We collect only the following data, all of it linked to your account:
| Data type | Details | When collected |
|---|---|---|
| Contact info | First and last name, email address, phone number, and an optional second phone number. | Account creation |
| Delivery addresses | Governorate, city/area, nearest landmark, and a contact phone number for the delivery itself. You may save more than one address, and we keep a copy of your primary address to pre-fill the checkout screen. | When you save an address, or when placing an order |
| Baby data (optional) | Baby's name, date of birth, and gender (male/female). Entered by you as the parent or guardian — never collected from a child. | When you create a baby profile — entirely optional |
| Push notification token | A technical identifier issued by Firebase Cloud Messaging for the app installed on your device, along with the platform (iOS/Android) and device language. It contains no personal information and is never used for tracking or advertising. | When you allow notifications |
| Order data | Products ordered, quantities, prices, order status and its history. | When placing an order |
| Content you post | Reviews and their text, photos attached to a review (maximum 3), comments and replies in the Baby Hub section, and suggestions you send us. | When you post it |
| Wishlist | The list of products you saved. | When you save an item |
| Shopping cart | The products you added to your cart and their quantities. Stored on our servers, not only on your device, so your cart is waiting as you left it when you open the app on another device. | When you add to the cart |
| Loyalty points | Your points balance and its transaction history (the reason for each grant or deduction and its date), the rewards you redeemed, and a record of which profile-completion items you claimed a reward for. | When points are granted or redeemed |
| Reporting & blocking data | When you report content: your identity as the reporter, the reason, your optional note, and a text snapshot of the reported content. When you block someone: your list of blocked users. | When you report or block |
| Profile picture (optional) | The picture you choose for your account from your gallery or camera. It is shown to you and to our staff, and next to your comments in the Baby Hub section. | When you upload it yourself |
| Photos attached to notes (optional) | One or more photos you attach to an order note (for example the size or model you want), or to a suggestion you send us. These reach our staff only. | When you attach them yourself |
When signing in with Google we receive only your name and email address. We never receive your password, contacts, or any other data. When signing in with Sign in with Apple we likewise receive only your name and email — the name reaches us once, on your first sign-in — and if you choose "Hide My Email" we never receive your real address at all, only an Apple relay address.
What we never collect: your location, your contact book, photos beyond the ones you upload yourself, advertising identifiers, or any data used to track you across other apps or websites we do not own. No payment data either: orders are cash on delivery only — the app never asks for a card number and contains no payment gateway. And no diagnostic data either: the app contains no behavioural analytics tool tracking how you move between screens, and no crash-reporting service sending anything off your device to us or to a third party.
The app lets a parent or guardian create an optional baby profile containing the baby's name, date of birth, and gender. The sole purpose of this data is to personalize content inside your own app: showing tips appropriate to the baby's age in months, and suggesting products suited to that stage.
To send notifications the app needs a push notification token issued by Google's Firebase Cloud Messaging service. On iOS devices, the message is delivered through the Apple Push Notification service (APNs).
| Kind | Examples | Does it need your consent? |
|---|---|---|
| Operational | Your order's status changed, delivery confirmation, a reminder to review a product you bought, general administrative announcements about the app. | No — these are part of the service you asked for, and reach you as long as notifications are allowed at the device level. |
| Promotional | Offers and discounts, new products, categories or brands, and a reminder about a cart you left without checking out. | Yes — explicit consent required. We send these only if you yourself turn on the "Offers & product notifications" switch. |
The in-app switch: Settings → Notifications → "Offers & product notifications". It is off by default on every account, and you can turn it off again at any time in the same place. Turning it off does not stop your order status notifications. You can also disable notifications entirely from your device settings.
We use your data to: create and manage your account, process and deliver your orders, contact you regarding your orders, send operational notifications, run loyalty points and their rewards, personalize tips based on your baby's age (if you created a baby profile), and review reports to keep content safe.
And with your explicit consent only (the "Offers & product notifications" switch in Settings): we use your cart contents and order history to send promotional notifications — such as reminding you about a cart you left behind, or telling you about an offer on a product or category. This is a marketing use and we call it by its name. If you do not turn the switch on, none of it happens.
What we never do, either way: we do not sell your data, we do not show ads inside the app, we do not share your data with any ad network or data broker, we do not track you across other apps or websites, and we do not use advertising identifiers. The only marketing possible is a notification from us to you about our own products, with your consent.
We do not sell your data or share it with third parties, except with the following parties and only to the extent necessary:
| Party | What they receive | Why |
|---|---|---|
| Delivery courier | Name, phone, and address | To deliver your order |
| Supabase (cloud infrastructure) | Database and sign-in accounts | To run the app |
| Cloudflare (R2 storage and CDN) | Uploaded images and videos: your profile picture, review photos, order-note and suggestion photos | Media storage and fast delivery |
| Brevo (email service) | Your email address and the message text | Sending account-confirmation and password-reset emails |
| Google — Firebase Cloud Messaging | Push token and notification text | Notification delivery |
| Apple — APNs | Push token and notification text (iOS devices) | Notification delivery |
| Google Sign-In | Name and email only (from them to us) | Sign-in |
| Sign in with Apple | Name and email only (from them to us); the email may be an Apple relay address | Sign-in |
These parties are technical service providers that process data on our behalf and only as far as running the service requires. None of them may sell your data or use it for their own purposes. Your data may be stored on their servers outside Iraq.
The app contains reviews, review photos, comments and replies written by users. This content is visible to other users, so do not post personal information you would not want shown.
The database is stored with Supabase and uploaded files with Cloudflare R2, on secure servers outside Iraq. Access to every row is restricted by strict access controls (Row Level Security) that prevent any user from reading another user’s data, and data is transmitted exclusively over encrypted connections (HTTPS). Passwords are hashed and cannot be viewed by anyone, including us.
Retention: we keep your account data for as long as your account exists. Technical notification logs are automatically deleted after 30 days. When you delete your account, data is permanently removed as described below.
Two narrow exceptions on account deletion — stated plainly rather than hidden under "everything is deleted":
| What remains | In what form | Why |
|---|---|---|
| Reports other users filed against your content | The report text and its reason remain, but your link to it is severed, so it becomes anonymized and cannot be traced back to you. | Platform safety: deleting an account must not erase a moderation record or serve as a way to escape review. |
| The technical notification send log | Kept anonymized with no identifier for you, and automatically deleted within 30 days regardless. | Diagnosing delivery failures. |
Reports that you filed against others are deleted in full along with your account.
At any time you can: edit your data from the profile page inside the app, or permanently delete your account from within the app (Profile → Settings → Delete Account). Deletion permanently and irreversibly removes: your account, your personal data, your baby profile, your orders, your saved addresses, your cart, your loyalty points and their history, wishlist, reviews and their photos, comments, your profile picture and the photos you attached to notes and suggestions, the push notification tokens for your devices, and the reports you filed along with your block lists — except for the two exceptions noted in section 7 above.
Rows are deleted from the database the moment you confirm. Uploaded image files are queued for deletion at that same moment and erased from the storage servers within 24 hours at most; during that interval they are linked to no account.
You may also ask us for a copy of your data or for correction of inaccurate data through the channels in section 10. We respond within 30 days at most.
We may update this policy when needed; the last-updated date appears at the top of this page. If a change is material — collecting a new kind of data, or adding a new party we share it with — we will tell you inside the app before it takes effect.
The party responsible for this data is the Baby Love store — Kufa–Najaf Street, opposite Al-Ghadeer Private Hospital, Najaf, Republic of Iraq. For privacy inquiries, to request a copy of your data, its correction or its deletion, or to report content:
We reply within 24 hours and process data requests within 30 days at most.