Terms of Service & Data Processing Agreement
Rahwan Shipping — last updated 14 July 2026.
These terms apply between Rahwan (“we”, the carrier) and the Shopify merchant who installs this app (“you”). By installing the app you accept them.
Part 1 — Terms of Service
1. What the service is
Rahwan is a last-mile delivery carrier in Egypt. This app offers Rahwan shipping at your checkout and sends orders placed with it to Rahwan for physical delivery. You must have a Rahwan vendor account and a valid API key to use it.
2. Shipping rates
Rahwan sets the delivery fee. The rate shown at your checkout is the rate we bill you, so the two cannot diverge. Where your Shopify plan does not support carrier-calculated rates, you add the rate manually and the app tells you the exact amount to use.
3. Your responsibilities
- Provide accurate delivery details. A parcel cannot be delivered to an address that does not exist.
- Keep your Rahwan API key secret. Anyone holding it can create orders on your account. Tell us at once if it is exposed and we will reissue it.
- Do not ship prohibited or illegal goods.
4. Availability
We aim to keep the service available but do not guarantee uninterrupted operation. If our systems are unreachable when a customer is checking out, the app serves the last known shipping rate rather than removing the shipping option — your checkout keeps working.
5. Ending the agreement
You may uninstall the app at any time. On uninstall we deactivate your shop and delete the stored API key. Orders already sent to Rahwan are still delivered. Forty-eight hours after uninstall, Shopify instructs us to erase the shop record and we do.
Part 2 — Data Processing Agreement
6. Roles
For your customers’ personal data, you are the controller and Rahwan is the processor. We process that data only to deliver the orders you send us, and only on your instructions.
Where Rahwan uses that data for its own delivery operations (dispatching couriers, collecting cash on delivery, keeping accounting records), Rahwan acts as a controller for those purposes, as a carrier necessarily must.
7. What we process
| Data | Why it is necessary |
|---|---|
| Customer name | To hand the parcel to the correct person. |
| Phone number | The courier calls on arrival; a delivery OTP confirms handover. |
| Delivery address | Where the courier drives. Without it the order cannot be fulfilled. |
| Order contents and value | To handle the parcel and, for cash on delivery, collect the right amount. |
We request nothing else. We do not receive payment card details. We do not use customer data for marketing, advertising, profiling, or automated decision-making, and we do not sell it. Ever.
8. Security measures
These are implemented, not aspirations:
- Encryption at rest. Every customer personal-data field — name, phone, email, address and coordinates — is encrypted with AES-256 in our database. A stolen disk image or a leaked database dump reveals nothing about any customer.
- Encryption in transit. TLS 1.2/1.3 on every endpoint.
- Encrypted backups. Database backups are encrypted with AES-256 before they leave our servers, so our storage provider holds ciphertext it cannot read. Restores are tested.
- Access logging. Every read of customer personal data is recorded — who, what, when, and from where. We can tell you exactly who viewed a given customer’s details.
- Restricted staff access. Access is role-based: a courier sees only the orders assigned to them.
- Staff passwords. Minimum 12 characters with complexity, checked against known breach corpora.
- Data minimisation in the app. The Shopify app itself stores no customer personal data at all — it forwards the order and retains only an order reference and a delivery status. This is enforced by the data model, not by policy.
9. Retention
Customer personal data is automatically destroyed 180 days after an order is completed, cancelled or failed. The order’s financial record is retained for accounting, but the name, phone number and address are erased. This runs on a schedule; it is not a manual promise.
10. Sub-processors
| Provider | Purpose | Data they can read |
|---|---|---|
| DigitalOcean (Frankfurt, EU) | Hosting | None in plaintext — all personal-data fields are encrypted by us before storage. |
| Backblaze B2 (US) | Off-site encrypted backups | None — backups are encrypted with a key Backblaze never holds. |
We will tell you before adding a sub-processor that can access customer personal data.
11. Your customers’ rights
We assist you in responding to requests from your customers. Shopify’s customers/data_request and customers/redact webhooks are implemented. Because the app stores no personal data, a data request against it returns nothing and a redaction request is satisfied immediately. For data held in Rahwan’s delivery system, contact us and we will act without undue delay.
12. Breach notification
If we become aware of a breach affecting your customers’ personal data, we will notify you and Shopify without undue delay, and tell you what was exposed and to whom. Our access log is what lets us answer that question precisely rather than vaguely.
13. Deletion
On uninstall we delete your stored API key and deactivate the shop. Forty-eight hours later, on Shopify’s shop/redact instruction, the shop record is erased. Customer data in the delivery system is erased on the retention schedule in §9, or sooner on request.
Contact
Rahwan — admin@giantrexcorp.com
Privacy policy: rahwan.co privacy policy