contact us.
Shopper data
When someone buys from a store on Bena’a, we store their name, phone number, address and governorate — and their email address if they gave one. That is what an order needs to arrive.
We also store the basket before it becomes an order, along with whatever was typed into the checkout form, so the merchant can follow up with someone who left without buying. That reaches only the merchant whose store it was — no other merchant, and not us.
We do not sell anyone’s data, and we do not use a merchant’s customers to market anything of our own.
Third-party services
A merchant can connect their store to other services from the App Center. When they do, data goes to that service under its policy rather than ours. The services that can be connected today:
- Google Analytics, the Meta Pixel and Google Ads — browsing and purchase events, so the merchant can measure their advertising.
- Klaviyo and Mailchimp — a shopper’s email and phone, so the merchant can message them.
- Paymob and Kashier — when a shopper pays by card. Card numbers are entered on the provider’s own page and never pass through or rest on our systems.
- WhatsApp (Meta) — when the merchant sends an order confirmation or an update.
Cookies and local storage
We use browser storage to remember your basket, that you are signed in, and the language you chose. None of it is advertising; without it the site does not work.
If a merchant has connected analytics or a pixel, those tools set cookies of their own. Those belong to them and are governed by their policies.
How long we keep things
Account and store data is kept while the account is active. Orders are kept because they are the merchant’s commercial and accounting record.
If you close your account we delete the store and its data. Orders may be retained for a period for accounting and legal reasons.
Your rights
You can ask for a copy of your data, for it to be corrected, or for it to be deleted. Email the address below and we will respond.
If you are a shopper who bought from a store on Bena’a, that request goes to the merchant first, because the data is theirs — and we help them carry it out.
Security
All traffic to the platform is encrypted. Passwords are hashed irreversibly, and payment receipts are stored in a location that is never served publicly.
That said: no system is completely secure, and we will not tell you otherwise.
Contact
For any question about this policy or your data: support@benaa.store