nanocookiez.Back to shop

Your information, handled carefully

Privacy Policy

Effective 25 August 2026

This policy explains what Nanocookiez collects when you browse our website, scan one of our QR codes, customise cookies, place an order, or contact us, and how we use and protect that information.

1. Who we are

Nanocookiez is a UAE custom-cookie business and is responsible for the personal information described in this policy. Privacy questions and requests can be sent to mrdrcngt@gmail.com.

2. Information we collect

Information you provide

  • Contact details, including your name, phone number, and optional email address.
  • Order and customisation details, including selected designs, box quantities, colours, inscriptions, notes, delivery date, and order status.
  • Delivery information. You may provide either a written address or a Google Maps link. If you choose “Use my location,” your browser asks for permission and the resulting coordinates are submitted with your order.
  • Messages and other information you send when contacting us about an order.

Payment information

Payments are completed on Ziina’s secure payment page. Nanocookiez receives and stores payment references and payment status, but does not receive or store your complete card number, expiry date, or CVV. Ziina processes payment information under its own privacy terms.

QR analytics

When you open a Nanocookiez campaign QR link, we record the campaign name and time of the scan. The scan record does not contain your name, phone number, email, precise location, raw IP address, or device fingerprint. If you later submit an order, the campaign name may be attached to that order so we can measure campaign conversions.

Technical and security information

Cloudflare and our website systems may process standard request information, such as IP address, browser or device information, request time, and requested pages, to deliver the website, prevent abuse, diagnose errors, and maintain security. Our rate limiter uses a one-way hash derived from an IP address; the raw IP address is not stored in the rate-limit database.

3. How we use information

  • To create, personalise, deliver, and support your order.
  • To contact you about customisation, delivery, payment, or order problems.
  • To process payments and confirm their status.
  • To count QR campaign scans and understand which campaigns lead to orders.
  • To secure the website, enforce rate limits, prevent fraud, troubleshoot problems, and comply with legal obligations.

We do not sell personal information and do not use QR analytics for behavioural advertising.

4. Cookies and local storage

The shop uses browser local storage to keep your cart on your device. After a campaign QR visit, it also keeps the campaign name and capture time for up to 30 days so an order can be attributed to that campaign. This local campaign record does not identify you by name and is not an advertising tracker. The private admin area uses a secure, HTTP-only sign-in cookie that expires after 12 hours. We do not currently set third-party advertising cookies.

You can clear the shop’s local storage using your browser settings, although doing so will remove your saved cart and campaign attribution.

5. When information is shared

We share information only when needed to operate the shop, fulfil an order, protect the service, or comply with law. Current service providers include:

  • Cloudflare, for website hosting, database storage, image delivery, security, and operational logs.
  • Ziina, for secure payment processing when payments are enabled.
  • Delivery providers or couriers, when necessary to complete your delivery.
  • Professional advisers, regulators, courts, or authorities where required by law or necessary to protect legal rights.

Some providers may process information outside the UAE. Where cross-border processing occurs, we take reasonable steps to use providers and safeguards appropriate to the information and applicable UAE requirements.

6. Retention

We keep order and transaction records only for as long as reasonably needed to fulfil orders, provide support, handle disputes, meet accounting or legal requirements, and protect against fraud. QR scan records are retained for up to 24 months and may then be deleted or converted into non-identifying totals. Campaign attribution stored in your browser expires after 30 days. Rate-limit database records are removed after approximately 24 hours. Provider logs follow the retention settings and legal obligations applicable to the relevant provider.

7. Security

We use access controls, secure administrator sessions, encrypted HTTPS connections, request validation, prepared database queries, rate limiting, security headers, and restricted access to protect information. No online service can promise absolute security, but we limit collection and take reasonable technical and organisational measures proportionate to the information we handle.

8. Your choices and rights

Subject to applicable UAE law, you may ask to access, correct, update, delete, restrict, or obtain a copy of personal information we hold about you, and you may object to or withdraw consent for certain processing. Some records may need to be retained where the law requires it or where they are needed for valid legal claims.

Send requests to mrdrcngt@gmail.com. We may need to verify your identity before acting on a request. You may also have the right to complain to the UAE Data Office or another competent regulator.

9. Children

This store is not designed to collect personal information directly from children. A parent or guardian should place and manage an order for anyone under 18.

10. Changes to this policy

We may update this policy when the shop, providers, or legal requirements change. The effective date at the top will show when the latest version applies. Material changes will be presented clearly on the website where appropriate.