TASSYIR LTD ("Tassyir", "we", "us", or "our") provides an e-commerce platform that merchants use to create and manage online stores. This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and the choices and rights you have.
It applies to both our website and merchant dashboard at app.tassyir.io and our "Tassyir" iOS mobile app (together, the "Service"). By creating an account or using the Service, you agree to the practices described here.
1. Who We Are
- Legal name
- TASSYIR LTD
- Role
- Data controller
- Address
- 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom
- General & legal enquiries
- [email protected]
- Support
- [email protected]
- Website
- https://tassyir.io
We are the data controller for the personal data described in this Policy. If you have a question or want to exercise your rights, contact us at [email protected].
2. Scope — Website and Mobile App
This Policy covers both our web dashboard (app.tassyir.io) and our iOS app. The same practices apply across both unless we say otherwise; where something is specific to one platform — for example, push notifications on iOS — we point it out.
This Policy describes data about you, the merchant who uses Tassyir. As a merchant, you also collect data about your own customers (such as orders and delivery details). For that customer data you are the controller and Tassyir acts as your processor — see "Store and business data you create" below and our Terms of Service.
3. Information We Collect
Account information you provide
- Name
- Email address
- Profile picture (if you sign in with Google or Facebook)
- Phone number
- The password you set for email sign-in (always stored in encrypted/hashed form — never in plain text)
Store and business data you create
- Stores and storefront settings
- Products, prices, inventory and media
- Orders and their status
- Delivery details and delivery-partner settings
- Your customers' information that you enter or that flows through your store (such as customer names, phone numbers and delivery addresses)
You control this content. You are responsible for having a lawful basis to collect your customers' data and to share it with us so we can provide the Service.
Sign-in / authentication data
You can create or access your account using any of the methods below. We only receive what each provider shares for sign-in, and we use it solely to create and identify your account:
- Email & password: the email address and password you provide.
- Sign in with Apple: we receive your name and email address — or Apple's private "Hide My Email" relay address if you choose it — only on your first sign-in. We use it solely to create or identify your account.
- Google: we receive your name, email address and profile picture.
- Facebook Login: with your permission, we receive your public profile (name and profile picture) and email address.
When you sign in with Apple, Google or Facebook, your use of that provider is also governed by their own privacy policies. To remove data obtained through Facebook Login, see our Facebook Data Deletion page at https://tassyir.io/facebook-data-deletion.
Analytics and product-usage data (via PostHog)
We use PostHog, a third-party analytics provider, as our processor to understand how the Service is used and to improve it. PostHog hosts this data in the European Union (eu.i.posthog.com). Through PostHog we collect the following, linked to your account:
- Your email address
- Your user ID
- A device identifier
- Product-interaction events (for example, screens viewed and features used)
- Crash diagnostics and crash reports
This is first-party product analytics, used only to operate, secure and improve Tassyir. We do not use it to track you across other companies' apps or websites, and we do not use it for advertising. This matches the privacy information declared for our iOS app, which does not request tracking permission.
Push notifications (iOS app)
If you use the iOS app, we register a device token with the Apple Push Notification service (APNs) so we can send you notifications about your orders and account. You can turn notifications off at any time in your device settings.
Information collected automatically
- IP address
- Device type
- App version and operating-system version
- Browser type and version (web)
- Diagnostic and log data needed to run and secure the Service
Authentication tokens stored on your device
To keep you signed in, we store a secure authentication token (a JWT) on your device — in the iOS Keychain (secure storage) in the mobile app, and in your browser's local storage on the web. It is used only for authentication.
5. How We Use Your Information
We use personal data for the following purposes:
- Provide the Service: create your account, run your stores, process orders and deliveries, and keep your data in sync across web and app.
- Authenticate you: sign you in and keep your session secure.
- Notifications: send order and account notifications, including push notifications on iOS and service emails.
- Improve and secure the Service: understand usage, diagnose crashes, fix bugs and develop new features (analytics).
- Security and fraud prevention: protect accounts and detect abuse and unauthorised access.
- Communicate with you: respond to support requests and send important service messages.
- Legal and compliance: meet our legal obligations and enforce our Terms.
6. Legal Bases for Processing (UK/EU GDPR)
Where UK or EU data-protection law applies, we rely on the following legal bases:
- Performance of a contract: to provide the Service you sign up for.
- Legitimate interests: to secure, maintain, analyse and improve the Service, where not overridden by your rights.
- Consent: where required (for example, certain optional integrations, or where you grant a provider permission to share data); you can withdraw consent at any time.
- Legal obligation: to comply with applicable law.
8. International Data Transfers
We are based in the United Kingdom and use service providers that may process data in the UK, the European Union and other countries. Where we transfer personal data internationally, we use appropriate safeguards — such as the UK International Data Transfer Agreement, EU Standard Contractual Clauses, or transfers to countries with an adequacy decision — to keep your data protected.
9. Data Retention
We keep your personal data for as long as your account is active and as needed to provide the Service. When you delete your account, we permanently delete your personal data, except where we must keep certain information to comply with legal, accounting or regulatory obligations, or to resolve disputes and enforce our agreements. Backups are deleted on a rolling schedule.
10. Your Rights
Depending on your location, you have the following rights over your personal data:
- Access: request a copy of the personal data we hold about you.
- Rectification: correct inaccurate or incomplete data.
- Erasure: delete your data (see "How to Delete Your Account and Data").
- Restriction & objection: restrict or object to certain processing, including processing based on legitimate interests.
- Portability: receive your data in a portable, machine-readable format.
- Withdraw consent: where we rely on consent, withdraw it at any time.
To exercise any of these rights, email [email protected]. You can also access and correct much of your information directly in the app or dashboard. We will respond within the time required by law. If you are in the UK or EU and believe we have mishandled your data, you may lodge a complaint with your data-protection authority (in the UK, the Information Commissioner's Office at ico.org.uk).
11. How to Delete Your Account and Data
You can permanently delete your account and personal data at any time:
- In the app: go to Settings → Delete account.
- By email: write to [email protected] from your account email address, and we will delete your account.
Deleting your account permanently removes your personal data from the Service, except where retention is required by law (see "Data Retention"). To remove data obtained specifically through Facebook Login, see our Facebook Data Deletion page at https://tassyir.io/facebook-data-deletion.
12. Security
We take the security of your data seriously and use measures including:
- HTTPS/TLS encryption for all data in transit
- Encryption of stored data at rest
- Secure token storage (iOS Keychain on mobile; protected local storage on web)
- Access controls and least-privilege access to our systems
No method of transmission or storage is completely secure, but we work to protect your data and to notify you and the authorities of any breach as required by law.
13. Children's Privacy
The Service is intended for businesses and merchants and is not directed to children. We do not knowingly collect personal data from anyone under 13 (or the higher minimum age required in your country). If you believe a child has provided us with personal data, contact [email protected] and we will delete it.
14. Third-Party Services
The Service integrates with third parties — including Apple, Google and Facebook (sign-in), PostHog (product analytics), the website analytics and advertising tools described in "Cookies and Website Tracking Technologies" (Google, Contentsquare and the Meta/Facebook Pixel) and delivery partners you choose. Their handling of your data is governed by their own privacy policies, which we encourage you to read. We are not responsible for the practices of third parties.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and notify you through the Service, our website or by email. Your continued use of the Service after an update means you accept the revised Policy.
16. Contact Us
If you have any questions about this Policy or your personal data, contact us:
- Legal name
- TASSYIR LTD
- General & legal enquiries
- [email protected]
- Support
- [email protected]
- Address
- 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom
- Website
- https://tassyir.io