Privacy Policy
Last updated: 6 October 2026
1. Who we are
SoukiX is a cash-on-delivery (COD) e-commerce platform operated by MR BOOST Agency (contact: agency.mrboost@gmail.com). This policy explains how we and the platform process data, including data accessed through the optional Google integration.
2. Data we collect from you
When you create an account and use SoukiX, we process:
- Account data — your name, email address and a password hash (never stored in plain text).
- Business data — the stores you create, their settings, branding and products.
- Order data — customer orders placed on your storefronts, including name, phone, address, wilaya/commune, items, prices, status and attribution data (e.g. UTM, click IDs) when present.
- Shipping reference data — the Algerian wilaya, commune and tariff dataset used to calculate delivery prices (non-personal, public reference data).
- Usage logs — audit entries of actions performed in the platform, including IP address and user agent where logged.
3. Why we use your data
- To operate and secure your account and stores.
- To display storefronts, process COD orders and calculate shipping.
- To provide the dashboard, analytics, backups and restore features.
- To enforce permissions and access controls.
4. The Google integration
You can optionally connect a Google account to export your orders to Google Sheets. This is an opt-in feature — it is never enabled without your explicit action.
4.1 Google data we access
- Your Google account email address — used to identify the connected account.
- Google Sheets — we list spreadsheets you choose, read/write rows in the spreadsheet you select, and append or update order rows you configure.
- Google Drive metadata (read-only) — used only to list spreadsheet names/IDs so you can pick one; we do not read the file content of non-spreadsheet documents.
4.2 How OAuth tokens are stored
- Your Google access and refresh tokens are stored server-side only in our secure database.
- Tokens are never exposed to browsers, frontend code, logs or other users.
- Access tokens are refreshed automatically with the refresh token when needed and are stored encrypted-side in transit (TLS).
4.3 How the data is used
Google data is used solely to provide the sheet-export feature you configure: writing the rows/mappings you choose into the spreadsheet you authorize, and updating order notes back to the same sheet when you use that functionality.
4.4 How to disconnect
You can disconnect the Google integration at any time from the store's Google Sheets settings page. Disconnecting deletes the stored tokens for that store. You can also revoke access directly in your Google account's security settings, which will cause exports to stop.
4.5 Sharing with third parties
Google data is not shared with third parties and is not sold. It is only transmitted to Google as part of the OAuth flow and the Sheets/Drive API calls you trigger. MR BOOST Agency employees access connected-account data only for support and only as needed.
5. Retention
Account and business data are kept while your account is active. When a store is deleted, its dependent records are removed (orders, products, media references, integrations, shipping rules). Backups may retain historical data for recovery purposes and older backups are rotated automatically. You may request account deletion by contacting us.
6. Security
We use HTTPS everywhere, server-side authentication with hashed passwords, signed session cookies, per-store permission enforcement and Cloudflare's managed security. No designed system is 100% secure, but we follow industry-standard protections.
7. Your rights
Subject to applicable law you may request access to, correction of, or deletion of your personal data, and you may withdraw the Google integration consent at any time (section 4.4). Contact: agency.mrboost@gmail.com.
8. Changes to this policy
We may update this policy from time to time; the “Last updated” date above reflects the latest revision.