Your information
Privacy Policy
Last updated: 9 October 2026
This policy describes the current Online Mall mobile app and this support website. Operator: Murad, Armenia. Privacy questions: muradpetrosyan.mp@gmail.com.
Information the app processes
- Account and profile: email address, account ID, display name, account role/type, authentication records and sessions. Password authentication is handled by Supabase Auth; passwords are not shown to shop owners.
- Shop-owner business data: shop name and description, public address, coordinates, opening hours, business phone/Instagram details, product descriptions, categories, prices, sizes, colors and stock. Owner assignment/invitation email and private ownership contact are separate from public shop information.
- Preferences and interest: saved products, shop follow/like records where supported, notification/alert preferences, and recently viewed/compare information stored on the device. Not every historical or stored capability is exposed in the current interface.
- Engagement analytics: app activity, shop/product views and discovery, saves and related event timestamps, shop/product IDs, and account or session identifiers where the implemented event uses them.
- Source and campaign information: source/medium/campaign parameters associated with app discovery, promotional interactions and shop marketing links. This support website does not add a marketing-tracking system.
- Intent events: directions, contact and Instagram clicks. A directions click is navigation intent, not evidence of a physical visit or purchase.
- Optional follow-up survey: eligibility action/times, whether the survey was shown or answered, self-reported visit/purchase answers and how much Online Mall influenced the visit. Results are for Admin-only research, not shop-owner/worker access. These are not verified visits or sales.
- Error reporting: error context, redacted message, fingerprint, timestamp and account ID where available. The app attempts to redact email addresses and authentication credentials before sending error reports.
- Images: product/shop images and information you choose to upload or provide for the business catalog. Inventory photo upload uses selected photos or the camera when permission is granted.
- Support correspondence: information you email to us, including the account email needed to handle support or deletion requests.
Why information is used
To operate accounts, show the public catalog, manage shop inventory and permissions, remember interest, handle support/deletion, understand discovery and shop engagement, conduct the optional offline follow-up experiment, and investigate errors/security issues.
Who can access it
Supabase provides the app's authentication, database, file storage and server-function infrastructure. Public shop/product business information is visible when authorized by marketplace visibility rules. Shop owners can manage their own shops and see permitted merchant analytics; Admin has marketplace-management access. Private owner email and survey results are not public catalog information. Product images use authorized, short-lived access rather than unrestricted permanent public links in the production-readiness implementation.
We do not give shop owners access to individual follow-up survey answers. Access restrictions are enforced by the backend, not only by hiding screens.
External services and permissions
Choosing Instagram, contact or directions can open an external app or website. Google Maps/Yandex Maps receive the shop destination coordinates when you choose directions. Opening the optional map preview uses OpenStreetMap. These services and your email provider process information under their own policies, including normal connection information such as IP address. Online Mall does not provide its own navigation or request your live GPS location for this feature.
Camera/photo access is for images you choose for inventory. Authentication sessions use secure device storage on native mobile; app preferences and recent/compare information may use local device storage.
This website and email callbacks
This site has no application analytics, advertising pixels, third-party fonts, account database or browser login session. Normal hosting infrastructure may process connection/access information. The callback page does not verify or store your account credentials: it keeps recognized email-link details temporarily in memory, removes them from the address bar, and forwards them to the installed app only when you press Continue. Do not share or email your authentication link.
Retention and deletion
Account-linked data is retained while needed to operate the account unless deleted. Some business records and anonymized operational/statistical history remain after account deletion. The current implementation does not establish a blanket automatic expiry for every event/history record, so we do not promise a fixed retention period. See the actual deletion behavior and request options. Hosting/provider backups may have their own retention cycles; deletion is not a promise of instantaneous removal from every backup.
You can request help accessing, correcting or deleting account information by contacting muradpetrosyan.mp@gmail.com. We may verify that you control the account before acting. Do not send passwords, authentication tokens, receipts or identity documents unless a genuinely necessary verification method is agreed with support.
Current product scope and updates
Online Mall currently has no checkout, reservations or Purchase QR verification. Legacy historical records are not an active purchase-verification service. We will update this page when relevant data practices change.