Privacy Policy
Effective Date: July 19, 2026 Version: 1
---
1. Who We Are
Mahmoud Adel Talaat Mohamed, a sole proprietor operating from New Cairo, First Settlement, Cairo, Egypt ("we", "us", "the Provider"), is the operator of the HoudaX service.
For questions about this Policy or your personal data, contact us:
- Email: Support@houdax.com
- WhatsApp: +20 101 122 5822
2. What This Policy Covers, and What It Does Not
This Policy describes how we handle personal data in two distinct roles, which have different legal meanings under Law No. 151 of 2020:
(a) As the data controller for information about you (the Client). We decide how and why your personal data — such as your name, phone, email, brand information, subscription and payment records, and support communications — is processed. This is the primary subject of this Policy.
(b) As a data processor for the personal data of your end customers (the people who shop at your store). When you upload customer data to your store, or when your end customers place orders through your store, the data belongs to you and is processed on your behalf. You are the data controller for that data. You must have your own privacy policy governing how you collect, use, and disclose your end customers' data, and you are responsible for informing your end customers of their rights. This Policy does not substitute for yours.
3. Personal Data We Collect About You
We collect only what is needed to provide the service:
When you register: your full name, phone number, email address, chosen brand name and subdomain, and preferred language.
When you use the service: login timestamps, the pages you visit within your dashboard, notification and reading history, and communications you send us through support tickets (including any attachments you upload).
When you pay: invoice records, payment status, subscription state, and the payment method identifier. If you pay by card, your card is tokenized directly by Paymob — the actual card number, expiry, and CVV are entered on Paymob's own interface and are never seen or stored by us. If you pay by Instapay, the bank transfer itself occurs on your bank's platform; we only record your confirmation of the payment and our confirmation upon verifying the transfer in our bank statement.
Technical data: IP address at signup and at consent, browser and device information, and error logs sufficient to diagnose problems.
Consent records: the specific version of these documents (Terms, Privacy, Refund) that you accepted, together with the date, time, and IP address of your acceptance.
4. What We Do Not Collect
We do not collect:
- Your full card number, expiry, or security code (these go directly to Paymob).
- Sensitive personal data as defined under Law No. 151 of 2020 (health data, biometric data, religious belief data, political opinion data), unless you volunteer such information in a support ticket, in which case we handle it in accordance with that law.
- Location data beyond the IP address.
- Data from your end customers (that belongs to you — see Section 2(b)).
5. Why We Use Your Data — Legal Bases
Under Law No. 151 of 2020, personal data must be processed with a legal basis. We rely on the following:
(a) Contractual necessity — to provide the service you have subscribed to (creating your account, delivering your website, processing your subscription, billing, sending service-related notifications, providing support).
(b) Legal obligation — to keep financial and tax records that Egyptian law requires us to retain.
(c) Legitimate interests — to detect and prevent fraud, abuse, and unauthorized access; to keep the service secure; to conduct anonymous aggregate analytics to improve the service (without identifying individual clients).
(d) Consent — for anything else, we ask for your consent, which you may withdraw at any time.
6. Who We Share Your Data With
We share the minimum data necessary with the following service providers, each of whom acts under their own data protection obligations and legally-binding contracts with us:
Paymob (Egypt) — Card tokenization and payment processing. Data shared: name, email, phone, invoice amount, and payment metadata. Card numbers themselves go directly from you to Paymob — we never see them.
Resend (email service) — Sending transactional emails (verification, receipts, reminders, ticket replies). Data shared: your email address, name, and the content of the email being sent.
Supabase (database and authentication) — Storing your account data and authenticating your logins. Data shared: all account and subscription data listed in Section 3. Servers are located in Europe (Frankfurt).
Cloudflare (infrastructure, storage, security) — DNS, CDN, storage of support ticket attachments, bot protection. Data shared: IP address, ticket attachments, and general traffic data.
Vercel (application hosting) — Running the HoudaX application. Data shared: all data processed by the application in the course of its operation. Servers are located in Europe (Frankfurt).
Telegram (internal alerts) — Sending internal operational alerts to the Provider (never your data to third parties). Data shared: your brand name and account status for events like new signups or payment issues.
Sentry (error monitoring) — Diagnosing technical errors. Data shared: error stack traces, which may incidentally include your user ID but not passwords or payment data.
We do not sell your personal data. We do not use it for advertising or marketing on behalf of third parties.
We disclose data to Egyptian legal authorities only where required by law, court order, or a lawful request from a competent authority.
6A. How Your Store's Backend Account Works
For each Client's individual store, the Provider creates a dedicated backend infrastructure account (currently with Supabase) to host that store's database. This account is registered using the Client's email address, but the password and administrative access are set and held by the Provider.
In practice, this means:
(a) the Client does not have direct login access to their store's backend infrastructure account unless the Provider provides the credentials on request;
(b) the Provider retains this access in order to build, maintain, troubleshoot, and support the Client's store as part of the subscription service;
(c) the Client may request the credentials to their backend account at any time by contacting Support@houdax.com. The Provider will evaluate such requests in light of the technical support and service continuity implications of shared or transferred access, and will respond within a reasonable time;
(d) upon termination of the Agreement, the Client may request that access to their backend account and its data be transferred or exported to them, subject to Section 11.3 of the Terms of Service (data portability upon termination).
This arrangement is disclosed here so that Clients understand, plainly: registering an account in your name does not, by itself, give you direct control of that account's credentials. If direct administrative access matters to you, request it in writing.
7. International Data Transfers
Some of the service providers we rely on (Supabase, Cloudflare, Vercel, Resend, Sentry) operate servers outside Egypt, primarily in the European Union and the United States. These transfers are protected by the contracts we hold with each provider and by their own compliance with international data protection standards. Where Law No. 151 of 2020 requires additional safeguards for cross-border transfers, we implement them.
8. How Long We Keep Your Data
Account profile (name, phone, email, brand name) — Until you request deletion; then anonymized after 30 days.
Subdomain (for reuse by another Client) — Released 90 days after account deletion.
Invoices, payment records, subscription history — Retained for the period required by Egyptian tax and commercial law (currently 5 years minimum for financial records); anonymized to the extent possible while satisfying that legal obligation.
Support ticket messages — Retained for 12 months after the ticket is closed, then deleted.
Support ticket attachments — Deleted from storage 12 months after the ticket is closed.
Notifications and in-app messages — Automatically deleted after 90 days.
Email delivery log (which template was sent when — no content) — Retained for 12 months.
Payment gateway webhook records (raw evidence of each payment event) — Retained for 3 years, or such longer period as required by Egyptian law.
Consent records (which policy version you accepted and when) — Retained for the life of your account plus 3 years.
Application-level audit logs (admin actions) — Retained for the life of your account plus 5 years.
9. Your Rights
Under Law No. 151 of 2020, you have the following rights regarding your personal data:
(a) Right of access — you may request a copy of the personal data we hold about you.
(b) Right of rectification — you may correct any inaccurate or incomplete data.
(c) Right of deletion — you may request that we delete your account and personal data, subject to the retention requirements above (invoices and financial records must be retained by law).
(d) Right to restrict or object — you may object to certain uses of your data.
(e) Right to withdraw consent — where processing is based on your consent, you may withdraw it at any time, which will end future processing based on that consent (but not affect processing that has already occurred).
(f) Right to data portability — you may request a one-time export of the content you have uploaded to your store, in a common format.
(g) Right to lodge a complaint — if you believe your rights have been violated, you may lodge a complaint with the Egyptian Personal Data Protection Center.
To exercise any of these rights, contact us at Support@houdax.com. We aim to respond within 30 days. Certain requests may require us to verify your identity before we act on them.
10. Data Security
We apply technical and organizational safeguards including:
(a) encryption of data in transit (TLS/HTTPS on all connections);
(b) database-level access controls (row-level security ensuring one Client cannot access another Client's data even in the event of an application bug);
(c) two-factor authentication for all administrative accounts;
(d) encrypted, off-site backups of the database (with the decryption key held only offline, so encrypted backups are useless without physical access to the key);
(e) restricted internal access to personal data (only the Provider has administrative access);
(f) monitored logging of administrative actions.
No security measure is perfect. We encourage you to use a strong, unique password for your HoudaX account and to enable any additional security features we offer.
11. Personal Data Breaches
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Egyptian Personal Data Protection Center within the period required by Law No. 151 of 2020, and we will notify affected Clients where the breach presents a high risk to them.
12. Cookies and Tracking
We use only essential cookies required to keep you securely logged in and to prevent bot abuse (via Cloudflare Turnstile). We do not use advertising cookies, cross-site tracking, or third-party analytics that identify individual users. Aggregate, anonymized usage statistics may be gathered from server logs solely to operate and improve the service.
13. Children
HoudaX is intended for business use by adults. If we learn that we have collected personal data from a person under 18, we will delete it. If you believe we hold data about a minor, contact us at Support@houdax.com.
14. Marketing Communications
We send you only service-related communications (verification emails, receipts, payment reminders, ticket replies, service notices). We do not send marketing emails unless you specifically opt in, and you can withdraw your consent at any time.
15. Changes to This Policy
We may update this Policy from time to time. Material changes will be published with a new version number. When we publish a new version, you will be asked to review it the next time you log in. We keep an audited record of the version each Client accepted and the date and time of acceptance.
16. Your Obligations as the Data Controller for Your End Customers
Because you (not us) are the data controller for the personal data of your end customers, you are responsible for:
(a) publishing your own privacy policy on your store that discloses your data practices to your end customers;
(b) obtaining any consent required from your end customers under Law No. 151 of 2020;
(c) responding to requests from your end customers to exercise their rights over their data;
(d) notifying us promptly of any known personal data breach affecting your end customers' data, so that we can assist you in fulfilling your legal notification obligations;
(e) ensuring that the personal data you upload to your store was lawfully collected and may be lawfully processed by you.
We act as your data processor for that data. We process it only on your documented instructions (which include your use of the admin panel) and for the purpose of providing the service to you. See Section 6A for how administrative access to your store's backend account works in practice — this affects who can directly access the infrastructure hosting that data, separately from who legally controls it.
17. Contact
Mahmoud Adel Talaat Mohamed New Cairo, First Settlement, Cairo, Egypt Email: Support@houdax.com WhatsApp: +20 101 122 5822