Privacy Policy
Last updated: 22 April 2026
1. Information We Collect
- Account data: name, email address, and password (stored as a secure hash) when you register.
- Profile data: delivery addresses, order history, and support ticket history.
- Usage data: product views, search queries, pages visited, and in-app events collected anonymously to our own servers to improve the service.
- Device data: device model and operating system version collected solely for crash diagnostics and compatibility purposes.
- Communications: messages sent through our built-in messenger between buyers and sellers.
2. How We Use Your Information
- To create and manage your account and authenticate your identity.
- To process orders and facilitate communication between you and sellers.
- To improve our platform based on aggregated, anonymised usage analytics.
- To send transactional notifications (order updates, support replies) — we do not send marketing emails without your explicit consent.
- To detect fraud and ensure the security of the platform.
3. Data Sharing
We do not sell your personal data. We share data only with the following parties: (a) sellers on our platform, to the extent necessary to fulfil your order (e.g. delivery address); (b) cloud infrastructure providers (hosting, object storage) bound by data-processing agreements; (c) law enforcement authorities when required by applicable law.
4. Data Security
All data is transmitted over HTTPS. Passwords are never stored in plain text. On the mobile app, authentication tokens are stored exclusively in the device Keychain (iOS) or Keystore (Android) — they are never written to unencrypted storage. We apply industry-standard encryption at rest for our databases.
5. Cookies and Tracking
Our website uses strictly necessary cookies for authentication and language preferences. We do not use third-party advertising trackers or cross-site tracking cookies. Our mobile app does not use any advertising SDKs. Analytics events are sent only to our own servers and are not shared with third parties for targeting.
6. Your Rights
- Access: request a copy of the personal data we hold about you.
- Rectification: ask us to correct inaccurate or incomplete data.
- Erasure: request deletion of your account and associated personal data.
- Portability: receive your data in a machine-readable format.
- Objection: opt out of analytics data collection at any time via the app settings.
7. Account Deletion
You can delete your account at any time directly from the mobile app — no email request is required.
How to delete your account:
1. Open the Ninhao app and sign in.
2. Go to Sales → Settings.
3. Scroll to Danger Zone and tap Delete account.
4. Read the warning, enter your password (if you signed up with email), optionally tell us why you are leaving, tick the confirmation checkbox and tap Delete my account.
Your session ends immediately when you confirm, and local data stored on your device should be wiped by the app.
You can also request deletion by writing to contact@ninhaomaniya.shop from the email address associated with your account. We will verify your identity and process the request within 30 days.
What happens during the grace period:
After you confirm deletion in the app, your account enters a 30-day grace period. During this time you may sign in again with your email and password and tap Restore account if you change your mind. Until the grace period ends (or you restore), we hide your profile from messenger search and invalidate your existing sessions.
What is permanently removed after the grace period:
Once the grace period expires (and you do not restore), we anonymise your profile (name, email, phone number), delete your saved delivery addresses, delete your messenger contacts and remove you from conversations as a participant, delete media you uploaded where allowed by law, revoke push notification tokens we hold on our servers, and soft-delete your account record. Reviews you wrote become attributed to “Deleted user” rather than removed when they relate to legitimate marketplace feedback.
What we must retain, and for how long:
Order history and invoices: retained for 5 years (or longer where required by local tax and commercial law). Personal identifiers are replaced with an anonymous reference — we keep only the data needed for accounting, tax, warranty and anti-fraud obligations.
Payment transaction metadata (amount, currency, timestamp, anonymised order ID): retained by our payment processor according to their own retention schedule, typically 7–10 years.
Messages exchanged with sellers: the other party may retain a copy of the conversation for dispute resolution. Your identifier in those messages is replaced with “Deleted user”.
Security logs (IP addresses associated with suspected fraud or abuse): retained for up to 12 months for platform security purposes.
Seller accounts with active orders:
If you are a seller and you own a company that is still under review or active on the platform, we may ask you to complete your seller obligations (for example close the company flow in the seller cabinet) before we can anonymise your account. Buyers are entitled to receive the goods or services they paid for.
Contact:
For any question about account deletion or to exercise your data-protection rights, contact us at contact@ninhaomaniya.shop. We respond within 30 days.
8. Data Retention
We retain your account data for as long as your account is active. When you delete your account (see Section 7 — Account Deletion), we remove your personal data after the grace period described there and keep only the minimum anonymised records required by law: order and invoice history is retained for 5 years in compliance with applicable commercial and tax legislation, and payment metadata is retained by our payment processor for 7–10 years. Support ticket records may also be retained for up to 5 years where needed to demonstrate how we handled your requests. You can request early deletion of any non-mandatory data at any time by contacting contact@ninhaomaniya.shop.
9. Children's Privacy
Ninhao is not directed to children under 13 years of age. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us immediately.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Significant changes will be notified via email or an in-app notice at least 14 days before they take effect.
11. Contact
For privacy-related questions or to exercise your rights, contact us at contact@ninhaomaniya.shop. We will respond within 30 days.