Privacy Policy

Effective date: August 24, 2025

This Privacy Policy explains how itsawah.com (operated by Awah Mohamed) collects, uses, discloses, and safeguards personal information when you visit or interact with our website, sign up to hear from us, or purchase our products/services.

If you have questions, contact [email protected].

 

1) Who we are (Controller)

 

For privacy law purposes, the data controller is Awah Mohamed (itsawah.com). You can reach us at [email protected].

 

2) What we collect

  • Identifiers and contact details: name, email address, and information you submit via forms.
  • Order and account data (if you purchase): items purchased, billing details (processed by our payment providers), support messages.
  • Internet / device data: IP address, user agent, pages viewed, referring URLs, and cookie/pixel identifiers.
  • Inferred preferences: topics you view or interact with (used to improve content and measure performance).

We collect data directly from you (forms, checkout, email replies) and automatically via cookies, pixels, and similar technologies.

 

3) How we use information

  • Provide the site and services (account, checkout, support).
  • Communicate (transactional emails; with your consent, marketing emails/SMS/WhatsApp).
  • Improve and secure the site (analytics, troubleshooting, abuse/fraud prevention).
  • Measure and advertise (analytics and ad platforms to understand performance and, where allowed, personalize ads).

 

4) Cookies, consent & controls (Complianz)

We use Complianz for consent management. In regions that require prior consent (e.g., EEA/UK), non-essential cookies/pixels are blocked until you consent in the banner.

You can change your choices anytime via Cookie Settings (from the banner or consent icon). We also honor Global Privacy Control (GPC) signals where legally required.

 

5) Analytics (Google Analytics 4)

We use Google Analytics 4 (GA4) to understand how visitors use the site. GA4 uses cookies and collects device and interaction data.

  • Consent regions: GA4 only runs after you opt-in through Complianz.
  • Other regions: GA4 may run by default; you can disable it in Cookie Settings or use tools provided by Google.

 

6) Advertising & Meta Conversions API

We use advertising and measurement tools (for example, Meta Ads, Google Ads, Microsoft Advertising, X Ads). We may send events to Meta via server-to-server using the Meta Conversions API (CAPI) to improve measurement and reduce fraud. This can include:

  • Hashed identifiers (e.g., hashed email if you provide it),
  • IP address and user agent,
  • Page views, sign-ups, and purchases,
  • A technical event_id used for deduplication with any browser pixel events.

Your choices: Manage advertising/analytics cookies in Cookie Settings, use a browser with GPC, or contact us at [email protected] to opt out of personalized advertising.

 

7) Email, SMS, and WhatsApp

With your consent, we send marketing communications. We may track email opens and clicks to gauge relevance. You can unsubscribe from any marketing email using the link provided. If you opt into SMS/WhatsApp, you can opt out at any time (e.g., reply STOP to SMS).

 

8) Payments

Payments are processed by our third-party payment providers. We do not store full payment card numbers on our servers. The provider’s privacy policy governs their processing.

 

9) Sharing of personal information

We do not sell your personal information for money. We share data with:

  • Service providers/Processors that host our site, process payments, send emails/messages, provide analytics/advertising, security/fraud prevention, and customer support—under confidentiality and data protection obligations.
  • Advertising/analytics partners as described above (including via server-to-server CAPI).
    We may disclose information to comply with law, enforce our terms, or protect rights and safety.

 

10) Affiliate links & redirects

Some links are affiliate links. Clicking them may place a cookie or share a non-sensitive identifier with the merchant to attribute referrals. The merchant’s site has its own privacy policy.

 

11) Data retention

  • Marketing contacts: until you unsubscribe or after 24 months of inactivity.
  • Transaction records: kept for 7 years where required for tax/accounting.
  • Server logs: up to 12 months for security and diagnostics.
    We may retain information longer if needed to comply with law or resolve disputes.

 

12) Security

We use administrative, technical, and organizational safeguards (e.g., TLS encryption, access controls). No method is 100% secure, but we monitor and improve protections. If a data breach poses a risk to you, we will notify you and regulators when legally required.

 

13) Children

Our services aren’t directed to children under 13 (or 16 in the EEA). If you believe a child provided us personal data, contact [email protected] and we will delete it.

 

14) International data transfers

We may transfer and store information outside your country. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) or rely on recognized transfer mechanisms. You can contact us to learn more.

 

15) Your privacy rights

Depending on your location, you may have rights over your personal data, including to access, correct, delete, restrict, object (including to profiling for direct marketing), and data portability. Where processing is based on consent, you can withdraw it at any time through Cookie Settings or by contacting us.

How to exercise your rights: email [email protected]. We may ask for information to verify your identity. We will respond within the time required by law.

 

16) California privacy notice (CPRA)

 

In the past 12 months we collected: identifiers (e.g., email, IP), commercial information (transactions), internet activity (pages, device, cookies), and inferences (preferences).

We do not sell personal information for money. We may “share” personal information (e.g., identifiers and internet activity) for cross-context behavioral advertising.

Opt-out: Use Cookie Settings to opt out of advertising cookies or enable a browser that sends GPC; we honor it. California residents may know, delete, and correct personal information and opt-out of selling/sharing. We will not discriminate for exercising rights. Submit requests at [email protected] (response within 45 days, extendable as permitted).

 

17) EEA/UK legal bases & supervisory authority rights

We process personal data on these legal bases:

  • Consent (e.g., analytics/advertising cookies, marketing communications),
  • Contract (to provide products/services you request),
  • Legitimate interests (e.g., site security, core analytics, measuring performance), balanced against your rights,
  • Legal obligations (e.g., tax, accounting, compliance).

EEA/UK residents may lodge a complaint with their local supervisory authority. We welcome the chance to address concerns first at [email protected].

 

18) Third-party sites

Our site may link to third-party websites. Their privacy policies govern their handling of your information.

 

19) Changes to this policy

We may update this policy from time to time. The “Effective date” above shows the latest version. Material changes will be highlighted on the site or via email where appropriate.

 

20) Contact

Questions or requests: [email protected]