Privacy policy
Dukkan is a point-of-sale system for small shops. This page explains who runs it, what the platform holds, where it is held, for how long, and what you can ask us to do with it.
Who we are
The platform is operated by Ismail A. Amassi, trading as Dukkan, Gaza, Palestine ("we", "the provider"). Every question, request or complaint about this page goes through the contact form, which reaches us directly. We aim to answer within two working days and to resolve a request within thirty days.
Two different roles
The platform handles two kinds of information, and its role is different for each.
- The merchant's own account. The shop's name, its address on the platform, the owner's login email, and the subscription that runs it. Here we decide what is collected and why — we are the controller.
- The shop's data. Products, prices, sales, staff, and the shop's own clients — including their names, phone numbers, purchase history and outstanding debts. This belongs to the merchant. We store and process it on the merchant's instruction and for no other purpose — we are the processor. The terms of that relationship are in the data processing addendum.
A shopper whose name appears in a shop's client list never signed up for anything here. Requests about that data go to the shop; we assist the shop, and do not decide on its behalf. If you are that shopper and the shop does not answer, write to us through the contact form and we will forward your request to the shop and tell you what we did.
Why we process it, and on what basis
- To run the service you asked for. Everything in the merchant's account and the shop's data is processed because it is necessary to provide the point-of-sale service under the terms of service.
- To keep the platform safe. Sign-in attempts, session tokens, device records and the activity log are processed because we have a legitimate interest in preventing unauthorised access and in being able to explain what happened when something goes wrong.
- To tell you things you need to know. The owner's email receives transactional messages only: verification, password resets, backup notices, replies to contact-form messages, and notices of changes to these documents. We send no marketing email.
Palestine has no general data-protection statute in force at the time of writing. We apply the commitments on this page and in the addendum as contractual obligations to every merchant, aligned with the principles of the EU General Data Protection Regulation, and where a merchant is subject to a data-protection law of their own country the addendum is written to meet the processor duties such laws impose.
What is stored
| Category | Examples | Role |
|---|---|---|
| Merchant account | shop name, subdomain, owner's email, plan, subscription dates | controller |
| Staff | name, role, hashed PIN | processor |
| Catalogue | products, categories, suppliers, units, prices, stock | processor |
| Sales | orders, order lines, discounts, payments, cash movements, shifts | processor |
| Shop clients | name, phone, purchase history, outstanding balance | processor |
| Devices | a server-generated identifier, a human-readable label (e.g. "Galaxy A15 · Android 15"), last-seen time | processor |
| Files | exports, backup bundles and attachments the shop produced, in private storage | processor |
| Operational logs | activity log entries, sign-in attempts, delivery records for the emails we send | mixed |
The mobile app collects no hardware identifier: no advertising ID, no IMEI, no Android ID. A terminal is identified by a random identifier the server issues at enrolment, which the owner can revoke from the Devices screen. The camera is used in-frame to read barcodes and nothing it sees is stored or transmitted.
Sub-processors and where your data is
| Sub-processor | What it does | Where |
|---|---|---|
| Supabase | the database, authentication, and file storage | Singapore (AWS ap-southeast-1) |
| Vercel | hosting and delivery of the web application; cookieless, aggregated visit statistics on the public marketing pages; cookieless page-performance timings | United States, with a global delivery network |
| Resend or Mailgun | delivery of transactional email, whichever is configured on the platform | United States |
| Sentry | crash and error diagnostics, only when a reporting key is configured, and with personal data removed before a report is sent | United States |
There are no others. No advertising network, no tracking pixels, no third-party scripts beyond the two Vercel measurements named above.
Visit statistics (Vercel Web Analytics) run only on the public marketing pages — the landing, demo, pricing and contact pages — never inside a signed-in shop, the admin panel, or the mobile app. They are cookieless: they store nothing on your device, build no profile of you across sites, and the events they record carry no name, email, phone number or anything typed into a form — only counts, such as "a demo request was submitted".
Performance timings (Vercel Speed Insights) run on every web page, including inside a signed-in shop. They measure how fast a page loaded — the route, the timing figures, the type of device and connection — and nothing else: no cookie, no identifier, no content of the page, no name, and nothing about the shop's records. They exist so that a slow till can be found and fixed.
Your data leaves Palestine. The database is in Singapore and the other sub-processors are in the United States. Each of them is bound to us by its own published data-processing terms, which include standard contractual clauses for international transfers and a commitment to process data only on our instructions. We will tell merchants at least thirty days before we add or replace a sub-processor, as the addendum sets out.
Cookies
The platform sets functional cookies only. There is no analytics cookie and no third-party cookie of any kind — both Vercel measurements described above are cookieless and store nothing on your device.
| Cookie | What it is for |
|---|---|
dukkan_session | keeps a signed-in staff member signed in |
dukkan_admin | the same, for a platform administrator |
dukkan_store | which store account is signed in |
dukkan_ownersel | which of an owner's shops is currently selected |
dukkan_switched | a one-shot notice that the selected shop changed |
dukkan_till | which till this browser is ringing up on |
dukkan_lang | Arabic or English, per device |
No consent banner is shown because none of these is used for anything but running the service. The light/dark theme is remembered in the browser's own storage on the device and never sent to us.
How long it is kept
- A live shop's data is kept while the shop is live. Nothing is deleted on a schedule while the subscription runs.
- A shop whose subscription has ended is blocked, not deleted. Its data is kept so that it can be reactivated. If it stays blocked for six months, we may delete it, and we will email the owner at least thirty days before we do, so the shop can be exported or renewed first.
- A deleted shop — closed by its owner, or deleted after that notice — is retained for ninety days and then permanently purged, together with everything that belongs to it.
- Saved exports, reports and attachments in file storage are removed 90 days after they are produced or detached.
- Backup bundles are kept to the most recent few per shop (8 by default) and the older ones are pruned.
- Sync tombstones — which carry no personal data, only "a row with this id is gone" — expire after 30 days.
- Operational logs follow platform-wide retention windows: the activity log is archived rather than deleted after at least 30 days, and sign-in attempt records and expired session tokens are removed after at least 7 days.
Taking your data with you
A shop owner can export their entire shop — catalogue, clients, sales history, settings — as a single file, at any time, from the store settings. That export is also the termination path: it is offered before a shop is deleted, and it is what the addendum means by return of data.
Security
Access to a shop's data is scoped to that shop at the database level. Staff PINs are stored hashed, never in plain text. Terminal credentials are revocable from the owner's Devices screen, and a stolen refresh token invalidates the whole device rather than being silently reused. File storage buckets are private; no uploaded file is world-readable. All traffic between your devices and the platform is encrypted in transit.
If we learn of a breach of security that affects a shop's data, we will tell the merchant without undue delay, and in any case within 72 hours of becoming aware of it, with what we know, what it affects, and what we are doing.
Your rights
If you are a merchant (the owner of a shop), you can at any time:
- See and correct your account details, in the store settings.
- Export your whole shop, from the store settings, in a machine-readable file.
- Delete your shop, by asking us through the contact form; it is retained for ninety days and then purged as described above.
- Object to any processing you believe goes beyond running the service, and ask us anything about what we hold; we answer within thirty days.
- Complain. If you are unhappy with our answer, you may take the matter to the courts of Gaza under the terms of service, or to any data-protection authority that has jurisdiction over you.
If you are a shop's client or a member of its staff, your data is held for that shop and the shop decides about it. Ask the shop first. The shop can correct or delete your record from its clients screen. If the shop does not answer, write to us and we will pass your request to the shop and tell you the outcome. Two things are honestly not yet built and we will not promise them here: a per-client export, and an erasure that reaches every place a name may have gone — receipts already saved, backups already taken, free-text log entries. Both are on our list.
We sell no data to anyone and use it for no purpose other than those on this page.
Children
The service is for businesses and their staff. It is not directed at anyone under eighteen, and a shop account may only be opened by an adult.
Changes to this page
The version in force is shown at the foot of this page. If we change this page in a way that reduces your rights or widens what we do with data, we will email every shop owner at least thirty days before the change takes effect, and where possible show a notice inside the product. Corrections and clarifications that do not reduce your rights take effect when published. Continuing to use the service after a change takes effect means you accept it; if you do not, you can export your shop and close it before that date.
Contact
Questions and requests about this page go through the contact form.