Privacy Policy
Last updated: 26 August 2026
MAKHOR (“we”, “us”) operates makhor.shop and the MAKHOR Android and iOS apps. This policy describes what we collect, why, and how you can delete it. We do not sell personal data and we never process boutique payments.
Who we are
MAKHOR is a social discovery product for Mukhawar and Abaya. Contact: hello@makhor.shop. Official site: https://makhor.shop.
Data we collect
We collect the email address and password you use to create an account, plus an optional display name, city, and country. Passwords are stored as bcrypt hashes, never plaintext. Social actions (likes, saves, follows) are stored against your account. Merchant content, if you open a boutique: photos and short videos, captions, optional prices, boutique contact details the merchant provided (WhatsApp, phone, address, map coordinates). Device camera and microphone are used on-device so a boutique can capture a post; we do not access them in the background. Technical: IP address and user-agent in server logs, crash diagnostics if Sentry is configured, and an httpOnly session cookie named makhoor_sid. We do not collect precise GPS from the device; map buttons open an external maps app with the boutique address the merchant entered.
How we use data
To show a relevant feed, let you create an account or log in with email and password, verify boutique email ownership, recover a password, like/save/follow, contact a boutique, prevent abuse, and keep the service secure. Verification and reset links are single-use transactional email, not login codes. Boutique WhatsApp is product contact, not login. We do not use your data for advertising networks or third-party tracking.
Legal bases (where GDPR/UAE PDPL apply)
Contract (providing the discovery feed), legitimate interests (security, ranking, abuse prevention), and consent where you send a message to a boutique via WhatsApp/call.
Who we share with
We do not sell data. Processors that host the product: Vercel (app), Neon (Postgres), Cloudflare R2 (media), Upstash (rate limits), Sentry (crashes, if enabled), and Resend (boutique verification and password-recovery email). Meta is not a processor for MAKHOR login. When you tap WhatsApp, Call, or Directions, your device opens those apps; that is your action, not a silent share by MAKHOR. Boutiques see public posts and aggregate tap counts, not your email, unless you message them yourself.
Cookies and sessions
We set a first-party httpOnly cookie named makhoor_sid after you create an account or log in with email and password. The cookie lasts 30 days, is Secure in production, and SameSite=Lax. We also store theme, city, and onboarding flags in local storage on your device. Native apps load https://makhor.shop in a WebView and use the same cookie.
Retention
Account data and social graph until you delete the account. Password hashes remain only while the account exists. Server logs are rotated by the host. Uploaded media remains while the post or boutique exists.
Account deletion
Sign in, then delete your account in the app (Profile) or on the web at the account deletion URL, or email support. Deletion removes your user record, sessions, likes, saves, follows, blocks, and reports you filed. If you own a boutique and no other user is attached, that boutique and its posts are deleted. This cannot be undone.
Children
MAKHOR is not directed at children under 13 (or 16 where that is the digital-consent age). We do not knowingly collect data from children. Contact us to remove an account opened in error.
Security
Sessions are random tokens stored as hashes. Passwords are hashed with bcrypt and never stored in plaintext. Uploads are type- and size-checked. APIs are origin-checked and rate-limited. Production requires HTTPS. Login is email and password, never WhatsApp or SMS.
International transfers
Processors may store data in the EU, US, or other regions. We choose managed providers with standard contractual clauses or equivalent safeguards where required.
Your rights
Access, correction, deletion, and objection: email hello@makhor.shop or use in-app deletion. You may also complain to your local data protection authority.
Changes
We will update this page when practices change. Continued use after the “Last updated” date means you accept the revised policy.
MAKHOR · makhor.shop
hello@makhor.shop
അക്കൗണ്ട് ഇല്ലാതാക്കുക