Privacy.

How GHOHARY collects, uses, stores, and protects your information — written to comply with EU GDPR, the UK Data Protection Act 2018, and UAE Federal Decree-Law No. 45/2021.

01 — Data Controller

GHOHARY (“we”, “us”, “our”) operates the website at www.ghohary.com and our atelier in Al Wahda, Dubai. We are the data controller for personal information collected through this site.

Privacy enquiries: WhatsApp or email s.ghohary@gmail.com.

02 — What We Collect

When you place an order, create an account, contact our atelier, or interact with our site, we may collect: your name, email address, telephone number, shipping and billing address, country of residence, order history, communication preferences, and a reference to your payment method.

Stripe processes and stores card details directly — we never see or store full card numbers.

We also collect technical information automatically (IP address, device type, pages viewed) for security and analytics.

03 — Lawful Basis

Under Article 6 GDPR, we rely on the following lawful bases:

  • Contract — to process and fulfil your order, arrange delivery, handle returns of faulty goods, and respond to enquiries.
  • Legal obligation — to retain order, invoice, and tax records as required by UAE and international tax law.
  • Legitimate interest — to secure our website, prevent fraud, and improve our service.
  • Consent — for marketing communications and optional cookies. You may withdraw consent at any time.
04 — How We Use It

We use your information to fulfil orders, arrange delivery, communicate about your purchase, respond to enquiries, prevent fraud, comply with legal obligations, and (with your consent) send occasional updates about new collections and atelier events.

We do not use automated decision-making or profiling that produces legal effects.

05 — Third Parties

We share information only with the service providers required to operate our business, under written contracts that restrict their use of your data:

  • Stripe — payment processing.
  • Resend — transactional email delivery.
  • Cloudflare R2 — image hosting.
  • Vercel — website hosting.
  • Upstash / Redis Cloud — encrypted order and account storage.
  • Shipping couriers (FedEx, DHL, Aramex, or local equivalent) — only the address and contact details required to deliver your order.

We do not sell, rent, or trade your personal information.

06 — International Transfers

Some of our service providers operate outside the UAE and the European Economic Area. Where personal data is transferred to a country without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or equivalent safeguards under UAE and UK law.

07 — Retention

We retain personal data only as long as necessary for the purpose it was collected:

  • Order and invoice records — seven (7) years from the date of the order, to satisfy tax obligations.
  • Account information — for as long as your account is active, plus 30 days after deletion to complete erasure across backups.
  • Marketing preferences — until you unsubscribe.
  • Customer service correspondence — up to three (3) years from your last contact.
08 — Your Rights

Subject to applicable law, you have the right to: access the personal data we hold about you, correct inaccuracies, request erasure, restrict or object to processing, request portability of your data, and withdraw any consent you have given.

Contact us on WhatsApp. We will respond within thirty (30) days.

EEA and UK customers may lodge a complaint with their local supervisory authority — for example the Irish Data Protection Commission (dataprotection.ie), the French CNIL (cnil.fr), or the UK ICO (ico.org.uk). UAE residents may contact the UAE Data Office (uaedataoffice.gov.ae).

09 — Cookies

Our cookie banner asks for consent before any non-essential cookie is placed. Strictly necessary cookies (cart state, currency selection, authentication) are required for the site to function and do not require consent.

You can change preferences at any time via the “Cookie Preferences” link in our footer.

10 — Security

We use industry-standard safeguards: TLS encryption in transit, encrypted storage at rest where applicable, restricted team access, and regular security review of our service providers.

No system is perfectly secure. If we ever discover a breach affecting your data, we will notify you and the relevant supervisory authority within seventy-two (72) hours, as required by GDPR Article 33.

11 — Children

GHOHARY does not knowingly collect personal data from anyone under sixteen (16) years of age. If you believe a minor has provided us with personal information, contact us on WhatsApp and we will delete it.

12 — Changes

We may update this policy from time to time. Material changes will be communicated by email to registered customers and shown as a banner on the site for thirty (30) days.

13 — Contact

Privacy & general enquiries: WhatsApp or email s.ghohary@gmail.com. Our terms and conditions form part of this policy.

Last updated · 6 May 2026