Privacy Policy
Last updated: 23 August 2026
This Privacy Policy explains how Romaine ("Romaine", "ro_maine", "we", "us", or "our") collects, uses, shares, and protects your personal data when you use the Romaine mobile application and related delivery services (the "Service") in the Arab Republic of Egypt.
Romaine is a boutique grocery and fresh-prep delivery service. This policy is drafted with the Egyptian Personal Data Protection Law No. 151 of 2020 ("PDPL") in mind.
By using the Service, you agree to the collection and use of your information as described in this policy.
---
1. Who we are
The data controller responsible for your personal data is:
- Company: New Rabia
- Registered address: 16 Ghernata st., Korba, Cairo, Egypt
- Contact for privacy matters: info@msol.dev
If you have any questions about this policy or how we handle your data, contact us using the details above.
---
2. What data we collect
We only collect data we need to take your order, deliver it, and improve the Service.
2.1 Data you give us
- Account & identity: your name and mobile phone number (used to create and verify your account by OTP).
- Delivery addresses: the addresses you save (street, building, apartment, landmarks) and any delivery notes.
- Order details: the items you buy, quantities, substitution preferences, and special instructions.
- Profile details (optional): date of birth and gender, if you choose to add them.
- Communications: messages you send us through support.
2.2 Data we collect automatically
- Location data: your delivery location (from the map/GPS or the address you select) so our drivers can reach you. We use location only in connection with a delivery you request.
- Device & push tokens: a Firebase Cloud Messaging (FCM) push token and basic device information, so we can send you order updates and notifications.
- Usage & technical data: app version, language preference, and basic diagnostic information to keep the app working.
2.3 Payment data
When you pay by card or wallet, your payment is processed by our third-party payment processor. Your full card number is entered into the payment processor's secure flow — Romaine does not store your full card details. We keep only the order's payment status and a reference needed for refunds.
---
3. How we use your data
We use your data to:
- create and secure your account and verify you by OTP;
- take, prepare, and deliver your orders;
- show you order tracking (preparing, ready, on the way, delivered);
- run the substitution flow — when an item is unavailable, our staff may propose a substitute that you approve, decline, or replace, and we record your choice;
- process payments, cancellations, and payment-aware refunds through the original payment channel;
- send you order and delivery notifications (via push and, where relevant, SMS);
- respond to support requests;
- meet legal, tax, and accounting obligations.
We do not sell your personal data.
---
4. Legal basis for processing (PDPL)
We process your data because it is necessary to:
- perform our contract with you (taking and delivering your order, handling payments and refunds);
- comply with legal obligations (e.g. tax and record-keeping);
- serve our legitimate interests in operating and improving the Service securely; and
- based on your consent, where required — for example for certain notifications or optional profile data. You may withdraw consent at any time (see Section 8).
---
5. Who we share your data with
We share only what is necessary, with:
- Our third-party payment processor — payment processing for card and wallet payments, and refunds.
- Google / Firebase (FCM) — to deliver push notifications and for basic app messaging infrastructure.
- Our delivery drivers — Romaine operates its own delivery fleet. The assigned driver sees the information needed to complete your delivery (name, phone, delivery address, and order contents).
- Service providers who host our systems and provide SMS/OTP, acting on our instructions.
- Authorities, where we are legally required to disclose data.
These parties are only permitted to use your data for the purposes we specify.
---
6. International transfers
Some of our providers (e.g. Google/Firebase) may process data on servers located outside Egypt. Where data is transferred abroad, we take steps consistent with the PDPL to ensure it remains protected.
---
7. How long we keep your data
- Account data: while your account is active.
- Order & delivery history: retained for the period required for accounting, tax, and dispute resolution.
- Payment references: kept as long as needed to support refunds and financial records.
- Push tokens: kept while the app is installed and active; removed when the token expires or you disable notifications.
When data is no longer needed, we delete or anonymise it.
---
8. Your rights
Under the PDPL, you have the right to:
- access the personal data we hold about you;
- correct inaccurate or incomplete data (you can edit most profile details in the app);
- delete your data and close your account;
- object to or restrict certain processing;
- withdraw consent where processing is based on consent;
- complain to the competent Egyptian data protection authority.
To exercise any of these rights, contact us at info@msol.dev. We will respond within the timeframes required by law.
---
9. Children
The Service is not intended for children under 18. We do not knowingly collect data from children. If you believe a child has provided us data, please contact us and we will remove it.
---
10. Security
We use technical and organisational measures to protect your data, including encrypted connections and access controls. Card details are handled inside the payment processor's secure environment and are not stored by Romaine. No system is perfectly secure, but we work to keep your data safe.
---
11. Changes to this policy
We may update this policy from time to time. We will change the "Last updated" date above and, for significant changes, notify you in the app.
---
12. Contact us
New Rabia
16 Ghernata st., Korba, Cairo, Egypt
Email: info@msol.dev