minogra
minogra

Asking nicely...

Privacy Policy

This Privacy Policy ("Policy") describes how Minogra Inc. ("Company", "we", "us") collects, uses, discloses, and protects personal data of users of the Minogra platform (the "Platform"). By using the Platform, you acknowledge the practices described herein.

Section 1. Data We Collect

1.1. Account Information. Name, email address, telephone number, and authentication credentials provided upon registration.

1.2. Order Information. Shipping and billing addresses, order history, and transaction records associated with purchases.

1.3. Usage Data. Pages viewed, searches performed, and interactions with listings, collected to operate and improve the Platform. Section 8 lists exactly which usage events we record, the lawful basis for each, and how long each is kept.

1.4. Device Information. IP address, browser type, operating system, and device identifiers.

Section 2. Use of Data

2.1. We process personal data for the following purposes:

  • Processing and fulfilling orders;
  • Communicating with you regarding your account and purchases;
  • Personalizing your experience on the Platform;
  • Improving and maintaining the Platform;
  • Detecting and preventing fraud and securing the Platform;
  • Complying with legal and regulatory obligations.

Section 3. Data Storage and Security

3.1. Personal data is stored on secured infrastructure with access controls and encryption applied to sensitive fields.

3.2. Data is categorized by purpose, and each category is retained only for as long as necessary to fulfill that purpose.

Section 4. Your Rights

4.1. Subject to applicable law, you have the right to:

  • Access the personal data we hold about you;
  • Request rectification of inaccurate data;
  • Request erasure of your data;
  • Restrict processing of your data;
  • Obtain a portable copy of your data;
  • Object to certain processing;
  • Withdraw consent at any time, without affecting prior lawful processing.

Section 5. Data Retention

5.1. We retain personal data for the duration of your account and for a period thereafter as required to comply with legal, tax, and accounting obligations (typically seven (7) years for transactional records).

Section 6. Third-Party Disclosure

6.1. We disclose personal data to third parties only as necessary:

  • Payment processors, to complete transactions;
  • Shipping carriers, to deliver orders;
  • Analytics providers, to measure and improve the Platform (Section 8 names the provider and the region);
  • Authorities, where required by law or legal process.

6.2. We do not sell personal data to data brokers or advertisers.

6.3. Bot Protection (Cloudflare Turnstile). The Platform uses Cloudflare Turnstile to protect checkout and other forms from automated abuse. Turnstile operates invisibly, without a visible challenge, and may process limited device and connection information (such as IP address and browser characteristics) to distinguish human visitors from bots. Cloudflare's processing of this data is governed by the Cloudflare Turnstile Privacy Addendum.

Section 7. Updates to This Policy

7.1. We may amend this Policy from time to time. Material changes will be communicated through the Platform. Continued use following any amendment constitutes acceptance of the revised Policy.

Section 8. Usage Analytics

8.1. What we record. The Platform records the following usage events: page views on a store's page, product views, products shown in search and category results, items added to or removed from the cart, checkout started, checkout completed, and impressions and clicks on sponsored listings. Each event carries: the event type and time; the store, branch and product concerned; the sales channel (marketplace, seller storefront, group buy); your country as derived from your connection (never the IP address itself); the language of the page; a coarse device class (desktop, mobile, tablet); the page path with identifiers removed; and, for checkout events, the order value and currency. We do not record your name, email address, IP address, search query text, or any account identifier in these events.

8.2. Visitor and session identifiers. With your consent to analytics cookies we set a random identifier (mn_aid; see the Cookie Policy) that lets us count returning visitors and group events into visits. It is generated at random, is never derived from your account, expires 180 days after it is first set (activity does not extend it), and is deleted the moment you withdraw consent. Without that consent no identifier is set and no page, product, search, cart or advertising event is recorded at all.

8.3. Lawful basis. We process these events on the following bases:

Purpose Events Basis
Counting checkouts started and completed per store, so that sellers can see how their store performs checkout started, checkout completed Legitimate interest (GDPR Art. 6(1)(f)): the seller already holds the order; the count adds no new personal data. These events carry the visitor identifier only if you consented to analytics, otherwise they are recorded without any identifier. You may object at any time (Section 8.6).
Measuring traffic, product interest, search results and cart behaviour; measuring sponsored listings page views, product views, search impressions, cart add/remove, ad impressions and clicks Your consent (GDPR Art. 6(1)(a); ePrivacy Directive Art. 5(3)). Under the Israeli Protection of Privacy Law providing this data is voluntary; there is no legal duty to provide it and you may withdraw at any time.

8.4. Who processes it. Usage events are processed on our behalf by Tinybird (Tinybird Data, Inc.) in the European Union (Frankfurt, Germany), and an archive copy without visitor or session identifiers is stored by Cloudflare, Inc. (R2 object storage). Both act as processors under a data processing agreement. Sellers see only aggregated counts for their own store; a product-level figure is shown to a seller only once it covers at least five distinct visitors, and no seller can see an individual visitor's journey.

8.5. Retention. Event-level records are kept for 90 days in the analytics warehouse. The identifier-free archive copy is kept for 14 months. Daily aggregates (counts per store, day and product, containing no visitor identifiers) are kept for 38 months. All three are deleted automatically when their period ends.

8.6. Your controls.

  • Withdraw consent from the cookie banner or the Cookie Policy page. The mn_aid cookie is deleted immediately and every event bearing that identifier is queued for deletion from the warehouse.
  • Object to the legitimate-interest processing in Section 8.3, or request erasure of your usage events, from your account's Advanced settings (which also lets you export the events linked to your orders), or by writing to privacy@minogra.com — guests may quote an order number. Deleting your account queues the same erasure automatically.
  • Erasure removes every event linked to your orders and every event bearing a visitor identifier that was ever linked to one of your orders; it is normally completed within one day and confirmed against the warehouse before the request is marked done.

For privacy inquiries, contact: privacy@minogra.com

Minogra Inc., Privacy Team

🍪

We value your privacy

We use cookies to enhance your browsing experience, serve personalized content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. Read our Privacy Policy and Cookie Policy.