Mahaleh Privacy Policy

Effective date: July 10, 2026

Mahaleh (محله) — also described as Iranian Business Hub Canada — is a Canadian directory, community, and marketplace platform available on iOS, Android, and the web at mahaleh.ca ("Mahaleh", "we", "us"). This policy explains, in plain language, what personal information we collect, why we collect it, who we share it with, how long we keep it, and the rights you have over it.

We are subject to Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and, for Quebec residents, Quebec's Act respecting the protection of personal information in the private sector as amended by Law 25.

Contact / Privacy Officer: The person in charge of the protection of personal information at Mahaleh is the platform owner. <!-- Law 25 s.3.1: publish the title and contact information of the person in charge. Insert the owner's legal name or title here before publication. --> Reach them at ircanbusinesshub.support@gmail.com (subject line "Privacy").

---

1. The short version

2. Information we collect

2.1 Information you provide

CategoryDetailsWhere it lives
AccountEmail address and password (password is handled by Firebase Authentication; we never see or store your plaintext password). Guests may browse with an anonymous session that has a random identifier and no email.Firebase Authentication
ProfileDisplay name, profile photo, city and province, languages you speak, preferred app language (EN/FR/FA), your selected metro area (e.g. Greater Toronto, Montréal, Vancouver), account role (user / business / admin), saved/followed businesses.Firestore users/{uid}
Public content (UGC)Reviews and ratings, community feed posts and comments, likes, marketplace listings (title, description, price, condition, city, photos), business listings you create or claim (name, address, phone, email, website, hours, photos), events you organize. This content is public and is shown with your display name.Firestore reviews, posts, marketplaceItems, businesses, events
MessagesChat conversations with businesses and marketplace sellers, including message text and photo attachments. Messages are visible only to conversation participants in the app, but they are stored on our servers in readable form (not end-to-end encrypted) so we can deliver them across your devices, send notifications, investigate abuse reports, and comply with legal obligations.Firestore conversations
Orders & ticketsItems ordered from a business, quantities, prices, order status; event tickets you claim (event, quantity, QR code payload). We do not currently process payments and do not collect card numbers (see §5 on future payments).Firestore orders, tickets
Reports & blocksContent you report (what you reported and why) and your private list of blocked users.Firestore reports, users/{uid}/blockedUsers
Waitlist / contactIf you join the pre-launch waitlist on mahaleh.ca: your email, city, whether you're a user or business, and language.Firestore waitlist

2.2 Information collected automatically

CategoryDetails
Approximate locationWe use the city/metro you select in the app to show relevant local listings. We do not currently collect precise GPS location from your device. If a future feature requires device location, we will ask for the platform location permission first and update this policy.
Push notification tokensA Firebase Cloud Messaging (FCM) device token per device, so we can deliver notifications (new messages, review replies, order updates). Stored under your account and deleted when it expires or fails delivery.
AnalyticsUsage events via Google Analytics for Firebase (screens viewed, feature interactions), coarse device information (device model, OS version, app version, language), and Google-generated app-instance identifiers. Analytics data may include IP-derived coarse location (city-level), processed by Google.
Crash & diagnosticsCrash reports via Firebase Crashlytics (stack traces, device state at crash, device model/OS, app version) to fix bugs.
Listing metricsAnonymous engagement counters on business listings (views, calls, direction taps, chats, shares). These are aggregate counters per listing — they do not record who viewed.

2.3 What we do NOT collect

3. Why we collect it (purposes)

We collect and use personal information only for these purposes:

  1. Provide the service — create and operate your account, display your public content, deliver messages, process orders and tickets, sync across your devices.
  2. Localize the experience — show listings for your metro and app content in your language.
  3. Notify you — push notifications and in-app notifications about activity that concerns you (new messages, replies to your reviews, order status). You can turn push notifications off in your device settings at any time.
  4. Keep the community safe — moderate reported content, enforce our Terms of Service, prevent fraud, spam, and abuse.
  5. Improve the app — aggregate analytics and crash reports to understand what works and fix what breaks.
  6. Comply with the law — respond to lawful requests, keep records we're required to keep, and (once payments launch) meet tax-reporting obligations for digital platforms.

We do not use your personal information for any purpose incompatible with these without asking you first.

4. Consent and legal basis

Under PIPEDA and Quebec law, we rely on your consent, given when you create an account or use a feature, and manifestly implied for purposes that are obvious and necessary to the feature you're using (e.g. we need your message text to deliver your message). For purposes that are not necessary to run the service, we ask separately:

5. Who we share it with

We do not sell or rent personal information. We share it only as follows:

6. International transfer (storage outside Canada)

Our infrastructure is provided by Google Firebase, with data stored primarily on servers in the United States. This means your personal information may be accessed by authorities in that jurisdiction under its laws. We use contractual safeguards (Google's data-processing terms and security commitments) to ensure a comparable level of protection.

Quebec residents: as required by Law 25, we have assessed the privacy impacts of communicating personal information outside Quebec and concluded, taking into account contractual and technical safeguards, that the information receives adequate protection. <!-- Owner: keep a written copy of this transfer assessment (PIA) on file — Law 25 s.17 requires it to exist, not to be published. -->

7. Retention — how long we keep it

DataRetention
Account & profileFor as long as your account exists, then deleted or anonymized on account deletion (see §8).
Public content (reviews, posts, listings)Until you delete it or your account is deleted. Note that content removed for moderation reasons may be retained in an internal archive as evidence for a limited period.
Chat messagesFor as long as the conversation exists; deleted when the account of a participant is deleted, subject to the other participant's copy of the thread context.
Orders & ticketsKept for the period required for accounting, tax, and dispute-resolution obligations (generally up to 7 years for transaction records once payments launch), then deleted or anonymized.
Push tokensDeleted automatically when invalid/expired, and on account deletion.
Analytics & crash dataRetained per Firebase defaults (Analytics user-level data: up to 14 months; Crashlytics: 90 days) and in aggregate thereafter.
Reports (moderation)Kept while relevant to enforcement, then archived or deleted.
WaitlistUntil launch communications conclude or you unsubscribe.

8. Deleting your account and your data

You can request deletion of your account and associated personal information at any time:

  1. In the app: Profile → Delete account → confirm your password → Delete forever. Your account and data are removed immediately. <!-- Shipped 2026-07-13 (Profile row → confirmation sheet → deleteAccount Cloud Function). This bullet is accurate as written. -->
  2. By email: send a request to ircanbusinesshub.support@gmail.com from the email on your account, or use the deletion request page at mahaleh.ca/delete-account. <!-- Page written (firebase/hosting/landing/delete-account.html); goes live with the Hosting deploy — required before Play submission (Data safety form needs a public deletion-request URL). -->

When your account is deleted we permanently delete your profile, your reviews, community posts and comments, marketplace listings, event tickets, and your registered device tokens. Chat messages you sent remain visible to the person you were talking to — that conversation is equally their record — but they are no longer linked to an identifiable account. We may retain limited records where the law requires it (e.g. moderation-enforcement evidence) or to resolve disputes.

9. Your rights

Under PIPEDA (all of Canada) you may:

Quebec residents additionally have, under Law 25:

To exercise any right, contact ircanbusinesshub.support@gmail.com. We respond within 30 days. If you are not satisfied, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, in Quebec, the Commission d'accès à l'information du Québec (cai.gouv.qc.ca).

10. Security

We protect personal information with safeguards appropriate to its sensitivity: encryption in transit (TLS) and at rest on Google's infrastructure, per-user database security rules that limit who can read and write each record, role-based admin access, and server-only writes for sensitive fields. No system is perfectly secure — in particular, remember that chat messages are not end-to-end encrypted (§2.1) and anything you post publicly is, by definition, public.

Breach notification: if a breach of security safeguards creates a real risk of significant harm (PIPEDA) or a risk of serious injury (Law 25), we will notify affected individuals and the Office of the Privacy Commissioner of Canada and, where Quebec residents are affected, the Commission d'accès à l'information, and we maintain an internal register of confidentiality incidents as Law 25 requires.

11. Children

Mahaleh is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, contact ircanbusinesshub.support@gmail.com and we will delete it. Users must meet the age requirements in our Terms of Service to buy or sell.

12. Cookies and similar technologies (web)

The web app at mahaleh.ca uses local storage and Firebase SDK identifiers strictly to keep you signed in, remember your language/metro, and provide the analytics and crash reporting described above. We do not use third-party advertising cookies.

13. Changes to this policy

We may update this policy as Mahaleh evolves (for example, when payments launch). We will post the updated policy at mahaleh.ca/privacy with a new effective date and, for material changes, notify you in the app or by email before they take effect.

14. Contact

Mahaleh — Privacy Officer Email: ircanbusinesshub.support@gmail.com (subject "Privacy") Web: mahaleh.ca requirements expect a real point of contact. A registered business address or PO box is fine. -->