212 Hive - Privacy Policy
Last updated: August 01, 2026
This Privacy Policy explains how 212 Hive handles personal information across its marketing site, merchant dashboard, public profiles, menus, checkout, subscriber tools, and loyalty programs.
It also explains when 212 Hive handles information for its own Platform purposes and when a merchant is responsible for information used in its customer relationship.
1. Who We Are and When This Policy Applies
212 Hive is a business platform operated from Morocco by Imad Atyat-Allah. It combines a merchant dashboard with public link-in-bio profiles, menus, checkout, and loyalty experiences.
- Operator
- Imad Atyat-Allah
- Brand
- 212 Hive
- Privacy contact
- [email protected]
- Country
- Morocco
This Policy applies when you visit our marketing site, create or use a merchant account, visit a 212 Hive-powered merchant page, place an order, subscribe to a merchant, or participate in a loyalty program.
It does not govern a merchant's independent activities outside 212 Hive. A merchant may provide an additional privacy notice for its own customer communications, delivery operations, marketing, exported records, or other business activities.
2. Our Role and the Merchant's Role
212 Hive determines why and how personal information is used for Platform accounts, authentication, security, service administration, Platform analytics, support, and our own communications. For those activities, 212 Hive is responsible for the processing.
A merchant determines why it collects and uses customer order details, subscriber information, loyalty activity, and other information for its store operations. For those business purposes, the merchant is normally responsible for the processing and 212 Hive hosts or processes the information to provide the Platform. In some situations, 212 Hive and the merchant may each have separate responsibilities for the same information.
For a request about a particular order, delivery, merchant subscription, or store relationship, contact the merchant first. You may also contact 212 Hive when the request concerns information stored or otherwise handled through the Platform.
3. Information We Collect
Merchant and staff accounts
- Name, email address, optional phone number and profile image, password credential or Google sign-in identifier, email and phone verification status, and last login method.
- Account status, user role, onboarding status, organization membership, invitations, order-notification preference, store ownership and transfer records, and administrator actions such as suspension or authorized support impersonation.
- Session and security information, including session token, IP address, user agent, expiry, active organization, and authentication or verification records.
- The date and version of Terms and Privacy Policy acceptance and the date of any marketing-email opt-in.
Store, profile, and catalog content
- Store and organization names, handles, logos, cover images, biography, social links, public profile links, link groups, QR identifiers, subscriber settings, and publication status.
- Appearance and SEO settings, Google Analytics identifier, map and music configuration, protected-link settings, and URLs submitted for media or metadata previews.
- Locations, business phone numbers, addresses, coordinates, opening hours, preparation times, pickup and delivery instructions, delivery zones, and fees.
- Categories, products, descriptions, prices, images, tags, modifiers, availability, visibility, location-specific availability, and uploaded media metadata.
- Loyalty program thresholds, reward type and label, collection and redemption settings, and publication status.
Information a merchant chooses to publish on a profile, menu, or loyalty page is public and may be viewed, copied, indexed, or shared by visitors and search engines.
Customers, carts, and orders
- Customer name and phone number, optional email address, last delivery address, order count, and amount spent with a particular merchant.
- Cart items, quantities, selected modifiers, cart status, and last activity.
- Order items and prices, subtotal, delivery fee, total, fulfillment type, merchant location, delivery address, precise delivery coordinates, optional notes, contact phone, status, cancellation reason and actor, and timestamps.
- Review rating, optional comment and images, publication status, and the related order, merchant, and customer identifiers if the review feature is used.
Loyalty customers and subscribers
- A Moroccan phone number submitted to access loyalty creates a limited customer account and session. We also process the related merchant, stamp balance, stamp events, available rewards, redemptions, and short-lived QR pass or manual code records.
- Email addresses submitted to a merchant subscription form, verification status, subscription status and dates, and time-limited verification codes and their use status.
Communications
- Messages and information you send when you contact us, request support, report a problem, or exercise a privacy right.
Usage, analytics, and technical data
- Visits and actions across the marketing site, dashboard, profile, menu, checkout, and loyalty surfaces, including store and content identifiers, store handles and names, page or surface, product and link details, QR activity, traffic source, referral and campaign parameters, and timestamps.
- Device type, browser, operating system, country or approximate location derived from technical data, IP address, user agent, cookie or similar identifier, network and request information, and application or security logs.
- Error and performance information needed to diagnose failures, protect the Platform, and understand feature reliability.
Payment data
212 Hive does not currently request or process card numbers, bank-account details, or online payments through checkout. A payment arranged directly with a merchant is governed by that merchant and the external payment method used.
4. Where Information Comes From
We receive information:
- Directly from you when you register, configure a store, upload content, subscribe, enter a phone number, place an order, use loyalty, or contact us.
- From a merchant or authorized staff member when they manage store content, orders, customer records, loyalty activity, organization staff, or invitations.
- Automatically from your browser, device, cookies, Platform activity, QR scans, server logs, and analytics tools.
- From Google when you use Google sign-in, subject to your Google settings and the permissions shown during sign-in.
- From public websites or supported third-party services when a merchant asks us to retrieve link, image, video, music, map, or other preview metadata.
5. Required and Optional Information
Merchant registration requires a name, email address, authentication method, and legal acceptance record. Information needed to create the store and organization is also required during onboarding. Optional fields are identified by the form or may be left blank.
Checkout requires a name, valid phone number, cart, and fulfillment details. An address and precise delivery coordinates are required for local delivery; a pickup location is required for pickup. Email and order notes are optional. Without required information, the Platform cannot submit or fulfill the order request.
A phone number is required to participate in loyalty. An email address is required to join a merchant subscriber list. You do not have to provide optional information, but some personalization or communication features may then be unavailable.
6. Why We Use Information
We use information to:
- Create and authenticate accounts, maintain sessions, verify contact details, support password resets, and manage organizations, staff, permissions, invitations, and store transfers.
- Provide and publish merchant profiles, menus, checkout, pickup and local-delivery tools, subscriber capture, QR codes, media, analytics, reviews, and loyalty programs.
- Validate carts, calculate prices and delivery fees, create orders, notify authorized merchant staff, track order status, and provide merchant customer records.
- Create loyalty membership records, issue and redeem stamps and rewards, and generate short-lived customer passes.
- Send verification, account, security, invitation, order, service, and support emails.
- Send 212 Hive marketing only where you have consented or another lawful basis applies, and allow you to object.
- Measure visits, traffic sources, clicks, products, QR activity, loyalty use, and service performance and provide aggregated or store-level analytics.
- Prevent spam, fraud, abuse, and unauthorized access; enforce our Terms; investigate errors; maintain security; and protect users and the public.
- Comply with legal obligations, respond to lawful requests, establish or defend legal claims, and manage our business.
7. Legal Grounds
Depending on the activity and applicable law, we process information with your informed consent; because it is necessary to perform a contract or take requested pre-contract steps; because it is necessary for a legal obligation; or for a legitimate interest that does not override your rights and freedoms, such as securing, administering, and improving the Platform and preventing fraud.
Examples of consent-based activity include an optional marketing opt-in, joining a merchant subscriber list, and permissions requested by your device or a third-party sign-in service. You may withdraw consent for future use, but withdrawal does not make earlier lawful processing invalid and may prevent us from providing the related optional feature.
Merchants are responsible for identifying and documenting a lawful basis for their own use of customer, subscriber, and loyalty information, including any marketing they send outside the Platform.
8. When We Share Information
We do not sell personal information.
We may disclose information to:
- The merchant and its authorized organization members when you order, subscribe, use loyalty, submit a review, or otherwise interact with that merchant. This can include contact, fulfillment, order, subscription, and loyalty information.
- Customers and the public when a merchant publishes store content, locations, products, delivery settings, social links, reviews, or loyalty information.
- Infrastructure and service providers that support hosting, databases, authentication, media storage and delivery, email, analytics, bot protection, rate limiting, maps, geocoding, monitoring, and technical operations.
- Google for Google sign-in and maps; Cloudflare for Turnstile and object storage; PostHog for product analytics; Geoapify for geocoding and map previews; Resend for email delivery; and Upstash for rate limiting, where those configured services receive the information needed to perform their function.
- Google Analytics when a merchant configures its own measurement identifier on a public profile. In that case, the merchant controls that Google Analytics configuration and is responsible for providing any required notice or choice.
- Supported third-party sites or services when a merchant asks us to retrieve or display a URL, video, map, music, image, or metadata preview.
- Professional advisers, insurers, auditors, or potential transaction parties subject to appropriate confidentiality duties when reasonably necessary for advice, financing, reorganization, or a sale of all or part of the business.
- Courts, regulators, law enforcement, public authorities, or other parties when required by law or reasonably necessary to protect legal rights, security, users, or the public.
Providers may change as the Platform evolves. Their processing is governed by their service terms, privacy terms, applicable agreements, and data-protection law.
9. Cookies and Analytics
212 Hive uses cookies, browser storage, and similar technologies. Necessary technologies maintain authentication sessions, protect forms and accounts, remember interface preferences, and keep a local shopping cart. Disabling them may prevent parts of the Platform from working.
A cookie banner lets you accept all optional cookies or manage them individually. Necessary cookies stay on. Analytics cookies (PostHog) and marketing cookies (Google Analytics, when a merchant has connected a measurement ID) stay off until you enable them. You can change that choice later from Cookie settings.
PostHog is used outside development environments to understand Platform usage and errors and to produce merchant analytics such as profile and menu views, link and product clicks, traffic sources, and device, browser, operating-system, and country breakdowns. A merchant can separately enable Google Analytics on its public profile.
Your browser and device may let you block or delete cookies and limit location or tracking permissions. Those controls do not remove records already stored in our databases. Optional analytics and marketing technologies are used only after you allow them in Cookie settings.
10. Location Information
For local delivery, the checkout asks the customer to select or share precise coordinates. We use those coordinates to compare the delivery point with active merchant locations and radius-based delivery zones, select an eligible location, and calculate the configured delivery fee. The order stores the coordinates and the address supplied by the customer.
If location permission is refused, local delivery cannot be quoted or placed through the current checkout, but an available pickup option may still be used. Store locations and map links configured by merchants may be processed through Google Maps and Geoapify to create maps, coordinates, labels, or previews.
11. Retention
We keep identifiable information only for the period reasonably necessary for the disclosed purpose, the merchant relationship, security, dispute resolution, and applicable legal, tax, accounting, or regulatory requirements. The period depends on the type of record and why it is held.
- Account, organization, store, catalog, media, and configuration records are generally kept while the account or store remains active and for a limited period afterward where needed for recovery, security, disputes, or legal compliance.
- Customer, order, fulfillment, loyalty, review, and merchant-subscriber records are generally kept while needed by the merchant to operate the relevant relationship and afterward for legitimate recordkeeping, disputes, fraud prevention, or legal obligations.
- Authentication sessions, verification links, email or subscriber codes, invitations, transfer links, and loyalty passes have functional expiry times, although limited logs or used-token records may remain for security and audit purposes.
- Analytics and security logs are retained according to the configured provider settings and for as long as reasonably needed to provide reporting, investigate incidents, and protect the Platform.
- Public merchant content remains visible until the merchant unpublishes it, the account or store is deactivated, or we remove it under our Terms or the law. Cached or indexed copies controlled by third parties may remain temporarily.
When information is no longer required, we take reasonable steps to delete, anonymize, or securely isolate it, subject to lawful backups and records that must be retained.
12. Your Privacy Rights
Subject to Law No. 09-08 and other applicable law, you may ask whether we process information about you, obtain access to it and available information about its origin, and request that inaccurate, incomplete, outdated, or unlawfully processed information be updated, corrected, erased, or blocked.
You may object to processing on legitimate grounds where the law permits, and you may object at any time to use of your information for direct marketing. You may also withdraw a consent for future processing. Other rights may apply based on your location.
To exercise a right, email [email protected] with enough information to identify you, the merchant or store involved if relevant, and the right you want to exercise. We may ask for proportionate proof of identity and clarification so that we do not disclose or change another person's information.
For merchant-controlled order, subscriber, or loyalty data, we may refer the request to the merchant or assist the merchant in responding. You may lodge a complaint with Morocco's Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP) if you believe your rights have not been respected.
13. International Processing
212 Hive is operated from Morocco, while some providers may process or store information in other countries. A foreign country may apply different privacy rules from Morocco.
International transfers are subject to Law No. 09-08 and any other applicable requirements, including CNDP formalities where required and an appropriate legal basis or contractual safeguard. You may contact us for more information about the providers used for a particular service.
14. Security
We use technical and organizational safeguards appropriate to the nature of the Platform, including access controls, authenticated sessions, email verification for merchant accounts, bot protection, rate limiting, scoped organization permissions, expiring passes and tokens, and security logging.
No internet service is completely secure. You are responsible for protecting your credentials and devices, restricting staff access, and securing any information you export, copy, or process outside 212 Hive. Notify us promptly at [email protected] if you suspect an account or data-security incident.
15. Children
212 Hive business accounts are intended for people with legal capacity to operate or represent a business. The Platform is not designed to knowingly collect personal information directly from children who cannot lawfully provide it or enter the relevant transaction without a parent or legal guardian.
Merchants are responsible for any age restrictions that apply to their products, content, customer relationships, or loyalty programs. If you believe a child provided personal information improperly, contact us and the relevant merchant so the situation can be reviewed.
16. Changes and Contact
We may update this Policy when the Platform, providers, legal requirements, or our practices change. We will update the date above and, for a material change, provide reasonable notice through the Platform, email, or another appropriate channel and request consent again where required.
Questions, rights requests, and privacy complaints may be sent to:
- Operator
- Imad Atyat-Allah
- Brand
- 212 Hive
- [email protected]
- Country
- Morocco