Privacy Policy
Last updated: August 26, 2026
Mahfouz Market (“Mahfouz”, “we”, “our”, or “us”) operates the Mahfouz Market app and related ordering, delivery, and staff services.
Information we collect
Customer and order data
• Name and phone number.
• Delivery addresses, saved address-book entries, building and delivery instructions.
• Precise location when a customer chooses “Use Current Location” or selects a map point to create a delivery address. Customer location is collected for that address action; it is not continuously tracked.
• Firebase authentication identity and user identifiers.
• Order contents, amounts, instructions, status, history, and related customer-service records.
Driver delivery location
When an authorized driver accepts the prominent location disclosure and starts an assigned active delivery, the app collects precise live location. On Android this may continue in the background through a visible foreground-service notification while the active delivery is underway. The active location is used to operate and secure the delivery, is visible to the customer tracking that order, and may be viewed by the owner or authorized managers responsible for deliveries. Live sharing is stopped when the delivery is successfully completed or tracking is otherwise stopped.
Staff-duty location
In app versions that provide staff-duty location, an employee may explicitly request this feature. No duty point is shared unless the employee has granted location permission, the owner has approved the request, and the employee is actively checked in. The current duty location may be viewed only by the owner and authorized managers for attendance, workplace safety, and operational supervision. Sharing stops after checkout. The feature updates the current point; it is not intended to create a route history.
Staff automatic arrival, attendance, and duty location
The continuous duty-sharing rule described above is separate from automatic arrival detection. In the newer Mahfouz Market app, an employee may explicitly enable automatic scheduled-arrival detection and grant precise/background location permission. The owner must also approve the feature. During a bounded scheduled-arrival window (up to four hours before the scheduled shift start through shift end), the app may detect entry into the employee’s scheduled branch geofence. When an in-range arrival is detected, the app records one auto-approved AUTO_ARRIVAL signal containing the arrival location and accuracy, arrival time, scheduled time, and early/late minutes. The employee and the owner or authorized managers are notified. AUTO_ARRIVAL does not complete official Check-in; the employee must still tap Check-in. If an employee attempts attendance outside the branch range, the app creates an owner override request and audit containing location, time, device information, owner decision, owner identity, and reason. Continuous staff current-location sharing begins only after employee consent, owner approval, and official Check-in, is visible only to the owner and authorized on-duty managers, keeps only the latest duty point rather than a route history, and stops at checkout. The employee can disable automatic arrival or revoke location permission in app settings. Attendance, automatic-arrival, and override audit records are retained as business records for operational, security, dispute-resolution, and legal needs and are deleted or anonymized when no longer required; Mahfouz does not claim automatic TTL or checkout deletion for those records.
Optional media and staff records
Authorized users may submit staff face-enrollment photographs for attendance identity setup. We also process staff identity, role, branch, duty, attendance, and access records needed for restricted staff and administrative features.
Delivery access guide and media
For delivery operations, authorized drivers or staff may capture and upload a building-entrance photo, an interphone or doorbell-panel photo (or record that no interphone exists), a short voice instruction, and written access instructions. These records are linked to the relevant delivery address and may include the order identifier, branch, customer phone or address identifier, address or map location, and the authorized staff or driver identity that created the record. The app records audio or takes a photo only after the authorized user deliberately starts that action and grants the relevant operating-system permission. The media and instructions are sent over HTTPS to the Mahfouz server and are available only to authorized drivers and administrative users who need them to complete or manage deliveries. They are used for delivery access, service operation, safety, fraud prevention, audit, dispute resolution, and support. Mahfouz does not sell these records. Google/Firebase does not receive the photo, voice note, or written access content merely because this feature is used; Firebase and Google continue to act as processors only for the app services described elsewhere in this policy. Delivery-access records are retained for future deliveries and operational, security, dispute-resolution, and legal needs. An authorized user may request deletion, and an administrator may remove the content from driver view; deletion-request and administrative audit records may be retained as needed for security, disputes, and legal obligations. We do not claim automatic deletion at checkout or after a fixed TTL.
How we use information
We use the information to:
• create and manage customer profiles and saved addresses;
• prepare, deliver, track, support, and account for orders;
• authenticate users and protect customer, driver, staff, and business accounts;
• operate authorized staff features, attendance, and delivery workflows;
• send service notifications and maintain security, fraud-prevention, audit, and reliability records; and
• comply with accounting, legal, and regulatory obligations.
Sharing and service providers
We do not sell personal data.
Information is disclosed only as needed to provide and secure the service:
• to the customer, driver, owner, or authorized Mahfouz managers where the app’s order, delivery-tracking, or staff-duty workflow requires it;
• to authorized Mahfouz personnel who need it for operations, customer support, accounting, security, or legal compliance;
• to Mahfouz-operated servers that process ordering and staff operations; and
• to Google/Firebase services acting as service providers, including authentication, database/storage, messaging, App Check, and mapping services.
These providers process information on our behalf under their applicable security and privacy terms. We may also disclose information when required by law or to protect users, Mahfouz, or others.
Security
We use access controls, role restrictions, authenticated requests, and encrypted network connections where supported. Access to restricted staff and administrative features requires authorization. No electronic system can be guaranteed completely secure.
Retention and deletion
We retain account and profile information while it is needed to provide the service. Orders, accounting, delivery, security, attendance, and audit records are retained as needed for operations, dispute handling, fraud prevention, legal obligations, and legitimate business records. Active driver and staff location points are updated only for the relevant workflow and sharing is disabled when that activity ends, but associated operational or security records may remain where required. Retention periods vary by record and legal need; we do not promise automatic deletion after a fixed time or immediate erasure at checkout.
You may request access, correction, or deletion through the “Delete Data” page on this site or by emailing mahfouz.market@gmail.com. We will verify the request and delete or anonymize applicable information, subject to records we must retain for legal, accounting, security, fraud-prevention, or dispute purposes.
Children
The app is not directed to children under 13, and we do not knowingly collect personal data from children under 13.
Changes
We may update this policy when the app or legal requirements change. The updated date above identifies the current version.
Contact
Mahfouz Market
Email: mahfouz.market@gmail.com
Staff business account and finance records
When a staff member has a Mahfouz business account, the Mahfouz server processes account movements, debit and credit amounts, running balances, document references, and the linked user identifier for accounting, employee-finance, security, audit, and legal-record functions. Detailed records remain on the Mahfouz server and are shown only through authenticated My Finance and authorized management workflows. Firebase Cloud Messaging receives only a generic event signal and the technical identifier needed for delivery; the push payload does not contain amounts, balances, client keys, document IDs, or other detailed finance fields. Google/Firebase acts only as a service provider/processor. Mahfouz does not sell this data. Records are retained according to operational, accounting, security, dispute-resolution, and legal requirements.