Effective May 2026 · Last updated May 2026
We're working with legal counsel to refine this policy before our public launch. If you have privacy questions, contact privacy@urukshelf.com.
Privacy
Privacy Policy
How URUK collects, uses, and protects your information across URUK Shelf, URUK Read, and related services.
1.Information we collect
For all users
- Account information (email, name, password hash)
- Communication content (support messages, contact form submissions)
- Usage information (page views, features used, IP for fraud detection)
- Cookies and similar technologies (session, preferences, analytics)
For publishers
- Business information (publisher name, address, tax ID)
- Catalog content (books you upload, including cover images, descriptions, prices)
- Payment information (gateway credentials, bank details for payouts — never card numbers, those go to gateways directly)
- Operational data (orders processed, customers, sales history)
For readers
- Order information (purchase history, shipping addresses)
- Payment information (processed by gateway, we receive only metadata like last 4 digits and transaction ID — never full card numbers)
- Account preferences (followed publishers, wishlist, language preference)
2.How we use information
To provide services
- Process orders and facilitate publisher fulfillment
- Maintain accounts and authenticate logins
- Display catalogs and orders correctly
To communicate
- Order confirmations, shipping updates (transactional)
- Account notifications, security alerts
- Marketing emails (only with explicit opt-in)
To improve the platform
- Analytics (anonymized when possible)
- Fraud prevention
- Customer support
Legal compliance
- Tax reporting where required
- Responding to lawful government requests
3.Information shared with publishers (for readers)
When you order from a publisher on URUK Read, we share:
- Your name and shipping address
- Your email (for order updates)
- Order details (which books, quantities, prices)
Publishers may use this for fulfillment and (with your separate opt-in per publisher) marketing.
4.Information shared with third parties
Payment processors (Stripe, Tap, PayTabs, HyperPay, MyFatoorah, Areeba): receive payment info to process transactions.
Email service (Mailjet for transactional, Mujaz for marketing): receives email + content for delivery.
Hosting and CDN (Vercel, Cloudflare): standard infrastructure providers.
Database (Neon PostgreSQL, AWS S3 for files): standard infrastructure.
Analytics: [TBD — Google Analytics? Plausible? None?]
We never:
- Sell your data to data brokers
- Sell your data to advertising networks
- Share your data with third parties for their own marketing
5.Cookies
Essential cookies (always on): session management, cart contents, authentication, fraud prevention. Required for platform functionality.
Analytics cookies (opt-in via banner): help us understand platform usage to improve.
Marketing cookies: none. We don't run third-party advertising.
You can manage cookie preferences in your account settings or by adjusting your browser.
6.Your rights
Under GDPR and applicable Arab data protection law, you can:
- Access your data — see everything we have
- Correct your data — update incorrect information
- Delete your account and data — permanent removal (with some exceptions for legal/tax retention)
- Export your data — receive a portable copy
- Withdraw consent for marketing — unsubscribe anytime
- Lodge a complaint — with your local data protection regulator
To exercise any of these, email privacy@urukshelf.com or use the contact form.
7.Data retention
- Account data: until you delete your account, then 30 days for restoration window
- Order data: 7 years (tax/legal retention requirements)
- Marketing data: until you unsubscribe
- Analytics data: 26 months
- Backups: 90 days before permanent deletion
8.International transfers
URUK uses globally distributed infrastructure (Vercel, Cloudflare). Data may be processed in the US, EU, or other regions. For EU users, we implement Standard Contractual Clauses to ensure adequate protection.
9.Children
URUK Read and URUK Shelf are not intended for children under 13. We don't knowingly collect data from children under 13. If you believe a child under 13 has provided us data, contact us and we'll delete it.
10.Changes to this policy
We may update this policy. For material changes, we'll notify users by email at least 30 days in advance.
11.Contact
For privacy questions, data requests, or complaints:
- Email: privacy@urukshelf.com
- Form: the contact page on urukshelf.com
- Mailing address: [TBD when URUK is incorporated]
Data Protection Officer: [TBD if required by jurisdiction]
Privacy questions? privacy@urukshelf.com or contact us.