Skip to content
ELECT-IGLOBAL
ELECT-I Global

Privacy Policy

What we collect, why we collect it, who it goes to and how long we keep it. Written to be read rather than to be defensible.

Last updated: July 1, 2026

01Who is responsible for your data

ELECT-I Global is a trading name operated by HDML (Egypt). HDML decides how and why personal data on this platform is processed, and is the point of contact for anything in this policy.

The email address at the bottom of this page is a monitored mailbox. Write to it for any request about your data and say what you want done.

02What we collect

Account data
Your name, email address, password (stored only as a hash by our authentication provider), preferred language and the tier your account holds.
Business data
Company name, country, phone number and any tax or VAT number you give us for invoices and customs paperwork.
Order data
Line items, quantities, prices, order status history, documents generated for the order, and the trade term and shipping method it was placed on.
Recipient delivery details
For prepaid orders, the name, email address, phone number, delivery address, postal code, tax identifier and delivery notes the recipient enters on the claim page. The merchant who paid never receives the full address — only the recipient's name, country and city.
Quotation and enquiry data
What you asked us to source, the destination, target price, and the contact details on the request. Supplier applications are treated the same way.
Payment data
The amount, currency, purpose, status and the payment provider's own reference for each attempt. Card details are entered on the payment provider's page and never reach our servers, so we never see or store a full card number.
Technical data
The IP address and forwarding headers of requests, used to apply rate limits to public forms and to the claim page, plus server logs of errors.
Integration data
For merchant API keys: the key identifier, its scopes, when it was last used, and the request nonces we store to reject replays. Webhook endpoints and their delivery history.

We do not run advertising trackers, we do not build behavioural profiles, and we do not sell data to anyone.

03Where it comes from

  • Directly from you, when you create an account, request a quotation, place an order, apply as a supplier or write to us.
  • From the merchant who prepaid an order, when they create it on a recipient's behalf. That is limited to the order lines and, optionally, an email address for the claim link.
  • Automatically from your requests: IP address, headers and timestamps, which we use for security and rate limiting.

04What we use it for

  • Creating and running your account, and applying the correct tier pricing.
  • Pricing, confirming, fulfilling and documenting orders, including the customs paperwork a shipment needs.
  • Answering quotation requests, supplier applications and messages you send us.
  • Issuing and verifying prepaid claim links, including the digest comparison shown to the recipient.
  • Taking payment, keeping the wallet ledger accurate and processing refunds.
  • Protecting the platform: rate limiting, replay protection, fraud checks and audit logs.
  • Meeting legal, accounting, customs and sanctions obligations.

We do not use your data for automated decisions that produce legal effects for you.

05Why we are allowed to

Performance of a contract
Everything needed to give you an account, price an order, take payment and ship goods.
Legitimate interests
Keeping the platform secure, preventing abuse and fraud, and answering enquiries you have sent us.
Legal obligation
Tax and accounting records, customs declarations, and sanctions and export-control screening.
Consent
Anything optional, such as an update we ask permission to send you. Consent can be withdrawn at any time.

06Who else sees it

Hosting and database
Supabase hosts the database and the authentication service; Cloudflare hosts and serves the application. Both process data on our instructions.
Payment provider
The active payment gateway receives the amount, currency, reference and the billing contact details it needs to take a payment. It is the party that handles card details, not us.
Suppliers and manufacturers
The line items needed to produce or pick your goods. Delivery details are shared only where the supplier ships directly.
Couriers and freight forwarders
The recipient's name, address, phone number and any tax identifier the destination requires, because a shipment cannot be delivered or cleared without them.
Customs and authorities
The commercial invoice, packing list and declaration data that the destination's rules require.
The merchant who prepaid
For a prepaid order, the recipient's name, country and city only — and only after the recipient has confirmed their details.
Professional advisers and authorities
Accountants, auditors and legal advisers under confidentiality, and any authority we are legally required to answer.

07International transfers

This is a cross-border trading platform, so data moves across borders by design. Order and delivery data reaches the country the goods are shipped to and the country the supplier operates from. Our own systems are operated from Egypt, and our hosting and database providers operate globally distributed infrastructure.

Where a transfer needs a safeguard under the law that applies to you, we rely on the provider's own contractual protections and on the necessity of the transfer for performing your contract.

08How long we keep it

Order, invoice and customs records
Kept for as long as tax, accounting and customs rules require, counted from the end of the financial year the order falls in.
Account data
Kept while the account exists. After closure we keep only what is attached to order records.
Claim page drafts
Delivery details saved while a recipient is filling the form are kept with the order once submitted, and cleared with the order's claim data when the link expires unused.
Quotation requests, supplier applications and messages
Kept while the enquiry is live and for a reasonable period afterwards so we can pick up a conversation where it stopped.
Security data
Rate-limit counters roll over with their window. API request nonces are kept only long enough to make replay impossible. Audit logs are kept for security review.

09Your rights

  • Ask for a copy of the personal data we hold about you.
  • Ask us to correct anything inaccurate — you can change most of it yourself in your account.
  • Ask us to delete data we no longer have a reason to keep. Records we must retain for tax, customs or accounting reasons cannot be deleted on request.
  • Object to processing based on our legitimate interests, and withdraw any consent you have given.
  • Ask for your data in a portable format.
  • Complain to the data protection authority that covers you.

Write to us with what you want done. We answer within thirty days and will ask you to confirm your identity first, because handing account data to the wrong person is the worst outcome available here.

10How it is protected

  • All traffic is served over HTTPS, with a strict content security policy and framing disabled.
  • Passwords are never stored by us in a readable form; authentication is handled by our provider.
  • Database access is scoped by row-level security, and the privileged key that bypasses it is used only from the server, behind an explicit authorisation check on every call.
  • API key secrets are stored encrypted, with a separate hash kept as an integrity cross-check. Request signatures and claim references are compared in constant time.
  • Claim tokens are 32 bytes from a cryptographic random source, and claim reference attempts are rate limited per token.

No system is perfect. If a breach affects you, we will tell you and the relevant authority within the time the law allows, and we will say what actually happened.

11Cookies

We set only the cookies the platform needs to work: a session cookie that keeps you signed in, a cookie remembering your language choice, and a short-lived signed cookie on the claim page that records that a recipient has proved a claim link is theirs.

There are no advertising cookies and no third-party analytics on this site, which is why you are not being asked to accept anything.

12Children

This platform is for businesses. It is not directed at children and we do not knowingly collect data from anyone under eighteen. If you believe we have, write to us and we will remove it.

13Changes to this policy

When this policy changes, the date at the top of the page changes with it. Where a change materially affects how we use data you have already given us, we will tell account holders directly rather than relying on you noticing the date.

Questions about this policy?

Write to us and a person will answer. If your question is about a specific order, include the order number.

Who you are contracting with

ELECT-I Global is a trading name operated by HDML (Egypt). HDML is the seller of record and the counterparty on every order placed through this platform.