HomeEcommercePOSIndustriesPricingBlog
Legal · Privacy

Privacy Policy

This policy explains what information Ra8m collects, why we collect it, who we share it with, and the choices you have. It covers Ra8m POS, the Ra8m desktop app, Ra8m Ecommerce storefronts, and this website.

We have written it in plain language on purpose. If anything here is unclear, ask us — the contact details are at the end.

Last updated:

Jump to a section

1.About this policy

Ra8m is a business platform for Iraqi merchants. It combines a point of sale, inventory and accounting, an online storefront, and integrated delivery. This policy applies to all of it, and to anyone whose information passes through it.

Because Ra8m sits between merchants and their customers, the same piece of information can reach us for two very different reasons. Section 4 explains which of those two roles we are in, and it determines who you should contact about your data.

2.Who we are and how to reach us

Ra8m is operated by Alhanoot for General Trading CO.L.L, a company registered in Iraq, with its registered office at Baghdad / Al-Sulaikh / M 316 / Z 5 / D 59.

In this policy, "we", "us" and "Ra8m" mean that company. "You" means whoever is reading — a merchant, a member of merchant staff, a shopper, or a visitor to our website.

3.Who this policy covers

Different people interact with Ra8m in different ways, and the rules below are not the same for each of them.

Merchants and their staff
Businesses that subscribe to Ra8m, and the cashiers, managers and owners who sign in. These are our direct customers.
Shoppers
People who buy from a merchant's Ra8m Ecommerce storefront, whether on a yourstore.ra8m.com address or the merchant's own domain.
Walk-in customers
People who buy in person and whose name or phone number a cashier records against a sale, an invoice or a loyalty record.
Patients and pharmacy customers
People served by clinic and pharmacy merchants, whose records may include health-related information. Section 6 deals with them specifically.
Website visitors
Anyone browsing www.ra8m.com, including people who never create an account.

4.When we decide, and when we only follow instructions

For a merchant's own account — the business details, the subscription, staff logins, and how the product is used — we decide what is collected and why. You should contact us about that information.

For everything a merchant records about their customers — sales, invoices, delivery addresses, loyalty records, patient files — we do not decide anything. We store and process it on that merchant's instructions, the way a filing cabinet holds documents without choosing what goes in them. The merchant is responsible for that information: for having a lawful reason to hold it, for telling their customers about it, and for answering requests about it.

If you are a shopper or a patient and you want to see, correct or delete your information, contact the merchant you bought from — not us. If you cannot reach them, write to us and we will help route the request, but we cannot act on their data without their instruction.

5.Information we collect

5.1Merchant account and business details

  • Name, phone number and email address of the person registering
  • Business name, business type or trade, and tax rate settings
  • Branch names and addresses, and the logo you upload
  • Your plan, add-ons, billing history and subscription status
  • Staff accounts, their assigned roles, and their operator PINs

5.2Operational data you enter into Ra8m

Everything you run your business with: products, variants, prices, stock levels and adjustments, suppliers, purchase orders, customers, invoices and receipts, refunds, cashier sessions and logs, expenses, and accounting entries.

5.3Storefront and order information

  • Shopper name and phone number
  • Delivery province, city and address
  • Order contents, totals, payment method and order status
  • Where a shopper has not created an account, a placeholder email generated at checkout so the order can be tracked

5.4Device and technical information

Collected automatically when you use Ra8m or visit our website: IP address, browser and operating system, device identifier, application version, pages viewed, approximate location derived from IP, and diagnostic data such as crash reports and error traces.

5.5Support conversations

Messages you send us by WhatsApp, email or in-app support, including any screenshots or files you attach. Please avoid sending us patient records or card numbers in a support message.

6.Pharmacy, clinic and health-related information

Ra8m is used by pharmacies and clinics. For those merchants the system may hold prescription records, medicine batch and expiry data, patient files, visit and treatment records, lab results, and insurance details.

We hold this information strictly as a processor, on the merchant's instructions. We do not decide what is recorded, we do not use it for our own purposes, and we do not use it for analytics, product research, advertising or profiling of any kind.

  • Access is restricted by database-level access rules, so one merchant can never see another merchant's records
  • Only the merchant's own authorised staff, in the roles the merchant assigns, can view these records
  • Our staff access this data only when a merchant asks us to for support, and only for as long as that takes
  • The merchant is responsible for holding the licences, lawful basis and patient consents that Iraqi law requires
We never transmit prescription contents, patient files, diagnoses or itemised medical information to a delivery provider, an advertising platform, or any analytics tool.

7.How we use information

  • To provide the service: process sales, sync stock, publish storefronts, create delivery orders, and generate reports
  • To operate accounts: registration, sign-in, phone verification, roles and permissions
  • To take payment for subscriptions and add-ons, and to send invoices and renewal notices
  • To provide support, investigate faults, and answer your questions
  • To keep the service secure: detect fraud and abuse, protect against unauthorised access, and maintain audit logs
  • To improve the product, using aggregated and de-identified usage statistics
  • To send service messages about outages, changes and billing — these are not marketing and cannot be turned off while you hold an account
  • To meet legal obligations and respond to lawful requests from competent authorities

We do not sell your information, and we do not sell or rent merchant or shopper data to advertisers.

8.The desktop app, offline data and the local print service

Ra8m POS can run as a desktop application installed on your own computer, alongside a small local print service that runs in the background so Ra8m can talk to thermal printers, cash drawers, scales and barcode scanners.

  • The print service listens only on your machine. Receipt contents and print jobs are handled locally between Ra8m and your hardware. They are not sent to us.
  • Offline sales are stored on your device. When the connection drops, sales, receipts and stock movements are queued in local storage on that machine and synced when connectivity returns.
  • Update checks. The desktop app periodically checks for updates and reports its version and operating system so the correct update can be served.
  • Diagnostics. If the app crashes, an error report may be sent to our diagnostics provider so we can fix the fault.
Data queued offline exists only on that device until it syncs. If the device is lost, wiped or reinstalled before syncing, that data cannot be recovered by us.

9.When we share information

We share information only where it is needed to run the service, and only with organisations bound to protect it. The categories are:

  • Cloud hosting and database providers — which store the data and run the service
  • Error-monitoring and diagnostics providers — which receive crash reports and performance data (see section 12)
  • Payment providers — which process subscription payments and, on storefronts, shopper payments (see section 11)
  • Messaging providers — which deliver verification codes and order notifications (see section 13)
  • Delivery providers — which fulfil storefront orders (see section 10)
  • Professional advisers — lawyers and accountants, under a duty of confidentiality
  • Authorities — where we are legally required to disclose, or where it is necessary to protect the safety or rights of a person

If our business is ever sold or reorganised, information may transfer as part of that transaction. This policy would continue to apply to it, and we would tell you before anything changed.

10.Delivery and last-mile logistics

When a merchant enables delivery on a Ra8m storefront, we pass the order's delivery details to Boxy, an independent last-mile logistics company, so the shipment can be created, priced, dispatched and tracked.

What is sent to Boxy:

  • Recipient name and phone number
  • Delivery province, city and address
  • Order reference, a summary of package contents, and — for cash on delivery — the amount to collect
  • The merchant's pickup branch, contact name and phone number

Boxy handles this information under its own terms and privacy notice, as an independent company rather than on our behalf, and its couriers will see the recipient's name, phone number and address in order to complete the delivery. See tryboxy.com for Boxy's own practices.

Prescription contents, patient files and diagnoses are never sent to a delivery provider. Only what is needed to physically deliver a package leaves Ra8m.

11.Payments and payment information

11.1What merchants pay us

Subscription and add-on payments are handled by a third-party payment processor. Card details are entered with that processor directly — we receive confirmation that a payment succeeded or failed, along with the amount, date and a reference. We never see or store full card numbers.

11.2What shoppers pay merchants

Storefront orders may be paid by Visa, Mastercard, Qi Card, ZainCash or cash on delivery, depending on what the merchant has enabled. That money is settled to the merchant, not to us. Each payment provider handles card and wallet details under its own privacy notice.

Against the order, Ra8m stores the payment method used, the amount, the status and a reference — not card numbers, PINs or wallet credentials.

12.Cookies, analytics, advertising and diagnostics

We and our providers use cookies, local storage and similar technologies. By category:

  • Strictly necessary — sign-in sessions, security, and remembering your language choice. The service does not work without these.
  • Analytics — how many people visit, which pages they use, and where they encounter difficulty, so we can improve the product.
  • Advertising and conversion measurement — on our marketing website, to measure which campaigns lead to sign-ups.
  • Diagnostics and session recording — our error-monitoring provider may record a replay of an app session around the time of an error, which can capture what was on screen at that moment, so that faults can be reproduced and fixed.
  • Web fonts — loaded from a third-party font service, which receives your IP address as part of the request.

You can block or delete cookies through your browser settings, and most browsers let you refuse third-party cookies specifically. Blocking strictly necessary cookies will stop you being able to sign in.

13.Phone verification and WhatsApp messages

We verify phone numbers by sending a one-time code, and merchants can have order notifications sent to shoppers. To do that, we pass the phone number — and, where relevant, the name and email associated with the account — to a messaging provider that delivers the message over WhatsApp or SMS.

The provider handles that information only to deliver the message. We use it to confirm the number is genuine, to protect accounts, and to send the notification the merchant asked for.

14.How long we keep information

We keep information for as long as it is needed for the purpose it was collected, and then delete or anonymise it.

InformationKept for
Merchant account and business dataThe life of the account
Sales, invoices and accounting recordsThe life of the account, then as required by Iraqi tax and commercial record-keeping law
Trial accounts that never convertThe 14-day trial, plus a short grace period, then deleted
Data after an account closesAn export window in which you can download everything, then deletion
BackupsA rolling window, after which older backups are overwritten
Error reports and session recordingsA short diagnostic retention period set with our provider
Website analyticsA limited retention period set with our analytics provider
Support conversationsWhile the account is open and for a reasonable period afterwards

15.How we protect information

  • Encryption in transit, and encryption at rest on our infrastructure
  • Database-level access rules that isolate each merchant's data from every other merchant
  • Role-based permissions inside Ra8m, so staff see only what their role allows
  • Operator PINs for point-of-sale terminals, so an unattended till cannot be used by anyone who walks up to it
  • Access controls and audit logging on our own systems, with staff access limited to what a person's job requires

No system is perfectly secure. If a breach occurs that is likely to affect you, we will tell affected merchants without undue delay and explain what happened, what we are doing about it, and what you should do.

16.Your choices and how to exercise them

Subject to applicable law, you can ask us to:

  • Give you a copy of the information we hold about you
  • Correct information that is wrong or out of date
  • Delete information we no longer have a reason to keep
  • Export your data — merchants can export sales, customers and reports as CSV at any time from inside Ra8m
  • Stop sending you marketing messages
Where to send your request: if you are a merchant, write to us directly. If you are a shopper or a patient, write to the merchant you dealt with — they control that information and we act on their instructions. We will assist any merchant handling such a request.

Send requests to support@hanooot.com. We aim to respond within 30 days, and we may need to verify your identity first so that we do not disclose someone's data to the wrong person.

17.If you are a merchant using Ra8m

When you record information about your own customers in Ra8m, you take on responsibilities that we cannot discharge for you:

  • Have a lawful reason to collect and hold the information you enter
  • Tell your customers what you collect and why — publish your own privacy notice on your storefront
  • Collect only what you actually need, and keep it accurate
  • Answer your customers' requests to see, correct or delete their information
  • Manage your staff accounts, roles and PINs, and remove access promptly when someone leaves
  • If you are a pharmacy or clinic, hold the licences and patient consents Iraqi law requires before recording health information

These obligations are set out in more detail in our Terms and Conditions.

18.Where information is processed

Ra8m runs on managed, industry-standard cloud infrastructure operated by specialist providers on our behalf. Data is encrypted in transit and at rest, and access is limited to what is needed to operate, secure and support the service.

Our providers are engaged under contracts that require them to protect the information they handle, to process it only on our instructions, and not to use it for their own purposes.

19.Children

Ra8m is a business tool and is not directed at children. We do not knowingly collect information from anyone under 18 in their own right. If you believe a child's information has reached us, contact us and we will delete it.

Where a merchant records information about a minor as their customer — for example a clinic recording a paediatric patient — that is the merchant's responsibility under section 17, and the merchant must have the consent of a parent or guardian.

20.Changes to this policy

We may update this policy as the product and the law change. The date at the top of this page always shows when it was last revised.

If a change materially affects your rights, we will give merchants notice by email or in-app message before it takes effect. Continuing to use Ra8m after that means you accept the updated policy.

21.Contact us

For any question about this policy, or to make a request about your information:

  • Email: support@hanooot.com
  • Phone: +964 776 080 9050
  • Post: Alhanoot for General Trading CO.L.L, Baghdad / Al-Sulaikh / M 316 / Z 5 / D 59, Baghdad, Iraq

Questions about your privacy?

Write to us and a person will answer. If your question is about data held by a merchant you bought from, tell us who they are and we will point you in the right direction.