The side notes are plain-words summaries. Where anything could be read two ways, the full clause governs.
Who this document covers
Three groups of people touch E-Comets: merchants and their staff, who hold accounts; shoppers, who buy from merchants' storefronts; and visitors to this marketing site. This document says what is collected about each, why, and what happens to it. For shoppers, one thing comes first: your relationship is with the shop you bought from. The shop is responsible for what it promises you; E-Comets hosts the shop's systems and holds its data to those systems' promises, which every storefront states plainly on its own privacy pages.
Accounts are opened by businesses, by a person of at least eighteen. The platform is not aimed at children and we do not knowingly collect a child's data; if you believe we hold some, tell us through the contact page and it is deleted.
What we collect about merchants
An account holds what you gave at registration: business name, email, phone. Running the platform adds operational records: invoices and their settlement, staff accounts and their permissions, sessions, and technical logs that record what the system did, each tagged with a request identifier so an incident can be traced. We collect nothing about you from data brokers and nothing beyond what running your store requires.
Your shoppers’ data
Shoppers on an E-Comets storefront have no accounts and no passwords. What a shop holds about a shopper is what a delivery needs: a name, a phone number, an address written the way Lebanese addresses work, and the order itself. That data belongs to the shop's relationship with its shopper. E-Comets processes it only to run the shop's systems: we do not use shopper data for our own marketing, we do not build profiles across shops, and we do not sell it — to anyone, ever. A shopper can see, correct, or ask for the deletion of their data through the storefront's own pages, and those requests reach the shop with the platform's machinery behind them.
The Meta Pixel on this site
This marketing site — not merchants' storefronts — runs a Meta Pixel. It records that a page was viewed and, on the register form, that a signup completed. No name, email, phone or other personal field is attached to either event. We use it to learn which of our own pages lead to signups. If Meta's own processing of pixel events concerns you, Meta's tools control that; blocking the pixel with a browser extension breaks nothing on this site.
Cookies
The platform sets cookies that make it work: a session cookie that keeps a merchant signed in, a cookie remembering which shop a session belongs to, a language cookie, and on storefronts a cart cookie holding item identifiers and quantities — never prices, which are always recomputed server-side. None of these are advertising cookies. The only third-party script on this site is the pixel described above.
How data is protected
Every store's data is isolated from every other store's at the database layer — row-level security enforced by the database itself, not by application code remembering to filter. Connections are encrypted in transit. Passwords are stored only as modern hashes and are never readable by anyone, including us. Card numbers never reach us: when you pay for a plan, the card is entered on MontyPay's secure page, which is certified to handle it, and what E-Comets stores about a payment is its reference, amount, date and outcome, never the number.
Who data is shared with
Four cases. Infrastructure: the platform runs on hosting providers who store data on our instructions and have no right to use it. Delivery: when a shop dispatches an order, the delivery details reach the courier the shop chose, because that is what a delivery is. Payment: when you pay for a plan, your name, your account email, the plan and the amount reach MontyPay, the payment service provider that takes the card, and are handled under its own privacy policy. Law: if a Lebanese authority lawfully requires data, we comply, and where the law allows it we tell the affected merchant. There is no fifth case; nobody buys data from us.
How long data is kept
As long as the account is open, plus what invoicing and Lebanese commercial record-keeping require after it closes. After cancellation, store data stays exportable for sixty days and is then deleted from live systems. Backups age out on their own schedule. A shopper's deletion request is honoured except where an order's financial record must legally survive; what remains is the transaction, not the profile.
Your rights
A merchant can export their store's data from the admin at any time, and can ask through the contact page for anything the export does not cover. A shopper's rights run through the storefront they bought from: seeing what is held, correcting it, stopping marketing messages while keeping order messages, and asking for deletion. Those pages exist on every storefront and the requests are honoured on the timelines stated there.
Changes and contact
When this document changes, a new numbered version is published here with its date; earlier versions stay reachable. Questions about privacy, or requests this document does not answer, reach a person through the contact page, by email at mohammad.mawla@hititans.com, or by phone on +961 71 452 261. The responsible party is E-Comets SAL, Beirut, Lebanon.
This page exists in English and العربية. Where they differ in meaning, that is a defect and not a translation choice, and it is reported rather than resolved by preferring one.