Location sharing is off. Tap here to enable before selecting products
Our network does not have pharmacies near you
Wishlist

Cart

Search by Medicine Name


العربية
Deliver to
× Apply
Filter
Main Categories
Sub Categories
Child Categories
Brands
Type
Skin Type
Formulation
Size
Concentration
Color
Age Range
Oral Care
Hair Type
Hair Color
Pack Size
Suitable For
Free From
Special Features
Scent
Flavor
Price :
Filter by :
Sort by:

Privacy Policy

Privacy and Personal Data Protection Policy

Last updated: June 2026

Welcome to Chefaa. This Policy describes how "Chefaa for Information Technology" collects, uses, shares, and protects your personal data when you use the Chefaa app and website, and explains your rights regarding that data.

By using our services, you agree to the collection and processing of your data in accordance with this Policy. Where the law requires your explicit consent (such as for sensitive health data), we will request that consent separately and specifically; reading this Policy alone does not constitute such consent.

This Policy applies to all users of the Chefaa app, the Chefaa website, and their related services.

1. Company Information

Legal Name: Chefaa for Information Technology

Legal Address: 86A, Street 260, Maadi, Cairo, Arab Republic of Egypt

Scope of Operation: Chefaa currently provides its services in the Arab Republic of Egypt. Chefaa previously had a legal entity and operations in the Kingdom of Saudi Arabia, which have since been discontinued; its website remains available for viewing only, without the ability to register or place orders.

Privacy Contact: [email protected]

2. Data Protection Officer

Chefaa currently manages data protection requests and inquiries through its internal technical operations team. For any inquiry regarding the privacy of your data or to exercise your rights, you may contact us at [email protected].

3. Data We Collect

3.1 Account Data

  • Name (mandatory)
  • Mobile number (mandatory, and verified)
  • Email address (mandatory, not subject to verification)
  • Gender (mandatory)
  • Date of birth (optional)

Your phone number is used as the primary method for login and identity verification.

3.2 Order Data

  • Medicines and products added to the shopping cart
  • Medical prescriptions (text or image) for medicines legally requiring one, where the decision to dispense rests with the pharmacy fulfilling the order
  • Address and pickup/delivery location to complete delivery
  • Additional notes added by the customer upon delivery
  • Order status and history of previous orders

3.3 Health Data (Optional – Sensitive Data)

We collect this data only with your consent, and you may skip entering it without affecting your use of our core services:

  • Chronic illnesses
  • Blood type
  • Height and weight

Given its sensitive nature, this data is handled with a higher level of protection, and is processed or transferred only to the extent necessary to provide the service, in accordance with the legal frameworks governing sensitive data in Egypt.

3.4 Location Data

  • Geographic location (GPS): explicit permission is requested from your device, and you have full freedom to allow or deny it. Enabling location is necessary to determine the products and prices available at pharmacies in your area (zone) capable of fulfilling your order.
  • Address details: street name, building, floor, apartment, and a distinguishing landmark for delivery.

3.5 Device Data

Collected automatically to protect our systems and diagnose technical issues you may encounter:

  • IP address
  • Device model
  • Browser type
  • Operating system version

3.6 Payment Data

Data related to payment transactions and order completion may be collected. Chefaa does not store full payment card data, bank card numbers, or their verification codes on its systems. Payments are processed through licensed payment service providers in accordance with applicable security standards.

4. Legal Basis and Purpose of Data Processing

We process your data on the basis of one or more of the following legal grounds:

Legal Basis Purpose
Performance of the contract between you and us Fulfilling and delivering orders
The legitimate interest of Chefaa and its users Account verification and protecting the system against fraud
Your explicit, written consent Processing optional health data
Your consent (opt-in) Sending marketing messages
Legal obligation Compliance with legal and regulatory requirements

5. How We Use Personal Data

Chefaa uses personal data for the following purposes:

Service Delivery

  • Creating and managing accounts.
  • Fulfilling orders.
  • Processing payments.
  • Delivering orders.
  • Providing technical support and customer service.

Service Improvement

  • Analyzing usage behavior.
  • Improving user experience.
  • Developing new features and services.
  • Measuring platform performance.

Communicating with Users

  • Sending order notifications.
  • Responding to inquiries.
  • Providing technical assistance.
  • Communicating regarding the account or orders.

Security and Fraud Prevention

  • Protecting systems and services.
  • Detecting suspicious activity.
  • Preventing fraud or misuse.
  • Investigating security incidents.

Legal Compliance

  • Complying with applicable legal and regulatory requirements.
  • Responding to legal requests issued by competent authorities.

Marketing

  • Sending offers, services, and marketing materials to users who have consented to receive them, where such consent is required.

6. Sharing Your Data with Other Parties

We share your data with the following categories of parties, only to the extent necessary to provide our services:

6.1 Pharmacies

We share order data (medicines, prescription where required, address) with the fulfilling pharmacy through a dedicated Chefaa portal.

6.2 Shipping Companies

To carry out delivery operations.

6.3 Electronic Payment Companies

Paymob: for processing payments within the app, the website, and points of sale, as well as collecting cash on delivery. Chefaa does not retain payment card data on its servers.

6.4 Messaging Service Providers

Cequens: for sending SMS and WhatsApp messages.

6.5 Analytics and Tracking Tools

These tools are used to share user behavior, events, and certain parameters associated with them, without direct identifying data:

  • Google Analytics 4 (GA4)
  • Firebase
  • Adjust
  • Microsoft Clarity
  • Google Search Console

6.6 Marketing and Advertising Tools

  • Meta Ads
  • Google Ads
  • Webengage (for sending in-app notifications, WhatsApp, email, SMS, and in-app banners)

6.7 Technical Tools

These tools are used only to share user behavior, IP address, operating system version, and device characteristics and model, without sharing your direct personal data:

  • Sentry (technical error monitoring)
  • Cloudflare (website protection)
  • Domix.ai (customer support and live chat)

7. Data Storage and International Transfer

Customer data is stored on Amazon Web Services (AWS) servers in the United States of America (Virginia).

Certain data is also shared with service providers based outside Egypt, within the limits set out in the previous section:

Country Entity
India Webengage
Germany Domix.ai
United States of America Sentry
Egypt (not considered an international transfer) Paymob

Chefaa is committed to taking appropriate measures to protect personal data during international transfers and to working towards compliance with applicable legal and regulatory requirements.

8. Sensitive Data

Sensitive data, as defined by law, includes: health data (psychological, mental, physical, or genetic), biometric data, financial data, religious beliefs, political opinions, security-related information, and children's data.

With respect to the optional health data we collect (chronic illnesses, blood type, height and weight), we:

  • Collect it only with your consent, given separately from this Policy at the time of entry
  • Are committed to obtaining any license or permit required from the competent personal data protection authority regarding the processing of this data, in line with the transitional period set by law
  • Grant you the full right to skip entering this data or to request its deletion at any time

9. Children's Data

Any user may use the Chefaa app and place orders, in accordance with the policies of the App Store and Google Play. For medicines requiring a medical prescription, this is clearly indicated to the customer, and the final decision on dispensing the medicine rests with the pharmacy fulfilling the order; Chefaa acts solely as a technical intermediary and does not take part in the sale decision.

If the user of the service is under 18 years of age, we recommend obtaining parental supervision or consent, particularly with respect to entering any sensitive health data.

10. Direct Marketing

We send you marketing messages only after obtaining your consent (opt-in). Each message will identify Chefaa as the sender and state that it is a marketing message, and you may stop receiving them at any time as follows:

Cancellation Mechanism Channel
Decline the permission upon installation, or disable it from your device settings In-app Push Notifications
Send the word "Stop" to the sending number SMS Text Messages
Block the sender's number WhatsApp
Click the unsubscribe link included in the message Email

11. Data Retention

We retain your data only for as long as necessary to achieve the purpose for which it was collected, as follows:

  • Account and Order Data: retained for as long as your account remains active.
  • Support Records: retained for as long as the current support tool remains in use.
  • Electronic Payment Data: you may delete it directly from your account at any time, provided there is no active order linked to the payment method to be deleted.
  • Once the purpose for retaining the data has ended, it is deleted or retained in a form that does not allow your identification (anonymized data), where retention continues to be required for legal reasons.

12. Data Security

Chefaa applies appropriate technical and organizational measures to protect your data, including:

  • A Web Application Firewall (WAF) to monitor for vulnerabilities and breaches
  • Use of a secure server for data transmission
  • Password-protected data, with access restricted to authorized employees according to their job roles only, through multi-factor authentication

While we are committed to applying the best available security practices, we do not guarantee absolute, unbreachable protection under all circumstances, given the constantly evolving nature of online security threats.

In the event of any breach affecting your data, Chefaa is committed to notifying the competent personal data protection authority within 72 hours of discovering the incident, and notifying you as an affected user within 3 business days of that notification, where required by law.

13. User Rights

You have the right to:

  • Access Your Data: request a copy of the data we store about you (preparing it may take up to one month, as no automated mechanism is currently available).
  • Correct Your Data: edit your personal data and order-related data yourself through your account.
  • Delete Payment Data: delete electronic payment methods linked to your account directly, provided there is no active order linked to them.
  • Delete Your Account Entirely: submit a request for the permanent deletion of your account and all of its data, which will be carried out within 3 months of the request date, given the possibility of pending processes or orders linked to the account.
  • Withdraw Your Consent: withdraw your consent to the processing of optional health data, or to receiving marketing messages, at any time.
  • Lodge a Complaint: file a complaint with the Personal Data Protection Center (PDPC) if you believe that the processing of your data violates the law.

To exercise any of these rights, you may contact us at [email protected].

14. Account Deletion

Users may request the deletion of their account through the app or by contacting the support team.

Once a deletion request is submitted:

  • The request is reviewed and the requester's identity is verified.
  • The account is disabled in accordance with internal procedures.
  • The data is deleted or anonymized within a period not exceeding 90 days, unless retaining certain data is required by law or for legitimate regulatory or security purposes.

15. Cookies

We use cookies to improve your experience, for analytics purposes, and to display content tailored to your previous visits to our website.

Cookies are divided into:

  • Persistent Cookies: remain stored until their expiry date or until you delete them.
  • Session Cookies: expire when the browser is closed.

You may disable cookies or enable a warning whenever a cookie is sent, through your browser settings, noting that this may affect the proper functioning of some of our services.

16. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices or in applicable laws. Any update will be published on this page along with the date of the last revision.

17. Contact Us

For any inquiry regarding this Policy or your personal data, please contact us at: [email protected]

Contact us