PRIVACY POLICY

ShopMahelso – MAHUGNON SERVICES LTD
Last updated: 19.11.2025

This Privacy Policy explains how MAHUGNON SERVICES LTD, a company registered in the United Kingdom (Company number: 16010860), whose registered office is located at 20 Wenlock Road, London, N1 7GU, United Kingdom, collects, uses, stores and protects your personal data when you use the ShopMahelso application.

By using ShopMahelso, you agree to the practices described in this policy.

For any questions regarding privacy, you can contact us at:
📧 support@shopmahelso.com

1. PERSONAL DATA COLLECTED

We only collect the data necessary for the proper functioning of ShopMahelso.

1.1. User account data:

  • First name and last name (if provided)
  • Email address
  • Supabase user ID
  • Encrypted password

1.2. Data related to your shop:

  • Shop name
  • Products, prices, photos
  • Sales and reports
  • Stock movements
  • Employees and roles

1.3. Transaction data:

  • Google Play identifiers (purchaseToken, productId, orderId)
  • FedaPay identifier
  • Payment method
  • Subscription dates

1.4. Technical data:

  • Device model
  • App version
  • Operating system & IP address
  • FCM token for push notifications

1.5. Usage data:

  • Actions performed inside the app
  • Error logs
  • Performance and crash information

2. USE OF DATA

We use your data to:

2.1. Provide and improve ShopMahelso:

  • Shop management
  • Synchronization via Supabase
  • Stock tracking
  • Employee and sales management

2.2. Premium payments & subscriptions:

  • Verification with Google Play
  • Verification with FedaPay
  • Management of your Premium status
  • Subscription expiry reminders

2.3. Notifications:

  • New sales and order activity
  • Low-stock alerts
  • Subscription status updates
  • Important system information

2.4. Customer support:

  • Support by email
  • Bug and incident resolution

3. LEGAL BASIS (GDPR)

The processing of your data is based on:

  • Performance of a contract (provision of the service)
  • Legitimate interest (app improvement, security)
  • Consent (for certain features, notifications, analytics)
  • Legal obligations (accounting, fraud prevention, etc.)

4. DATA SHARING

We never sell your personal data.

Data may only be shared with:

  • Supabase (authentication, database, storage)
  • Google (Play Billing, Firebase Cloud Messaging)
  • FedaPay (Mobile Money payments)
  • Security and analytics services (if applicable)

All these partners must comply with the GDPR, Google’s security standards, and other applicable legal obligations.

5. DATA RETENTION

  • Active account: data is retained for as long as you use the service.
  • After account deletion: data is kept for a limited period, generally up to 3 years.
  • Technical logs: around 12 months.
  • Subscription-related data: retained for the period required by tax and accounting law.

6. SECURITY

We implement technical and organizational security measures, including:

  • Encryption of communications via HTTPS / TLS
  • Secure authentication via Supabase
  • Role-based permissions per shop
  • Anti-fraud mechanisms from Google / FedaPay
  • Protection of “service role” keys and secrets on the server side

7. YOUR RIGHTS (GDPR)

In accordance with the GDPR, you have the following rights:

  • Right of access
  • Right to rectification
  • Right to object
  • Right to erasure (“right to be forgotten”)
  • Right to data portability
  • Right to restriction of processing
  • Right to withdraw your consent (for processing based on consent)

To exercise your rights, you can contact us at: support@shopmahelso.com

8. CHILDREN

ShopMahelso is not intended for children under 13 years old. We do not knowingly collect data about children under this age.

9. INTERNATIONAL DATA TRANSFERS

Your data may be stored or processed in the European Union, the United Kingdom, or the United States, with appropriate safeguards such as:

  • Application of the GDPR and UK GDPR
  • Standard Contractual Clauses approved by the European Commission
  • Enhanced security measures implemented by our service providers

10. ACCOUNT DELETION

You can request deletion of your account:

  • Directly from the app (if the feature is available), or
  • By contacting us by email.

Effects of deletion:

  • Permanent deletion of data stored in Supabase (except where retention is required by law).
  • Termination of your Premium status.
  • Deletion of the FCM token associated with your device.

11. CHANGES TO THIS POLICY

We may update this Privacy Policy if the app, applicable laws, or our internal practices change. In case of material changes, we will inform you through a message in the app or by email, when appropriate.

12. CONTACT

MAHUGNON SERVICES LTD
20 Wenlock Road, London, N1 7GU, United Kingdom
Company number: 16010860
📧 support@shopmahelso.com