This policy explains what information Ra8m collects, why we collect it, who we share it with, and the choices you have. It covers Ra8m POS, the Ra8m desktop app, Ra8m Ecommerce storefronts, and this website.
We have written it in plain language on purpose. If anything here is unclear, ask us — the contact details are at the end.
Last updated:
Ra8m is a business platform for Iraqi merchants. It combines a point of sale, inventory and accounting, an online storefront, and integrated delivery. This policy applies to all of it, and to anyone whose information passes through it.
Because Ra8m sits between merchants and their customers, the same piece of information can reach us for two very different reasons. Section 4 explains which of those two roles we are in, and it determines who you should contact about your data.
Ra8m is operated by Alhanoot for General Trading CO.L.L, a company registered in Iraq, with its registered office at Baghdad / Al-Sulaikh / M 316 / Z 5 / D 59.
In this policy, "we", "us" and "Ra8m" mean that company. "You" means whoever is reading — a merchant, a member of merchant staff, a shopper, or a visitor to our website.
Different people interact with Ra8m in different ways, and the rules below are not the same for each of them.
For a merchant's own account — the business details, the subscription, staff logins, and how the product is used — we decide what is collected and why. You should contact us about that information.
For everything a merchant records about their customers — sales, invoices, delivery addresses, loyalty records, patient files — we do not decide anything. We store and process it on that merchant's instructions, the way a filing cabinet holds documents without choosing what goes in them. The merchant is responsible for that information: for having a lawful reason to hold it, for telling their customers about it, and for answering requests about it.
Everything you run your business with: products, variants, prices, stock levels and adjustments, suppliers, purchase orders, customers, invoices and receipts, refunds, cashier sessions and logs, expenses, and accounting entries.
Collected automatically when you use Ra8m or visit our website: IP address, browser and operating system, device identifier, application version, pages viewed, approximate location derived from IP, and diagnostic data such as crash reports and error traces.
Messages you send us by WhatsApp, email or in-app support, including any screenshots or files you attach. Please avoid sending us patient records or card numbers in a support message.
Ra8m is used by pharmacies and clinics. For those merchants the system may hold prescription records, medicine batch and expiry data, patient files, visit and treatment records, lab results, and insurance details.
We hold this information strictly as a processor, on the merchant's instructions. We do not decide what is recorded, we do not use it for our own purposes, and we do not use it for analytics, product research, advertising or profiling of any kind.
We do not sell your information, and we do not sell or rent merchant or shopper data to advertisers.
Ra8m POS can run as a desktop application installed on your own computer, alongside a small local print service that runs in the background so Ra8m can talk to thermal printers, cash drawers, scales and barcode scanners.
When a merchant enables delivery on a Ra8m storefront, we pass the order's delivery details to Boxy, an independent last-mile logistics company, so the shipment can be created, priced, dispatched and tracked.
What is sent to Boxy:
Boxy handles this information under its own terms and privacy notice, as an independent company rather than on our behalf, and its couriers will see the recipient's name, phone number and address in order to complete the delivery. See tryboxy.com for Boxy's own practices.
Subscription and add-on payments are handled by a third-party payment processor. Card details are entered with that processor directly — we receive confirmation that a payment succeeded or failed, along with the amount, date and a reference. We never see or store full card numbers.
Storefront orders may be paid by Visa, Mastercard, Qi Card, ZainCash or cash on delivery, depending on what the merchant has enabled. That money is settled to the merchant, not to us. Each payment provider handles card and wallet details under its own privacy notice.
Against the order, Ra8m stores the payment method used, the amount, the status and a reference — not card numbers, PINs or wallet credentials.
We verify phone numbers by sending a one-time code, and merchants can have order notifications sent to shoppers. To do that, we pass the phone number — and, where relevant, the name and email associated with the account — to a messaging provider that delivers the message over WhatsApp or SMS.
The provider handles that information only to deliver the message. We use it to confirm the number is genuine, to protect accounts, and to send the notification the merchant asked for.
We keep information for as long as it is needed for the purpose it was collected, and then delete or anonymise it.
| Information | Kept for |
|---|---|
| Merchant account and business data | The life of the account |
| Sales, invoices and accounting records | The life of the account, then as required by Iraqi tax and commercial record-keeping law |
| Trial accounts that never convert | The 14-day trial, plus a short grace period, then deleted |
| Data after an account closes | An export window in which you can download everything, then deletion |
| Backups | A rolling window, after which older backups are overwritten |
| Error reports and session recordings | A short diagnostic retention period set with our provider |
| Website analytics | A limited retention period set with our analytics provider |
| Support conversations | While the account is open and for a reasonable period afterwards |
No system is perfectly secure. If a breach occurs that is likely to affect you, we will tell affected merchants without undue delay and explain what happened, what we are doing about it, and what you should do.
Subject to applicable law, you can ask us to:
Send requests to support@hanooot.com. We aim to respond within 30 days, and we may need to verify your identity first so that we do not disclose someone's data to the wrong person.
When you record information about your own customers in Ra8m, you take on responsibilities that we cannot discharge for you:
These obligations are set out in more detail in our Terms and Conditions.
Ra8m runs on managed, industry-standard cloud infrastructure operated by specialist providers on our behalf. Data is encrypted in transit and at rest, and access is limited to what is needed to operate, secure and support the service.
Our providers are engaged under contracts that require them to protect the information they handle, to process it only on our instructions, and not to use it for their own purposes.
Ra8m is a business tool and is not directed at children. We do not knowingly collect information from anyone under 18 in their own right. If you believe a child's information has reached us, contact us and we will delete it.
Where a merchant records information about a minor as their customer — for example a clinic recording a paediatric patient — that is the merchant's responsibility under section 17, and the merchant must have the consent of a parent or guardian.
We may update this policy as the product and the law change. The date at the top of this page always shows when it was last revised.
If a change materially affects your rights, we will give merchants notice by email or in-app message before it takes effect. Continuing to use Ra8m after that means you accept the updated policy.
For any question about this policy, or to make a request about your information:
Write to us and a person will answer. If your question is about data held by a merchant you bought from, tell us who they are and we will point you in the right direction.