Privacy Policy
Version of 4 October 2026 · SEO by Yoni FZC
This Privacy Policy explains how SEO by Yoni FZC handles personal data in connection with Radar by Yoni: what we collect, why, who we share it with, how long we keep it, and the rights people have. Last updated: 4 October 2026.
Who we are
Radar by Yoni is provided by SEO by Yoni FZC, trade licence 4413478.01, Business Centre,Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates.. Website: https://yourdomain.com.
For any question about privacy, or to use your rights, email privacy@yourdomain.com.
We are a company in the United Arab Emirates and we follow the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL). Stores that use Radar by Yoni are in many countries. When we handle data of people in other countries, we also follow the data protection laws that apply to them and to the store, for example the ones listed below.
Our role: controller and processor
We handle two kinds of personal data, and our role is different for each:
- Data about store owners and their workers (the people who use Radar by Yoni). We decide how this data is used, so we are the controller.
- Data about a store's customers and visitors. The store owner decides why this data is collected and used, so the store owner is the controller. We process it only on the store owner's behalf and on their instructions, as a processor.
Each store owner must have a lawful basis for their customers' data, under the data protection laws that apply to them and their customers, for example the ones listed below, and their own privacy notice. We give store owners suggested text for this in the app.
If you are a customer of a store that uses Radar by Yoni, please contact that store first.
What data we handle
About store owners and workers:
- account details: name, email, phone number, business name and sign-in details;
- usage records: sign-ins, and which pages and buttons you use in the app;
- questions typed into the "Ask me" box;
- billing records and messages you send us.
From the store, read-only, on the store owner's behalf:
- orders, order lines, order notes, discount codes, refunds and refund notes;
- products, variants, stock levels, and product costs if recorded;
- customers: name, email and phone number;
- shipping addresses of recent orders that are not yet delivered;
- unfinished checkouts (Shopify only);
- the marketing source of each order: first and last visit source, and campaign tags;
- blog article titles and dates.
From connected services, only if the store owner gives access: data from Google Analytics 4 (Viewer access), Google Search Console (Restricted access), Google Ads (read-only, through our manager account) and Meta Ads (read-only, as a partner).
From the journey tracker, only if the store owner adds it: anonymous steps of visits (page path, step name, device type, the address of the product viewed, and the words typed in the store's search box with the number of results) and a salted hash of the IP address that changes every day. Searches that look like an email address or a phone number are dropped. It collects no names, emails or phone numbers and uses no cookies.
From the store's public website, once a week: the home page and a best-selling product page, as any visitor sees them, to check good practices (reviews, returns policy, payment options, speed).
Records we create: which emails we sent, to whom, when, and whether they were opened; the WhatsApp chats and emails that the store's team opened from the app; and, for the "Customer of the month", the chosen customer, the text of the certificate and a private link to it.
Public and third-party data: public catalogue pages of competitors the store owner lists, and search data from DataForSEO based on search keywords and the store's public website address.
From personal emails to customers, only if turned on for the store: the short emails written and sent on the store's behalf, the replies customers send to the store's mailbox (read from that mailbox and stored encrypted), automatic answers and bounces, whether a customer followed the link of the email, and the orders made within 7 days after that.
Why we use data
- To provide the service: reports, advice cards, alerts, daily and weekly emails, WhatsApp links for the owner, and worker task links.
- To answer "Ask me" questions.
- To respect "do not contact" choices that the store owner records.
- To support our clients and to improve the service, using usage records.
- To produce anonymous, aggregated market insights.
- To tell anonymous success stories (no store name, products, customers or city), as explained in "Anonymous success stories".
- To recommend our own services to the store owner when their numbers show a problem those services fix.
- To bill for the service and keep business records.
- To keep the service secure and prevent abuse.
- To meet our legal obligations.
Legal bases
For data about store owners and workers, we rely on:
- the contract with the store owner, to provide and support the service;
- our legal obligations, for example for billing records;
- consent, where the law requires it, for example for the optional connections a store owner chooses to turn on;
- where the law allows, our interest in improving and securing the service.
For customer and visitor data, the store owner is responsible for the legal basis. We process that data only to provide the service to the store owner, under our agreement with them.
Artificial intelligence
All numbers are calculated on our own server. We use an AI provider, Anthropic (maker of Claude), only to write wording and to answer "Ask me" questions.
Before any text leaves our server, we remove customer names, emails and phone numbers. The AI never receives customer names. Store owners can turn the AI off. The app then uses built-in text.
For some features the AI also searches the public web: prices of a product at other stores in the store's country, and research on good practices for online stores. We send only the product name or the topic and a few store figures, never customer data. Only sources the AI really read are kept.
Market insights
We combine anonymous, aggregated numbers from all stores that take part to show trends. They never include names, customers, products or store names. A figure is shown only when at least 10 stores of the same type contribute, and no single store can dominate it. A store can opt out in Settings. Stores that opt out do not receive market insights.
Anonymous success stories
We may tell, anonymously, results that stores obtained with Radar by Yoni, for example in an article on our website. A case uses only figures that Radar by Yoni measured in the store, and never names the store, its products, its customers or its city. It gives only the broad sector and region (a country or larger), rounded figures or percentages and approximate dates. Before we publish a case, we check that it cannot point to a single store.
No personal data is part of a case. When our AI provider helps write a case, it receives only these anonymous figures.
Who we share data with
We do not sell personal data. We share data only with these service providers (sub-processors), and only what each one needs:
- Hostinger: hosts our servers, where data is stored and processed.
- Anthropic: writes wording and answers "Ask me" questions. It receives text with customer names, emails and phone numbers removed.
- Google: when a store owner connects Google Analytics 4, Search Console or Google Ads, we read that data from Google.
- Meta: when a store owner connects Meta Ads, we read ad data as a partner.
- DataForSEO: receives search keywords and the store's public website address. Never customer data.
- Our email provider: sends emails to store owners and workers through SMTP.
- Hostinger (email): hosts the mailbox on the store's domain that sends personal emails to customers and receives their replies. If the store uses a paid email service instead (such as Amazon SES, Postmark or Brevo), that service sends those emails on the store's behalf.
We may also share data if the law or a competent authority requires it, to protect our legal rights, or as part of a sale or merger of our business, with the same protections in place.
International transfers
We are in the UAE, and some of our providers, such as Anthropic, Google and Meta, may process data in other countries. So personal data may be processed outside the country where a store or its customers are. When data moves between countries, we take the steps the laws that apply require, such as using providers with suitable data protection terms and, where needed, standard contractual clauses. The sections below explain this for each law. We also keep what we send to a minimum. For example, customer names, emails and phone numbers are removed before any text goes to our AI provider.
How long we keep data
- Delivery addresses: deleted a few days after the order.
- Journey tracker data: 45 days.
- Other store data (orders, products, customers and similar): while the account is active, and deleted when the store owner asks us to delete it or the service ends.
- Data from connected services: while the connection and account are active.
- Account details, usage records and "Ask me" questions: while the account is active.
- Billing records: as long as the law requires (UAE law, and the law of the store's country where it applies).
- Anonymous, aggregated market figures: these cannot identify anyone, so they may be kept.
- Personal emails to customers and their replies: 12 months, then the text is deleted. The list of customers who asked not to get emails is kept, so we keep respecting their choice.
Security
- Our access to stores and connected services is read-only.
- Customer names, emails, phone numbers and addresses are encrypted at rest.
- Numbers are processed on our own server. Personal details are removed before any text goes to our AI provider.
- Only staff who need it can access data, and our support access to an account is logged.
- The journey tracker is rate limited to prevent abuse.
No system is perfectly secure. If a breach affects personal data, we will act quickly, inform the store owners affected, and inform the authorities where the law requires.
Your rights
Under the PDPL, and under the data protection laws that apply to you, for example the ones listed below, you can ask to:
- access the personal data we hold about you;
- correct data that is wrong or incomplete;
- delete your data;
- object to, or ask us to stop, certain uses of your data, and withdraw consent you gave.
Some laws give you more rights, such as receiving your data in a portable format. The sections below list them.
To use these rights, email privacy@yourdomain.com. We may ask you to confirm who you are. We will reply without undue delay, and within any time limit the law that applies sets.
Store owners can also delete all their data from Radar by Yoni with the delete button in the app.
If you are a customer of a store, please contact the store. You can also ask the store not to contact you, and the store can mark you "do not contact" in Radar by Yoni.
If you are not happy with our answer, you can complain to the data protection authority where you live or work. In the UAE this is the UAE Data Office. The sections below name the authority for other countries.
If you are in one of these countries
The text above applies everywhere. Some countries give people extra rights or set extra rules. If you, or the store you buy from, are in one of the places below, that section applies too.
If you are in the United Arab Emirates (PDPL)
The UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) applies. We are a UAE company, so we follow it for all the data we handle. If a business is in a free zone with its own data protection law, such as the DIFC or ADGM, that law may apply instead.
Your rights: you can ask for information about how your data is used and for a copy of it, ask for it to be transferred to another provider, ask for it to be corrected or deleted, ask for certain uses to be restricted or stopped, and object to decisions made only by automated means that seriously affect you.
How to use them: if you are a customer of a store, contact the store first. The store decides about your data, and we help it answer. You can also email us at privacy@yourdomain.com. Store owners and workers can email us directly.
Transfers outside the UAE: we rely on the grounds the PDPL allows, such as countries with adequate protection or contracts with suitable data protection terms.
Regulator: the UAE Data Office. You can complain to it.
If you are in Saudi Arabia (PDPL)
The Saudi Personal Data Protection Law (PDPL) and its regulations apply to personal data of people in the Kingdom, also when the data is processed outside the Kingdom.
Your rights: you can ask to be told how and why your data is used, to access it and get a copy in a clear and readable form, to have it corrected, completed or updated, and to have it destroyed when it is no longer needed. Where we use your data based on your consent, you can withdraw it.
How to use them: if you are a customer of a store, contact the store first. The store decides about your data, and we help it answer. You can also email us at privacy@yourdomain.com. Store owners and workers can email us directly.
Transfers outside the Kingdom: we rely on the conditions set by the PDPL and its rules on transfers outside the Kingdom, such as countries with adequate protection or appropriate safeguards like standard contractual clauses.
Regulator: the Saudi Data and Artificial Intelligence Authority (SDAIA). You can complain to it.
If you are in Qatar (Law No. 13 of 2016)
Qatar's Law No. 13 of 2016 on the Protection of Personal Data Privacy applies.
Your rights: you can withdraw your consent, object to processing that is not needed for its purpose or is excessive, unfair or unlawful, ask to be told about the processing and to access your data, ask for it to be corrected, and ask for it to be deleted.
How to use them: if you are a customer of a store, contact the store first. The store decides about your data, and we help it answer. You can also email us at privacy@yourdomain.com. Store owners and workers can email us directly.
Transfers outside Qatar: the law allows personal data to move across borders, as long as this does not breach the law or seriously harm you or your privacy. We send only what the service needs.
Regulator: the authority in Qatar responsible for personal data privacy. You can complain to it.
If you are in Oman (Royal Decree No. 6/2022)
Oman's Personal Data Protection Law, issued by Royal Decree No. 6/2022, and its executive regulations apply.
Your rights: you can withdraw your consent, ask for your data to be corrected, updated or blocked, ask what data is processed and why, get a copy of it, ask for it to be transferred to another controller, ask for it to be erased unless it must be kept, and be told of a breach that affects it.
How to use them: if you are a customer of a store, contact the store first. The store decides about your data, and we help it answer. You can also email us at privacy@yourdomain.com. Store owners and workers can email us directly.
Transfers outside Oman: data is transferred only under the conditions set by the law and its executive regulations.
Regulator: the Ministry of Transport, Communications and Information Technology. You can complain to it.
If you are in Bahrain (Law No. 30 of 2018)
Bahrain's Personal Data Protection Law, Law No. 30 of 2018, applies.
Your rights: you can ask whether your data is processed and get a copy of it, object to processing that causes you or others harm or distress, object to direct marketing, ask for wrong data to be corrected, blocked or erased, and object to decisions based only on automated processing.
How to use them: if you are a customer of a store, contact the store first. The store decides about your data, and we help it answer. You can also email us at privacy@yourdomain.com. Store owners and workers can email us directly.
Transfers outside Bahrain: data is transferred to countries the regulator recognises as giving enough protection, or in the other cases the law allows.
Regulator: the Personal Data Protection Authority. You can complain to it.
If you are in the European Union or the European Economic Area (GDPR)
The EU General Data Protection Regulation (GDPR) may apply when a store is in the EU or EEA, or sells to people there. For its customers' data, the store is the controller and we are its processor. We follow the GDPR's rules for processors and act only on the store's instructions.
Your rights: you can access your data and get a copy, have it corrected or erased, restrict its use, receive it in a portable format, object to its use (and at any time to direct marketing), withdraw consent at any time without affecting earlier use, and not be subject to decisions based only on automated processing that have legal or similarly significant effects on you.
How to use them: if you are a customer of a store, contact the store first. The store decides about your data, and we help it answer. Store owners and workers can email us at privacy@yourdomain.com. We answer within one month, or tell you why we need more time, as the GDPR allows.
Transfers outside the EU and EEA: we are based in the UAE. When personal data is transferred from the EU or EEA to us or to our providers, we use safeguards the GDPR allows, such as the European Commission's standard contractual clauses, or an adequacy decision where one exists for the destination.
Store owners who need a data processing agreement under Article 28 of the GDPR can ask us for one at privacy@yourdomain.com.
Regulator: the data protection authority of the EU or EEA country where you live or work, or where you think the law was broken. You can complain to it.
If you are in the United Kingdom (UK GDPR)
The UK GDPR and the Data Protection Act 2018 may apply when a store is in the UK, or sells to people there. For its customers' data, the store is the controller and we are its processor. We act only on the store's instructions.
Your rights: you can access your data and get a copy, have it corrected or erased, restrict its use, receive it in a portable format, object to its use (and at any time to direct marketing), withdraw consent at any time, and not be subject to decisions based only on automated processing that have legal or similarly significant effects on you.
How to use them: if you are a customer of a store, contact the store first. The store decides about your data, and we help it answer. Store owners and workers can email us at privacy@yourdomain.com. We answer within one month, or tell you why we need more time, as the law allows.
Transfers outside the UK: when personal data is transferred from the UK to us or to our providers, we use safeguards UK law allows, such as the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, or UK adequacy regulations where they exist for the destination.
Store owners who need a data processing agreement can ask us for one at privacy@yourdomain.com.
Regulator: the Information Commissioner's Office (ICO). You can complain to it.
If you are in the United States (California CCPA and similar state laws)
The California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the CCPA), applies to businesses that meet its thresholds. Several other US states have similar laws, and we handle requests under them in the same way.
For a store's customer data, we act as the store's service provider. We use that data only for the purposes our contract with the store and the law allow. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
Your rights: you can ask to know what personal information is collected, used and disclosed, and get a copy of it; ask for it to be deleted or corrected; opt out of its sale or sharing; limit the use of sensitive personal information; and you will not be treated differently for using these rights.
How to use them: if you are a customer of a store, contact the store first. The store decides about your data, and we help it answer. Store owners and workers can email us at privacy@yourdomain.com. You can use an authorized agent. We check who is asking before we act on a request.
Transfers: your data may be processed outside the United States, including in the UAE, under contracts that protect it.
Regulators: the California Privacy Protection Agency and the California Attorney General enforce the CCPA.
If you are in Canada (PIPEDA)
The Personal Information Protection and Electronic Documents Act (PIPEDA) applies. In some provinces, such as Quebec, Alberta and British Columbia, provincial privacy laws may apply too.
Your rights: you can ask to access the personal information held about you, challenge its accuracy and have it corrected, and withdraw your consent, subject to legal or contract limits and reasonable notice.
How to use them: if you are a customer of a store, contact the store first. The store decides about your data, and we help it answer. You can also email us at privacy@yourdomain.com. Store owners and workers can email us directly.
Transfers outside Canada: your information may be processed outside Canada, including in the UAE and the United States, by us and our providers. It is protected by contracts while it is there, but it may be accessible to the courts and authorities of those countries under their laws.
Regulator: the Office of the Privacy Commissioner of Canada, or the provincial privacy commissioner where a provincial law applies. You can complain to them.
If you are in Mexico (LFPDPPP)
Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) applies. For its customers' data, the store is the controller ("responsable") and we act as its processor ("encargado"), only on the store's instructions.
Your rights: the ARCO rights, which are access, rectification, cancellation and opposition. You can also revoke your consent and limit the use or disclosure of your data.
How to use them: if you are a customer of a store, send your request to the store, which answers within the time limits the law sets. We help it answer. Store owners and workers can email us at privacy@yourdomain.com.
Transfers: sending data to us and our providers, as processors working only for the store, is not a transfer that needs your consent under the law. We do not use it for our own purposes.
Regulator: the federal authority for the protection of personal data. Since 2025 this is the Secretaría Anticorrupción y Buen Gobierno, which took over from the former INAI.
If you are in Argentina (Law No. 25.326)
Argentina's Personal Data Protection Law No. 25.326 applies.
Your rights: you can access your data free of charge at intervals of no less than six months, unless you show a legitimate interest to do so sooner. You can also ask for your data to be corrected, updated or deleted, and for it to be kept confidential.
How to use them: if you are a customer of a store, contact the store first. The store decides about your data, and we help it answer within the time limits the law sets. You can also email us at privacy@yourdomain.com. Store owners and workers can email us directly.
Transfers outside Argentina: data is transferred only to countries with adequate protection, or under the exceptions and safeguards the law allows, such as contracts with the protection clauses approved by the regulator.
Regulator: the Agencia de Acceso a la Información Pública (AAIP), the supervisory body of Law No. 25.326. It handles complaints from people whose data protection rights have not been respected.
If you are in Colombia (Law 1581 of 2012)
Colombia's Law 1581 of 2012 on the protection of personal data (habeas data) and its regulations apply.
Your rights: you can know, update and correct your data, ask for proof of the authorization you gave, be told how your data is used, revoke your authorization and ask for your data to be deleted when the law allows, and access your data free of charge.
How to use them: if you are a customer of a store, contact the store first. The store decides about your data, and we help it answer. You can also email us at privacy@yourdomain.com. Before you complain to the regulator, you must first send your request or claim to the store or to us.
Transfers outside Colombia: when data is sent to a processor abroad, such as us or our providers, it is protected by a contract as Colombian rules require. Other transfers abroad are made only to countries with adequate protection or in the cases the law allows.
Regulator: the Superintendencia de Industria y Comercio (SIC). You can complain to it.
If you are in Brazil (LGPD)
Brazil's General Data Protection Law (Lei Geral de Proteção de Dados, Law No. 13.709/2018) applies. For its customers' data, the store is the controller and we are its processor.
Your rights: you can confirm whether your data is processed and access it, correct data that is incomplete, wrong or out of date, have unnecessary or excessive data anonymized, blocked or deleted, receive your data in a portable form, have data processed with your consent deleted, know who your data is shared with, be told what happens if you refuse consent, revoke your consent, and ask for a review of decisions made only by automated processing.
How to use them: if you are a customer of a store, contact the store first. The store decides about your data, and we help it answer. You can also email us at privacy@yourdomain.com. Store owners and workers can email us directly.
Transfers outside Brazil: data is transferred only as the LGPD allows, such as to countries with adequate protection or with the standard contractual clauses approved by the ANPD.
Regulator: the Autoridade Nacional de Proteção de Dados (ANPD). You can complain to it.
Cookies
The app uses one session cookie only, to keep you signed in. We do not use advertising or tracking cookies in the app. The journey tracker does not use cookies.
When you choose a language on a public page, we also remember it in a small cookie, so the next page opens in the same language.
Children
Radar by Yoni is a service for businesses. It is not meant for children, and we do not knowingly collect data from children as users of the app.
Changes to this policy
We may update this policy. The date at the top shows the current version. If a change is important, we will tell store owners by email or in the app.
This policy is available in English, Spanish and Arabic. The English version is the binding one.
Contact
SEO by Yoni FZC, Business Centre,Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates..
Email: privacy@yourdomain.com
Website: https://yourdomain.com
What changed
- 24 Sep 2026: First version of these pages.
- 27 Sep 2026: Added: we can use your numbers to recommend our services to you; email log; emails to customers from your own email app; customer of the month; the journey tracker now also records products viewed and store searches; weekly check of your public website; AI web research for good practices.
- 27 Sep 2026: Clarified (no change to your rights or obligations): screenshots and videos of the app use a made-up demo store; alerts for orders with many items and the "Loyal buyer" label use the same order data as before.
- 1 Oct 2026: The legal pages now cover stores in other countries, with a section for each privacy law, and are available in English, Spanish and Arabic. The English version is the binding one.
- 2 Oct 2026: Added: personal emails to your customers, sent on your behalf from a mailbox on your own domain, with the replies kept in the app for 12 months; new email provider entry; new paragraph in the text for your store's privacy policy.
- 2 Oct 2026: Clarified (no change to your rights or obligations): you can choose to add a coupon code of your own store to the personal emails; the emails can mention a true fact from the customer's own orders.
- 4 Oct 2026: Added: we may tell, anonymously, the results a store obtained with Radar by Yoni (no store name, products, customers or city; only the broad sector and region, rounded figures and approximate dates).