Naaora
    Naaora

    Privacy Policy

    Last updated: · Version 2.0

    How we handle your personal data across the Naaora platform

    1. Data controller

    Naaora is the trade name under which Avatechtools S.L. provides its services.

    • Legal name: Avatechtools S.L.
    • Registered address: Calle El Colo nº 2, Benalmádena (Málaga), España
    • Privacy contact: support@naaora.com

    See also our Legal Notice, which contains the company's full identifying details.

    2. Who this policy applies to

    Naaora is an e-commerce platform made up of several products that share the same infrastructure and the same controller. This policy applies to everyone who interacts with us:

    • Website visitors: people browsing naaora.com without an account.
    • Merchants: people who use Naaora to build and run their store from the admin panel, the Naaora Lite app or the point-of-sale terminal.
    • Store staff: employees a merchant grants access to the point of sale or to the panel with limited permissions.
    • Partners: professionals and agencies who build stores for third parties or refer the platform.
    • Naaora Academy students: people accessing our training content.
    • Naaora Marketplace buyers: people who purchase through our marketplace.

    What this policy does NOT cover

    Online stores created by our merchants have their own privacy policy. When you buy from one of those stores, the controller of your data is the merchant, not Naaora; we act solely as a processor on their behalf. See section 16 for details.

    3. What data we process

    We only process the data needed to deliver the service. Depending on your relationship with us, this may include:

    • Account data: first and last name, email address, hashed password, phone number, language and profile picture.
    • Store data: trade name, domain, logo, settings, opening hours, payment and shipping methods.
    • Catalogue data: products, variants, prices, inventory and images you upload to the platform.
    • Order data: amounts, order lines, status, payment and shipping method, and incidents.
    • Point-of-sale data: cash sessions, cash counts, terminals, shifts and in-store sales.
    • Billing data: legal name, tax ID, tax address, subscription plan and payment history.
    • Usage data: pages visited, features used, access frequency and in-product actions.
    • Technical data: IP address, session identifier, browser type and version, operating system and device.
    • Support data: messages you send us by email, contact form or WhatsApp, and their history.

    We do not request or process special categories of data (health, beliefs, ethnic origin, biometrics or sexual orientation). Please do not send us this kind of information.

    4. Where your data comes from

    • Directly from you: when you create an account, set up your store, subscribe to a plan or contact us.
    • Automatically: through cookies and similar technologies when you browse our site or use the product.
    • From merchants: when a merchant registers an employee on the point of sale, they provide us with that person's contact details.

    Logging in with Facebook and with Google

    You can sign up and log in to Naaora using your Facebook or Google account. This is handled through Firebase Authentication (Google) and, for Facebook, through Meta's “Facebook Login”.

    When you choose this option, the provider shares the following public profile data with us, and nothing else: your email address, your name, your profile picture and the unique identifier the provider assigns to your account. The permissions we request from Facebook are limited to “email” and “public_profile”.

    • We do not access your friend list, your posts, your messages, your pages or any other content in your account.
    • We never post anything on your behalf and never interact with your account on the social network.
    • We use that data solely to create your Naaora account, identify you when you log in and contact you about the service.

    How to revoke access

    You can withdraw the permission you granted to Naaora at any time from the apps settings of your Facebook or Google account. Doing so means you will no longer be able to log in with that method, but your Naaora account and your data will still exist until you request their deletion.

    5. Why we use your data and on what legal basis

    Every processing activity serves a specific purpose and relies on a legal basis under Article 6 GDPR:

    PurposeData processedLegal basisRetention
    Create and manage your account and give you access to the platformAccount dataPerformance of a contract (Art. 6(1)(b))While the account is active, plus 30 days after closure
    Deliver the service: store, catalogue, orders and point of saleStore, catalogue, order and point-of-sale dataPerformance of a contract (Art. 6(1)(b))While the account is active
    Bill the subscription and meet our accounting and tax obligationsBilling dataLegal obligation (Art. 6(1)(c))6 years from the last entry (Spanish Commercial Code)
    Answer your enquiries and provide supportSupport and account dataContract and legitimate interest (Art. 6(1)(b) and 6(1)(f))3 years from the last contact
    Keep the platform secure and prevent fraud and abuseTechnical data and access logsLegitimate interest (Art. 6(1)(f))12 months
    Measure product usage and improve itUsage and technical dataConsent for analytics cookies (Art. 6(1)(a))Up to 14 months
    Generate product descriptions, titles and content with artificial intelligenceCatalogue data and the prompts you enterPerformance of a contract (Art. 6(1)(b))While the account is active
    Send you marketing communications and product newsName and email addressConsent (Art. 6(1)(a)), withdrawable at any timeUntil you withdraw consent

    6. Artificial intelligence features

    Naaora includes features that generate content automatically: product descriptions and titles, category suggestions and image enhancement. To do this we send our AI providers the product information and the prompts you enter.

    We do not send these providers your customers' data or any order information. Our providers act as processors and are contractually barred from using that content to train their models.

    AI features are an aid: generated content must be reviewed by you before publishing, and you remain responsible for whatever you ultimately publish in your store.

    7. Cookies and similar technologies

    We use first-party cookies that are strictly necessary for the service to work, and analytics cookies that are only activated if you consent. You can change your decision at any time from the cookie preferences panel.

    Read our Cookie Policy

    8. Who we share your data with

    We do not sell your personal data and we do not share it with third parties for advertising purposes.

    To deliver the service we rely on providers that process data on our behalf. We have a data processing agreement in place with all of them under Article 28 GDPR:

    ProviderPurposeLocation
    Google (Firebase Authentication)User authentication, including login with Google and with FacebookEU and USA
    Meta PlatformsFacebook Login, when you choose that methodEU and USA
    Google AnalyticsSite and product usage analytics (only with your consent)EU and USA
    MongoDB AtlasPlatform databaseEU
    Amazon Web ServicesFile and image storage and content deliveryEU (Ireland)
    RenderHosting of the platform APIUSA
    CloudflareHosting and delivery of the public websiteGlobal network
    OpenAI and ReplicateAI content generation and product image processingUSA
    Mailjet and ResendTransactional email and notificationsEU
    Stripe and PayPalPayment processing, when the merchant enables these methodsEU and USA

    In addition, we may disclose your data:

    • To courts, tribunals and public authorities where there is a legal obligation.
    • To our legal and accounting advisers, where necessary to defend our rights.
    • To a third party in the event of a merger, acquisition or sale of assets, informing you beforehand.
    • To any other recipient, where you have given us your express consent.

    9. International transfers

    Some of our providers are established outside the European Economic Area, mainly in the United States. In those cases the transfer relies on the Standard Contractual Clauses approved by the European Commission or on the provider's certification under the EU-US Data Privacy Framework.

    We also apply supplementary measures such as encryption in transit and minimisation of the data transferred. You can request a copy of the safeguards in place by writing to our contact address.

    10. How long we keep your data

    We keep each category of data for the period stated in the table in section 5. As a general rule:

    • Your account and store data are kept while the account is active.
    • If you close your account, we delete or anonymise your data within 30 days, except for data we must keep by law.
    • Billing data is kept for 6 years as required by the Spanish Commercial Code and tax legislation.
    • Our backups are overwritten on a cycle of no more than 90 days, so deleted data may persist there for that period.
    • Once those periods elapse, data is securely deleted or irreversibly anonymised.

    11. How we protect your data

    We apply technical and organisational measures appropriate to the risk:

    • Encryption of all communications using TLS.
    • Encryption of data at rest in the database and in file storage.
    • Passwords stored using key derivation functions, never in plain text.
    • Role-based access control and least-privilege principle within the team and the platform itself.
    • Access logging and continuous monitoring to detect incidents.
    • Regular backups and tested recovery procedures.

    Should a security breach occur that poses a high risk to your rights, we will inform you without undue delay and notify the supervisory authority within 72 hours.

    12. Your rights

    The GDPR grants you the following rights over your personal data:

    • Access: find out what data of yours we process and obtain a copy.
    • Rectification: correct inaccurate data or complete incomplete data.
    • Erasure: ask us to delete your data when it is no longer needed.
    • Portability: receive your data in a structured, commonly used format, or have us transmit it to another controller.
    • Objection: object to processing based on our legitimate interest.
    • Restriction: ask us to suspend processing temporarily while a claim is resolved.
    • Withdrawal of consent: withdraw at any time the consent you gave us, without affecting the lawfulness of processing carried out beforehand.

    How to exercise them

    Write to support@naaora.com from the email address linked to your account, stating which right you wish to exercise. If we cannot identify you with certainty, we may ask for additional documentation.

    We will respond within one month of receiving your request. If the request is particularly complex we may extend that period by two further months, telling you why.

    Exercising these rights is free of charge.

    Right to lodge a complaint

    If you believe we have not handled your request properly, you can lodge a complaint with the Spanish Data Protection Agency (www.aepd.es), the competent supervisory authority in Spain.

    13. Deleting your account and your data

    You can ask us at any time to delete your Naaora account and the personal data associated with it. We have published a page with step-by-step instructions:

    How to delete your account and your data

    If you signed up with Facebook or Google, deleting your Naaora account is independent from your account on those platforms: deleting one does not delete the other.

    Deleting your account means losing access to your store and its content. We recommend exporting your catalogue and order data beforehand.

    14. Minors

    Naaora is a service aimed at professionals and businesses. It is not intended for anyone under 16 and we do not knowingly collect data from minors. If we find that we have processed a minor's data without the authorisation of their parent or guardian, we will delete it. If you believe this has happened, please contact us.

    15. Automated decisions and profiling

    We do not take decisions based solely on automated processing that produce legal effects on you or similarly significantly affect you. The AI features described in section 6 generate content suggestions that you review and choose to publish or discard.

    16. Naaora as a data processor

    When a merchant uses Naaora to run their store, their customers' (buyers') data is processed by Naaora solely on their instructions. In that relationship the merchant is the controller and Naaora acts as processor, under Article 28 GDPR.

    This means that if you bought from a store built with Naaora and want to exercise your rights over that data, you should contact the merchant who owns the store, whose privacy policy you will find on their own site. If you write to us, we will forward your request to the merchant.

    The terms of that arrangement, including security measures, the list of sub-processors and confidentiality obligations, are set out in the data processing agreement that forms part of our terms of service.

    17. Changes to this policy and contact

    We may update this policy to reflect changes in the service or in applicable law. Where the change is material, we will notify you by email or through a prominent notice on the platform, reasonably in advance of it taking effect. The date of the last update appears at the top of this document.

    Contact

    For anything related to this policy or to the processing of your personal data, you can write to us at:

    Need help?