PSES
Privacy Policy
This policy explains how the Palestinian Smart Marketplace app collects, uses and protects data.
Data we process
- Account data such as name, email, phone number, account identifier and profile image if provided.
- Shopping data such as cart, favorites, delivery addresses and locations, orders, notes, payment method, PSES token balance and related transaction history.
- Social content such as Community posts, Feed videos and thumbnails, comments, likes, shares and reports.
- Private messages, conversation participants and read state. Private messages are not public.
- Limited usage signals such as video watch duration, hidden content, interactions, notification tokens, crash, security and performance logs.
- An approximate or precise delivery location when you use a feature that requires it and grant permission.
- Smart sizing processes a recent front-facing image with a scale reference. The source image is not stored in your account; approximate measurements, confidence ranges and quality results may be stored.
- Virtual try-on processes the photo you select together with the product image and stores the private result for a limited period so you can view or delete it.
Why we use data
- Create and secure accounts and operate app features.
- Fulfill and deliver orders, show order history and send updates.
- Operate Messages, Feed, Community, basic recommendations and the Quds assistant.
- Save preferences, respond to support and prevent fraud and abuse.
- Diagnose failures, improve performance and comply with valid legal requests.
Artificial intelligence
- When you message Quds, your message and limited recent context from that conversation are sent to Vertex AI to generate a response. Your messages and the response remain in your private conversation.
- Smart sizing and virtual try-on send the images you select to Vertex AI to perform the requested task, not to identify you or read the serial number of a banknote reference.
- AI suggestions can be wrong. Prices, stock and order status come from trusted PSES systems.
Services we use
- Google Firebase for authentication, database, cloud functions, notifications, App Check, crash reporting and performance.
- Cloudflare Stream and R2 for uploading, storing and delivering PSES media.
- Google Vertex AI for Quds and supported AI image processing.
- Google Maps and address services for maps and readable location labels.
- Delivery or support providers receive only the minimum data needed to provide the service.
We do not sell personal data or use it for third-party targeted advertising.
Public and private content
Feed videos, Community posts, comments and display names may be visible to app users or visitors. Addresses, orders, wallet, favorites, private messages and support requests are not public and are controlled by account permissions.
Payment
Supported methods are cash on delivery or PSES token balance. The app does not collect payment-card numbers or financial passwords. This policy will be updated before a new payment provider is enabled.
Retention and deletion
- Data is kept as needed to provide the service, maintain security and resolve disputes.
- A virtual try-on input photo is deleted after processing. Its private result is currently retained for up to 30 days or until you delete it. The original smart-sizing photo is not stored in PSES storage.
- You can delete specific data in the app where the feature supports it, including a virtual try-on result, a saved address, content you posted, or a message/conversation from your side.
- You can delete your account in Settings → Privacy and device → Delete account and data.
- You can also use the external account deletion page.
- An active order may need to be cancelled when eligible or completed first.
- After deletion, the account and associated data are removed from active systems. Limited records may remain where necessary for security, fraud prevention, disputes or legal obligations.
- Aggregated non-identifying statistics may remain after account linkage is removed.
Security and choices
We use encrypted transport, Firebase Auth, account-scoped access rules, server-side sensitive operations and short-lived upload URLs. Passwords are not stored in Firestore and storage keys are not embedded in the app.
You can disable notification or location permission in device settings and request explanation, correction or deletion.
Privacy contact
Email psespalestine@gmail.com. Never send your password or verification code.