Privacy and consent basics for Egyptian stores

Collect data with clear consent and keep auditable preference records.

Compliance and scale

Every order on an Egyptian online store quietly hands you something valuable and sensitive: a real person's name, a phone number that reaches them, a home or work address in their governorate, and a growing history of what they buy. That data is what makes cash on delivery, courier handoffs, and a friendly follow-up on WhatsApp possible, but it also makes you responsible for it. Treating customer data with clear consent is not a legal nicety bolted on after launch; it is part of the trust that convinces a first-time buyer to type their address into your checkout at all.

This lesson is about the consent lifecycle rather than the privacy page itself, which has its own home. The thread runs from collecting only what you genuinely need, through telling buyers plainly how their data is used, to getting explicit permission before you market to them, honoring it when they ask to be removed, and keeping a quiet record of every choice they made. None of this is legal advice; it is awareness-level guidance to keep you on the right side of Egypt's Personal Data Protection Law (PDPL) and, more importantly, your customers' trust. For anything binding, talk to a lawyer.

Collect only what the order actually needs

The simplest privacy rule is also the most protective: do not ask for data you will not use. A cash-on-delivery order in Egypt genuinely needs a name, a reachable phone number, and a full governorate address so the courier can deliver and confirm. It does not need a national ID number, a date of birth, or a second phone number "just in case." Every extra field is something you now have to store, secure, and answer for, and it adds friction that quietly costs you conversions on mobile.

  • Map each checkout field to a real purpose: delivery, payment confirmation, or order updates.
  • Drop fields that exist only because a form template offered them.
  • If you ever need something unusual, explain why right next to the field.

Tell buyers, in plain language, how their data is used

Consent is only real when the customer understands what they are agreeing to. Buyers are handing over a phone number and a home address to a store they may have found through Instagram an hour ago, so a short, honest explanation does real work. Say what you collect (name, phone, address, order history), why you collect it (to fulfil and deliver the order, confirm COD, and provide support), who sees it (your team and the courier who delivers), and that you do not sell it. Keep this in Arabic and English, and keep the privacy page itself current. The full page is covered in the essential trust pages for launch.

Marketing consent is a separate, explicit yes

This is the distinction that trips up most Egyptian merchants. A buyer who places a COD order has given you their phone number to deliver that order. They have not, by that act alone, agreed to receive promotions, broadcast lists, or "back in stock" blasts on WhatsApp. Marketing is a separate permission, and it should be an explicit opt-in:

  1. Use a clear, unticked checkbox at checkout or signup: "Send me offers and updates on WhatsApp / email." Pre-ticked boxes are not real consent.
  2. Treat WhatsApp and email as different channels — agreement to one is not agreement to the other.
  3. Make it easy to stop: an "unsubscribe" link in emails and a simple "stop" reply on WhatsApp, honored quickly.

Sending offers to a list that never opted in is the fastest way to get your number reported and blocked, which costs you the channel entirely. How you actually run those permitted messages is covered in lifecycle messaging on email and WhatsApp.

Honor deletion and removal requests

Sooner or later a customer will message "remove my data" or "delete my account." Have a simple, human answer ready rather than ignoring it. Acknowledge the request, remove or anonymise their personal details where you are not legally required to keep them (some financial and invoice records you must retain), take them off every marketing list, and tell them it is done. A buyer who asks to leave and is treated respectfully often comes back; one who is ignored leaves a complaint.

Keep an auditable record of every choice

This is the part most stores skip, and it is the whole reason consent matters in practice: if you cannot show that a customer agreed, you effectively did not have their consent. Against each customer, keep a record of what they agreed to, on which channel, and when — for example, "opted in to WhatsApp offers, at checkout, 14 March." When they unsubscribe or ask for deletion, record that too, with its date. You do not need a fancy system; you need a single source of truth that is retrievable later, kept up to date as choices change, and accessible only to the people who should see it. If a buyer ever disputes a message, that timestamped record is your honest answer.

Related lessons

This Storix Academy lesson is published as "Privacy and consent basics for Egyptian stores". Every step below is written for merchants selling online in Egypt, so apply one change at a time and measure the result before moving on.