Skip to content
Tajarat
Experience For Merchants Legal Center Contact
عربيJoin the launch list
Legal Center

Privacy Policy

The Arabic version is based on the supplied legal documents without substantive rewriting. English translations are provided for accessibility; language priority remains governed by the source document.

← Legal Center
TajaratTajarat for TRADING LLCCR 240440License 331174info@tajarat.app
اقرأ بالعربية

Document content

Privacy Policy

Introduction and Scope of this Policy

Tajarat / تاجرات respects the privacy of its users and is committed to handling personal data responsibly and transparently in accordance with the laws applicable in the State of Qatar. This Policy explains the categories of data the Platform may collect, the purposes for which it may be used, the parties with whom it may be shared, retention periods, the measures taken to protect it, and the rights available to data subjects.

This Policy applies to the Customer App, the Merchant App or Portal, the website, the Admin Panel, and the payment, delivery, notification, support and integration services connected with the Platform. It does not apply to independent third-party services except to the extent that Tajarat itself processes the relevant data.

2. Who We Are and Our Role in Data Processing

Tajarat operates as a managed electronic marketplace (Managed Marketplace). Where Tajarat determines the purposes and means of processing, Tajarat is the party responsible for that processing to the extent provided by law.

Merchants, payment providers, delivery providers or technical service providers may act as independent parties or as data processors, depending on the nature of the relationship and the actual role of each party. It should not be assumed that all parties perform the same legal role in every processing activity.

3. Definitions

3.1. Personal Data: any information relating to an identified or directly or indirectly identifiable natural person.

3.2. Processing: any operation performed on data, including collection, recording, organization, storage, use, disclosure, transfer, alteration and deletion.

3.3. User or Customer: any person who uses the Platform to browse, register, purchase or communicate.

3.4. Merchant: any person or business accepted by the Platform to offer and sell products.

3.5. Service Provider: any third party that assists in operating the Platform or providing services connected with it.

3.6. Special-Category Data: data that requires additional protection under applicable law because of its nature or the impact of its processing.

3.7. Data Subject: the natural person to whom the Personal Data relates.

3.8. Platform: all Tajarat applications, websites, portals and digital services.

4. Data Processing Principles

We seek to process data in accordance with the principles of lawfulness, transparency, purpose limitation, data minimization, accuracy, storage limitation and security. We aim to collect only data that is proportionate and necessary for specified purposes, and not to use it for an incompatible purpose without an appropriate legal basis.

5. Data We Collect from Users

Depending on how the Platform is used, we may collect:

5.1. Account Data: name, phone number, email address, authentication data, language, account status and communication preferences.

5.2. Order Data: order number, products, quantities, prices, discounts, order status, cancellation, returns and exchanges.

5.3. Address and Delivery Data: recipient name, phone number, area, address, selected location and delivery instructions.

5.4. Limited Payment Data: transaction amount, payment reference, status, payment method, and refund or dispute information made available by the payment provider.

5.5. Support Data: messages, complaints, images, documents and communication history.

5.6. Content Data: ratings, comments and images uploaded by the User.

5.7. Technical Data: device type, operating system, app version, browser, IP address, technical identifiers, usage logs and crash logs.

5.8. Preference and Interaction Data: searches, viewed products, cart activity, and categories or options selected by the User.

6. Data We Collect from Merchants

As necessary, we may collect the Merchant or store name, legal or trade name, contact details, address, identity, registration or licensing documents, bank account or settlement information, product and inventory data, Orders, sales, returns, complaints, login records and operational change logs.

This data is used to manage the commercial relationship, perform verification, operate the store, fulfil Orders, calculate fees and commissions, carry out settlements, prevent fraud, and comply with legal and contractual obligations.

7. Data Voluntarily Provided by the User

A User may provide additional information such as size or color preferences, delivery instructions, or a product image when submitting a complaint. Sensitive or unnecessary data should not be submitted unless required to address a specific request or complaint.

8. Special-Category Data

Tajarat does not ordinarily seek to collect Special-Category Data. If a User voluntarily provides health-related information, such as information about an allergy connected with a product, or an image necessary to evidence harm or a complaint, that data will be processed only to the extent necessary for the relevant legitimate purpose and subject to appropriate safeguards.

9. Children and Minors

The Platform is not directly targeted at children. A minor should not provide data or enter into a transaction except as permitted by law and, where required, under the supervision and with the consent of a parent or legal representative. If it is discovered that a minor's data has been collected unlawfully, the Platform will take appropriate steps to delete it, restrict it or otherwise regularize the legal position.

10. Purposes for Which We Use Data

Depending on the circumstances, we use data to:

10.1. Create, verify and secure Accounts.

10.2. Fulfil Orders, payments and deliveries, and process cancellations, returns and refunds.

10.3. Enable Merchants to manage products, Orders and settlements.

10.4. Provide support and handle complaints and disputes.

10.5. Improve search, recommendations and the user experience.

10.6. Send operational and security notifications.

10.7. Conduct direct marketing where consent or another appropriate legal basis exists.

10.8. Detect fraud and misuse and protect Accounts.

10.9. Perform analytics, measure performance and resolve technical faults.

10.10. Comply with the law, protect rights and evidence transactions.

11. Legal Basis for Processing

Depending on the nature of the processing, Personal Data may be processed on one or more available legal bases, such as necessity for performance of a contract or taking steps connected with it, consent where required, compliance with a legal obligation, protection of rights and claims, or legitimate interests permitted by law, taking individual rights into account.

The Platform does not rely on consent where consent is not the true legal basis for the processing. Where processing is based on consent, the consent may be withdrawn without affecting the lawfulness of processing carried out before withdrawal.

12. Consent Management

Where the law requires consent, the Platform seeks to obtain it in a clear, specific and demonstrable manner. The Platform may retain a record of the type of consent, the date, the channel through which it was given and any subsequent withdrawal.

Users may manage certain consents and preferences through app or device settings or by contacting the Platform. Withdrawal of consent does not affect communications or processing that are necessary to fulfil an Order or comply with a legal obligation where an independent legal basis applies.

13. Budget Assistant and Recommendations

The Platform may process the entered budget, selected categories, price range and interaction history with results in order to provide more relevant recommendations. This feature is a shopping assistance tool and is not intended to make a legal, financial or other decision having a material effect on the User's rights on the User's behalf.

Results may be based on price, availability, category and other ranking factors. The purchasing decision remains with the User after reviewing the product details.

14. Sharing Data with Merchants

When an Order is placed, the Platform may share with the Merchant the data necessary to fulfil it and provide after-sales service, such as Order details, selected options and contact or delivery information, to the extent necessary.

A Merchant may not use Customer data for independent marketing, share it, or retain it for unauthorized purposes without a valid legal basis. Merchants are subject to confidentiality, security and data-protection obligations under the applicable agreements and Policies.

15. Sharing Data with Delivery Companies

The Platform may share recipient details, phone number, address, selected location, Order number, delivery instructions and cash-on-delivery status to the extent necessary to carry out delivery or resolve a delivery-related issue.

16. Sharing Data with Payment Providers

Electronic payments are processed through approved payment providers. The Platform may share the Order number, amount, currency, required verification data, transaction status and refund or dispute information.

Tajarat does not ordinarily retain the full card number or CVV security code. Data provided directly by the User to the payment provider is subject to that provider's policies and independent legal role.

17. Technical Service Providers

The Platform may use hosting, cloud computing, notification, mapping, SMS, email, analytics, crash monitoring, support, cybersecurity, development and maintenance services.

We seek to give service providers only the minimum data necessary, enter into appropriate contractual arrangements regarding confidentiality, security and use of data, and conduct reasonable review of providers according to the level of risk.

18. Firebase and Notifications

The Platform may use Firebase or similar services to send notifications and operate technical functions. Notification tokens, technical identifiers, device type, app version and crash data may be processed depending on the configuration.

Notifications may be disabled through device settings, although doing so may affect receipt of certain important alerts.

19. Maps and Geolocation

The Platform may use Google Maps or similar mapping services to identify a delivery address. The Platform does not use precise location unless the relevant feature is enabled or the related permission is granted, and then only to the extent necessary for the stated purpose. Location permissions may be managed through device settings.

20. Cookies and Similar Technologies

The website may use cookies and similar technologies to operate the service, preserve sessions and preferences, provide security, measure performance, perform analytics and, where permitted, support marketing.

These technologies may be categorized as necessary, functional, analytical and marketing technologies. Consent is requested where legally required, and Users may manage choices through a consent tool or browser settings where available.

21. Direct Marketing

The Platform does not send direct electronic marketing communications except in accordance with legal requirements and any required consents. Users may unsubscribe through the designated link, settings or by contacting the Platform.

Opting out of marketing does not stop necessary operational communications such as Order confirmations, verification codes, delivery updates and security alerts.

22. Analytics and Aggregated Data

The Platform may use usage data to measure performance, understand interaction patterns and improve the service. Where appropriate, the Platform seeks to use aggregated or anonymized data. Data is not treated as anonymous where it can reasonably be linked back to a specific person.

23. Advertising and Retargeting

If the Platform uses personalized advertising, retargeting or advertising identifiers, this will be done in accordance with consent settings, the law and the policies of advertising providers. Users may manage certain choices through device or browser settings or available privacy tools.

24. Data Retention

The Platform retains data for the period necessary for the purpose for which it was collected and to comply with legal and accounting requirements, resolve disputes, prevent fraud and protect rights.

Final retention periods are determined in an approved internal schedule that takes account of the type of data, purpose and legal requirements. Examples include: Account data for the life of the Account and a necessary period after closure; Order and invoice records for the applicable legal and accounting period; complaint data for as long as necessary to manage and evidence the complaint; marketing data until consent is withdrawn, together with a limited record proving the opt-out; and security logs for a period proportionate to the relevant risk.

When data is no longer required, it is deleted, anonymized, restricted or securely archived in accordance with the law and approved Policies.

25. Backups and Deletion

Deleted data may remain for a limited period in backups until it is overwritten or deleted in accordance with the backup cycle, with use restricted and without restoration to active systems except for legitimate recovery purposes. Technical periods are specified in the internal retention and backup Policy.

26. Information Security

The Platform implements technical and organizational measures appropriate to the nature of the data and risks. These may include encryption in transit, secure password storage, permissions management, role separation, logging and monitoring, backups, security updates and access management.

No electronic method is absolutely secure. The Platform therefore does not guarantee absolute security, but is committed to taking appropriate and reasonable precautions in accordance with the law.

27. Incident and Data-Breach Response

Where a security incident involving data is suspected, the Platform takes steps to investigate, contain and remediate the incident, assess the type of data and affected persons and the level of risk, and preserve appropriate records and evidence.

The Platform notifies competent authorities or affected persons where notification is legally required, in accordance with applicable procedures and timelines. It maintains an internal incident-response procedure covering responsibilities and escalation.

28. Transfers of Data Outside the State of Qatar

Some data may be processed or hosted outside the State of Qatar when international service providers are used. In such cases, the Platform seeks to assess the nature of the transfer, the recipient and the risks, and to implement safeguards and procedures required by law.

Depending on the circumstances, safeguards may include data-processing agreements, appropriate contractual commitments, access controls and encryption, and selection of providers that offer an appropriate level of protection. Mere use of the Platform does not constitute a waiver of legal rights relating to international transfers.

29. Data Subject Rights

Subject to the law and the circumstances, rights may include:

29.1. The right to be informed and to receive transparency regarding processing.

29.2. The right of access to data.

29.3. The right to request correction of inaccurate or incomplete data.

29.4. The right to request deletion where legally available.

29.5. The right to withdraw consent where processing is based on consent.

29.6. The right to object to direct marketing and certain processing where permitted by law.

29.7. The right to submit a complaint to the competent authority.

29.8. Any other rights granted by applicable law.

Certain rights may be subject to limitations or exceptions, such as the need to retain records to comply with the law, perform a contract, protect rights or prevent fraud.

30. Exercising Rights and Identity Verification

Privacy requests may be sent to info@tajarat.app, together with a description of the request and the contact details associated with the Account. The Platform may request additional information to the extent necessary to verify identity and protect data from unauthorized disclosure.

The Platform handles requests within the periods prescribed by law. If the law does not specify a particular period, the Platform seeks to respond within a reasonable time having regard to the nature and complexity of the request.

31. Account Deletion

Account deletion may be requested from within the app where that function is available or through an approved contact channel. The Platform may retain certain data after closure of the Account where necessary for legal or accounting obligations, disputes, anti-fraud purposes or evidence of transactions. Retained data must be restricted to the purposes that justify continued retention.

32. Data Accuracy

Users and Merchants are required to provide accurate and current data. Failure to update a phone number, address, store information or settlement details may prevent or delay the provision of certain Services.

33. Merchant Responsibility for Customer Data

A Merchant must maintain the confidentiality of Customer data and may not use it outside fulfilment of the Order, after-sales service and authorized purposes. A Merchant is prohibited from conducting marketing without a valid legal basis, sharing data with an unauthorized party, storing it in insecure systems, or using it to bypass the Platform.

A violation may result in restriction, suspension or termination of the Merchant Account, without prejudice to legal or contractual liability.

34. Data Protection by Design and by Default

The Platform seeks to consider data protection when designing new features and systems, minimize requested data, restrict access, select default settings proportionate to the purpose, and conduct risk assessments where new processing is high impact or unusual.

35. Service Provider and Risk Management

The Platform seeks to assess service providers that process data according to the nature and sensitivity of the service, review security and privacy aspects, and contractually impose appropriate obligations. A provider may be reassessed following a material change, security incident or emergence of new risks.

36. External Links and Services

The Platform may include links to or integrations with independent services. Tajarat does not control the privacy practices of those parties when a User interacts with them directly, and Users should review their policies before providing data.

37. Disclosure to Competent Authorities and Protection of Rights

The Platform may disclose data where required by law, pursuant to an order or request from a competent authority, or where disclosure is necessary to protect rights or safety or investigate unlawful activity, while seeking to limit disclosure to what is necessary.

38. Bank Disputes and Claims

Where there is a banking dispute, chargeback request or other dispute, the Platform may share necessary data with the payment provider, bank, Merchant, delivery company, advisers and competent authorities for the purpose of verifying the transaction, protecting rights and responding to the claim.

39. No Sale of Personal Data

Tajarat does not sell Personal Data belonging to Users or Merchants. Data may be shared only for the purposes and in the circumstances described in this Policy, or where legally required or permitted.

40. Privacy Contact Point

The current contact point for privacy inquiries and requests is:

info@tajarat.app

The Platform may appoint a privacy officer or data protection officer and update contact details when necessary. Use of a general contact address does not mean that there are no defined internal responsibilities for managing compliance, data incidents and data subject requests.

41. Changes to the Privacy Policy

This Policy may be updated when Services, practices or laws change. The updated version will be published with its effective date, and appropriate notice will be given for material changes where required. Data will not be used retroactively for a new incompatible purpose without an appropriate legal basis.

42. Language

This Policy may be provided in Arabic and English. In the event of conflict, the Arabic version shall prevail unless the law requires otherwise.

43. Integration of Documents

The Terms and Conditions, Privacy Policy, Cookie Policy, Merchant Onboarding Agreement, and all policies referenced on the website or in the application form an integral part of these terms, and use of the Platform constitutes express agreement to comply with them.

44. Contact and Complaints

For privacy inquiries, rights requests or complaints:

info@tajarat.app

Where appropriate, the request should include the name, contact method associated with the Account, a clear description of the matter and any information that assists with identity verification or identification of the relevant transaction.

Tajarat

A women-focused multi-vendor fashion and beauty shopping experience in Qatar.

info@tajarat.app+974 7771 5954

Legal Center

Customer & User TermsPrivacy PolicyMerchant Registration & Acceptance TermsAll documents

Business details

Tajarat for TRADING LLCCR 250485Commercial License 331174State of Qatar
© 2026 tajarat for trading LLC. All rights reserved.العربية