WhatsApp icon

WhatsApp

Email icon

support@tarsah.com

tarsah logo navbar TARSAH
  • Store
  • Services
    • Embroidery
    • Screen Printing
  • About us
  • Blog
    • profile avatar
    • profile avatar
      • Log in
      • Sign up
← Back to Home

Privacy Policy v1.0

Privacy Policy

Language
🇬🇧 English ✓ 🇪🇬 العربية ✓ 🇩🇪 Deutsch ✓ 🇧🇬 Български ✓

📋 Table of Contents

  • 1. Introduction
  • 2. Who We Are (Data Controller)
  • 3. Information We Collect
  • 4. How We Use Your Information
  • 5. Data Storage and Security
  • 6. How We Share Your Information
  • 7. Data Retention
  • 8. Cookies and Tracking Technologies
  • 9. Your Privacy Rights
  • 10. Children's Privacy
  • 11. International Data Transfers
  • 12. Third-Party Links
  • 13. Changes to This Privacy Policy
  • 14. Contact Us
1

Introduction

Welcome to Tarsah ("we," "us," or "our"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, services, and products.

We operate across multiple regions to serve you better:

  • European Operations: Germany and Bulgaria (serving EU customers)
  • Middle East & Africa Operations: Alexandria, Egypt (serving Egypt, Middle East, and African customers)

By using our services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use our services.

2

Who We Are (Data Controller)

Company Name: Tarsah

European Operations:

  • Germany Office: Freisinger Strasse 17, 10781, Berlin.
  • Bulgaria Office: Manastirski Livadi 140A Todor Dzhebarov, Sofia.

Middle East & Africa Operations:

  • Alexandria, Egypt Office: Al Mansheya Al Kobra 113 Al Gazaar Street

Contact Information:

  • Email: support@tarsah.com
  • Data Protection Inquiries: support@tarsah.com
3

Information We Collect

3.1 Information You Provide to Us

We collect information that you voluntarily provide when you:

  • Create an account
  • Make a purchase
  • Contact customer support
  • Subscribe to our newsletter
  • Participate in surveys or promotions

Types of information collected:

  • Personal Identification: Name, email address, phone number, date of birth
  • Billing Information: Billing address, shipping address
  • Payment Information: Payment card details (processed securely by our payment providers)
  • Account Credentials: Username and encrypted password
  • Communication Data: Messages, feedback, and support inquiries

3.2 Information Collected Automatically

When you use our services, we automatically collect:

  • Device Information: IP address, browser type, operating system, device identifiers
  • Usage Data: Pages visited, time spent on pages, links clicked, purchase history
  • Location Data: Approximate location based on IP address (for fraud prevention and localized services)
  • Cookies and Tracking Technologies: See Section 8 for details

3.3 Information from Third Parties

We may receive information about you from:

  • Payment processors (transaction verification)
  • Social media platforms (if you connect your account)
  • Marketing partners (aggregated analytics)
4

How We Use Your Information

4.1 Essential Business Operations

  • Process and fulfill orders: Product delivery, order confirmations, shipping updates
  • Account management: Create and maintain your account
  • Customer support: Respond to inquiries and resolve issues
  • Payment processing: Secure transaction handling
  • Fraud prevention: Verify identity and prevent unauthorized access

Legal Basis (EU): Contract performance, legitimate interests, legal obligations

4.2 Service Improvement

  • Analyze usage patterns: Improve website functionality and user experience
  • Product development: Develop new features and services
  • Quality assurance: Monitor and improve service quality

Legal Basis (EU): Legitimate interests

4.3 Marketing and Communications

  • Promotional emails: Send newsletters, special offers, and product updates (with your consent)
  • Personalized recommendations: Suggest products based on your preferences
  • Surveys and feedback: Request your opinions to improve our services

Legal Basis (EU): Consent (you can opt-out anytime)

4.4 Legal and Compliance

  • Comply with legal obligations: Tax reporting, regulatory compliance
  • Enforce terms and policies: Protect against violations
  • Legal proceedings: Defend legal claims

Legal Basis (EU): Legal obligations, legitimate interests

5

Data Storage and Security

5.1 Where We Store Your Data

Primary Data Storage:

  • All customer data is stored on Amazon Web Services (AWS) servers located in Ireland (EU-West-1 region)
  • This ensures EU customers' data remains within the European Economic Area (EEA)

Regional Data Processing:

  • European customers: Orders and customer service handled by our Germany and Bulgaria offices
  • Middle East, Africa, and Egypt customers: Orders and customer service handled by our Alexandria, Egypt office

5.2 Data Transfers

When necessary, we transfer data between our regional offices:

  • EU to Egypt transfers: We use Standard Contractual Clauses (SCCs) approved by the European Commission
  • Egypt to EU transfers: Encrypted and subject to the same SCCs
  • All transfers comply with GDPR Article 46 requirements

5.3 Security Measures

We implement industry-standard security measures:

  • Encryption: SSL/TLS encryption for data in transit, AES-256 encryption for data at rest
  • Access controls: Role-based access, multi-factor authentication for staff
  • Regular audits: Security assessments and penetration testing
  • Data backup: Regular encrypted backups stored securely
  • Incident response: Procedures to detect, investigate, and respond to data breaches

Note: While we strive to protect your data, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.

6

How We Share Your Information

We do NOT sell your personal information. We only share your data in the following circumstances:

6.1 Service Providers (Data Processors)

We share information with trusted third parties who help us operate our business:

  • Payment processors: Stripe, PayPal (to process payments)
  • Shipping carriers: DHL, FedEx, local couriers (to deliver orders)
  • Email service providers: For transactional and marketing emails
  • Cloud hosting: AWS Ireland (data storage)

All service providers are contractually obligated to protect your data and use it only for specified purposes.

6.2 Legal Requirements

We may disclose your information if required by law:

  • Court orders, subpoenas, or legal processes
  • To protect our rights, property, or safety
  • To prevent fraud or security threats
  • In connection with investigations by law enforcement

6.3 Business Transfers

If we are involved in a merger, acquisition, or asset sale, your information may be transferred. We will provide notice before your data is transferred and becomes subject to a different Privacy Policy.

6.4 With Your Consent

We may share your information for purposes not described in this policy with your explicit consent.

7

Data Retention

We retain personal data only for as long as is strictly necessary for the purposes for which it was collected, in accordance with the principles of data minimisation and storage limitation under Article 5(1)(e) of the EU General Data Protection Regulation (GDPR).

Retention periods are defined to meet contractual needs, statutory obligations, and legitimate business interests. Once these periods expire, data is securely deleted, pseudonymised, or fully anonymised so that it can no longer be linked to an identifiable individual (Article 17 GDPR – Right to Erasure).

Data Type Retention Period Legal Basis (Reference)
Account information Until account deletion + 30 days for technical backup Performance of contract (Art. 6(1)(b)), legitimate interest (Art. 6(1)(f))
Order history and invoices 7 years after purchase (consistent with EU and Egyptian tax laws) Legal obligation – accounting records (Art. 6(1)(c))
Payment records / transaction logs 7 years (anti-fraud and audit requirements) Legal obligation (Art. 6(1)(c))
Marketing consent records Until withdrawal of consent + 90 days for audit proof Consent (Art. 6(1)(a)) and accountability (Art. 7(1))
Customer support communications 3 years after last interaction Legitimate interest – service quality and dispute handling (Art. 6(1)(f))
Legal agreement acceptance logs Indefinitely (as evidence of lawful consent and compliance) Legal obligation & defence of legal claims (Art. 6(1)(c),(f))
Website cookies / analytics data 1 – 24 months (see Cookie Policy) Consent (Art. 6(1)(a)), legitimate interest (Art. 6(1)(f))

Data retention schedules are reviewed annually to ensure ongoing compliance with Article 30 GDPR – Records of Processing Activities. Security measures for deletion and anonymisation follow Article 32 GDPR – Security of Processing.

In exceptional cases (e.g., ongoing disputes, chargebacks, or legal claims), certain data may be retained longer solely for the purpose of defending or exercising legal rights, after which it will be permanently erased.

8

Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience:

8.1 Types of Cookies We Use

  • Essential Cookies: Required for website functionality (login, shopping cart)
  • Functional Cookies: Remember your preferences (language, currency)

8.2 Your Cookie Choices

You can manage cookies through:

  • Our cookie banner: Accept, reject, or customize preferences
  • Browser settings: Block or delete cookies (may affect functionality)
9

Your Privacy Rights

Depending on your location, you have specific rights regarding your personal data:

9.1 EU/EEA Residents (GDPR Rights)

  • Right to Access: Request a copy of your personal data
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your data (with exceptions)
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests or direct marketing
  • Right to Withdraw Consent: Withdraw consent at any time (for consent-based processing)
  • Right to Lodge a Complaint: File a complaint with your local Data Protection Authority

9.2 Egyptian Residents

Under Egyptian data protection principles:

  • Right to access your personal information
  • Right to correct inaccurate data
  • Right to object to processing for direct marketing
  • Right to file complaints with the Egyptian Data Protection Authority (when established)

9.3 International Customers

We respect privacy rights under applicable laws in your jurisdiction. Contact us to exercise your rights.

9.4 How to Exercise Your Rights

To exercise any of these rights:

  1. Email: support@tarsah.com
  2. Subject Line: "Privacy Rights Request - [Your Request Type]"
  3. Include: Your name, email address, and description of your request

We will respond within:

  • EU requests: 30 days (may extend to 60 days for complex requests)
  • Other requests: 30-45 days

Identity Verification: We may request additional information to verify your identity before fulfilling requests.

10

Children's Privacy

Our services are not intended for children under 16 years of age (or 13 in some jurisdictions). We do not knowingly collect personal information from children.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at support@tarsah.com. We will delete such information promptly.

11

International Data Transfers

As we operate across multiple regions, we handle personal data in accordance with the European Union General Data Protection Regulation (GDPR) and equivalent local privacy principles.

  • For EU customers: All personal data is securely stored on Amazon Web Services (AWS) servers located in Ireland (EU/EEA). Data is not transferred or stored outside the European Economic Area. Certain operations—such as customer support or refund processing—may involve limited, remote access by authorized Tarsah personnel located in Egypt, performed under strict confidentiality and security controls. No copies or permanent transfers of EU customer data occur outside the EU.
  • For Egyptian customers: Personal data is likewise stored on AWS Ireland servers and may be processed within the European Union for order fulfillment, billing, or customer service purposes, all under GDPR-compliant safeguards.

Tarsah does not transfer or process personal data in the United States, Canada, or any other non-EU jurisdictions. All international processing complies with applicable data protection laws and uses appropriate technical and organizational measures to maintain data integrity and confidentiality.

12

Third-Party Links

Our website may contain links to third-party websites (e.g., social media, payment processors). We are not responsible for the privacy practices of these sites. Please review their privacy policies before providing any information.

13

Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect:

  • Changes in our practices
  • Legal or regulatory requirements
  • New features or services

When we make changes:

  • We will update the "Effective Date" at the top
  • For material changes, we will notify you via email or prominent website notice
  • Continued use of our services after changes constitutes acceptance

Version History: You can view previous versions of this policy by contacting us.

14

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices:

Data Protection and General Inquiries:

  • Email: support@tarsah.com

Last updated: November 05, 2025

Version 1.0

Questions about these terms? support@tarsah.com

  • Find a store
  • Register
  • become a reseller
  • feedback
  • Our Terms
  • Privacy Policy
  • Refund Policy
  • Exchange Policy
  • Delivery Policy
  • Contact Us
  • Sustainability
  • Shipping Policy
newsletter

Subscribe for our newsletter

© 2025 copyright tarsah.com