This policy explains what personal data instore collects, why, who receives it, how long we keep it and how you can use your rights under Moroccan Law 09-08. It describes what our software actually does today — including what it doesn’t do yet.
The short version
You sign in with your phone number and a code we send on WhatsApp, or by SMS where we offer it. We don’t ask for an email address or a password.
When you order, the shop receives what it needs for that order. It receives your profile only if you choose to share it with that shop.
If you verify your identity, your ID photos are encrypted and only our review team sees them. Shops only learn that you’re verified.
When you browse, your location stays on your device: we never store it. A delivery pin is kept only with the order or the saved place you put it on.
Usage statistics are off unless you allow them, and they don’t identify you. No advertising, no selling of your data, no other company’s trackers.
You can access, correct and ask us to delete your data. Closing your account today stops all sharing and signs you out everywhere, but erasing the data from our systems isn’t available yet (see “How long we keep it”).
Who we are
instore is the platform behind instore.ma, the shops’ instore pages (such as yourshop.instore.ma, or a web address a shop uses with instore), the account site account.instore.ma and pro.instore.ma. We decide how the personal data needed to run the platform is used — your account, sign-in, identity verification, the orders and bookings that pass through us and everything else this policy describes — and we are responsible for it.
Each shop decides, and is responsible for, how it uses the data it receives about you, on its in-store computer and at its till. “What shops receive” explains what that is.
Your account and sign-in
Phone number — to sign you in, and so that the shop can reach you about an order (a courier writes to you through your order page; the courier app doesn’t show your number). One number, one account.
First and last name — shown to the shops you order from, and compared with your ID if you verify your identity.
City — the city you told us you shop in, to show you shops near you. We store the city, never a precise position.
Saved places — each place you save: its name (“Home”), the pin you placed on the map and an optional note (a floor, a landmark). You can change or delete them at any time; a deleted place is removed from our systems.
Favourites — the shops and products you save. Removing one deletes it.
WhatsApp updates — whether you allow shops to send you order updates on WhatsApp. Off until you turn it on.
Sign-in codes — we never keep a code itself, only a one-way scrambled form to check it. A code works for a few minutes and is deleted once used.
Sessions — when you sign in, your browser receives a session cookie and we record the session: the site, the type of browser (for example “Chrome on Android”), when it started, when it was last used and when it ended. A session ends after 30 days without use, and after 90 days at most (180 days on account.instore.ma).
Security — to stop abuse, we limit how many codes and requests come from one network. For some actions — for example each choice you make about sharing with a shop — we keep the first part of your network address and the type of browser.
Orders, bookings and purchases
Online orders — the shop, the items and options, your note, pickup or delivery, the time you chose, the delivery address and pin, your name and phone number, the prices, fees and discounts, the points, cagnotte or promo code used, each change you made, the order’s progress and, if it was cancelled, who cancelled it and why.
During a delivery — the messages you exchange with the courier and the shop, and the courier’s position (see “If you deliver for a shop”).
After an order — your rating and review and the shop’s reply, a problem you report, and your delivery feedback (with a photo if you add one). A published review shows your first name only.
Purchases in shops — when a shop’s till records a sale under your account (after you show your instore code, or read to the cashier the code we sent you), the sale reaches our systems with your account attached. It is part of the copy of your data you can ask for.
Bookings — the shop, the services, the time, the name and phone number you typed and your note. Bookings are not linked to your account.
Points and cagnotte — your balance at each shop and the history of what you earned and used.
Identity verification
If you choose to verify your identity, we collect a photo of your ID document and a selfie taken with your camera, the name you entered, the version and time of the consent you gave, and the network address you sent them from (so we can spot one person opening many accounts). If you start on a computer and continue on your phone, we also keep a short history of that hand-off: which step happened when, the first part of the network address and the type of browser.
The photos are encrypted on our servers. They are never sent to shops, never shown publicly and never used for anything but this check, and only our review team can open them. A person — not an automatic system — compares them with your name. If you try again after a refusal, the new photos replace the old ones. Shops you share your profile with see only that you’re verified, and since when.
Location, maps and search
Shops near you — if you allow it, your browser gives the page your position, or you place a pin yourself. That position stays on your device for this visit only. When it’s sent to our servers to sort shops by distance, it’s first rounded to about 100 metres, and we never store it or write it in our logs. The city you choose is remembered on your device.
Delivery — the pin you put on an order goes, with the order, to the shop and to the courier who delivers it.
Maps — our street maps come from our own map server, so looking at a map tells no other company where you’re looking. If you switch a map to Satellite, the satellite images come from Esri, which then receives your network address and the area shown.
Address search — when you search for an address on a map, your search words go to OpenStreetMap’s Nominatim service, which returns matching places. Nothing is sent until you press search.
Directions — the “Get directions” link opens Google Maps with the shop’s location; from there, Google’s privacy policy applies.
Searching on instore — what you type in the search is used to answer you, and is never stored or written in our logs.
Usage statistics (optional)
To improve shop pages, we’d like to count how they’re used: menus and products opened, items added to the basket, checkouts started, orders placed, and taps on the menu grouped into large areas of the screen. These statistics stay with us — no other company receives them — and contain no name, phone number, address or free text. They use a temporary random identifier, not your account.
They’re off until you allow them. If your browser sends a “Do Not Track” or “Global Privacy Control” signal, we collect nothing and don’t ask. You can change your choice here at any time:
WhatsApp and other messages
We send sign-in codes and the result of an identity verification on WhatsApp, from instore’s own number. Where we offer it, you can ask for a sign-in code by SMS instead, and we use SMS automatically if your number isn’t on WhatsApp.
A shop can send you order updates on WhatsApp only if you turned on WhatsApp updates. It can chat with you or send you credit-book reminders only if, in addition, you share your profile with it; your replies are kept so that the shop can see the conversation.
Neither instore nor any shop sends you promotional messages today. A shop could only do so if you ticked “may send me offers” when you shared your profile with it.
What shops receive
For each order — the shop you order from receives your name, phone number, the items, your note, the time you chose and, for delivery, the address, its name (such as “Home”) and the pin. This is what it needs to prepare and hand over your order, and it receives it whether or not you share your profile. The order is stored on the shop’s in-store computer.
If you share your profile — you decide this shop by shop: on the shop’s page, in your account’s Shops list, by showing your instore code at its till, or by reading to its cashier a code we send you that names the shop. The shop then receives your name, phone number, whether you’re verified (and since when — never your documents), your points or cagnotte at that shop, your purchases there, including earlier ones, and only the saved places you ticked. It can then recognise you at the till and online.
Your record at that shop — each shop sees how many of your orders there it cancelled because you didn’t come or because the order wasn’t genuine. Other shops never see it.
To stop sharing with a shop, write to us at support@instore.ma. From then on, the shop receives nothing new about you from us.
The copy already on the shop’s in-store computer is no longer updated, but it isn’t removed yet: removing it is part of the erasure that isn’t available yet (see “How long we keep it”).
Each shop is responsible, under the law, for how it uses the data it holds about you. For a question about that data, contact the shop — or write to us and we’ll help you reach it.
Why we may use your data
Law 09-08 (Article 4) allows us to use your data on these grounds:
To provide the service you asked for — your account, sign-in, orders, bookings, deliveries, points and cagnotte, and the details a shop needs for each order. This is the contract between you and us, and between you and the shop.
With your consent — identity verification, sharing your profile with a shop, WhatsApp updates from shops and usage statistics. You can withdraw your consent at any time; this doesn’t affect what was done before.
For our legitimate interests — keeping instore secure and preventing fraud, fake orders and abuse (limits on codes, security records, the record of missed orders a shop sees), and answering your requests.
To comply with the law — when a law or an authority requires us to keep or to hand over data.
Who else receives data
We don’t sell your data and we don’t share it for advertising. Besides the shops (above), the following receive personal data, each only for what is described:
Our team — people at instore see your data only when their work requires it: checking an ID, helping with an order, answering you. Each time someone opens your customer record in our admin tools, it’s logged, and that log is part of the copy of your data.
Couriers — while a delivery waits for a courier, the couriers who can take it (the shop’s own and, when the shop uses instore’s delivery service, that service’s couriers nearby) see your name, the delivery address and its pin. The courier who takes it also sees the order’s total, and you can message each other during the delivery.
Contabo (Germany) — rents us the servers that run our central systems, these websites and our map server.
WhatsApp (Meta) — delivers our codes and messages, and the messages shops send you. It receives your phone number and the message. We connect to WhatsApp with open-source software (WAHA) that runs on our own servers.
Bird — sends a sign-in code by SMS where we offer it. It receives your phone number and the message, and processes them in the European Union.
Esri (United States) — supplies the satellite images, only after you switch a map to Satellite. It receives your network address and the area shown.
OpenStreetMap Foundation (United Kingdom) — runs the Nominatim address search. It receives your search words and your network address when you search for an address on a map.
Route planning — to draw a delivery’s road route and estimate its arrival time, our servers send the courier’s position and the destination — map coordinates only, never a name or phone number — to a route-planning server based on the open-source OSRM software. This can be the public server of the OSRM project.
Cloudflare — answers for our domain names (DNS). Your visits don’t pass through Cloudflare.
Authorities — when Moroccan law requires it, for example under a court order.
Data sent outside Morocco
Some of these providers are outside Morocco: Contabo (our servers) is a German company and Bird processes data in the European Union; WhatsApp (Meta), Esri and Cloudflare are American companies; the OpenStreetMap Foundation is in the United Kingdom. These transfers are needed to provide what you asked for — delivering your code, showing a map, finding an address — and we make to the CNDP the declarations that Law 09-08 requires for them.
How long we keep it
While your account exists — your profile, saved places, favourites, orders, bookings, purchases, points and cagnotte, reviews, messages and verification record (including the photos) are kept. We haven’t yet set periods after which old orders or messages are deleted automatically.
Deleted automatically — a sign-in code as soon as it’s used; the record of each SMS we send (which contains neither your number nor the code) after 90 days; a verification hand-off 24 hours after it ends (its link stops working after 10 minutes if no phone opens it); the courier’s position, from our central systems, as soon as the delivery or the shift ends. Your position for sorting shops is never stored.
When you delete something — a saved place or a favourite you delete is removed at once.
Kept as proof — the history of your sharing choices (what you agreed to, when and where), the steps of each verification hand-off and the log of who opened your customer record are kept, and our systems don’t allow them to be changed.
Usage statistics — they identify no one; we haven’t set a fixed period for them yet.
Backups — a copy of our central database is made every day and kept for 30 days, on backup equipment we run ourselves. Shops’ in-store computers keep their own backups, replaced over time.
What closing your account does today: it closes at once, stops all sharing with shops, signs you out everywhere and blocks sign-in with that phone number. Erasing your data from our systems is not available yet, so your data is kept for now — including your ID photos if you sent them, and the copies already on the in-store computers of shops you shared with. We will update this policy when erasure becomes available.
How we protect it
Connections to instore are encrypted (HTTPS).
Session cookies can’t be read by the pages’ scripts, and sign-in codes are stored only in a scrambled, one-way form.
ID photos are encrypted with a key held only on our servers.
Only our team can use our admin tools, and opening a customer record there is logged.
A shop’s in-store computer, and what it holds, is in the shop’s care. Our team can connect to it to install updates and fix problems.
No system is perfectly secure. If an incident affects your data, we act to limit it and inform you and the authorities as the law requires.
Your rights
Under Law 09-08, you have the right to:
Access — know whether we hold data about you and get a copy of it (Article 7).
Correct — have inaccurate or incomplete data corrected, completed or updated (Article 8). You can change your name, city, places and choices in your account; while a verification is being checked and once you’re verified, your name is locked — write to us to correct it.
Delete — have data deleted that is inaccurate, incomplete or that we have no reason to keep (Article 8). “How long we keep it” explains what a deletion does today.
Object — object, for legitimate reasons, to a use of your data, and object at any time, free of charge, to its use for marketing (Article 9).
Withdraw your consent — for identity verification, sharing with a shop, WhatsApp updates and statistics, at any time.
To get a copy of your data, close your account or stop sharing with a shop, write to us at support@instore.ma.
For any request, write to support@instore.ma. So that we know it’s you, we may ask you to confirm from the phone number of your account.
If you think we haven’t respected your rights, you can complain to the CNDP (Commission nationale de contrôle de la protection des données à caractère personnel): www.cndp.ma.
Cookies and storage on your device
We don’t use advertising cookies, and no other company tracks you through instore. What we store on your device:
Sign-in cookies — keep you signed in on the site you’re using (__Host-sid, and __Host-idp on account.instore.ma), carry a sign-in from one instore site to another (__Host-tx, a few minutes) and let your phone send verification photos for your account (__Host-vh, 20 minutes). They are needed for the service, and the pages’ scripts can’t read them.
Your choices — your language, your statistics choice, the city you chose, the cards you dismissed and, on some shop sites, your “Not now” answer to a sharing request (90 days).
Your progress — your basket at each shop and your last booking request, so that reloading the page doesn’t lose them; a note that you’re signed in, or that a sign-in is under way (never the session itself); and, only if you allow statistics, the statistics waiting to be sent.
This visit only — your position for sorting shops, and a note that the opening animation has played.
Couriers — the courier page keeps the courier signed in on the device.
Clearing your browser’s data for our sites removes all of this and signs you out.
If you deliver for a shop
Couriers are added by the shop they deliver for or, for instore’s delivery service, by our team. If you’re one of them, we use your phone number and name to sign you in (with a WhatsApp code) and to show you by name to the shop and its customers; your deliveries, the cash you collect and hand over, and your messages with customers and the shop; and, only while you’re on shift, your position. We keep only your latest position, show it to the customer and the shop during a delivery, and delete it from our central systems when a delivery or your shift ends; the shop’s in-store computer may keep the last position it received with its record of the delivery. You may be asked to verify your identity, as customers are.
If you contact us as a business
When you ask for a demo on pro.instore.ma or apply to list your shop on instore.ma/sell, we keep what you enter — your name, your phone number or email, your shop’s name, city and type, and your message — with the language you used and the version of the notice shown to you. We use it only to contact you about instore, and only our team sees it. It is kept until we set a period for it; write to us if you no longer want us to contact you.
Changes to this policy
We update this policy whenever what our software does with your data changes, and the date at the top shows the current version.
Contact and complaints
For any question about your data or this policy, write to support@instore.ma. You can also complain to the CNDP: www.cndp.ma.
For businesses
Run a shop? instore is a point of sale that keeps selling offline, with an online page for every shop. instore for business