Last Updated: January 1, 2025
Data Collection
We collect the following categories of personal data:
- Identity Data: name, email address, phone number, date of birth
- Contact Data: delivery address, billing address, location data
- Transaction Data: order history, payment methods, delivery preferences
- Technical Data: IP address, device type, browser information, cookies
- Behavioral Data: search history, product views, preferences, reviews
Data Usage
Your data is processed for the following purposes:
- Account creation, authentication, and management
- Order processing, delivery coordination, and payment processing
- Customer support and service communications
- Platform improvement, analytics, and personalization (with consent)
- Legal compliance, fraud prevention, and security monitoring
Data Sharing
We share data only as necessary with:
- Delivery partners: limited to address and contact details for order fulfillment
- Payment processors: transaction data for payment authorization
- Store partners: order details for preparation and fulfillment
- Service providers: cloud hosting, analytics, customer support tools (under DPA)
- Legal authorities: when required by law or to protect rights and safety
Your Rights
Under GDPR and applicable data protection laws, you have the right to:
- Access: request a copy of all personal data we hold about you
- Rectification: correct inaccurate or incomplete personal data
- Erasure: request deletion of your personal data (Right to be Forgotten)
- Restriction: limit processing of your personal data in certain circumstances
- Portability: receive your data in a structured, machine-readable format
- Objection: object to processing based on legitimate interests or direct marketing
- Withdraw Consent: revoke previously granted consent at any time
- Complaint: lodge a complaint with your local data protection supervisory authority
Data Retention
We retain personal data according to the following schedule:
- Account data: retained for the lifetime of your account plus 90 days
- Transaction records: retained for 7 years as required by financial regulations
- Support communications: retained for 2 years after case resolution
- Analytics data: anonymized after 26 months, or immediately upon data deletion request
Contact Data Protection Officer
For questions about this privacy policy or to exercise your data protection rights, contact our Data Protection Officer:
Email: dpo@mygodly.com
Registered Address: Dubai Digital Park, Dubai, UAE
Supervisory Authority: UAE Data Office (TDRA)