Who we are

MAROSOAP was founded in 2022, and it is more than just a platform—it embodies our deep love for Moroccan culture and our desire to bring its treasures to the world. Our vision stretches from the vibrant markets of Marrakech to the stunning landscapes of the Atlas Mountains, where we focus on promoting traditional and artisanal products by supporting cooperatives and artisans in marketing their goods in modern ways.

Additional information

In addition to the rights and procedures outlined in this privacy policy, the following information may be relevant to you:

Changes to This Privacy Policy

We may update this privacy policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. Any changes will be posted on this page, and the revised policy will take effect immediately upon publication. We encourage you to periodically review this page for any updates.

Third-Party Links

Our website may contain links to external websites that are not operated by us. We are not responsible for the privacy practices or the content of these third-party websites. We recommend reviewing the privacy policies of any third-party sites you visit.

Minors

Our services are not intended for individuals under the age of 18, and we do not knowingly collect personal data from minors. If you believe that we have collected data from a minor, please contact us immediately so that we can take the necessary steps to remove such data.

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this privacy policy or as required by law. Once your data is no longer needed, we will securely delete or anonymize it in accordance with applicable data protection laws.

Security Measures

We implement appropriate technical and organizational measures to safeguard your personal data from unauthorized access, disclosure, alteration, or destruction. These measures include encryption, firewalls, and secure servers. However, please be aware that no method of online transmission or storage is 100% secure, and we cannot guarantee the absolute security of your data.

How to Contact Us

If you have any questions or concerns regarding this privacy policy, or if you wish to exercise any of your rights, please contact us using the details provided in the "Contact Information" section above.

How We Protect Your Data

We take the protection of your personal data seriously and are committed to ensuring its security. We have implemented various technical and organizational measures to safeguard your data against unauthorized access, loss, misuse, or alteration. Below are the key ways in which we protect your data:

Encryption

We use encryption protocols such as Secure Socket Layer (SSL) to ensure that data transmitted between your device and our website is secure. This encryption protects your sensitive information, such as personal details and payment information, from unauthorized access during transmission.

Access Control

Access to your personal data is restricted to authorized personnel only. We have implemented strict access control mechanisms to ensure that only those who need to use your data for legitimate business purposes can access it.

Data Anonymization and Pseudonymization

Where applicable, we use techniques like data anonymization and pseudonymization to reduce the risks of exposing personal data. This helps protect your information, even if unauthorized access occurs.

Secure Storage

Your personal data is stored on secure servers that are protected by firewalls and other security measures to prevent unauthorized access. We regularly monitor our systems for any potential vulnerabilities and take proactive steps to address them.

Regular Security Audits

We conduct regular security audits and assessments to identify and address any potential weaknesses in our data protection processes. This helps us stay ahead of evolving security threats and ensure that your data remains safe.

Third-Party Security

If we use third-party service providers to process your data, we ensure that they adhere to strict security standards and are compliant with data protection regulations. These providers are required to implement appropriate security measures to safeguard your data during processing.

Data Breach Response

In the unlikely event of a data breach, we have established protocols in place to respond quickly and efficiently. We will notify you and any relevant authorities as required by law, and take immediate steps to mitigate any potential harm to your personal data.

Ongoing Improvements

We continuously evaluate and improve our data protection practices to ensure that we provide the highest level of security for your personal data. We stay up-to-date with industry best practices and legal requirements to maintain the integrity of our security measures.

Your Responsibilities

While we take extensive steps to protect your data, you also have a role in safeguarding your personal information. We recommend that you use strong, unique passwords for your accounts and be cautious when sharing your personal data online. If you believe your account has been compromised, please contact us immediately.

What data breach procedures we have in place

We take the protection of your personal data seriously, and in the unlikely event of a data breach, we have implemented comprehensive procedures to ensure a swift and effective response. Our data breach procedures are designed to minimize the risk to your personal data and to comply with applicable data protection laws.

Immediate Action

If a data breach occurs, our team will take immediate action to assess the scope of the breach and contain any risks to personal data. This includes stopping any unauthorized access and securing affected systems to prevent further exposure of data.

Identification and Assessment

We will assess the nature and extent of the breach, including the type of data affected and the potential risks to individuals. Our team will determine whether the breach is likely to result in a high risk to your rights and freedoms, considering factors such as:

  • Type of personal data involved (e.g., sensitive data, payment information, etc.)
  • The scale of the breach and the number of individuals affected
  • Potential impact on your privacy and security

Notification of Affected Individuals

If we determine that the breach poses a high risk to your rights and freedoms, we will notify affected individuals without undue delay. This notification will include:

  • The nature of the breach, including the type of personal data affected
  • The steps we are taking to address the breach and mitigate any risks
  • Actions you can take to protect yourself, if applicable
  • Contact information for further inquiries

We will notify you via email or other communication channels, depending on the contact details we have on file for you.

Notification to Regulatory Authorities

As required by data protection laws, we will notify the relevant data protection authority (e.g., the Data Protection Commission or other local authorities) of the breach if it poses a significant risk to your privacy. This notification will be made within 72 hours of becoming aware of the breach, unless we are able to demonstrate that the breach is unlikely to result in any risk to your rights and freedoms.

Preventive and Corrective Measures

Following the breach, we will take corrective actions to prevent a recurrence. This may include:

  • Updating security protocols and improving system defenses
  • Conducting a detailed internal investigation to identify how the breach occurred
  • Training staff and enhancing awareness on data protection measures

Ongoing Monitoring and Support

We will monitor the situation closely to ensure the breach is fully contained and no further data loss or exposure occurs. We may also provide you with ongoing support, including advice on protecting your information and credit monitoring services, if necessary, at no cost to you.

Commitment to Data Protection

While we strive to prevent data breaches through robust security measures, we are committed to being transparent and responsive if one occurs. Our goal is to protect your personal data and minimize any impact caused by a breach. We continuously review and improve our data protection practices to ensure we are prepared for any eventuality.

Third Parties We Receive Data From

In order to provide our services and improve the user experience, we may receive personal data from third-party sources. We ensure that these third parties are compliant with data protection regulations and have appropriate safeguards in place to protect your personal information.

Third-Party Service Providers

We work with various third-party service providers to facilitate our operations, such as payment processors, shipping companies, and customer support platforms. These providers may share certain personal data with us in order to fulfill their services. For example:

  • Payment processors: We may receive payment details and transaction information from payment gateways when you make a purchase on our site.
  • Shipping companies: We may receive your address, contact details, and order information from logistics partners to ensure timely delivery of products.
  • Customer support platforms: If you contact our support team, we may receive information related to your support request from the platform used for customer service interactions.

Social Media Platforms

If you choose to interact with us through social media platforms, we may receive data from those platforms based on your activity, such as:

  • Social media profiles (e.g., Facebook, Instagram, LinkedIn) if you choose to share them with us
  • Publicly available information or insights, such as engagement metrics or preferences

Advertising and Marketing Partners

We may also receive data from advertising and marketing partners for the purpose of targeting and optimizing our ads. This data may include demographic information, online behavior, and interests that help us deliver relevant content to you. For example:

  • Google Analytics and other analytics providers may share insights about how users interact with our website, including browsing habits, which can help us improve our marketing strategy.
  • Ad networks such as Facebook Ads, Google Ads, or other platforms may provide us with information about user interactions with our ads.

Publicly Available Sources

In certain cases, we may also receive information about you from publicly available sources, such as:

  • Public records or data lists that are legally accessible
  • Business directories and social media platforms where you may have publicly shared your contact details or other information

Legal and Regulatory Authorities

We may receive information from legal or regulatory authorities, such as government agencies, courts, or law enforcement, in response to a subpoena, court order, or other legal obligations. This information may include personal data relevant to a legal investigation or compliance with regulatory requirements.

Consent and Transparency

We are committed to transparency and ensuring that you are aware of the third parties with whom we share or receive your personal data. Whenever possible, we will inform you about the third parties from whom we receive data, and we will only share your personal information in accordance with this Privacy Policy and applicable laws.

Automated Decision Making and/or Profiling

We value your privacy and strive to maintain transparency regarding how your personal data is used. As part of our operations, we may use automated systems to process your personal data. This section outlines our practices related to automated decision-making and profiling.

Automated Decision Making

Automated decision-making refers to processes where decisions are made solely based on automated data processing, without human intervention. We do not currently use automated decision-making processes that have significant legal or other effects on individuals. However, we may use automated systems for internal business purposes, such as:

  • Processing transactions, including payment verification, to ensure the accuracy of the information provided.
  • Automating customer support queries or ticketing, to efficiently manage and prioritize service requests.

Profiling

Profiling involves using personal data to evaluate certain aspects of an individual, such as their preferences, behaviors, or other characteristics. We may use profiling in the following cases:

  • Marketing and Personalization: We may use automated systems to personalize content and advertisements based on your browsing behavior and interests. This helps us provide you with relevant offers and improve your overall experience on our website.
  • Analytics and Performance: We may analyze your interactions with our website, such as which pages you visit and how long you stay on them, in order to improve our website’s design and functionality.
  • Behavioral Targeting: We may use automated profiling to deliver targeted ads through third-party advertising platforms (e.g., Google Ads, Facebook Ads), helping us reach individuals who are likely to be interested in our products or services based on their past behavior and interests.

Right to Object and Opt-Out

You have the right to object to automated decision-making and profiling that significantly affects you. If you wish to opt-out of personalized marketing or profiling, you can do so by adjusting your preferences in the relevant sections of our website (such as unsubscribing from marketing emails or disabling cookies). Additionally, you may contact us directly to request that we cease processing your data for these purposes.

Human Intervention and Review

In cases where automated decision-making and profiling significantly impact your rights or freedoms, you have the right to request human intervention in the decision-making process. If you believe that an automated decision was made in error or needs further review, please contact us at the provided contact information.

Data Protection and Safeguards

We take data protection seriously and ensure that appropriate safeguards are in place to minimize risks associated with automated decision-making and profiling. These safeguards include ensuring that our processes are transparent, that you have the right to opt-out, and that any decisions made based on profiling can be reviewed manually if necessary.

Payments

We are committed to ensuring that your payment information is handled securely and in compliance with all applicable privacy regulations. When you make a payment through our website, the following applies:

Payment Methods

We offer various payment methods, including credit cards, debit cards, and other electronic payment services. When you make a payment, you may be asked to provide personal and financial details such as your name, address, payment card number, and other information necessary to process the transaction.

Third-Party Payment Processors

We use third-party payment processors to handle your payments. These processors are responsible for securely processing your payment information, and they may collect and store your personal and financial details as part of the transaction. We do not store your full payment details (such as your credit card number) on our servers. All payment information is processed securely by the payment service provider.

Security of Payment Information

We employ industry-standard encryption technology (such as Secure Sockets Layer (SSL)) to ensure that your payment information is transmitted securely. However, please be aware that no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security. We encourage you to use secure networks and devices when making payments online.

Payment Data Retention

We retain payment transaction data for as long as necessary to fulfill the purposes of the transaction and to comply with legal obligations. For example, we may retain payment records for accounting, auditing, and tax compliance purposes. Payment information will be stored only for the time required by law or to resolve disputes, and will be securely deleted or anonymized thereafter.

Refunds and Cancellations

In the event that you request a refund or cancellation, we may need to verify your payment details to process the refund. Any payment-related disputes will be resolved in accordance with our terms and conditions and refund policies. Please contact our customer service team for assistance with any payment-related issues.

Payment Fraud Prevention

We take steps to prevent fraudulent transactions and protect both you and us from financial loss. We may monitor and review payment transactions to detect and prevent fraud. If we suspect any fraudulent activity, we reserve the right to cancel or block payments, and take any appropriate action as required by law.

Sharing of Payment Data

Your payment details are shared only with trusted third-party payment processors who assist in completing the transaction. We do not share your payment information for marketing or other purposes unless required by law. Please review the privacy policy of the payment processor for more details on how your payment data is handled.

Contact Us Regarding Payments

If you have any questions about how your payment information is handled, or if you need assistance with a payment issue, please feel free to contact us at [email protected].

Payments via Stripe

We use Stripe, a third-party payment processor, to handle payments securely on our website. By making a purchase on our site, you acknowledge that your payment information will be processed through Stripe, which operates under its own privacy policy.

What Data We Collect

When you make a payment via Stripe, we collect the necessary information required to process your transaction. This includes your name, billing address, payment method (credit/debit card), email address, and other relevant transaction details. Stripe will collect your payment card details (such as card number, expiration date, and CVV) for the purpose of processing your payment.

Stripe's Privacy Policy

Stripe is a PCI-compliant service, which means it adheres to the highest standards of security when handling payment data. You can review Stripe’s privacy policy directly on their website: https://stripe.com/privacy.

Security of Payment Information

Stripe uses advanced encryption methods (such as SSL) to securely process payments. All payment information is transmitted via encrypted channels, and Stripe uses tokenization to avoid storing sensitive data like your full credit card number. Stripe may also perform fraud detection measures to ensure that your payment is legitimate.

Data Retention

Stripe retains payment information for as long as necessary to process the transaction and comply with legal obligations. We do not store your full payment information on our servers. However, Stripe may retain certain transaction details to manage billing disputes, refunds, or customer support requests, as outlined in their privacy policy.

Refunds and Cancellations

If you request a refund or need to cancel a payment, we will work with Stripe to process your request. Refunds will be issued based on Stripe’s policies, and may take several business days to reflect on your account.

Fraud Prevention

Stripe actively works to prevent fraudulent transactions by employing sophisticated security measures and monitoring transactions for signs of fraud. If any suspicious activity is detected, Stripe may place a hold on your transaction or request additional verification before completing the payment.

Sharing Payment Data with Stripe

Your payment information is shared with Stripe solely for the purpose of processing your transaction. Stripe may share this information with its service providers or as required by law, but they are prohibited from using your information for marketing purposes without your consent. Please refer to Stripe’s privacy policy for more details on how they handle your data.

Contacting Us About Payments via Stripe

If you have any questions regarding payments processed through Stripe, or need assistance with a payment issue, please contact us at [email protected].