Shreeli (“we”, “us”) operates the Shreeli mobile application, a marketplace that connects buyers in Morocco with travelers who carry requested items on flights into Morocco. This policy explains what personal data we process, why, who we share it with, and what control you have.
By using Shreeli you agree to this policy. If you do not agree, please do not use the app.
1. Who is responsible for your data
Shreeli is the data controller for the personal data described here.
- Privacy contact: [email protected]
- General support: [email protected]
2. Data we collect
Data you give us
| Category | Examples | Why we need it |
|---|---|---|
| Account | Name, email address, phone number, password, profile photo | Create and secure your account |
| Identity verification | Photo of your passport or national ID, a selfie, phone confirmation | Confirm you are a real person before money and goods change hands |
| Orders | Items requested, store links, product photos, price, reward offered, delivery address in Morocco, deadlines, notes | Publish your order and let travelers respond |
| Trips | Origin and destination, departure and arrival dates, available luggage weight, optional flight details | Match your trip with buyers on that route |
| Messages | Chat messages and any photos or files you send in a conversation | Let you coordinate a delivery |
| Reviews and disputes | Ratings, written reviews, dispute descriptions and evidence you upload | Operate the reputation and dispute systems |
| Payment details | Billing information you enter at checkout | Take payment — see section 4 |
Data collected automatically
- Device and diagnostics — device model, operating system version, app version, language and currency settings, and crash reports.
- Push token — a Firebase Cloud Messaging token so we can send notifications about your orders, offers, and messages.
- Approximate location — derived from your IP address to preselect your country and currency. We do not collect continuous or background GPS location.
- Usage data — screens opened and actions taken inside the app, used to fix problems and improve the product.
Sensitive data
Your identity documents and selfie are sensitive data. We collect them only for verification, we do not use them for advertising or profiling, and we never sell them. Some checks — such as detecting a face or reading text on a document — run on your device and the intermediate results are not transmitted to us.
3. Why we process your data, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Creating your account and providing the service | Performance of a contract with you |
| Verifying identity, preventing fraud, keeping the marketplace safe | Legitimate interest and legal obligation |
| Taking payment and holding funds until delivery | Performance of a contract |
| Sending notifications about your own orders, trips, and messages | Performance of a contract |
| Sending marketing messages | Your consent, which you may withdraw at any time |
| Diagnostics, crash reporting, and product improvement | Legitimate interest |
| Responding to lawful requests from authorities | Legal obligation |
4. Payments
Payments are processed by Stripe. Your full card number is entered directly into Stripe’s payment sheet and is never stored on our servers or in the app. We receive only a payment reference, the amount, the status, and the last four digits of the card. Stripe processes this data as an independent controller under its own privacy policy.
5. Who we share data with
We do not sell your personal data. We share it only with:
- Other users, and only what is necessary. A traveler who makes an offer sees your first name, profile photo, rating, verification status, and the order details. Your full delivery address and phone number are revealed only after you accept an offer. Buyers see the traveler’s first name, photo, rating, verification status, and trip details.
- Service providers who process data on our behalf, bound by contract:
- Supabase — database, authentication, file storage, and realtime messaging.
- Stripe — payment processing.
- Google Firebase — push notifications and crash reporting.
- Google Maps Platform — turning an address into map coordinates.
- AI providers — when you share a product link with the app, the page content may be sent to an AI provider to extract the product name, price, and image. Do not paste personal information into these fields.
- IP geolocation providers — to infer your country from your IP address.
- Authorities, where we are legally required to disclose, or to establish or defend legal claims.
6. International transfers
Our providers may process data outside Morocco, including in the European Union and the United States. Where data leaves Morocco we rely on the transfer safeguards those providers offer, including the European Commission’s standard contractual clauses, and on the authorisations required by Moroccan law.
7. How long we keep data
| Data | Retention |
|---|---|
| Account data | While your account is open |
| Order, trip, and payment records | 10 years after the transaction, to meet accounting and tax obligations |
| Identity verification documents | 5 years after account closure, for fraud and anti-money-laundering purposes |
| Chat messages | While your account is open, then deleted with it |
| Diagnostics and crash reports | Up to 24 months |
After a deletion request we remove or irreversibly anonymise your data except where the law requires us to keep it for the periods above.
8. Your rights
You have the right to access your data, correct it, delete it, object to or restrict processing, withdraw consent, and receive a copy in a portable format.
To exercise any of these, write to [email protected] from your registered email address. We respond within 30 days.
To delete your account, see Delete my account.
Morocco — you may lodge a complaint with the Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP), the authority responsible for Law 09-08.
European Economic Area and United Kingdom — if you are located there, you may also complain to your national supervisory authority.
9. Security
Data is encrypted in transit with TLS and at rest by our hosting providers. Access to identity documents is restricted to staff who need it to run verification. Passwords are stored only as salted hashes. Delivery uses a single-use code that confirms handover between the two parties.
No system is perfectly secure. If a breach affects your rights we will notify you and the CNDP as the law requires.
10. Children
Shreeli is not for anyone under 18. We do not knowingly collect data from children. If you believe a minor has an account, contact [email protected] and we will remove it.
11. Changes to this policy
We may update this policy. Material changes will be announced in the app or by email before they take effect. The date at the top shows the current version.
12. Contact
Questions about this policy: [email protected]