01 · Who we are
[LEGAL NAME], registered in Iran under number [REG. NO.] at [REGISTERED ADDRESS], is responsible for the personal data described here. Where one of our stores collects data under its own brand, that store is named in its own notice and this policy applies to the group services behind it.
02 · What we collect
Three kinds of thing. What you type into a form — your name, company, email, phone and whatever you write in the message box. What an order needs — delivery address, order contents and the payment reference our provider returns to us. And what a web server records — IP address, browser, the pages you opened and when.
We do not ask for national ID numbers, and we never store card numbers. Payment happens on the provider's page, not ours.
03 · Why we collect it
To answer you, to fulfil an order or a contract, to keep the accounting records the law requires us to keep, and to see which pages are worth writing more of. Marketing email goes only to people who asked for it, and every message has a one-click unsubscribe.
04 · Cookies and analytics
This site sets the cookies it needs to work — your language choice and your session — and nothing else by default. Analytics run on our own servers with [ANALYTICS TOOL]; there is no advertising network, no cross-site tracking and no third-party tag manager on any page.
05 · Where your data lives
On servers we run inside Iran, at [FACILITY], [CITY]. Backups stay in the same jurisdiction. If a specific service ever required data to leave the country we would name it here first and ask you before it did.
06 · Who else sees it
Only the parties an order needs: the payment gateway [PROVIDER], the courier handling your delivery, and where the law requires it, the relevant authority. We do not sell personal data, and we do not share it with advertisers. Suppliers who process data on our behalf are bound by written agreement and may not use it for anything else.
07 · How long we keep it
Enquiries for [N] months unless they become a project. Order and accounting records for [N] years, because the tax rules say so. Server logs for [N] days. Newsletter details until you unsubscribe, then we keep only the fact that you did, so we do not add you again by mistake.
08 · Your rights
You can ask what we hold about you, ask us to correct it, ask us to delete it, and withdraw consent for marketing at any time. Write to [PRIVACY@DOMAIN] and we will answer inside [N] days. Deletion may be refused only for records we are legally required to keep, and we will tell you which ones and why.
09 · Security
Traffic is encrypted in transit, access to production systems is limited to named staff with individual accounts, and backups are encrypted and tested. No system is perfect: if a breach ever affected your data we would tell you and the relevant authority, with what we know and what we are doing about it.
10 · Changes and contact
When this policy changes we update the date at the top and keep the previous versions available. If a change materially affects how we use data you have already given us, we will say so directly rather than quietly. Questions go to [PRIVACY@DOMAIN] or [PHONE].