Policies

TK Store DZ Privacy Policy

What TK Store DZ collects about accounts, orders, chats and sellers, how it is used and shared with providers, cookies, and your access and correction rights.

Applies to:
Buyers, sellers and visitors
Last updated:
Update notice:
Updates are posted on this page

1.Introduction

This policy explains how TK Store, which operates the TK Store DZ platform, collects, uses, shares and protects users’ data when they use the website, the applications or the related services.

It is written to describe what actually happens on the platform in the current operating model. When our services or the parties we work with change, this page is updated.

2.Scope of this privacy policy

This policy applies to buyers, sellers, members of seller teams and visitors of TK Store DZ, and to the data processed through accounts, orders, conversations, delivery and disputes on the platform.

It does not apply to external websites or services operated by sellers or third parties, even when the user reaches them through a link delivered on the platform. See sections 17 and 18.

3.Who is responsible for processing the data

TK Store is responsible for the processing described in this policy and operates the public platform under the name TK Store DZ.

For any privacy-related request or question, use the admin chat inside the platform first when it is available; otherwise use the official WhatsApp number designated by TK Store (see section 24).

4.Data we collect

We collect data that the user provides directly (when registering, buying, messaging or uploading documents), data generated by use of the platform (order, transaction and conversation history), and limited technical data created automatically while the service runs. These categories are detailed in the following sections.

5.Account and identity data

When an account is created or the profile is edited, we may collect:

  • First name and last name.
  • E-mail address and phone number, and their verification status.
  • Address and wilaya when entered in the profile or at checkout.
  • A profile picture, if added.
  • The password, which is stored as a hash and never in plain text.
  • The sign-in method: e-mail and password, or sign-in with Google. With Google, we receive from Google the e-mail address and the basic profile data linked to the account. In the iPhone app you can also sign in with Apple: Apple sends us a signed token that identifies your Apple ID for TK Store DZ, your e-mail address (or an Apple private relay address if you choose “Hide My Email”) and, on the first sign-in only, the name you chose to share. So that we can end the link with Apple when you delete your account, we keep an encrypted Apple authorization token; it is used for nothing else and is removed once Apple confirms that the link is revoked.
  • Internal account identifiers, the join date, the last login date, and the account status (active, suspended, banned) and its reason where one exists.

Signing in creates authentication sessions stored as hashed tokens on our servers, with their expiry dates.

6.Order and transaction data

For every order we keep a record including:

  • The product and variant purchased, quantity, prices, amounts, commission and the seller’s net amount.
  • The payment method (such as the TK Points wallet or an external payment provider), the payment status, and the references or transaction identifiers returned by the payment provider.
  • The contact details attached to the order: name, e-mail address, phone number and wilaya.
  • The order status, cancellation, dispute or refund reasons, and refunded amounts.
  • TK Points wallet movements (top-ups, debits, refunds) and seller balance and payout movements.

Bank card data and other sensitive payment credentials are not entered on TK Store DZ when paying through an external provider; they are handled on the payment provider’s interface, and we keep only the references, transaction status and amounts needed to fulfil the order, reconcile payments and process refunds.

7.Communication, support and dispute data

Messages exchanged in the platform chat between buyer and seller, in the admin chat and in dispute correspondence are stored, including text, attachments and voice messages when sent, with sending times and delivery and read status.

We also keep in-platform notifications and a record of the operational e-mails we send (such as account confirmations, password resets and seller-team invitations).

The ratings and reviews you publish about products, sellers’ replies to them, and the testimonials you submit are stored linked to your account and order and may be displayed publicly on the platform.

8.Seller and verification data

To activate and review a seller account, we may collect, in addition to account data:

  • The store name, description, logo and images.
  • Payout account details (RIB) and the name and address linked to them, for transferring earnings.
  • The tax identification number (NIF) and statistical identification number (NIS) where they exist.
  • The auto-entrepreneur card (or the commercial register for registered traders), a copy of the identity card and a selfie for verification when requested, and the signed Seller Convention.
  • Submission, review and decision dates, and the rejection reason if any.

Verification documents are stored as private media that is not shown publicly, and access to them is limited to what review and operations require. This policy does not describe internal security procedures.

We may keep a reference identifier with the payment provider in order to execute seller payouts.

9.Delivery and digital access data

Delivery data includes the codes, keys, account credentials and access or download links that the seller adds and the buyer receives. Licence values are stored encrypted on our servers and shown to the buyer who owns the order, to the seller who supplied them for that order, and to authorised TK Store staff only when needed for delivery, support or dispute handling.

If a product requires information from the buyer (such as an e-mail address, a username or a password), it must be exchanged only through approved platform channels and only to the extent necessary for delivery. The seller is responsible for handling that information to the minimum necessary.

For some managed subscriptions, the platform may log access events (such as a verification-code request) with limited technical data for security and abuse-prevention purposes.

10.Technical and usage data

When the platform is used, limited technical data such as the IP address, browser or device type and request times may be recorded in server logs and in the security and audit logs of certain sensitive operations (such as administrative actions and managed-account access events).

This data is used to run and protect the service and to investigate problems and fraud; it is not used to build marketing profiles.

The TK Store DZ apps also send, with each request, the platform (iPhone or Android), the app version and the chosen language. They are used to apply the rules of each app, to keep sessions secure and to diagnose problems.

11.Cookies and local storage

What the platform stores in your browser:

  • Language cookie: remembers the language you chose (Arabic, French or English).
  • Authentication cookies: a cookie used to renew the session, and a temporary cookie used to access private media (such as chat attachments); both are restricted to encrypted (HTTPS) connections in production and cannot be read by scripts.
  • Browser storage (local storage and session storage): the session token and basic account data while you are signed in, the shopping cart, and temporary state for a payment in progress that is cleared when the tab is closed.
  • Campaign-measurement cookie (website only): when you reach the website through a link that carries campaign parameters — for example a social-media post, a sponsored link or a link shared by TK Store DZ — the website records the campaign, the page you landed on and the time of the visit, and keeps a random visitor identifier in a first-party cookie issued by TK Store DZ. It is used only to understand where visits come from and which campaigns lead to orders. If you sign in or place an order, that campaign information may be associated with your account and with the order; an order is attributed to a campaign only if it is placed within 30 days of the visit from that campaign. The cookie holds only that random identifier; it cannot be read by scripts and is sent only over encrypted connections to TK Store DZ’s own measurement service. It is kept for up to 30 days after your last campaign visit; if you use the website while signed in (opening it while signed in, signing in, or reaching checkout or payment), the cookie may be renewed for a further 30 days from that use. That renewal only changes how long the cookie stays in your browser: an order is still attributed to a campaign only if it is placed within 30 days of the visit from that campaign, and signing in does not extend that window. No device or browser fingerprint is created, and raw IP addresses are not stored as part of the campaign-visit record (server logs are described in section 10).
  • Meta advertising-measurement cookies (_fbp, and _fbc when you arrive from a Meta advert): set by Meta’s measurement script, which the website loads for advertising measurement; this measurement is separate from the campaign measurement above. These cookies hold Meta’s own identifiers and let Meta match visits and purchases to its adverts. For that purpose the website reports page views, product views, additions to the cart and checkout starts to Meta, and TK Store DZ’s servers report purchases. Depending on what is available, these reports carry those identifiers and connection details (IP address and browser type); purchase reports also carry the order value and currency, the product identifiers, quantities and item prices, an internal account identifier in hashed form and, where available, the e-mail address and phone number in hashed form. The website’s own campaign-measurement feature described above does not itself send the campaign data it records to Meta.
  • Snapchat advertising-measurement cookies (_scid, _scid_r and _sctr on this website, and Snapchat’s own cookies on its domain): set by Snapchat’s measurement script, which the website loads for advertising measurement; this measurement is separate from the campaign measurement above. These cookies hold Snapchat’s own identifiers and let Snap Inc. match visits and purchases to its adverts. For that purpose the website reports page views, product views, additions to the cart and checkout starts to Snapchat, and TK Store DZ’s servers report purchases. Depending on what is available, these reports carry those identifiers, the Snapchat click identifier when you arrive from a Snapchat advert, and connection details (IP address and browser type); purchase reports also carry an internal order reference, the order value and currency, the product identifiers, quantities and item prices, an internal account identifier in hashed form and, where available, the e-mail address and phone number in hashed form. The website’s own campaign-measurement feature described above does not itself send the campaign data it records to Snapchat.

Signing in with Google calls Google’s service, which may set its own cookies under Google’s policy. You can delete cookies and local storage from your browser settings; doing so signs you out and empties the cart.

12.How we use the data

We use the data to:

  • Create, manage and verify accounts.
  • Execute orders, payments and delivery, and manage the TK Points wallet and seller payouts.
  • Enable communication between buyer and seller and with the administration inside the platform.
  • Handle disputes and refunds and enforce platform policies.
  • Review and moderate sellers and products.
  • Send notifications and operational messages about the account and orders.
  • Measure which campaigns and traffic sources bring visitors and orders to the platform, using the campaign-measurement cookie described in section 11.
  • Protect the platform and its users and prevent fraud and abuse.
  • Meet applicable legal and accounting obligations.

13.Fraud prevention and security

We may use order, payment, conversation and technical records to detect fraud, payment manipulation or abuse of the dispute mechanism, and to protect accounts and the platform.

We apply reasonable technical and organisational measures to protect data, such as hashing passwords, encrypting stored licence values, and restricting access to private media and verification documents. No system, however, can guarantee absolute security.

14.Sharing data with service providers

We do not sell users’ data. We share data only for the purposes described in this policy, and only to the extent needed, with:

  • The other party to the transaction: the seller sees the contact and delivery details needed to fulfil the order, and the buyer sees the store name and its public information.
  • Payment service providers, to execute payments, refunds and seller payouts (see section 15).
  • Infrastructure, hosting and storage providers on which our servers, databases and media run (see section 16).
  • The e-mail delivery provider used for operational messages.
  • Google, when you choose to sign in with Google.
  • Meta, for advertising measurement on the website, as described in section 11.
  • Snap Inc. (Snapchat), for advertising measurement on the website, as described in section 11.
  • Messaging services used to send internal operational alerts to the TK Store team.
  • Competent authorities, where required by law or to protect the rights of users or the platform.

15.Payment providers

When paying through an external provider, the payment is completed on that provider’s interface under its own terms and privacy policy. TK Store receives from the provider the transaction references, status and amount, and may share with it the order identifier, the amount and the contact details needed to complete the payment.

When paying from the TK Points wallet, the transaction is processed inside the platform without passing payment data to an external party.

To transfer seller earnings, the payout account details (RIB) and the linked name are shared with the transfer service provider.

16.Hosting and technical infrastructure

The platform runs on servers and databases managed by TK Store with hosting providers, and media (product images, private attachments, verification documents) is stored on storage infrastructure managed by TK Store or a storage provider. This infrastructure may change over time while keeping the level of protection described in this policy.

18.Courses, e-books and externally hosted content

What TK Store processes itself (the order, the payment, the delivered link and the conversations) remains subject to this policy. A seller may ask for an e-mail address to grant access to their external platform; this is exchanged only through the platform chat and only to the extent necessary.

19.Gaming account credentials

For Gaming Accounts, the delivered data are the account’s login credentials and, where needed, its recovery information. They are handled like any other delivery data: stored encrypted on our servers and shown only to the buyer of the order, to the seller who supplied them, and to authorised TK Store staff when needed for delivery, support or a dispute (see section 9).

Sellers must not hand over more personal data than the account requires: before delivery they must remove saved payment methods and unrelated personal information from the account, and should remove personal phone numbers or social-login links where feasible. Credentials must never be placed in a product’s title, description or images. Buyers should change the password and security settings after delivery.

20.The TK Store DZ apps for iPhone and Android

The TK Store DZ apps give access to the same account, orders, licences and conversations as the website, and this policy applies to them in the same way. In addition:

  • Permissions: the app asks for access to the camera, photos, files or microphone only when you choose a profile photo, attach a picture or a file in a chat, or record a voice message. What you send in a chat is shared only in that conversation.
  • Session security: your sign-in session is kept in the secure storage of your device (the Keychain on iPhone, the Keystore on Android).
  • No tracking: the apps contain no advertising, analytics or attribution tools, do not use the device advertising identifier, and do not track you across other companies’ apps or websites. Orders placed in the apps are not sent to advertising platforms.
  • Payments: to pay for an order, the app opens the payment provider’s page; your payment credentials are not entered in the app.
  • Account deletion: you can delete your account yourself in the app (My Profile, then Security, then Delete Account). See section 22 and the account deletion page.

21.Data retention

We retain information for as long as reasonably necessary for the purposes described in this policy, including transaction records, dispute handling, security, legal and accounting obligations, and platform operations.

Some temporary data expires automatically, such as authentication sessions, expired verification codes, and unpaid orders that are cancelled once the payment deadline has passed. Campaign-visit records and the statistics derived from them (section 11) are kept for ongoing historical, analytical, operational and commercial analysis; under the current policy there is no fixed automatic deletion period for these analytics records, and they may be retained, together with the aggregated campaign statistics and the campaign attributed to each order, as part of the platform’s historical business records. This is separate from the 30-day attribution window, which only determines whether an order is linked to a campaign and has nothing to do with how long records are kept. These records may be deleted or unlinked from an account when this policy changes, when a legal requirement so requires, or under the account-deletion rules below.

When an account is deleted, the records that must be kept for these purposes (orders, payments, licences, disputes, conversations and security logs) are kept under the name “Deleted User”, and the personal data that is no longer needed is erased. At the same time, the campaign-visit records that were linked to the account have the account identifier removed and are marked as erased; they then hold no account identifier and may remain in that form as historical analytics. The campaign attribution kept with an order retains neither the visitor identifier of the browser nor a directly reusable link to the account; it may remain with the order as part of its operational and accounting history.

22.Access, correction and deletion

From their account, users can edit their profile data (name, phone number, address, picture), change their password, and view their orders and wallet.

Users can delete their account themselves in the TK Store DZ app (My Profile, then Security, then Delete Account), or ask for it from the website through the TK Admin chat; the account deletion page explains both and what is kept. To request access to other data or a correction, the user contacts TK Store through the channels listed in section 24. These requests are handled manually and reviewed taking into account transaction records, disputes, fraud and security requirements, legal obligations and operational requirements; we may keep certain records where necessary for those purposes or to protect the rights of users and the platform.

23.Changes to this privacy policy

We may update this policy when our services, providers or obligations change. The updated version is published on this page with its last-updated date.

24.Contact

For any privacy-related request or question about this policy:

  • Use the admin chat inside the platform as the first option, when available.
  • If it is not available, use the official WhatsApp number designated by TK Store.