Privacy Policy
Effective 4 October 2026.
What we collect
For customers, Freej processes account name, email, Bahrain phone number, credentials, order history, delivery details, order notes, and customer-selected payment-proof images. Guest checkout processes the name, phone number, delivery details when selected, and order contents. For merchants, Freej also processes business profiles, menus, uploaded images, private verification documents, fulfilment records, security logs, and an app-install identifier with an Expo push token when notifications are enabled. Favorites and guest-order access references are stored on the customer’s device.
Why we use it
We use data to operate discovery and ordering, authenticate accounts, allow cafés to fulfil orders, notify signed-in merchants about new orders and payment proofs, review business submissions, prevent fraud and abuse, provide support, and understand aggregate service performance. We do not use advertising identifiers or sell personal information.
Sharing and payments
Order details are shared only with the café receiving that order and authorized platform administrators where operationally necessary. Customer-selected payment proofs are visible only to that café and authorized administrators. Push tokens and notification content are sent to Expo and the applicable Apple notification infrastructure solely to deliver merchant order alerts. Notification bodies contain the order number and event type, without customer contact or address details. Freej does not collect card credentials and does not process food-order payments. Payment is handled directly between customer and café.
Storage, retention, and deletion
Data is stored on the configured Hostinger service and its infrastructure providers. Verification documents and payment proofs are private. Active account data and active push tokens are retained while the account or signed-in install operates; a push token is disabled at sign-out or when the provider reports that the device is no longer registered. Security logs are normally retained for up to 12 months. Customers and merchants can initiate permanent deletion inside the app. Sessions are revoked, personal account data and private uploads are removed, and retained order history is anonymized. Merchant deletion also removes the public café, menu, media, verification documents, and push tokens. Some anonymized transaction records may be retained where reasonably required for legal, accounting, dispute, fraud-prevention, or security purposes. See account deletion.
Security and rights
We use encrypted HTTPS transport, password hashing, hashed access tokens, access controls, input validation, and restricted private files. No system can guarantee absolute security. Contact us to request access, correction, or deletion, subject to applicable Bahrain law.
Contact
Email support@YOURDOMAIN.com.
