Privacy policy
Last updated: 30 September 2026
This policy explains how EROS STORE (https://erosstore.co, "we" or "Eros") collects, uses and shares your personal information when you use:
- our website; and
- the Eros app on iOS and Android (the "App").
By using the website or the App, you confirm that you have read this policy. If you do not agree with it, please do not use our services.
1) Who we are and how to contact us
- Website: https://erosstore.co
- Email: INFO@EROSSTORE.CO
- Main service jurisdiction: Iraq
If you are not satisfied with our response to a privacy complaint, you may contact the competent data protection authority in your country (including the relevant authorities in Iraq where applicable).
2) What "personal information" means
Any information that can identify you directly or indirectly, such as your name, phone, email, addresses, device identifiers, photos you upload, and your order history and activity in the App or on the website.
3) Information we collect and why
a) Account and registration
Examples: name, phone number, email (if provided), gender, date of birth (if you enter it), profile photo (where available), shipping and delivery addresses, account preferences.
Purpose: creating and managing your account, signing in, personalising your experience, and contacting you about orders and your account.
Source: directly from you.
App notes: your phone number is verified with a code sent by message (including WhatsApp or SMS where we offer them). We do not use passwords, and we do not store payment card data in the App.
b) Orders, payment and shipping
Examples: order details, billing and shipping addresses, phone, email, payment status, shipping and delivery records.
Purpose: performing the contract (selling products), processing payment, shipping, invoices and confirmations, fraud prevention, and after-sales service.
Payment: online payment happens on a hosted payment page run by the payment provider. The App does not collect or store full card numbers; card data is processed by the payment provider under its own policies.
c) Customer support and communication
Examples: the content of messages by email, WhatsApp or support channels, and the related contact details.
Purpose: answering questions, solving problems and following up on orders.
d) Device and usage information (website and App)
Examples: IP address, device type and operating system and its version, App version, App install identifier, interface language, pages or screens you visit, searches and browsing in the catalogue, cart events and basic interface interaction, crash and performance logs.
Purpose: running the service correctly, improving stability and performance, understanding usage to improve products and experience, security, and measuring our advertising (section 4).
Source: collected automatically when you use the website or the App.
e) Push notifications (App)
Examples: the device notification token (such as FCM/APNs) and your subscription preferences.
Purpose: sending order and shipping updates, alerts and offers you agree to.
Note: you can turn notifications off in your device settings at any time. This does not stop you using the store, but order alerts may not reach you.
f) Camera and photos (App)
The App may ask for camera or photo access only in these cases:
- Visual product search (when enabled): the photo you choose or take is processed to find similar products. It is sent over an encrypted connection to our servers and cloud processors to compute a similarity representation (embedding) and return results. We do not use visual-search photos to build an advertising profile, and we do not keep the search photo after the search completes (transient processing), apart from technical logs needed for security and stability.
- Product and order review photos (optional): if you attach a photo to a review or a return request, it is stored to display it or to handle the request after review, and for content safety.
- Profile photo (where available): stored to show in your account.
- Photos in chats with the shopping assistant "Venus" (optional): you can attach up to 3 photos per message, such as a photo of your skin or a product, for more accurate advice. See section "g" below.
You can refuse the permission; the related feature may then not work, but you can still browse and buy.
g) The "Venus" shopping assistant and your data (if you use it)
"Venus" is the smart shopping assistant in the App: she answers your questions, suggests products that suit you and follows up on your routine. This section explains plainly what happens to your data when you use her.
- What is sent and where: when you chat with Venus, your text messages and attached photos (up to 3 per message) are sent to the AI service Gemini by Google, a third party that processes this data to generate replies under its own policies (Google Privacy Policy). Anything you write or attach in the chat may be processed by Google for this purpose.
- Photos you attach: we store chat photos in our cloud storage (Cloudflare R2), linked to your account, so your conversation stays complete on all your devices and Venus can refer back to them later (for example, comparing your skin today with an earlier photo). This storage lasts until you delete your account, unlike visual-search photos in section "f", which are processed transiently.
- Photos and information about other people: if you ask Venus about someone else and attach their photo or share information about them, it is stored in your account and processed the same way. You are responsible for getting that person's consent first.
- Venus's memory: Venus remembers facts you tell her, such as skin type and concerns, pregnancy or breastfeeding, and facts about people you ask about, to give personalised advice without asking again. Some of this is sensitive (health-related); share only what you are comfortable with, as the feature also works without these details.
- Proactive messages: Venus may send you a notification on her own based on your chats or past orders (for example, a routine follow-up). These are deliberately limited, and you can stop them at any time: tell Venus «لا تراسليني», or turn off App notifications in your device settings.
- Internal review: chat texts and your ratings of replies are stored and may be reviewed by authorised staff to monitor and improve quality and fix errors.
- Voice input: if you speak to Venus, your voice is turned into text by your device's speech recognition (the operating system, which may process audio under its provider's policies); we receive only the resulting text and store no recording.
- Retention and deletion: chats, photos and memory stay linked to your account until you delete it. When account deletion completes (section 8), chat photos, Venus's memory and chat logs are deleted, except what we must keep for legal or accounting reasons.
- Two plain notes: Venus's advice is shopping information, not a diagnosis or medical advice. We do not sell your chats or photos to anyone, but Google processes chat content and photos to provide the AI service and Cloudflare hosts the storage, each under its agreements as a service provider.
h) Cookies and similar technologies (mainly the website)
We use cookies and similar technologies to run the store, session, cart, analytics and marketing, including Meta's cookies on the website (_fbp and _fbc) that link your visit or purchase to an ad you clicked (section 4). You can manage cookies in your browser settings; blocking them may affect parts of the website.
i) What we do not collect on purpose
- We do not request your precise GPS location.
- We do not collect contacts from your phone's address book.
- We do not show other companies' ads inside the App.
- We do not use Google Play Billing to buy store products; purchases go through our own commerce system and Shopify.
4) Analytics, advertising and measurement
We use the following tools:
- Shopify analytics;
- Google Analytics and related Google services;
- Firebase in the App (Analytics, Crashlytics, Performance, Remote Config, App Check and Cloud Messaging);
- Meta (Facebook and Instagram) to measure and show our ads, as detailed below.
What we send to Meta and why
We advertise our products on Facebook and Instagram. To know which ad led a customer to an order, and to show our ads to people who are interested, our servers send Meta events about your use of the store:
- Events: purchases (order value and the products in it), and from the App also: viewing a product or product list, adding to cart, starting checkout, searching (with the words you searched for), adding to the wishlist, and creating an account.
- Hashed data: your phone number, email and customer number are converted into an irreversible hash (SHA-256) before they are sent; they are never sent as they are.
-
Device data: IP address, device type and operating system and its version, App version, App install identifier, and on the website Meta's cookies (
_fbpand_fbc). - Your device's advertising identifier (IDFA on iPhone, or the Google advertising ID on Android): sent only if you allow tracking; on iPhone when you choose "Allow" in the "Allow the app to track your activity" prompt, and on Android when the advertising ID is not deleted or limited in your device settings. With every event we also tell Meta whether you allowed tracking or not.
Purpose: measuring how our ads perform, and showing ads for our products to you or to people similar to our customers (including ads for products you viewed). Meta uses this data under the Meta Privacy Policy.
How to control this
- iPhone: Settings → Privacy & Security → Tracking, then turn off Eros. The advertising identifier is then not sent, and we tell Meta you did not allow tracking.
- Android: Settings → Google → Ads, then "Delete advertising ID". The identifier is then not sent.
- Meta ad settings: https://www.facebook.com/adpreferences
- Google ads: https://adssettings.google.com
- Digital Advertising Alliance: http://optout.aboutads.info/
- Google Analytics browser opt-out: https://tools.google.com/dlpage/gaoptout
Because industry standards on the "Do Not Track" signal differ, we may not change all collection practices automatically when a browser sends it.
5) Who we share information with
We share personal information only when needed to provide the service or to meet legal obligations, with:
- Shopify: running the store, catalogue, accounts and orders. Shopify policy: https://www.shopify.com/legal/privacy
- Payment gateways and shipping/delivery providers: processing payment and fulfilling and delivering orders.
- Google and Firebase: notifications, analytics, crashes, performance, remote configuration and App security, and the Gemini AI service (processing Venus chat messages and photos, section 3/g).
- Cloudflare: back-end services for the App and website and data storage (reviews, visual search, Venus chats, photos and memory, and security).
- Meta (Facebook and Instagram): measuring and showing our ads, as in section 4.
- Messaging providers (such as WhatsApp and SMS): phone verification, support and order notifications.
We may also share aggregated or de-identified information (that does not identify you) to improve products or with suppliers for operational purposes.
We may disclose information when required by law, or to protect our rights, user safety or prevent fraud.
We do not sell your personal information.
6) How we use information (summary)
- Showing products and running the cart and orders.
- Processing payment, shipping and after-sales service.
- Managing your account, notifications and support.
- Improving the App and website, security and abuse prevention.
- Personalising the experience and offers in line with your preferences and applicable law.
- Measuring and showing our ads (section 4).
- Meeting legal and accounting requirements.
7) Retention
We keep information as long as needed for the purposes above, or as long as required by law, accounting or dispute resolution, then delete or de-identify it.
Indicative examples (may vary):
- Order records: longer, for accounting and legal reasons.
- Review photos on a published product: while the review is published or until the content is removed.
- Notification tokens: while the device is subscribed or until you unsubscribe or delete your account.
- Visual-search photos: transient processing, not stored.
- Advertising device data linked to an order (such as the advertising identifier): deleted from our systems within 30 days; what reached Meta is kept by Meta under its policy.
- Venus chats, chat photos and memory: until you delete your account (section 3/g).
8) Your rights and choices
Depending on applicable law, these may include: accessing your information or requesting a copy; correcting inaccurate data; requesting deletion or restriction of processing; objecting to some kinds of marketing; withdrawing consent that was the basis for processing (without affecting what was done lawfully before).
Deleting your account (App): in the App: Account → Profile → Delete account. A request is submitted for review and deletion is expected within 3 business days, and you are signed out of the App. In some cases you can cancel the request before processing completes, as shown in the interface.
You can also email INFO@EROSSTORE.CO for privacy requests.
We may need to verify your identity before carrying out some requests, and may keep what the law requires even after deletion (such as order invoices).
9) Minors
Our services are not directed at anyone under 18, and we do not knowingly collect personal information from children. If you are a parent or guardian and believe a child has given us data, contact us to request deletion.
10) Security
We use reasonable technical and organisational measures to protect data in transit (such as HTTPS), in our systems and with our processors. No transmission or storage method on the internet is 100% secure, so absolute security cannot be guaranteed.
11) Links and third-party services
The website or App may link to third-party services (such as the payment gateway page). Their practices are governed by their own policies, and we are not responsible for them.
12) International transfers
Your data may be processed on servers outside Iraq (for example by Shopify, Google, Firebase, Cloudflare, Meta and payment providers), under reasonable safeguards and these providers' practices.
13) Changes to this policy
We may update this policy from time to time; the "Last updated" date appears at the top. Continuing to use the website or App after publication means you have seen the updated version. For material changes we may notify you through the website, the App or email where possible.
14) Quick summary for App users
- Card payment: on a secure payment gateway page; we do not store card numbers in the App.
- Camera and photos: for visual search, reviews, return requests, profile photo or Venus chats, and only with your permission.
- Notifications: optional; they use the device notification token.
- Venus assistant: your messages and photos are processed by Google Gemini and stored with your account until you delete it; she may message you proactively, and you can tell her «لا تراسليني» to stop that.
- Analytics and crashes: through Firebase and Google to improve the service.
- Advertising: we send Meta purchase and browsing events with hashed contact data; your device's advertising identifier is sent only if you allow tracking (section 4).
- Precise location: not requested.
- Account deletion: requested in the App, expected within 3 business days.




























