Privacy policy
What ShopiyCart collects, why, who else ever sees it, and what you can ask us to do about it.
Last updated 25 August 2026
Who This Policy Is For
ShopiyCart is a platform that other businesses build their shops on. That means two different people read this page, and the answers are not the same for both.
- Merchants — businesses that open an account with us and run a store on ShopiyCart.
- Shoppers — people who buy something from a store that happens to run on ShopiyCart.
If you are a shopper, the business you bought from decides what happens to your information. We hold it for them. Their own privacy notice is the one that governs your purchase, and their contact details are on the store you used.
The Difference That Decides Everything Else
For a merchant's own account — the person who signs up, the staff they invite, the plan they pay for — we decide what is collected and why. We answer for that directly.
For a shopper's information — the order, the address, the phone number — the merchant decides. We only do what their store is set up to do, and we do not use that information for our own purposes, sell it, or move it to another merchant.
So a shopper asking to see or delete their information should ask the store they bought from. If a request reaches us instead, we pass it to that merchant rather than acting on their data ourselves.
What We Collect From Merchants
- Your name, email address and phone number.
- Your store: its name, its address on our domain, and any domain of your own you connect.
- Your staff — the people you invite, and the role you give each of them.
- Your plan, and the record of what has been billed and paid.
- Anything you write to us for support.
- Ordinary technical records: IP address, browser, and the time of a request. These are what let us tell a real sign-in from an attack on your account.
What We Hold on a Merchant's Behalf
When someone buys from a store on ShopiyCart, the store's records may include their name, email address, phone number, delivery addresses, what they ordered and what it cost, the state of that order, the language they chose, and whether they agreed to hear from the store again.
If a shopper creates an account on a store, we also keep the means of signing them back in. Passwords and password-reset codes are stored hashed, never as text: a copy of the database is not enough to get into an account.
What We Never See
We do not take card numbers, expiry dates or security codes, and we could not show you one if you asked. Paying happens on the payment provider's own page or in the payment sheet on your phone, which is not ours.
What comes back to us is the provider's reference for the payment, the amount, the currency and whether it succeeded. That is the whole of it. For cash on delivery there is no card in the first place.
Why We Process Any of It
- To run the service a merchant has signed up for, which is the substance of our agreement with them.
- To take, pay for, and deliver orders that shoppers have chosen to place.
- To keep accounts and stores from being broken into or abused.
- To answer support requests, and to bill for the plan.
- To meet obligations we cannot decline, such as keeping accounting records.
We do not build advertising profiles, and we do not track anyone across other websites.
Where It Is Kept
Our infrastructure providers operate in more than one country, so information may be processed outside Kuwait. Where that happens we require the provider to protect it to the standard described here and to process it only on our instructions.
How Long We Keep It
Account and store information is kept while the account is open. When a merchant closes their account we delete or anonymise what we hold within a reasonable period, apart from what we are required to keep.
Records of orders and payments are kept for as long as accounting and tax law requires, which is longer than the account itself may last.
Technical logs are short-lived and kept only for security and diagnosis.
What You Can Ask For
You can ask us to show you what we hold about you, to correct it, to delete it, to stop a particular use of it, or to hand it over in a form you can take elsewhere. Where we relied on your consent you can withdraw it, and that does not undo what was lawful before you did.
Merchants should write to us at the address below. Shoppers should ask the store they bought from, because the answer is theirs to give.
We will not charge you for asking, and we will come back to you within a reasonable period.
How It Is Protected
Traffic is encrypted in transit. Passwords and reset codes are stored hashed. Each store's data is separated from every other store's at the level of the query, not merely by what a screen chooses to display. Staff access follows the role a merchant assigned, and no more than that. No card data is stored at all, because we never receive any.
No system is beyond reach. If a breach ever affects your information and the law requires you to be told, we will tell you.
Children
ShopiyCart is a tool for running a business and is not directed at children. We do not knowingly collect information from a child. If you believe a child has given us information, write to us and we will remove it.
Changes to This Policy
If we change how we handle information we will update this page and move the date at the top. If a change materially affects merchants, we will tell them rather than leaving it to be noticed.
How to Reach Us
[registered company name], commercial licence [commercial licence number], [registered address], Kuwait.
Questions about privacy: [privacy@yourdomain].
If you are in Kuwait and you are not satisfied with our answer, you may take the matter to the Communication and Information Technology Regulatory Authority (CITRA).