Nafis Saffron

Privacy

What we keep, and why

This page is not written to be skipped. Everything here is what we actually do — if any of it reads as vague, ask us and we will make it clearer.

Last rewritten: August 2026

The short version

  • We do not sell, rent, or share your details with advertising networks.
  • We ask for the minimum we need to get an order to your door.
  • Your card number never reaches our servers — payment happens inside the bank's gateway.
  • Ask us to delete your account and we delete it. No retention team, no exit survey.

What we hold

Signing in needs a phone number and nothing else. There is no password; a six-digit code is texted to you each time and does the same job.

  • Your mobile number — to sign you in and tell you where your order is.
  • Your name and address — because the courier has to know where the parcel goes and who to hand it to.
  • Your email, if you choose to add one — used for receipts and dispatch notices only.
  • Your order history — so you can look it up and we can support it.
  • Aggregate site traffic — which pages work and which do not.

We do not ask for anything beyond that list: no national ID, no date of birth, no occupation or income. If a form ever asks you for those, it is not ours.

Why we need it

Every item above has one job and is used for that job: take the order, ship it, and find it again if something goes wrong.

Marketing messages go out only if you ticked the newsletter box yourself. Unsubscribing is one click, and it sticks.

Who else sees it

For an order to arrive, a few people outside Nafis have to see a small part of it — and only that part:

  • The courier: name, address and phone. Nothing gets delivered without them.
  • The payment gateway: the amount and the order reference. Card details stay with the bank and are never visible to us.
  • The SMS provider: your mobile number, to send the sign-in code.
  • A legal authority: only where the law requires it, and only what was asked for.

Beyond that list, your details go nowhere. We do not sell them, rent them, or hand them to “advertising partners”.

How long we keep it

A sign-in code expires minutes after it is sent and is then discarded.

Orders stay as long as your account is open, because you may want to look them up too. Financial records of a sale are kept for as long as Iranian tax and commercial law requires — that part is not ours to shorten.

When an account is deleted, the personal details go with it and what remains is an unnamed financial record.

Cookies

Our cookies do three things: hold your basket, remember that you are signed in, and report anonymously which pages get read.

There are no third-party advertising cookies on this site. Clear the cookies in your browser whenever you like — the only thing you lose is the current basket and session.

What you can ask for

  • A copy of what we hold about you.
  • A correction to anything recorded wrongly.
  • Deletion of your account and everything attached to it.
  • Removal from the newsletter, with nothing about your orders changing.

Message us from the number you registered with and any of these is done. Usually the same day; a week at the very worst.

How we look after it

The whole site runs over encrypted HTTPS, database access is limited to the few people whose work needs it, and card details never reach us in the first place — there is nothing there to steal.

No system is perfectly secure and we will not pretend otherwise. If something happens that puts your details at risk, you will hear it from us rather than from somewhere else.

If this page changes

The date at the top updates every time we change something here. If a change actually affects your data, we will tell you before it takes effect.

Still have a question?

Anything about your data that this page did not answer, ask. There is a real person behind these.