سهّلها
سياسة الخصوصية
آخر تحديث: 1 تشرين الأول 2026
تشرح هذه السياسة ما نجمعه من بيانات عندما تستعمل تطبيق سهّلها والمتاجر الإلكترونية المبنية عليه، ولماذا نجمعه، ومع من نشاركه، وكيف تتحكّم به. ونحن هنا تعني سهّلها. نصف في هذه الصفحة ما يحدث فعلاً في أنظمتنا، ونحدّثها كلّما تغيّر شيء منه.
1. من نحن ولمن هذه السياسة
سهّلها منصّة عراقية تساعد التاجر على استلام طلباته من واتساب وإنستغرام وماسنجر وتيك توك وشوبيفاي ومن متجره الإلكتروني، وترتيبها، وإرسالها لشركات التوصيل. نستعمل في هذه السياسة ثلاث كلمات:
- «التاجر»: صاحب الحساب في التطبيق، ومعه الموظّفون الذين يدعوهم.
- «الزبون»: من يطلب من التاجر أو يراسله عبر حساباته المربوطة أو متجره الإلكتروني.
- «الزائر»: من يتصفّح متجراً إلكترونياً مبنياً على سهّلها.
بيانات الزبائن تخصّ التاجر، وهو المسؤول عنها أمام زبائنه. نحن نعالجها نيابةً عنه ولغرض واحد: تقديم الخدمة التي طلبها.
2. ما نجمعه عنك كتاجر
- بيانات الحساب: اسمك، ورقم هاتفك، وبريدك الإلكتروني، وكلمة السرّ، وصورة حسابك إن رفعتها.
- بيانات المتجر: اسم المتجر ورابطه، وهاتفه، ونوع البضاعة، والمحافظة والمنطقة والعنوان، والشعار، وروابط حساباتك، والسياسات التي تكتبها لمتجرك.
- الموقع الجغرافي: فقط عندما تطلب تحديد نقطة استلام الطلبات، وبعد إذنك. نحفظ الإحداثيات مع متجرك لتستعملها شركة التوصيل، ولا نتتبّع موقعك بعدها.
- المنتجات والصور: أسماء المنتجات وأوصافها وأسعارها ومخزونها وصورها. نزيل من الصورة بيانات الموقع والكاميرا المضمّنة فيها قبل حفظها، والصور التي ترفعها تظهر للعامّة في متجرك.
- الحسابات التي تربطها: عند ربط فيسبوك أو إنستغرام أو واتساب للأعمال أو تيك توك أو شوبيفاي نحفظ رموز الوصول التي تمنحنا إيّاها تلك المنصّة، ومعرّفات صفحاتك وحساباتك الإعلانية وبكسلاتك، وأرقام إنفاقك الإعلاني لنعرضها في لوحة الأداء.
- حسابات شركات التوصيل: اسم المستخدم وكلمة السرّ أو مفتاح الربط الذي تدخله، أو بيانات الحساب الذي نفتحه لك.
- الاشتراك والمدفوعات: باقتك، وفواتيرك، ومبلغ كل دفعة وحالتها ورقمها المرجعي. لا نستلم رقم بطاقتك ولا نحفظه.
- جهازك: رمز الإشعارات ونوع النظام (iOS أو Android)، ومعرّف عشوائي يولّده التطبيق. نسجّله مع رقم هاتفك ومعرّفات الحسابات التي تربطها لحماية التجربة والباقة المجانية من إساءة الاستعمال.
- الدعم: رسائلك مع فريق الدعم داخل التطبيق.
- الموظّفون: أرقام من تدعوهم لمتجرك وصلاحياتهم.
- السجلّات التقنية: وقت آخر دخول، وسجلّات في خوادمنا لتشخيص الأعطال وحماية الخدمة، وقد تحتوي على أرقام هواتف أو عناوين IP.
كلمة السرّ: نحفظها بصيغة مجزّأة (hash) للتحقّق من دخولك، لا بنصّها. ونحفظ معها نسخة مشفّرة في مكان محميّ منفصل لا يصل إليه التطبيق، نستعملها عندما نفتح لك حساباً لدى شركة توصيل حتى تدخله بنفس كلمة السرّ.
3. ما نعالجه عن زبائنك
تصلنا هذه البيانات لأنك ربطت حساباتك أو فتحت متجرك الإلكتروني، ونعالجها لتقديم الخدمة لك فقط، كما في قسم «لماذا نستعمل البيانات»:
- بيانات الطلب: اسم الزبون، ورقم هاتفه، ومحافظته ومنطقته وعنوانه التفصيلي، والمنتجات والكمية والسعر، وملاحظاته.
- المحادثات: الرسائل والتعليقات والإشارات التي تصل لواتساب وإنستغرام وفيسبوك المربوطة بمتجرك، ومعها اسم المرسل ورقمه أو معرّفه، لنستخرج منها الطلبات. وعند ربط صفحة فيسبوك نستورد أيضاً محادثات ماسنجر وإنستغرام لآخر 30 يوماً، لتظهر في إحصاءات لوحة الأداء.
- نماذج تيك توك: ما يكتبه الزبون في نموذج الطلب داخل إعلانك.
- طلبات شوبيفاي: بيانات الطلب كما يرسلها متجر شوبيفاي المربوط.
- السلّات المتروكة: إذا بدأ الزبون بكتابة بياناته في صفحة الطلب ولم يكمله، نحفظ ما كتبه لتتمكّن من متابعته.
- الشحن والتتبّع: رقم الشحنة وحالتها، واسم المندوب ورقمه كما تصلنا من شركة التوصيل.
4. زوّار المتجر الإلكتروني والكوكيز
- إحصاءات الزيارة: مفتاح جلسة عشوائي، والصفحات التي زارها، ونوع الجهاز، والدولة والمحافظة والمدينة التقريبية التي تستنتجها Cloudflare من عنوان IP، ومصدر الزيارة وروابط الحملات، ومقاييس سرعة الصفحة. لا نحفظ عنوان IP في سجلّ الزيارات.
- عند إتمام الطلب: نحفظ مع الطلب عنوان IP ونوع المتصفّح (راجع «مدّة الاحتفاظ»)، ومعرّفات نقرة الإعلان (مثل fbc وttclid) وتبقى مع الطلب ما دام محفوظاً. نستعملها لربط الطلب بالإعلان الذي جاء منه الزبون.
- التخزين في المتصفّح: نحفظ سلة التسوّق ومفتاح الجلسة في متصفّح الزائر نفسه.
- كوكيز قياس الإعلانات: نضع ملفات تعريف باسم _fbp و_fbc و_ttp و_tc تبقى حتى 90 يوماً، وتحمل معرّفات يستعملها قياس إعلانات ميتا وتيك توك.
- إذا ربط التاجر بكسل ميتا أو تيك توك بمتجره الإلكتروني، نرسل من خوادمنا لحسابه الإعلاني أحداث التصفّح والسلة والطلب، ومعها عنوان IP ونوع المتصفّح، وبيانات مجزّأة (hash) مثل هاتف الزبون واسمه ومحافظته متى كتبها في صفحة الطلب ولو لم يكمله. ولا نحمّل في صفحات المتجر أي سكربت إعلاني من طرف ثالث.
- يستطيع الزائر حذف الكوكيز وبيانات المواقع من إعدادات متصفّحه في أي وقت.
5. لماذا نستعمل البيانات
- تشغيل الخدمة: استلام الطلبات وترتيبها، وإرسالها لشركات التوصيل، وطباعة البوليصات، وعرض متجرك الإلكتروني وصفحة الطلب.
- حماية حسابك: إرسال رمز التحقّق إلى واتساب رقمك عند التسجيل والدخول، وكشف إساءة الاستعمال.
- الإشعارات: تنبيهك بالطلبات والرسائل وردود الدعم على جهازك.
- رسائل التتبّع: مفعّلة افتراضياً عند إرسال الطلب لشركة التوصيل. نرسلها لزبونك من رقم واتساب سهّلها الرسمي باسم متجرك، وفيها اسمه الأوّل والمنتجات والسعر والعنوان، وزرّ يرسل له رابط صفحة يتابع منها طلبه. وإذا ردّ الزبون عليها أو ضغط أحد أزرارها تصلنا ردوده، ونحفظ رقمه ووقت ردّه لنعرف متى يسمح واتساب بمراسلته. تستطيع إيقافها أو جعلها يدوية من «الإعدادات» ثم «تتبع الطلبات». نرسلها نيابةً عنك بالتخويل الذي تمنحنا إيّاه في شروط الاستخدام، وأنت مسؤول عن أن يكون لك حقّ التواصل مع زبائنك.
- قياس الإعلانات: عند ربط صفحاتك وحساباتك في ميتا أو حسابك الإعلاني في تيك توك نرسل لها تلقائياً أحداث محادثات الإعلانات والطلبات وتوصيلها، وإذا ربطت بكسلاً بمتجرك الإلكتروني نرسل له أحداث التصفّح والطلب، لتقيس المنصّة نتائج إعلاناتك. يتوقّف الإرسال بفصل المنصّة.
- الإحصاءات: عرض أداء متجرك ومبيعاتك في التطبيق.
- الدعم وإصلاح الأعطال وتحسين الخدمة.
لا نبيع بياناتك ولا بيانات زبائنك لأي جهة.
6. الذكاء الاصطناعي
نستعين بخدمة Gemini من Google لقراءة نصوص الرسائل ونماذج تيك توك والإعلانات، واستخراج تفاصيل الطلب منها مثل المنتج والكمية والسعر والاسم والعنوان، ولمطابقة عنوان الزبون مع مناطق شركة التوصيل. نرسل لها النصّ الذي تحتاجه المهمّة فقط، وفي وقتها.
راجع الطلب المستخرج آلياً قبل إرساله لشركة التوصيل، ويمكنك تعديله من التطبيق. لا نستعمل بياناتك لتدريب نماذج ذكاء اصطناعي خاصّة بنا، ونستعمل Gemini بحساب مدفوع باسم المنصّة، وبحسب شروط Google لهذا الحساب لا تُستعمل البيانات المرسلة لتحسين نماذجها.
8. أين تُحفظ البيانات وكيف نحميها
- تُحفظ البيانات خارج العراق: قاعدة البيانات لدى Supabase في فرانكفورت، وخوادمنا في الاتحاد الأوروبي، والصور والنسخ الاحتياطية لدى Cloudflare. وتصل صفحات المتاجر الإلكترونية لزوّارها حول العالم عبر شبكة Cloudflare.
- الاتصال بين التطبيق والمتجر وخوادمنا مشفّر (HTTPS).
- كل تاجر لا يصل إلا لبيانات متاجره، بقواعد مفروضة في قاعدة البيانات وفي الخادم.
- رموز الوصول لمنصّات ميتا وتيك توك وشوبيفاي لا يعرضها التطبيق ولا المتجر، ويستعملها خادمنا وحده. أمّا بيانات دخولك لحسابك لدى شركة التوصيل فتظهر داخل حسابك في شاشة «شركة التوصيل» لتستعملها، ولا تظهر لأي تاجر آخر.
- النسخ الاحتياطية مشفّرة.
لا يوجد نظام على الإنترنت محميّ تماماً، لذلك نراجع إجراءات الحماية ونطوّرها باستمرار. وإذا وقع حادث أمني يمسّ بياناتك سنبلغك به.
9. مدّة الاحتفاظ
- بيانات حسابك ومتجرك وطلباتك وبيانات زبائنك، ومعها ما يُحفظ مع طلبات المتجر الإلكتروني (عنوان IP ونوع المتصفّح ومعرّفات نقرة الإعلان) وجلسات صفحة الطلب: نحتفظ بها ما دام حسابك قائماً، وتُحذف عند حذف الحساب.
- كوكيز قياس الإعلانات في متصفّح الزائر: تنتهي خلال 90 يوماً من آخر زيارة.
- جلسات الزيارة: تُدمج تفاصيلها في إحصاءات يومية بعد انتهاء الجلسة، وتُحذف الإحصاءات اليومية بعد 30 يوماً، وتبقى الجلسات التي انتهت بطلب حتى 24 شهراً.
- النسخ الاحتياطية: نسخة يومية تبقى 7 أيام، وأسبوعية تبقى 4 أسابيع، وشهرية تبقى 12 شهراً. لذلك قد تبقى بيانات حذفتها في نسخة احتياطية مشفّرة حتى 12 شهراً ثم تزول تلقائياً. لا نستعمل النسخ إلا لاسترجاع الخدمة بعد عطل.
10. حذف الحساب
تستطيع حذف حسابك بنفسك من داخل التطبيق: من «الإعدادات»، ثم «الدعم»، ثم «حذف الحساب» بآخر الصفحة. الحذف فوري ونهائي ولا يمكن التراجع عنه.
عند الحذف:
- تُحذف متاجرك ومتجرك الإلكتروني ورابطه، ومنتجاتك وصورها، وطلباتك وبيانات زبائنك ومحادثاتهم.
- يُفصل ربط واتساب وإنستغرام وفيسبوك وتيك توك وشوبيفاي، وتُحذف رموز الوصول المحفوظة عندنا.
- تُحذف بيانات حسابات التوصيل المحفوظة عندنا، ويتوقّف وصول موظّفيك.
- نحتفظ بسجلّ الفواتير والمدفوعات دون اسمك أو رقم هاتفك، للأغراض المحاسبية.
- حسابك لدى شركة التوصيل ومبالغ الدفع عند الاستلام تبقى لديها، فسوِّها معها مباشرةً. وما أرسلناه سابقاً لميتا أو تيك توك أو شركات التوصيل تحكمه سياساتها.
- الأيام المتبقّية من باقتك لا تُسترجع، إلا بحسب سياسة الاسترجاع في شروط الاستخدام.
- تزول بقايا بياناتك من النسخ الاحتياطية خلال 12 شهراً كحدّ أقصى، كما في «مدّة الاحتفاظ».
إذا لم تستطع دخول التطبيق، راسلنا من رقمك المسجّل وسنحذف الحساب بعد التحقّق من ملكيّته.
لفصل منصّة واحدة دون حذف الحساب: من «الإعدادات» ثم «ربط المنصات». عند الفصل نحذف رموز الوصول ومعلومات الصفحات والحسابات الإعلانية المرتبطة بها.
11. حقوقك وخياراتك
- الاطّلاع والتصحيح: تجد أغلب بياناتك في التطبيق وتستطيع تعديلها، ولأي بيان آخر راسلنا.
- الحذف: احذف حسابك كاملاً كما في القسم السابق، أو اطلب منّا حذف بيانات محدّدة.
- الأذونات: تستطيع سحب إذن الموقع والإشعارات من إعدادات جهازك في أي وقت.
- رسائل التتبّع لزبائنك: مفعّلة افتراضياً، وتستطيع إيقافها أو جعلها يدوية من «الإعدادات» ثم «تتبع الطلبات».
- الربط: افصل أي منصّة من «الإعدادات» ثم «ربط المنصات».
إذا كنت زبوناً لأحد المتاجر: تواصل مع التاجر نفسه لطلب الاطّلاع على بياناتك أو تصحيحها أو حذفها، فهو صاحبها. وإذا لم تستطع الوصول إليه، راسلنا وسنوصل طلبك له أو نساعدك.
12. الأطفال
سهّلها خدمة للتجّار، ولا يجوز فتح حساب لمن هو دون 18 سنة. لا نجمع عن قصد بيانات أطفال، وإذا علمنا أن حساباً يعود لقاصر سنحذفه.
13. تغيير هذه السياسة
قد نحدّث هذه السياسة عندما تتغيّر الخدمة أو القانون. ننشر النسخة الجديدة هنا مع تاريخ التحديث، وإذا كان التغيير جوهرياً نبلغك عبر التطبيق قبل سريانه.
14. تواصل معنا
لأي سؤال عن خصوصيتك أو طلب يخصّ بياناتك:
- الدعم داخل التطبيق: من «الإعدادات» ثم «الدعم».
- واتساب: +964 770 750 6269
- البريد الإلكتروني: main@shlha.io
- العنوان: النجف، العراق
Privacy Policy (English)
Last updated: 1 October 2026
This is the English version of the Shlhaa privacy policy. It describes the same practices as the Arabic policy above; if the two ever conflict, the Arabic text prevails.
1. Introduction
Welcome to Shlhaa (سهّلها, also written “Sahelha”; “we”, “us”, “the Service”). We are committed to protecting your privacy and the security of your data. This Privacy Policy explains how we collect, use, and protect information when you use the Shlhaa app and the online stores built on it, across connected platforms including WhatsApp, Instagram, Facebook Messenger, TikTok, and Shopify.
Shlhaa is used by merchants (store owners and the staff they invite) to receive and manage their orders. The data of a merchant’s customers belongs to that merchant; we process it on the merchant’s behalf and only to provide the service the merchant requested.
By using Shlhaa, you agree to the practices described in this policy.
2. Data We Collect
We collect only the data necessary to process orders, provide delivery services, and run the merchant’s store:
- Order Data: Recipient name, phone number, email (when provided), address (province, district, area, detailed address, and postal code when provided), product ordered, quantity, price, notes, and payment status, and the shipment number and status and the courier’s name and phone as received from the delivery company. For Shopify stores, this order data is imported automatically from your Shopify orders. For TikTok, it comes from the order form in the merchant’s lead ads. If a visitor starts filling in an online store’s checkout page without completing it, what they typed is saved as an abandoned cart so the merchant can follow up.
- Conversation Data: Messages sent and received, comments, and mentions on the WhatsApp, Instagram, and Facebook accounts a merchant connects, including the replies the merchant sends from those accounts (and, when a connected number also uses the WhatsApp Business app, from that app), with the sender’s name and phone number or platform ID and, where Meta provides them, their username and profile picture. We use them to detect and extract orders, to update an order when the merchant confirms or cancels it in the conversation, and to help the merchant identify the customer. When a Facebook Page is connected, we also import Messenger and Instagram conversations from the last 30 days to show them in the merchant’s performance statistics.
- Posts and Comments: Where comment tools are enabled for a connected account, the posts on that Facebook Page or Instagram account and the comments on them, with each commenter’s name or username, read from Meta to show them to the merchant and, only at the merchant’s request, to reply to, hide, or delete comments or to like content.
- Account Data: Facebook Page ID, Instagram Business Account ID, WhatsApp Business account and phone number IDs, ad account and pixel IDs (Meta and TikTok), Shopify store domain, connected account profile information (name, username, profile picture), and the access tokens these platforms grant us.
- Ad Performance Data: Advertising metrics (impressions, clicks, reach, spend) from connected ad accounts, used solely for merchant analytics.
- Merchant Data: Name, phone number, email, password, profile photo; store details (name, link, phone, business type, province, area, address, logo, links to the merchant’s social accounts, store policies); products and their photos (we remove embedded location and camera data from photos before saving them, and product photos are public in the store); the phone numbers or email addresses of invited staff and their permissions; support chat messages; and subscription and payment records (plan, invoices, amount, status, and reference number).
- Location: Only if the merchant chooses to set a pickup point for orders and grants permission, we collect the device’s precise location (GPS coordinates) and save it with the store for the delivery company. We do not track the merchant’s location after that.
- Delivery Accounts: The username and password or API key the merchant enters for a delivery company, or the details of the delivery account we open for them.
- Device and Technical Data: Push-notification token, operating system (iOS or Android), and a random identifier generated by the app, stored with the merchant’s phone number and connected account IDs to protect the free plan from abuse; last login time; and server logs used to diagnose faults and protect the service, which may contain phone numbers, IP addresses, platform IDs, or short excerpts of messages.
- Online Store Visitors: A random session key, pages visited, device type, approximate country, province, and city derived by Cloudflare from the IP address (the IP address itself is not saved with visits), traffic source and campaign parameters, and page-speed metrics. At checkout, the IP address, browser user agent, and ad click IDs (such as fbc and ttclid) are saved with the order. Stores set first-party cookies named _fbp, _fbc, _ttp, and _tc (up to 90 days) used for Meta and TikTok ad measurement, and keep the cart and session key in the visitor’s browser. Store pages do not load any third-party advertising script, and visitors can delete cookies and site data in their browser settings at any time.
Passwords are stored as a one-way hash for login. We also keep an encrypted copy in a separate protected store that the app cannot reach, used only to open delivery-company accounts for the merchant with the same password. We do not receive or store bank card numbers or banking information: subscription payments are entered directly on our payment provider’s (Wayl) page.
3. How We Use Data
We use collected data exclusively for:
- Processing and recording orders in our order management system.
- Sending orders to approved delivery companies for fulfillment, and printing shipping labels.
- Sending order confirmation or cancellation notifications to merchants.
- Displaying customer names and profile information to help merchants identify customers.
- Providing advertising performance analytics to merchants.
- Preparing daily performance summaries for merchants.
- Verifying the merchant’s phone number with a one-time code sent on WhatsApp at sign-up and login, and detecting abuse.
- Notifying the merchant’s device about orders, messages, and support replies.
- Order tracking messages: when an order is sent to a delivery company, we send the merchant’s customer a WhatsApp message from Shlhaa’s official number on behalf of the store, with the customer’s first name, the products, price, and address, and a button that sends a link to a tracking page. If the customer replies or taps a button, we receive the reply and save their number and reply time to know when WhatsApp allows messaging them. This is on by default; the merchant can turn it off or make it manual in Settings → Order Tracking (الإعدادات ← تتبع الطلبات). We send these messages on the merchant’s behalf under the authorization the merchant gives us in the Terms of Service, and the merchant is responsible for having the right to contact their customers.
- Measuring the merchant’s own ads, as described in “Data Sharing”.
- Support, fixing faults, and improving the service.
Automated order extraction (AI): We use Google’s Gemini service to read the text of messages, TikTok form entries, and ads, to extract order details such as product, quantity, price, name, and address, and to match the customer’s address to the delivery company’s regions. We send only the text a task needs, at the time it is needed. We use Gemini through a paid account under which, per Google’s terms, submitted data is not used to improve Google’s models, and we do not use your data to train AI models of our own. Merchants should review extracted orders, and can edit them, before sending them to a delivery company.
4. Data Sharing
We do not sell your data or your customers’ data to anyone. Each party below receives only what it needs for its role:
- Approved delivery companies: For the sole purpose of delivering orders — the shipment details (customer name, phone, address, products, amount, notes) and the store’s name, phone, and pickup point. When we open a delivery account for a merchant: the merchant’s name, store name, phone, email, business type, address, location, and the account’s username and password.
- The merchant (store owner) and the staff they authorize: To manage and track their orders, within the permissions the merchant grants.
- Meta (Facebook, Instagram, WhatsApp): To receive messages for the merchant’s connected accounts and send replies from them, and to send verification codes and order tracking messages from Shlhaa’s WhatsApp number.
- Meta ad measurement, on the merchant’s behalf: When a merchant connects a Facebook Page or Instagram account, we create a dataset in the merchant’s own Meta account if it has none. When the store’s plan includes conversion measurement, we send to the merchant’s datasets, through the Conversions API, an event when a customer starts a conversation from an ad or sends their phone number in a conversation, and events for orders, cancellations, and deliveries with the order value. These events include hashed (SHA-256) customer identifiers — phone number, first and last name, gender inferred from the name, province, country, and a customer ID derived from the phone number for that merchant only — and the page-scoped or Instagram-scoped customer ID and ad click ID as provided by Meta. If the merchant connects a pixel to their online store, we send its browsing, cart, and order events from our servers with the IP address, browser user agent, and hashed checkout details (such as phone, name, and province) once the visitor types them, even if the order is not completed. This data goes only to the merchant’s own ad accounts, to measure the merchant’s own ads, and it stops when the merchant disconnects the platform.
- TikTok: To receive order forms from the merchant’s lead ads. When a merchant connects their TikTok ad account, we create an event set in it. When the store’s plan includes conversion measurement, we send order status events for lead-form orders with TikTok’s lead ID and the customer’s phone number hashed. If the merchant connects a TikTok pixel to their online store, we send its browsing, cart, and order events from our servers in the same way as described for Meta above (with the IP address, browser user agent, and hashed checkout details). This stops when the merchant disconnects TikTok.
- Shopify: To receive the store’s orders, sync its products, and update fulfillment status.
- Service providers that process data on our behalf, only to provide their services to us: Supabase (database), Hetzner (the servers that run our service), Cloudflare (network, security, image storage, and encrypted backups), Google (Gemini, and Firebase Cloud Messaging for notifications; iPhone notifications also pass through Apple’s push service), Sentry (technical error reports from the store server, configured not to include customer data or order contents), and OpenSRS (domain registration: domains bought through us are registered in Shlhaa’s name, so the merchant’s details do not appear in public WHOIS).
- Wayl: To process subscription and domain payments. Payment details are entered on Wayl’s page directly.
- Holders of an order tracking link: The partially masked customer name, product, province and area, price, delivery company and shipment steps, the store’s name and the merchant’s account phone number, and the courier’s name and phone once the order is out for delivery.
- The Shlhaa team: Authorized staff access a merchant’s account data only when needed, such as answering a support request, fixing a fault, or opening a delivery account.
- Authorities: When required by Iraqi law or a court order.
Delivery companies, Meta, TikTok, Shopify, and Wayl receive data as independent parties, each under its own privacy policy.
5. Data Storage and Security
Order data is stored in secure cloud databases (Supabase, in Frankfurt) with restricted access permissions: each merchant can reach only their own stores’ data, enforced both in the database and on our server. Our own servers (Hetzner) are in the European Union, and images and backups are stored with Cloudflare, so data is stored outside Iraq. Online store pages are delivered to visitors worldwide through Cloudflare’s network. We use encrypted connections (HTTPS) for all data transfers between the app, the online stores, and our servers. Access tokens for Meta, TikTok, and Shopify are stored server-side and never shown in the app or the store; the delivery-company login details a merchant saves are shown only to that merchant, inside their own account. Backups are encrypted.
No system on the internet is completely secure, so we review and improve our safeguards continuously. If a security incident affects your data, we will notify you.
6. Data Retention
- Account, store, order, and customer data: kept while the merchant’s account exists, and deleted when the account is deleted. This includes what is saved with online-store orders (IP address, browser type, ad click IDs) and checkout sessions.
- Access tokens for Meta, TikTok, and Shopify, and the related Page and ad account information: deleted when the merchant disconnects that platform or deletes the account.
- Ad-measurement cookies in the visitor’s browser: expire within 90 days of the last visit.
- Visit sessions: merged into daily statistics after the session ends; daily statistics are deleted after 30 days, and sessions that ended with an order are kept for up to 24 months.
- Backups: daily backups are kept for 7 days, weekly backups for 4 weeks, and monthly backups for 12 months, so deleted data may remain in an encrypted backup for up to 12 months before it disappears automatically. Backups are used only to restore the service after a failure.
7. Your Rights
You have the right to:
- Request access to your stored data.
- Request correction of any inaccurate information.
- Request complete deletion of your data from our systems.
- Withdraw from the service at any time.
Most of your data is visible and editable in the app. You can withdraw the location and notification permissions from your device settings at any time, disconnect any platform from Settings → Platform Connections (الإعدادات ← ربط المنصات), and turn off order tracking messages from Settings → Order Tracking (الإعدادات ← تتبع الطلبات).
To exercise any of these rights, follow the Data Deletion Instructions below or contact us via the email below.
If you are a customer of a store that uses Shlhaa, contact that merchant to access, correct, or delete your data, as the merchant owns it. If you cannot reach the merchant, contact us and we will pass your request on or help you.
8. Data Deletion Instructions
Merchants can delete their account and all its data themselves in the Shlhaa app:
- Open the Online Store tab (المتجر الإلكتروني) and tap More (المزيد).
- Tap Settings (الإعدادات), then Support (الدعم), and scroll to the bottom of the page.
- Tap Delete account (حذف الحساب), then Continue (متابعة), and enter your password.
- Tap Send code (إرسال الرمز); the code arrives on WhatsApp. Enter it, type the word حذف (“delete”), and tap Delete my account permanently (احذف حسابي نهائياً).
Deletion is immediate and permanent and cannot be undone. When an account is deleted:
- Your stores, online store and its link, products and their photos, orders, customer data, and conversations are deleted.
- WhatsApp, Instagram, Facebook, TikTok, and Shopify are disconnected, and the access tokens we hold are deleted.
- Saved delivery-account details are deleted, and your staff lose access.
- Invoice and payment records are kept without your name or phone number, for accounting.
- Your account with the delivery company and any cash-on-delivery amounts remain with that company; settle them with it directly. Data already sent to Meta, TikTok, or delivery companies is governed by their policies.
- The remaining days of your plan are not refunded, except under the refund policy in the Terms of Service.
- Remaining copies in encrypted backups disappear within 12 months at most (see Data Retention).
If you cannot log in to the app, message us from your registered phone number (WhatsApp: +964 770 750 6269) and we will delete the account after verifying ownership.
To disconnect a single platform without deleting your account: Settings → Platform Connections (الإعدادات ← ربط المنصات). When a platform is disconnected, we delete its access tokens and the related page and ad account information.
You can also remove Shlhaa’s access from your Facebook settings (Business integrations) or Instagram settings (Apps and websites). This stops our access to that account; to delete the data we already hold, follow the steps above or contact us.
If you messaged or ordered from a business that uses Shlhaa and want your data deleted, ask that business, or contact us with the business’s name and we will help.
9. Use of Meta Platforms
Shlhaa operates through Meta’s APIs, including the Instagram Graph API, Instagram Messaging API, Messenger Platform, WhatsApp Business Platform, Marketing API, and Conversions API. We comply with all Meta policies regarding data use and user privacy. We use conversation data only to provide the service to the merchant who connected the account: detecting and processing orders, showing the merchant’s own conversation statistics, and measuring the merchant’s own ads by sending conversation and order events to the merchant’s own Meta datasets, as described in “Data Sharing”. Message text may be processed by our service provider Google (Gemini) only to extract order details, as described in “How We Use Data”. We do not sell Platform Data or use it for any other purpose. We use the Human Agent message tag only for legitimate customer service follow-ups beyond the standard 24-hour messaging window.
Where comment tools are enabled for a connected account, we read the posts and comments of that Facebook Page or Instagram account to show them to the merchant, and we reply to, hide, or delete comments, or like content, only at the merchant’s request.
We process Platform Data on behalf of the merchant who connected the account, and only to provide the Service to that merchant as described in this policy. We do not use it to discriminate against people, to make eligibility decisions about them (such as for housing, employment, insurance, or credit), or for surveillance, and we do not try to reverse hashed data. If Meta sends us a request from a person about their data, we pass it to the merchant concerned and help them respond. When a merchant disconnects an account or deletes their Shlhaa account, we delete the related data as described in Data Retention and Data Deletion Instructions.
10. Use of TikTok
Shlhaa connects to TikTok’s APIs to receive order forms from the merchant’s lead ads and, when the merchant connects their ad account, to send order events to the merchant’s own TikTok event set as described in “Data Sharing”. Disconnecting TikTok stops this and deletes the stored access tokens.
11. Use of Shopify Platform
Shlhaa connects to Shopify through the Shopify Admin API to import new orders, sync products, update order status, and write back delivery tracking information. We comply with Shopify’s data protection requirements, including its mandatory compliance webhooks. When a store uninstalls the app and a shop data erasure is requested, we delete that store’s Shopify connection and access tokens; orders already imported belong to the merchant’s Shlhaa account and are deleted with it. When a customer data erasure is requested, we remove that customer’s personal information from the related orders. When a customer data request is received, we make the stored data available to the store owner.
12. Children
Shlhaa is a service for merchants and may not be used by anyone under 18. We do not knowingly collect children’s data; if we learn that an account belongs to a minor, we will delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated “Last updated” date, and we will notify merchants in the app before material changes take effect. We encourage you to review this page periodically.
14. Contact Us
If you have any questions about this Privacy Policy or our data practices:
- Email: main@shlha.io
- WhatsApp: +964 770 750 6269
- In the app: Settings → Support (الإعدادات ← الدعم)
- Support page: shlha.io/support
- Address: Najaf, Iraq
- Website: shlha.io · shlhaa.com