Storix privacy policy for merchants and shoppers
Last updated: upon first publication by the platform operator.
1. Who we are
Storix is the software platform that merchants use to run their online stores. Depending on how you reach us, you may be:
- A visitor or prospective merchant browsing our marketing site or signing up.
- A merchant user — a store owner or a team member using the Storix admin, billing, or integrations.
- A shopper buying from a store that a merchant operates on Storix. In that case the merchant is the controller of your order and customer data; Storix processes it on the merchant's behalf as part of running the platform.
This privacy policy explains how Storix handles store and customer data across those roles, including the difference between data we control directly and shopper data we process for merchants. Storix protects store and customer data with encryption, strict access controls, and clear retention limits, and gives both merchants and shoppers practical rights over the information we hold.
We're based in Egypt and serve the Egyptian market first, with customers across the MENA region. This policy is written with the Egyptian Personal Data Protection Law (Law 151 of 2020) in mind; where other local laws give you stronger rights, those apply too.
2. What this policy covers
This policy explains, in plain language: what personal data we collect, why we use it, how long we keep it, who we share it with, where we store it, and what you can do about it. It covers the websites and services Storix operates directly. It does not cover third-party sites that merchants link to from their storefronts — those have their own policies.
3. The personal data we collect
Depending on what you do with Storix, we may process:
- Account and identity data — name, email, mobile number, national ID or company registration number (where required for KYC), company name, preferred language, and the login identifiers we use to sign you in.
- Device and usage data — IP address, device and browser type, approximate location derived from IP, pages you visit, timestamps, error logs, and security signals we use to spot fraud and abuse.
- Billing and subscription data — your plan, invoices, and payment references returned by licensed payment providers. We don't store full card numbers on Storix servers — those stay with the payment provider (Paymob, Fawry, or similar) that is PCI-DSS certified.
- Support and communication data — messages you send us, any files you attach, and the metadata we need to reply (ticket ID, timestamps, the agent who handled it).
- Store operational data — your store configuration (domain, currency, tax profile), logs of actions taken in the admin, and the operational records we need to keep the service running and to meet our obligations under Egyptian commercial and tax law.
If you're a shopper buying from a merchant's store: the merchant receives the order details they need to fulfil your purchase (name, shipping address, phone, items, total). Storix processes that data on the merchant's behalf as part of running the platform, under our agreement with the merchant and this policy. For questions about how a specific merchant uses your data, please contact the merchant first.
4. Why we use your data (legal basis)
Under Egyptian PDPL, we process your data on the following bases:
- Performance of a contract — to run the platform you signed up for, process your orders, bill your subscription, and provide support.
- Legal obligation — to keep tax records, respond to lawful requests from Egyptian authorities, and meet anti-money-laundering or consumer protection duties.
- Legitimate interest — to secure the service, prevent fraud, improve reliability, and communicate essential service updates.
- Consent — for anything beyond the above: marketing emails you can opt into, optional analytics, and non-essential cookies. You can withdraw consent at any time without affecting the service itself.
We do not sell your personal data to anyone.
5. Cookies and similar technologies
We use cookies and similar storage on your device to keep you signed in, remember your language and theme, measure basic performance, and protect the service. You control the non-essential ones from the cookie banner or from your account settings — our Cookie policy lists the details (category, provider, retention). Strictly necessary cookies (session, security, CSRF) cannot be turned off because the site won't work without them.
6. Who we share data with
We share data with a small set of service providers that we need to run the platform:
- Cloud hosting and storage — our data centres and object storage (primarily in the MENA region; see section 8).
- Payment providers — licensed Egyptian processors (Paymob, Fawry, and similar) handle card and wallet payments.
- Email and SMS delivery — for order confirmations, password resets, and notifications you opted into.
- Fraud and abuse prevention — analytics and turnstile services used sparingly and only where strictly necessary.
- Customer support tooling — ticketing and chat systems used by our support team.
Every provider is under a written contract that limits them to processing data on our instructions and requires them to protect it at least as well as we do.
We may also disclose information when a court, regulator, or another Egyptian authority legally requires it, or when we need to protect someone's safety or defend a legal claim. If we're ever involved in a merger or sale of the business, we'll make sure appropriate safeguards stay in place.
7. Data Protection Officer
In line with PDPL Art. 27, we have appointed a Data Protection Officer (DPO). You can reach the DPO for any question about this policy, to exercise your rights, or to raise a concern. Contact details are published at the bottom of this site.
8. Where your data is stored
We prefer to keep Egyptian customer data within Egypt or the MENA region where possible. Some of our service providers operate globally, so data may be processed in other countries. When that happens we rely on the safeguards PDPL Art. 14 requires: your consent for marketing transfers, adequacy of the destination country, or standard contractual commitments that preserve your rights.
9. Security
We take security seriously. We use encryption in transit and at rest, role-based access, strong password hashing, session protection, and audit logs. Our team is trained on secure development practices and we run routine security reviews. No service can promise absolute security, but we work hard to reduce the risk and, if we ever learn of a breach that affects your personal data, we will notify the Data Protection Center and affected individuals within 72 hours as required by PDPL Art. 34.
10. How long we keep data
We keep personal data only as long as we need it:
- Account data — while your account is active, and for a short wind-down period after you close it.
- Order and billing data — at least five (5) years after the transaction, as required by the Egyptian Tax Authority and commercial record-keeping rules (Law 91 of 2005 and related regulations).
- Support tickets — up to two years after closure for quality and dispute purposes.
- Server logs and security events — up to 12 months, unless a specific incident requires longer retention.
- Marketing preferences — until you unsubscribe, plus a suppression record so we don't email you again by mistake.
After these periods we either delete the data or anonymise it so it can no longer be linked to you.
11. Your rights
Under PDPL you have the right to:
- Access the personal data we hold about you.
- Correct anything that's wrong.
- Delete your data where there's no overriding legal reason to keep it.
- Restrict or object to certain kinds of processing.
- Withdraw consent for anything we do on a consent basis — with no effect on the service itself.
- Portability — receive the data you gave us in a common, machine-readable format.
- Complain to the Egyptian Data Protection Center (under the NTRA) if you think we handled your data wrongly.
To use any of these rights, email our DPO (contact at the bottom of the site). We'll reply within the timeframes PDPL sets — usually within 30 days. If your request relates to shopper data held by a specific merchant, please contact the merchant first; we'll assist them if they need us to.
12. Children's data
Storix is not aimed at children. We don't knowingly collect personal data from anyone under the age of consent for data processing under Egyptian law. If you're a parent and you think your child gave us data, email our DPO and we'll remove it.
13. Links to other sites
Merchant stores — and occasionally our own site — link to third-party websites (payment pages, shipping carriers, social media). Those sites have their own privacy policies. We're not responsible for what they do with your data; please read their notices before you share anything with them.
14. Changes to this policy
We may update this policy from time to time. If the change is significant — for example, a new category of data or a new third-party processor — we'll tell you before it takes effect (by email, in-app notice, or a prominent banner on our site). Continued use of Storix after the new date means you've accepted the update, to the extent Egyptian law permits.
15. Contact us
Questions, requests, or complaints about this policy go to our Data Protection Officer using the contact box below or the contact details at the bottom of the site.
You also have the right to contact the Egyptian Data Protection Center directly.
Last updated: 2026-07-22