Loading Awshta
Getting your experience ready
Loading Awshta
Getting your experience ready
Legal
How Awshta collects, uses and protects your information across our website and mobile app
This policy explains what we collect when you use Awshta, why we collect it, who we share it with, and the choices you have. It describes what the platform does today — not what it might do later.
Awshta is a multi-vendor online marketplace that connects buyers with independent sellers. This Privacy Policy applies to our website at https://awshta.com and to the Awshta mobile app (together, the "Platform"), and describes how we handle personal information processed through them.
Where the website and the mobile app behave differently — most notably in the analytics they use and the payment methods they offer — this policy says so rather than describing them as one product.
By creating an account, placing an order, or otherwise using the Platform, you acknowledge that you have read and understood this Policy. If you do not agree with it, please do not use the Platform.
We collect the following categories of information, and only the specific fields described below.
Reviews and product questions are public. They are published on the product page together with the name and profile photo on your account. Chat messages and contact-form messages are not public.
If you apply to sell on Awshta we collect additional information, including identity documents and bank details. This is described in the Seller Information section below.
Some information is kept in your browser's local storage (or, in the mobile app, in the app's own storage on your device) and is not sent to our servers unless you act on it:
When the Platform communicates with our servers, standard connection information — such as your IP address, the request your device makes and the time it was made — is processed to deliver the service, apply rate limits and keep the Platform secure. While you are signed in, the Platform also keeps a live connection open to our servers so that chat and notifications arrive in real time. Our analytics providers also receive usage information, described in the Analytics section.
We use the information we collect to:
As a buyer, the information you provide — your account details, saved addresses, order contents and the contact phone number for each order — is used to process and deliver your purchases.
Because Awshta is a multi-vendor marketplace, a basket containing items from more than one seller is split into a separate order per seller. Each seller receives only what they need to fulfil their own parcel, including your name, delivery address and the contact phone number for that order. Sellers can also see the name, email address, phone number and profile photo of customers who have ordered from them, so they can provide support on those orders.
Placing a guest order creates an Awshta account for the email address you give, and we email you a temporary password. If that email address already belongs to an account, the order is linked to it and you are signed in to that account — and we email the account holder to tell them it happened. Please use your own email address at checkout.
When you request to become a seller you submit a store name and a description. Once approved, you can add further details through the seller dashboard. Some of it is published on your storefront; some of it is used only to verify you and to pay you.
As a seller, you can see information about customers who have ordered from you — their name, email address, phone number, profile photo and the delivery details for their order. You must handle that information responsibly, use it only for fulfilling and supporting those orders, and not disclose it to anyone else.
Cash on Delivery is the only payment method a buyer can currently select on the Awshta website. You pay the courier in cash when your parcel arrives, and no payment credentials are collected or stored by us.
JazzCash and EasyPaisa are shown at checkout as coming soon and cannot be selected. Our systems are integrated with both providers but the channels are switched off, so no payment data is sent to them today. If we enable them we will update this Policy first, and the wallet PIN would in any case be entered only inside the provider's own app — never on Awshta.
We record each payment attempt so that orders can be reconciled and disputes investigated. Provider request and response payloads are redacted before they are stored and are never returned by our API.
Deliveries are carried out by Leopards Courier Service. To quote and then book your delivery, we send the courier the information needed to move the parcel: the pickup and delivery cities, your name, delivery address and contact phone number, the parcel's weight and dimensions, and — for a Cash on Delivery order — the amount to collect from you.
The courier sends us status updates as your parcel moves, which we store against your order and show you. Leopards processes this information under its own privacy practices, and we recommend reviewing them if you would like to know more.
Anyone holding an Awshta order number can look up that order's delivery status on our order tracking page without signing in. That lookup deliberately returns no personal details — no name, phone number, address, email address or item list.
When you are signed in, the Platform keeps a live connection to our servers so your notification feed and your chat messages update in real time. Notifications are created for events such as an order being placed, an order or payment status changing, a new review, a product question being asked or answered, and seller-application decisions. You can read, mark as read and delete them from your account.
We can send the same notifications as push notifications to your browser or phone, delivered through Google's Firebase Cloud Messaging service. On the website they are off until you turn them on in your account settings and your browser asks for permission. In the Android app, we ask for notification permission after you sign in. A notification contains a short title and message about the event, plus a reference to the order, product or page it relates to.
You can turn push notifications off at any time in your browser's site settings or your phone's app notification settings. Signing out also removes your device's push token from your account.
We use analytics to understand which parts of Awshta people use, so we can fix what is not working and improve what is. Both of the tools we use are provided by Google.
The website loads Google Analytics 4 on every page. It records the pages you visit, approximate location derived from your IP address, and general device and browser information, and it sets first-party cookies to recognise a returning browser. This runs from the moment a page loads; we do not currently offer an on-site control to switch it off, so if you would rather not be measured, use your browser's cookie or tracking controls.
The Awshta mobile app uses Firebase Analytics, also from Google. It records the screens you open and a fixed set of shopping events — signing in, registering, searching (including the search term), viewing a product or a product list, adding to or removing from the cart or wishlist, starting checkout, completing a purchase, sharing a product, submitting a review, asking a question, and the equivalent actions in the seller tools. When you are signed in, your Awshta account identifier is attached to those events so that a single person's journey can be followed across screens.
We use this information to measure and improve the Platform. We do not sell it, we do not use it to serve advertising, and we do not combine it with data from other companies to profile you. Google processes it as our analytics provider under its own terms, and its handling of the data is governed by Google's privacy policy.
We rely on a limited number of third parties to run the Platform:
Each of these receives only the information it needs to perform its function. Sellers may also link from their storefronts to their own social media pages; those sites are operated by others and governed by their own privacy policies.
We do not sell your personal information. We share it only in the following circumstances:
We take reasonable technical and organisational measures to protect your information. Traffic between the Platform and our servers travels over encrypted HTTPS connections; passwords are stored only as salted hashes; access to your account is controlled by short-lived tokens that are refreshed automatically and revoked when you sign out; uploads are validated before they are written to disk; and sensitive request and response data from payment providers is redacted before it is stored.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. You are responsible for keeping your password confidential and for activity that occurs under your account. Tell us promptly if you believe your account has been accessed by someone else.
We retain your personal information for as long as your account is active and for as long as we need it to run the marketplace, complete your orders, resolve disputes, settle sellers, enforce our agreements and meet our legal obligations. Order, delivery and financial records are kept even after an account is closed, because they are the record of transactions that actually happened and may be required for tax, accounting and dispute purposes.
Each order stores a snapshot of the products it contained, so your order history stays accurate even if a seller later edits or removes the listing.
Information kept only on your device — your cart, wishlist, checkout draft and stored delivery city — is removed when you clear it, sign out, clear your browser's site data, or uninstall the app.
A push-notification token is deleted from your account when you sign out on that browser or device.
You can do the following yourself, while signed in:
If you signed in with Google, you can also remove Awshta's access from your Google Account's security settings. This stops future Google sign-ins but does not delete your Awshta account or its order history.
To stop receiving marketing email, use the unsubscribe option in the email or ask us using the contact details below. An opt-out is applied across all of our marketing lists. Service messages about your account and your orders are not marketing and will continue.
To close your account, contact us using the details below. Closing an account deactivates it, revokes every active session and prevents further sign-in; order and financial records associated with it are retained as described in Data Retention.
Depending on where you live, you may also have rights to access, correct, delete or export your personal information, or to object to or restrict certain processing. Contact us and we will respond in accordance with applicable law.
Awshta is not directed to children. The Platform is intended for users who are at least 18 years old, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it.
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date shown at the top of this document. Where a change materially affects how we handle your information — for example if we introduce a new payment provider or a new analytics tool — we will make that clear on the Platform. Your continued use of Awshta after an update takes effect means you accept the revised Policy.
If you have questions about this Privacy Policy, want to exercise a right described above, or would like your account closed, you can reach us at:
Privacy enquiriesprivacy@awshta.comGeneral supportsupport@awshta.comPhone+92 300 0131373Please read this document carefully. By continuing to use Awshta you acknowledge that you have read and understood it.
Back to top