Mortaga

Legal

Privacy Policy

Last updated: August 2026

This page explains what Mortaga collects when you use the site or the dashboard, why, who it's shared with, and how it's protected. It covers merchants who connect a store and the customers who use a merchant's returns portal.

What we collect

  • Account details: name, email address, and a password. The password is never stored as text: it's hashed with a random salt, so we cannot read it back even if asked to.
  • Store connection details: your Shopify domain and access token, and the API key of any courier account you connect, such as Bosta. Both tokens are encrypted at rest and never sent to any browser, including your own.
  • Order and return data synced from your Shopify store, and the returns your customers file: order number, contact details, reason, photos if attached, and the outcome.
  • Customer contact details on a return: name, email and/or phone number, used only to identify the order and to send updates about that specific return.
  • Technical data: IP address and browser identifier, recorded against security-relevant events (sign-in, password reset, admin actions) for fraud and abuse prevention.
  • A waitlist email, if you join one, used only to notify you, nothing else.

Cookies

One functional cookie keeps you signed in (httpOnly, so a script on the page cannot read it). We don't use advertising or cross-site tracking cookies. If analytics is enabled it runs in an aggregate, non-invasive form to understand traffic, never to build an ad profile of you.

Who it's shared with

We don't sell data. It's shared only with the services that make the product work:

  • Shopify: to read your orders and issue refunds/exchanges/store credit, using the permissions you grant when you connect.
  • Courier companies (currently Bosta): to book courier pickups, only if you connect a courier account.
  • Resend: to send verification codes, password resets, and return-status emails.
  • PocketBase, our database, stores the data listed above so the service keeps working across restarts.

How it's protected

  • Passwords are hashed (scrypt), never stored as plain text.
  • Shopify and courier credentials are encrypted at rest (AES-256) and only decrypted server-side, at the moment a request needs them.
  • Sign-in, verification, and password reset are all rate-limited against brute-force attempts.
  • The site only answers on its real domain and only over HTTPS in production.

Your data, your call

Ask us to see or delete your account and everything tied to it. Email the address below. Deleting a merchant account removes the account, its stores, and their orders and returns; it does not undo refunds or credit already issued through Shopify.

Questions

This is a plain-language summary, not written or reviewed by a lawyer. Treat it as a good-faith description of current practice, not a legal instrument. For anything specific, or to exercise a data request, contact us at support@mortaga.site.

© 2026 Mortaga · Returns and exchanges for Egyptian e-commerce

Home Pricing About Terms Refunds Delivery Privacy Contact
Visa Mastercard Meeza