Privacy & data

Privacy Policy

A clear explanation of the information Mahfouz Market uses to operate customer orders, deliveries, staff services, attendance, and business accounts.

Last updated August 25, 2026Mahfouz Market · Beirut, Lebanon
01

We do not sell personal data

02

Customer location is not continuously tracked

03

Restricted data requires authenticated access

01

Information we collect

Customer and order data

  • Name, phone number, customer profile, and authentication identifiers.
  • Delivery addresses, saved address-book entries, building details, and delivery instructions.
  • Order contents, quantities, amounts, notes, status, history, and customer-service records.
  • Notification token and limited device or security information needed to authenticate, protect, and operate the service.

Customer location

Precise location is collected when a customer chooses Use Current Location or selects a map point to create a delivery address. It is used for that address and delivery request; customers are not continuously tracked.

Driver delivery location

When an authorized driver accepts the location disclosure and starts an assigned active delivery, the app may collect precise live location. On Android, this can continue in the background through a visible foreground-service notification. The current location supports the active delivery and may be viewed by the customer tracking that order and by the owner or authorized managers. Sharing stops when the delivery is completed or tracking is otherwise stopped.

Staff duty, attendance, and automatic arrival

Staff duty location requires employee permission, owner approval, and an active check-in. It is available only to the owner and authorized managers for attendance, safety, and operational supervision. The feature keeps the current point rather than a route history and stops after checkout.

If an employee enables automatic scheduled-arrival detection and grants the required location permission, the app may check entry into the scheduled branch geofence during a bounded shift window. An arrival signal can include location, accuracy, arrival and scheduled times, and early or late minutes. Official attendance may still require the employee to tap Check-in. Outside-range attendance can create an owner-approval request containing time, location, device information, decision, owner identity, and reason.

Optional staff and delivery media

Authorized users may submit face-enrollment photographs and derived identity templates for attendance setup, as well as delivery-access photographs or audio instructions. We also process the staff identity, role, branch, duty, attendance, and access records needed for restricted features.

02

How we use information

  • Create and maintain customer profiles and saved addresses.
  • Prepare, deliver, track, support, and account for orders.
  • Authenticate users and protect customer, driver, staff, and business accounts.
  • Operate approved attendance, staff, delivery, and administrative workflows.
  • Send service notifications and maintain security, fraud-prevention, audit, and reliability records.
  • Meet accounting, legal, and regulatory obligations.
03

Sharing and service providers

We do not sell personal data.

Information is shared only when needed to provide and secure the service:

  • With the customer, assigned driver, owner, or authorized managers when an order, delivery-tracking, or staff workflow requires it.
  • With authorized Mahfouz personnel for operations, support, accounting, security, or legal compliance.
  • With Mahfouz-operated servers that process ordering, accounting, and staff operations.
  • With Google and Firebase services acting as processors, including authentication, database or storage, messaging, App Check, and mapping services.

Information may also be disclosed when required by law or when necessary to protect users, Mahfouz Market, or others.

04

Staff business accounts and finance records

When a staff member has a Mahfouz business account, the Mahfouz server processes account movements, debit and credit amounts, running balances, document references, and the linked user identifier for accounting, employee-finance, security, audit, and legal-record functions. Detailed records remain on the Mahfouz server and are shown only through authenticated finance and authorized management workflows. Push messaging receives only a generic event signal and the technical delivery identifier; the push payload does not contain amounts, balances, client keys, document IDs, or other detailed finance fields.

05

Security

We use authenticated requests, role restrictions, access controls, and encrypted network connections where supported. Restricted staff and administrative features require authorization. No electronic system can be guaranteed completely secure.

06

Retention and deletion

Account and profile information is retained while needed to provide the service. Orders, accounting, delivery, security, attendance, and audit records are retained as needed for operations, disputes, fraud prevention, legitimate business records, and legal obligations. Active location sharing ends with its relevant workflow, but associated operational or security records may remain where required. Retention periods vary by record and legal need.

You may request access, correction, or deletion by emailing mahfouz.market@gmail.com. We verify requests and delete or anonymize applicable information, subject to records that must be retained for legal, accounting, security, fraud-prevention, or dispute purposes.

07

Your choices and permissions

  • Choose whether to provide a current customer location or select an address manually.
  • Review location disclosures and device permissions before enabling driver or staff features.
  • Disable automatic arrival and change location permission in device settings.
  • Ask us to correct inaccurate profile information or review an applicable data request.
08

Children

The app is not directed to children under 13, and we do not knowingly collect personal data from children under 13.

09

Changes and contact

We may update this policy when the app, our services, or legal requirements change. The date at the top identifies the current version.

Mahfouz Market, Beirut, Lebanon — mahfouz.market@gmail.com