Privacy Policy
Privacy and Personal Data Protection Policy
Welcome to Chefaa. This Policy describes how "Chefaa for Information Technology" collects, uses, shares, and protects your personal data when you use the Chefaa app and website, and explains your rights regarding that data.
By using our services, you agree to the collection and processing of your data in accordance with this Policy. Where the law requires your explicit consent (such as for sensitive health data), we will request that consent separately and specifically; reading this Policy alone does not constitute such consent.
This Policy applies to all users of the Chefaa app, the Chefaa website, and their related services.
1. Company Information
Legal Name: Chefaa for Information Technology
Legal Address: 86A, Street 260, Maadi, Cairo, Arab Republic of Egypt
Scope of Operation: Chefaa currently provides its services in the Arab Republic of Egypt. Chefaa previously had a legal entity and operations in the Kingdom of Saudi Arabia, which have since been discontinued; its website remains available for viewing only, without the ability to register or place orders.
Privacy Contact: [email protected]
2. Data Protection Officer
Chefaa currently manages data protection requests and inquiries through its internal technical operations team. For any inquiry regarding the privacy of your data or to exercise your rights, you may contact us at [email protected].
3. Data We Collect
3.1 Account Data
- Name (mandatory)
- Mobile number (mandatory, and verified)
- Email address (mandatory, not subject to verification)
- Gender (mandatory)
- Date of birth (optional)
Your phone number is used as the primary method for login and identity verification.
3.2 Order Data
- Medicines and products added to the shopping cart
- Medical prescriptions (text or image) for medicines legally requiring one, where the decision to dispense rests with the pharmacy fulfilling the order
- Address and pickup/delivery location to complete delivery
- Additional notes added by the customer upon delivery
- Order status and history of previous orders
3.3 Health Data (Optional – Sensitive Data)
We collect this data only with your consent, and you may skip entering it without affecting your use of our core services:
- Chronic illnesses
- Blood type
- Height and weight
Given its sensitive nature, this data is handled with a higher level of protection, and is processed or transferred only to the extent necessary to provide the service, in accordance with the legal frameworks governing sensitive data in Egypt.
3.4 Location Data
- Geographic location (GPS): explicit permission is requested from your device, and you have full freedom to allow or deny it. Enabling location is necessary to determine the products and prices available at pharmacies in your area (zone) capable of fulfilling your order.
- Address details: street name, building, floor, apartment, and a distinguishing landmark for delivery.
3.5 Device Data
Collected automatically to protect our systems and diagnose technical issues you may encounter:
- IP address
- Device model
- Browser type
- Operating system version
3.6 Payment Data
Data related to payment transactions and order completion may be collected. Chefaa does not store full payment card data, bank card numbers, or their verification codes on its systems. Payments are processed through licensed payment service providers in accordance with applicable security standards.
4. Legal Basis and Purpose of Data Processing
We process your data on the basis of one or more of the following legal grounds:
| Legal Basis | Purpose |
|---|---|
| Performance of the contract between you and us | Fulfilling and delivering orders |
| The legitimate interest of Chefaa and its users | Account verification and protecting the system against fraud |
| Your explicit, written consent | Processing optional health data |
| Your consent (opt-in) | Sending marketing messages |
| Legal obligation | Compliance with legal and regulatory requirements |
5. How We Use Personal Data
Chefaa uses personal data for the following purposes:
Service Delivery
- Creating and managing accounts.
- Fulfilling orders.
- Processing payments.
- Delivering orders.
- Providing technical support and customer service.
Service Improvement
- Analyzing usage behavior.
- Improving user experience.
- Developing new features and services.
- Measuring platform performance.
Communicating with Users
- Sending order notifications.
- Responding to inquiries.
- Providing technical assistance.
- Communicating regarding the account or orders.
Security and Fraud Prevention
- Protecting systems and services.
- Detecting suspicious activity.
- Preventing fraud or misuse.
- Investigating security incidents.
Legal Compliance
- Complying with applicable legal and regulatory requirements.
- Responding to legal requests issued by competent authorities.
Marketing
- Sending offers, services, and marketing materials to users who have consented to receive them, where such consent is required.
6. Sharing Your Data with Other Parties
We share your data with the following categories of parties, only to the extent necessary to provide our services:
6.1 Pharmacies
We share order data (medicines, prescription where required, address) with the fulfilling pharmacy through a dedicated Chefaa portal.
6.2 Shipping Companies
To carry out delivery operations.
6.3 Electronic Payment Companies
Paymob: for processing payments within the app, the website, and points of sale, as well as collecting cash on delivery. Chefaa does not retain payment card data on its servers.
6.4 Messaging Service Providers
Cequens: for sending SMS and WhatsApp messages.
6.5 Analytics and Tracking Tools
These tools are used to share user behavior, events, and certain parameters associated with them, without direct identifying data:
- Google Analytics 4 (GA4)
- Firebase
- Adjust
- Microsoft Clarity
- Google Search Console
6.6 Marketing and Advertising Tools
- Meta Ads
- Google Ads
- Webengage (for sending in-app notifications, WhatsApp, email, SMS, and in-app banners)
6.7 Technical Tools
These tools are used only to share user behavior, IP address, operating system version, and device characteristics and model, without sharing your direct personal data:
- Sentry (technical error monitoring)
- Cloudflare (website protection)
- Domix.ai (customer support and live chat)
7. Data Storage and International Transfer
Customer data is stored on Amazon Web Services (AWS) servers in the United States of America (Virginia).
Certain data is also shared with service providers based outside Egypt, within the limits set out in the previous section:
| Country | Entity |
|---|---|
| India | Webengage |
| Germany | Domix.ai |
| United States of America | Sentry |
| Egypt (not considered an international transfer) | Paymob |
Chefaa is committed to taking appropriate measures to protect personal data during international transfers and to working towards compliance with applicable legal and regulatory requirements.
8. Sensitive Data
Sensitive data, as defined by law, includes: health data (psychological, mental, physical, or genetic), biometric data, financial data, religious beliefs, political opinions, security-related information, and children's data.
With respect to the optional health data we collect (chronic illnesses, blood type, height and weight), we:
- Collect it only with your consent, given separately from this Policy at the time of entry
- Are committed to obtaining any license or permit required from the competent personal data protection authority regarding the processing of this data, in line with the transitional period set by law
- Grant you the full right to skip entering this data or to request its deletion at any time
9. Children's Data
Any user may use the Chefaa app and place orders, in accordance with the policies of the App Store and Google Play. For medicines requiring a medical prescription, this is clearly indicated to the customer, and the final decision on dispensing the medicine rests with the pharmacy fulfilling the order; Chefaa acts solely as a technical intermediary and does not take part in the sale decision.
If the user of the service is under 18 years of age, we recommend obtaining parental supervision or consent, particularly with respect to entering any sensitive health data.
10. Direct Marketing
We send you marketing messages only after obtaining your consent (opt-in). Each message will identify Chefaa as the sender and state that it is a marketing message, and you may stop receiving them at any time as follows:
| Cancellation Mechanism | Channel |
|---|---|
| Decline the permission upon installation, or disable it from your device settings | In-app Push Notifications |
| Send the word "Stop" to the sending number | SMS Text Messages |
| Block the sender's number | |
| Click the unsubscribe link included in the message |
11. Data Retention
We retain your data only for as long as necessary to achieve the purpose for which it was collected, as follows:
- Account and Order Data: retained for as long as your account remains active.
- Support Records: retained for as long as the current support tool remains in use.
- Electronic Payment Data: you may delete it directly from your account at any time, provided there is no active order linked to the payment method to be deleted.
- Once the purpose for retaining the data has ended, it is deleted or retained in a form that does not allow your identification (anonymized data), where retention continues to be required for legal reasons.
12. Data Security
Chefaa applies appropriate technical and organizational measures to protect your data, including:
- A Web Application Firewall (WAF) to monitor for vulnerabilities and breaches
- Use of a secure server for data transmission
- Password-protected data, with access restricted to authorized employees according to their job roles only, through multi-factor authentication
While we are committed to applying the best available security practices, we do not guarantee absolute, unbreachable protection under all circumstances, given the constantly evolving nature of online security threats.
In the event of any breach affecting your data, Chefaa is committed to notifying the competent personal data protection authority within 72 hours of discovering the incident, and notifying you as an affected user within 3 business days of that notification, where required by law.
13. User Rights
You have the right to:
- Access Your Data: request a copy of the data we store about you (preparing it may take up to one month, as no automated mechanism is currently available).
- Correct Your Data: edit your personal data and order-related data yourself through your account.
- Delete Payment Data: delete electronic payment methods linked to your account directly, provided there is no active order linked to them.
- Delete Your Account Entirely: submit a request for the permanent deletion of your account and all of its data, which will be carried out within 3 months of the request date, given the possibility of pending processes or orders linked to the account.
- Withdraw Your Consent: withdraw your consent to the processing of optional health data, or to receiving marketing messages, at any time.
- Lodge a Complaint: file a complaint with the Personal Data Protection Center (PDPC) if you believe that the processing of your data violates the law.
To exercise any of these rights, you may contact us at [email protected].
14. Account Deletion
Users may request the deletion of their account through the app or by contacting the support team.
Once a deletion request is submitted:
- The request is reviewed and the requester's identity is verified.
- The account is disabled in accordance with internal procedures.
- The data is deleted or anonymized within a period not exceeding 90 days, unless retaining certain data is required by law or for legitimate regulatory or security purposes.
15. Cookies
We use cookies to improve your experience, for analytics purposes, and to display content tailored to your previous visits to our website.
Cookies are divided into:
- Persistent Cookies: remain stored until their expiry date or until you delete them.
- Session Cookies: expire when the browser is closed.
You may disable cookies or enable a warning whenever a cookie is sent, through your browser settings, noting that this may affect the proper functioning of some of our services.
16. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices or in applicable laws. Any update will be published on this page along with the date of the last revision.
17. Contact Us
For any inquiry regarding this Policy or your personal data, please contact us at: [email protected]