Privacy Policy
Last updated: September 2, 2026
This policy explains how OnlineStores handles information about sellers (people who run stores on the platform) and buyers (people who order from those stores). Individual stores also publish their own privacy pages describing how the seller handles buyer information. We do not sell personal information and we do not use it for third-party advertising.
1. Who is responsible for your data
OnlineStores is operated by Samir Tannoury, an individual sole trader based in Lebanon. For account, service, security, support, and billing operations, the operator decides why and how personal information is processed. Contact: info@altajeronline.com (sellers can also reach us through the dashboard).
When a buyer places an order, the order details are collected for the store the buyer ordered from. The seller who receives them and decides how to use them may also have duties as a separate or joint controller under local law. Buyers may contact OnlineStores first at the email above; we will route a request to the seller where that is necessary.
OnlineStores is funded by seller subscriptions. It has no advertising business.
2. Information we collect from sellers
- Account and sign-in — name, email, account id, and session data supplied through Clerk, using the sign-in method you choose there.
- Store data — everything you enter to run your store: store details, phone and WhatsApp numbers, pickup address, products, images, video links, prices, categories, policies, shipping cities and fees, and settings.
- Staff — the email addresses of people you invite, their role, and the invitation status.
- Billing — plan, payment provider, customer and subscription references, billing status and period dates, and (for manually activated plans) a record of the amount, method, and months paid. For a subscription bought in the mobile app we receive the store's purchase record — the product bought, the transaction identifier, and the renewal or expiry date — through RevenueCat. We do not receive or store your card number; the payment provider or the app store handles it.
- Mobile app — if you use the seller app and allow notifications, the push token issued for that installation, so new-order alerts can reach the device; it is deleted when you sign out or turn notifications off. The app also reports the platform and app version with its requests, and reads your store's own data to show it to you.
- Usage — order counts, share-link clicks by platform (Facebook, Instagram, TikTok, WhatsApp), and product statistics, used to show you your own store analytics and to apply plan limits.
- Emails — operational emails we send you (such as new-order notifications and staff invitations) through our email provider, and their delivery metadata.
- Technical and security data — application and access events, errors, IP-related rate-limit and abuse records, and log metadata generated by the infrastructure.
An account identifier and the minimum store information needed to publish a storefront are required for the seller service; declining an optional item (such as a video link or staff invitation) affects only that feature.
3. Information we collect from buyers
- Order data — when you order, we store your name, phone number, country, city, delivery address, the items ordered, and the link source (such as Facebook or Instagram) on behalf of the store you ordered from, so the seller can confirm, deliver, and support your order. Buyers do not create accounts.
- Order tracking — you can look up your own order with the order number and the phone number used on it.
- WhatsApp contact — the seller confirms orders by messaging you on WhatsApp from the seller's own number. Those messages travel over WhatsApp under WhatsApp's own terms; OnlineStores prepares suggested text but is not a party to the conversation.
- Fraud prevention — phone numbers linked to repeated fake or refused orders may be flagged platform-wide so sellers are protected. Flags affect how orders are highlighted to sellers; they do not block ordering by themselves. Our lawful basis is our and sellers' legitimate interest in preventing order fraud.
- On your device — your cart and language preference are stored in your own browser and reach us only when you place an order. We do not run advertising trackers.
- Technical and security data — standard access logs, including IP address, used for security, rate limiting, and troubleshooting.
For buyers, the order form fields are required to place an order — without them the seller cannot deliver. Nothing else is required.
4. Why we use information and our legal grounds
We use the information above to operate stores and orders, notify sellers, deliver share links with source attribution, administer plans and payments, prevent fraud and abuse, provide support, operate and improve the product, and meet legal obligations.
Where EU, UK, or similar law applies, the ground depends on the person and purpose:
- Contract — to provide a seller account, host the storefront, deliver paid features, administer the seller relationship, and process the subscription.
- Legitimate interests — to record and pass a buyer's order to the store it was placed with; secure and administer the service; prevent fraud and abuse (including the shared phone-number flags); apply limits; show sellers statistics about their own store; and diagnose problems. We must balance each interest against the person's rights and stop or change the processing where those rights override it.
- Consent — only where an applicable law requires consent and we obtain it through a valid choice, for example for a non-essential storage technology.
- Legal obligation — for records or actions required by tax, payment, consumer, security, or other applicable law.
Do not submit health, ethnicity, religion, politics, or other specially protected information, or another person's personal information, in product content, order notes, or support messages; the platform does not need it and does not filter it automatically before storage.
5. AI processing
The current product sends no personal information to AI providers: social-media captions are generated from templates, not by AI. If an AI drafting feature is added later, it would send product details only — never buyer personal information — and this notice will be updated before that happens.
6. Service providers and recipients
Providers change as the product develops. The material services for the current product are:
- Clerk — seller sign-in, identity, and account sessions.
- Resend — operational email delivery (new-order notifications, staff invitations).
- Paddle — subscription payments made on the website. Paddle acts as merchant of record for those transactions and can act as an independent controller for fraud, tax, and legal-compliance purposes.
- Apple and Google — subscriptions bought in the mobile app are sold and charged by the App Store or Google Play under the account signed in on your device. Those stores are independent controllers for the transaction; we see the purchase record, never your payment details.
- RevenueCat — receives and verifies those store purchase records on our behalf, so the right plan is activated for the right store.
- Expo push service, Apple (APNs) and Google (FCM) — delivery of push notifications to the seller app. A notification carries the order number and store name so you know what it is about; buyer contact details are not put in it.
- Hosting and storage infrastructure — the application, database, media files, and logs run on cloud infrastructure (Amazon Web Services for the production deployment). Product images and media are stored in object storage.
Information is otherwise shared only with: the seller you ordered from (your order details); couriers engaged by the seller, for delivery; and authorities, only where the law requires it. Ask us through your dashboard for the current legal entity, role, location, and privacy terms of a particular provider.
7. International transfers
OnlineStores is operated from Lebanon and serves sellers and buyers in the Middle East; hosting and the providers above can process information in other countries, including the United States and Europe. Personal information may therefore leave the country where the seller or buyer is located, including for countries that local law does not consider equivalent. Where a transfer safeguard is legally required, the applicable arrangement may include controller/processor terms, EU Standard Contractual Clauses, the UK Addendum, an adequacy decision or Data Privacy Framework certification, or another valid mechanism covering the actual entity and data flow. Contact us for the mechanism currently relied on.
8. What is public
A published storefront shows the store's name, products, prices, images, policies, and contact details to anyone with the link. Seller emails, buyer orders, statistics, billing details, and private dashboard screens are not public. A storefront link can be forwarded, so published store information should not be treated as confidential.
9. Retention and deletion
- Seller account and store — kept while the account is active. Closing the account removes the store and its content, subject to the items below.
- Orders — order records are kept while needed for operations, disputes, and bookkeeping, then deleted. Sellers remain responsible for orders accepted before closure, so recent order records can be retained for the corresponding period.
- Fraud-prevention flags — flagged phone numbers may be kept longer than the orders that produced them, for as long as the fraud-prevention purpose requires.
- Payment and tax — transaction records may be retained for the period required for accounting, tax, fraud, chargeback, or legal claims.
- Logs and backups — application logs and database backups are kept for limited operational periods and then expire; data removed from the live system can persist in a backup until that backup expires.
- Providers — identity, payment, email, and hosting providers keep their own security, legal, transaction, and backup records under their terms.
10. Cookies and device storage
The website uses browser storage for Clerk sign-in, language preference, and the buyer's cart. The mobile app stores the same kinds of thing on the device itself — the sign-in session, your language and theme choice, and the push token — and no advertising identifier is collected. We do not use advertising cookies or cross-site advertising trackers. Signing out clears or invalidates authentication state but does not necessarily remove language or cart values; clear the site's data in your browser to remove them.
11. Security
We use HTTPS for user-facing connections, encryption at rest for stored data, access controls designed to separate stores, rate limiting, and restricted administrative access. No service can guarantee perfect security. If a personal-data breach requires notice, we will notify affected people and the relevant authority within the applicable period.
12. Your rights
Depending on the law that applies, you may ask us to:
- give you access to and a copy of your personal information;
- correct inaccurate or incomplete information;
- delete information or restrict how it is used;
- provide eligible information in a portable format;
- withdraw consent, without affecting processing already lawfully completed; and
- object to processing based on legitimate interests, including fraud flags, subject to any compelling lawful grounds we are permitted to rely on.
Sellers can edit their data in the dashboard or close their account. Buyers can ask the store they ordered from — or the OnlineStores team through the storefront's contact details — to access, correct, or delete their information, subject to records we must keep by law. We may verify identity or ask for details needed to locate a record.
For requests governed by Lebanese Law 81/2018, we will complete a valid access, correction, completion, update, or erasure request within 10 calendar days; under that law you may apply to the competent Lebanese courts to enforce access and correction rights. EU/UK requests are generally due within one month, subject to a lawful extension notified within that month; where applicable, you may complain to the supervisory authority where you live or work.
13. Seller responsibilities
Buyer names, phone numbers, and addresses concern real people. Sellers must use them only to confirm, deliver, and support the order, keep them secure, respect valid rights requests, and not use them for unrelated marketing, tracking, or disclosure without a lawful basis. Depending on the use, a seller may need their own privacy notice and lawful basis; the privacy page prefilled for each store is a template, not legal advice.
14. Children
The platform is not directed at children under 16, and we do not knowingly collect their information. Sellers must be at least 18. If you believe a child has provided information, contact us for deletion.
15. Changes and contact
We may update this notice when the product, providers, or law changes; the date above identifies the current version. We will give any advance and durable notice required when a material change affects rights or introduces a materially different use. This notice is currently available only in English, even though the product interface supports other languages; the English version controls only to the extent local law permits. Questions, rights requests, or complaints: email the OnlineStores team at info@altajeronline.com, or reach us through your dashboard if you are a seller.
See also the Terms of Service and Refund Policy.