Menasa AI Privacy Policy
Last updated: 27 September 2026
This policy explains how Menasa handles personal data when you use Menasa AI: the website at menasa.ai, the Menasa dashboard, the Menasa mobile app, the partner portal, and the storefronts and tools we host for merchants. It is written to be read, so it is short where it can be. Our Terms of Service govern your use of the service and take precedence on questions of liability.
1. Who we are
Menasa AI is provided by Menasa, with its registered address at AstroLabs, Jumeirah Lakes Towers (JLT), Cluster R, Unit R6, Unit Code RET-R6-100, PO Box 336851, Dubai, United Arab Emirates. We have offices in Kuwait City, Kuwait and Dubai, United Arab Emirates. In this policy "Menasa", "we" and "us" mean that company.
Contact for everything in this policy: privacy@menasa.net. Privacy questions and requests: privacy@menasa.net.
2. Two roles: whose data is whose
Menasa AI is a platform that businesses ("merchants") use to run an online store, a customer list, a shared inbox and AI assistants. That means we hold two very different kinds of personal data, and our responsibility differs for each.
Data about our merchants: Menasa is the controller. This is data about the people who sign up for and use Menasa AI: store owners, their team members, our partners (resellers), and people who contact us. We decide why and how it is used, and this policy describes that.
Data merchants put into Menasa AI: the merchant is the controller, Menasa is the processor. This is data about a merchant's own shoppers, customers, contacts, conversations, orders and employees. The merchant decides what to collect and why; we process it only to provide the service to that merchant, on their instructions and under our Terms. In particular, the merchant is responsible for:
- having a lawful basis for collecting and using their customers' data;
- publishing their own privacy notice on their storefront and wherever else they collect data, and telling their customers who they share data with;
- obtaining and recording any consent the law requires before sending marketing (for example WhatsApp or email campaigns), before recording calls, and before adding tracking pixels to their storefront;
- answering their customers' requests to see, correct or delete their data. Menasa AI gives merchants tools to do this (see section 10).
If you are a shopper or a customer of a store that uses Menasa AI, please contact that store first: it decides how your data is used. If you contact us, we will pass your request to the store, and help it respond where we can.
3. Data we collect about merchants and their teams
- Account and sign-in: name, email address, the sign-in method you choose (email and password, Google or Apple), and whether two-step sign-in is enabled. Passwords are handled by Google Firebase Authentication; we never see or store your password.
- Store details: business name, business type, country, currency, branches and their addresses, store address (web address) and any domains you connect or buy through us.
- Team: the name, email, role, branches and access end date of each person you invite.
- Billing: your plan, invoices, credits, payments and payment status. Card payments for your Menasa subscription are made through our payment provider; we keep the provider's references and card tokens, never your full card number.
- Usage: what you use and how much (for example orders against your plan, AI replies, campaign emails, voice and document reads), which we meter to bill you and to apply your plan's limits; and a record of important actions taken in your store (who changed what, and when).
- Device and technical data: IP address, browser and device type, request logs, error reports, and, if you allow notifications, the push-notification token for your browser or phone.
- Conversations with our AI: what you ask Mena and your AI employees, their answers, the actions they proposed and whether you approved them, and any personal instructions you give them. If you use Mena's voice, her spoken replies are produced by Google Cloud Text-to-Speech; what you say aloud is turned into text by your own browser or device's speech service before it reaches us.
- Files you upload: product photos, logos, documents you give your AI employees to learn from, receipts and invoices. Product photos and similar storefront images are publicly accessible by design, because shoppers must see them; finance documents and inbox files are stored privately and opened through short-lived links.
- When you contact us or apply to be a partner: your name, company, email, phone and message. For partners, also commission and payout records.
- If you onboard as a MyFatoorah supplier through the dashboard: the business details and documents you provide, which we pass to MyFatoorah for its checks.
4. Data we process for merchants (as their processor)
Depending on what a merchant switches on, we store and process on the merchant's behalf:
- shopper accounts and sign-in (email, Google, Apple, Facebook, or guest checkout), names, phone numbers, emails, delivery addresses and map locations;
- orders, returns, loyalty points, gift cards, bookings, abandoned checkouts and newsletter subscriptions;
- CRM contacts, notes, tasks, deals, per-channel marketing consents and activity history;
- inbox conversations and attachments from WhatsApp, Instagram, Messenger, email, Telegram, Slack and the store's website chat; WhatsApp call records and, only if the merchant turns recording on, call recordings and transcripts;
- data imported from, or kept in sync with, a merchant's Shopify or WooCommerce store, and orders received from delivery or marketplace apps the merchant connects;
- the merchant's employee and payroll records, if they use payroll.
We use this data only to provide and support the service to that merchant, keep it secure, and meet our legal obligations. We do not sell it, and we do not use one merchant's customer data for another merchant or for our own marketing.
5. How we use merchant data, and our legal bases
| Why | Legal basis |
|---|---|
| Create and run your account, host your store, provide features you turn on | Performance of our contract with you |
| Bill you, collect payment, apply plan limits and credits | Contract; legal obligations (tax and accounting) |
| Keep the service secure, prevent fraud and abuse, investigate errors | Our legitimate interests in a safe, working service |
| Send service messages (invoices, security alerts, changes to the service) | Contract; legitimate interests |
| Improve the product, including the instructions our AI follows (see section 6) | Legitimate interests |
| Send you news and offers about Menasa | Your consent where the law requires it; you can opt out at any time |
| Comply with the law and respond to lawful requests | Legal obligation |
6. Artificial intelligence
- Where it runs. Mena and the AI employees run on Google's Vertex AI (Gemini models), inside Menasa's own Google Cloud project. Under Google Cloud's terms, Google does not use this data to train its models. Menasa does not train AI models on your data or your customers' data.
- What it sees. An AI assistant sees only what the person asking it is allowed to see in the dashboard: the same role, permissions and branches. An assistant answering a shopper sees only that shopper's own conversation, orders and contact record.
- You stay in charge. Mena may look things up and create internal records such as notes or tasks on her own. Anything that publishes, edits or deletes something, or involves money, is shown to you for approval first, and we record what you were shown. Customer-facing assistants that a merchant switches on reply to shoppers in the inbox without a person approving each reply; the merchant decides whether to switch them on and should tell their customers where the law requires.
- AI can be wrong. AI output can be inaccurate or incomplete. Check it before you rely on it, especially for prices, tax, legal or financial matters. You are responsible for actions you approve and for what your customer-facing assistants say on your behalf.
- Improving it. We keep records of AI errors and failed tasks and use them, together with our own test conversations, to improve the instructions our assistants follow. Instructions never contain one store's data.
- Chat history with Mena and the AI employees is kept for 90 days.
7. Who we share data with
We share personal data only with service providers who help us run Menasa AI (our sub-processors), with services a merchant chooses to connect, when the law requires it, or in a merger or sale of our business (under the same protections).
Our sub-processors:
- Google Cloud (hosting, database, file storage, Firebase Authentication, push notifications, Vertex AI, Text-to-Speech, BigQuery analytics, Google Maps and Places when a merchant enables maps).
- Cloudflare (store addresses and custom domains, domain registration for domains bought through Menasa, and network delivery).
- Algolia (search over products, customers, orders and conversations).
- Mailgun (sending email and receiving inbox email; EU region).
- Tap Payments and MyFatoorah (Menasa's own billing and payments).
- Sentry (error reports, when enabled).
- Apple (push notifications to the iOS app) and Expo (app updates).
Services a merchant connects. When a merchant connects a payment gateway (for example Tap, MyFatoorah, Hesabe, Tabby, Tamara, Stripe or others), a courier (for example iCarry, Armada, Aramex or others), Meta (WhatsApp, Instagram, Messenger), Telegram, Slack, Shopify, WooCommerce, a delivery or marketplace app, or Qlub, we send that service the data it needs to do the job the merchant asked for. Each of these services processes data under its own terms and privacy policy, and the relationship is between the merchant and that service. Menasa is responsible for its own processing, not for how those services handle data they receive. Card numbers are entered on the gateway's own page or form: Menasa does not receive or store them. A merchant's own credentials for these services are kept in Google Cloud Secret Manager, not in our database.
8. Where data is stored and international transfers
Our main database, file storage and servers are in Google Cloud's Doha region (me-central1). Some processing happens elsewhere: analytics (BigQuery) and email (Mailgun) in the European Union; AI requests on Google's global Vertex AI service, which can process them in other countries including the United States; and the global networks of Cloudflare, Algolia and our other providers. So your data, and your customers' data, may be processed outside your country. Where the law in your country requires it, we rely on the transfer mechanisms it allows, such as contractual safeguards with our providers, and we transfer only what the service needs.
9. How long we keep data
- Account data: while your account is active, then as described under account deletion below.
- A deleted or cancelled store: 30 days, then its data, files, credentials and search records are purged.
- Chats with Mena and the AI employees: 90 days.
- Order history imported from Shopify or WooCommerce: 24 months by default (a store can choose 1 to 120 months).
- Orders in our search index: 3 months (they remain in the store's records).
- Menasa's own invoices and subscription records: as long as tax and accounting law requires, including after a store is deleted.
- Backups: daily backups are kept for 7 days and weekly backups for 14 weeks, so deleted data can remain in backups for up to about 14 weeks before it is overwritten.
- Merchant data (orders, customers, conversations and the rest) is kept for as long as the merchant keeps it in their store, since it is their business record.
- Logs, usage and security records: for as long as needed for billing, security and resolving disputes.
10. Your rights
Depending on where you live, you may have the right to know what we hold about you, get a copy, correct it, delete it, object to or restrict some uses, withdraw consent, and complain to a data protection authority. The laws that may apply include Kuwait's CITRA Data Privacy Protection Regulation, the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), Saudi Arabia's Personal Data Protection Law, Qatar's Law No. 13 of 2016, Bahrain's Personal Data Protection Law (Law No. 30 of 2018), Oman's Personal Data Protection Law (Royal Decree No. 6/2022), Egypt's Law No. 151 of 2020, Jordan's Personal Data Protection Law (Law No. 24 of 2023) and Lebanon's Law No. 81 of 2018. Rights and exceptions differ between these laws; we apply the one that governs your data.
Merchants and team members: many things you can do yourself in Settings (correct your details, change sign-in, delete your account). For anything else, email privacy@menasa.net. We may need to confirm your identity, and we will reply within the time the applicable law allows.
Shoppers and customers of a store: contact the store. Merchants can download everything they hold about a contact as a file, and erase a contact. When a contact is erased, their profile, notes, conversations and messages are deleted; orders stay in the store's records because they are tax records, but are no longer linked to the profile; and a one-way coded marker of their email and phone is kept so they are not added back to marketing lists by mistake.
11. Deleting your account
You can delete your own Menasa login in Settings › Sign-in security. We show you what will happen first. If you are not a store's owner, you leave that store. If you own a store with a team, ownership passes to the next most senior member. If you are the only person in a store, the store is cancelled and permanently purged after 30 days; until then, it can be restored by contacting us. Menasa keeps its own invoices as described above.
12. Security
We protect data with measures including encrypted connections, encryption at rest by our cloud provider, strict separation between stores (tested regularly), role- and branch-based access for store teams, credentials held in Secret Manager rather than in the database, private storage for sensitive files, required two-step sign-in and audit logs for Menasa staff, and access by our staff only when needed to support you. No system is perfectly secure, and we cannot guarantee that data will never be accessed without authorisation. If a breach affects your data, we will notify you and the authorities where the applicable law requires.
13. Cookies and similar technologies
The menasa.ai website sets no advertising or analytics cookies. It remembers your language and currency choice in your browser's storage, and loads fonts from Google Fonts and scripts from a content-delivery network, which see your IP address when they are fetched.
The dashboard and apps use browser storage to keep you signed in (Firebase Authentication) and remember preferences such as language and theme, and may send error reports.
Storefronts use the storage needed for the basket, checkout and sign-in. If a merchant adds analytics or advertising pixels (such as Google Analytics, Google Tag Manager, Meta, TikTok, Snapchat or Hotjar) to their storefront, those are the merchant's choice and responsibility, including any consent the law requires.
14. Children
Menasa AI accounts are for people aged 18 or over who run or work for a business. We do not knowingly collect data from children for our own purposes. Merchants are responsible for how their storefronts treat children's data.
15. Changes to this policy
We may update this policy as the product or the law changes. We will post the new version here with its date and, for significant changes, tell merchants by email or in the dashboard before they take effect. Continuing to use Menasa AI after that means the updated policy applies.
16. Governing law and contact
This policy is governed by the laws of the United Arab Emirates, without prejudice to any mandatory rights the data protection law of your country gives you.
Questions or requests: privacy@menasa.net.
If the English and Arabic versions differ, the English version prevails.