Henar
Henar Privacy Policy
This policy explains how personal data is collected, used, shared, retained, and protected when you use the Henar mobile application and related services.
Effective date: 3 September 2026
1. Controller and contact
Controller: Henar. For privacy questions, access or correction requests, withdrawal of marketing consent, or account deletion support, contact rumeysa1057seker@gmail.com.
2. Data we collect
Henar processes the following data to provide the service:
- Phone number and one-time verification records for sign-in and account security.
- Name, date of birth, and gender to create and manage a customer account.
- Saved delivery addresses, district information, and the address snapshot made at checkout for delivery and support.
- Account identifier, language preference, and order/purchase history to provide the account, basket, checkout, and order support features.
- If you opt in to marketing notifications: installation identifier, APNs device token, app version, language, time zone, and notification-open information.
- A one-way representation of the IP address to prevent OTP abuse; this is retained only for short-term rate limiting.
3. How we use data
We use data for authentication, account and preference management, catalog browsing, basket and order processing, delivery, customer support, fraud and abuse prevention, security, and technical operation.
Marketing notifications are sent only when your in-app preference and Apple notification permission are enabled. You can turn this preference off in the app. Henar does not use data to track you across other companies’ apps or websites.
4. Sharing and service providers
The name, phone, delivery, and order information necessary to fulfil an order may be shared with the relevant seller. Data is shared only to provide the service, maintain security, meet legal obligations, or carry out communication you choose.
- OTPiQ and its WhatsApp/SMS delivery channels for one-time verification codes.
- Apple Push Notification service (APNs) to deliver notifications you have enabled.
- Railway and Cloudflare to operate API, DNS, CDN, and image infrastructure.
- WhatsApp when you initiate a Profile or order-support link; WhatsApp’s own privacy policy applies.
5. Retention and account deletion
We retain account, address, and transaction data while your account is active and as needed to provide the service. OTP verification and security rate-limit records are kept only for the relevant security need.
When in-app account deletion succeeds, the account is deactivated; name, phone, date of birth, gender, and saved addresses are anonymized, session tokens are revoked, and notification-device records are cleaned up. Order and transaction records may be retained as necessary for legal obligations, accounting, dispute resolution, and security; customer profile fields in those records are kept in anonymized form.
6. Your choices and rights
You can manage profile and notification settings in the app. You can delete your account through the in-app deletion flow or email a privacy request. We may ask for account-related information to verify the request. We respect applicable rights of access, correction, deletion, objection, and complaint.
7. Security and transfers
We protect data in transit with HTTPS/TLS, limit access to what is needed for the role, and protect authentication tokens. Service providers may process data in the countries where they operate; we seek appropriate technical and contractual safeguards.
8. Changes to this policy
We may update this policy when our services or legal obligations change. The current version and effective date are always published on this page.