Mahaleh Privacy Policy
Effective date: July 10, 2026
Mahaleh (محله) — also described as Iranian Business Hub Canada — is a Canadian directory, community, and marketplace platform available on iOS, Android, and the web at mahaleh.ca ("Mahaleh", "we", "us"). This policy explains, in plain language, what personal information we collect, why we collect it, who we share it with, how long we keep it, and the rights you have over it.
We are subject to Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and, for Quebec residents, Quebec's Act respecting the protection of personal information in the private sector as amended by Law 25.
Contact / Privacy Officer: The person in charge of the protection of personal information at Mahaleh is the platform owner. <!-- Law 25 s.3.1: publish the title and contact information of the person in charge. Insert the owner's legal name or title here before publication. --> Reach them at ircanbusinesshub.support@gmail.com (subject line "Privacy").
---
1. The short version
- We collect what you give us (account, profile, reviews, posts, listings, messages, orders) plus limited technical data (device push tokens, analytics, crash reports) needed to run the app.
- We do not sell your personal information. Ever.
- Content you post publicly (reviews, posts, marketplace listings, business info) is visible to other users — that is the point of the platform.
- Chat messages are private between participants but are NOT end-to-end encrypted. They are stored on our servers and can be accessed by us where necessary for safety, moderation, or legal compliance.
- Our servers are operated by Google (Firebase) and are located primarily in the United States.
- You can ask us to access, correct, or delete your information at any time: ircanbusinesshub.support@gmail.com.
2. Information we collect
2.1 Information you provide
| Category | Details | Where it lives |
|---|---|---|
| Account | Email address and password (password is handled by Firebase Authentication; we never see or store your plaintext password). Guests may browse with an anonymous session that has a random identifier and no email. | Firebase Authentication |
| Profile | Display name, profile photo, city and province, languages you speak, preferred app language (EN/FR/FA), your selected metro area (e.g. Greater Toronto, Montréal, Vancouver), account role (user / business / admin), saved/followed businesses. | Firestore users/{uid} |
| Public content (UGC) | Reviews and ratings, community feed posts and comments, likes, marketplace listings (title, description, price, condition, city, photos), business listings you create or claim (name, address, phone, email, website, hours, photos), events you organize. This content is public and is shown with your display name. | Firestore reviews, posts, marketplaceItems, businesses, events |
| Messages | Chat conversations with businesses and marketplace sellers, including message text and photo attachments. Messages are visible only to conversation participants in the app, but they are stored on our servers in readable form (not end-to-end encrypted) so we can deliver them across your devices, send notifications, investigate abuse reports, and comply with legal obligations. | Firestore conversations |
| Orders & tickets | Items ordered from a business, quantities, prices, order status; event tickets you claim (event, quantity, QR code payload). We do not currently process payments and do not collect card numbers (see §5 on future payments). | Firestore orders, tickets |
| Reports & blocks | Content you report (what you reported and why) and your private list of blocked users. | Firestore reports, users/{uid}/blockedUsers |
| Waitlist / contact | If you join the pre-launch waitlist on mahaleh.ca: your email, city, whether you're a user or business, and language. | Firestore waitlist |
2.2 Information collected automatically
| Category | Details |
|---|---|
| Approximate location | We use the city/metro you select in the app to show relevant local listings. We do not currently collect precise GPS location from your device. If a future feature requires device location, we will ask for the platform location permission first and update this policy. |
| Push notification tokens | A Firebase Cloud Messaging (FCM) device token per device, so we can deliver notifications (new messages, review replies, order updates). Stored under your account and deleted when it expires or fails delivery. |
| Analytics | Usage events via Google Analytics for Firebase (screens viewed, feature interactions), coarse device information (device model, OS version, app version, language), and Google-generated app-instance identifiers. Analytics data may include IP-derived coarse location (city-level), processed by Google. |
| Crash & diagnostics | Crash reports via Firebase Crashlytics (stack traces, device state at crash, device model/OS, app version) to fix bugs. |
| Listing metrics | Anonymous engagement counters on business listings (views, calls, direction taps, chats, shares). These are aggregate counters per listing — they do not record who viewed. |
2.3 What we do NOT collect
- Precise GPS location.
- Contacts, photos library scans, microphone, or camera access beyond photos you deliberately attach.
- Payment card numbers (payments, when launched, will be handled by Stripe — see §5).
- Advertising identifiers for cross-app tracking. We do not run third-party ad networks.
3. Why we collect it (purposes)
We collect and use personal information only for these purposes:
- Provide the service — create and operate your account, display your public content, deliver messages, process orders and tickets, sync across your devices.
- Localize the experience — show listings for your metro and app content in your language.
- Notify you — push notifications and in-app notifications about activity that concerns you (new messages, replies to your reviews, order status). You can turn push notifications off in your device settings at any time.
- Keep the community safe — moderate reported content, enforce our Terms of Service, prevent fraud, spam, and abuse.
- Improve the app — aggregate analytics and crash reports to understand what works and fix what breaks.
- Comply with the law — respond to lawful requests, keep records we're required to keep, and (once payments launch) meet tax-reporting obligations for digital platforms.
We do not use your personal information for any purpose incompatible with these without asking you first.
4. Consent and legal basis
Under PIPEDA and Quebec law, we rely on your consent, given when you create an account or use a feature, and manifestly implied for purposes that are obvious and necessary to the feature you're using (e.g. we need your message text to deliver your message). For purposes that are not necessary to run the service, we ask separately:
- Marketing email (CASL): We will only send you commercial electronic messages (newsletters, promotions) with your express consent, and every such message will identify us and include a working unsubscribe that we honour within 10 business days, as required by Canada's Anti-Spam Legislation (CASL). Joining the waitlist is consent to be contacted about the launch of Mahaleh; you can unsubscribe at any time. Transactional messages (order confirmations, security notices) are not marketing and are sent as part of the service.
- Withdrawing consent: You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice, by adjusting settings, deleting content, or contacting ircanbusinesshub.support@gmail.com. Withdrawing consent for information necessary to the service may mean we can't provide the service.
5. Who we share it with
We do not sell or rent personal information. We share it only as follows:
- Other users (by design). Your public content (§2.1) is visible to anyone using Mahaleh, including guests and, for approved business listings, visitors to the web app. Your display name and photo accompany your public content. Chat messages are shared with the other participant(s) in the conversation.
- Service providers (processors). - Google LLC (Firebase / Google Cloud): hosting, database (Cloud Firestore), file storage, authentication, push notifications, analytics, and crash reporting. Google processes this data on our behalf under the Google Cloud / Firebase data processing terms. - Stripe (future): when in-app payments launch, payment processing and seller payout onboarding will be handled by Stripe, Inc. Stripe will collect payment details directly (we never see full card numbers) and, for sellers, identity-verification information required by financial regulations. Stripe acts under its own privacy policy for those functions. This policy will be updated before payments go live.
- Business owners. If you order from a business or message it, the business owner sees the information needed to serve you (your name, your message, your order contents).
- Legal. We may disclose information if required by law, court order, or lawful authority request, or where necessary to protect the safety of users or the public, investigate fraud or abuse, or defend legal claims.
- Business transfer. If Mahaleh is sold, merged, or reorganized, personal information may be transferred as part of that transaction, with this policy continuing to apply.
6. International transfer (storage outside Canada)
Our infrastructure is provided by Google Firebase, with data stored primarily on servers in the United States. This means your personal information may be accessed by authorities in that jurisdiction under its laws. We use contractual safeguards (Google's data-processing terms and security commitments) to ensure a comparable level of protection.
Quebec residents: as required by Law 25, we have assessed the privacy impacts of communicating personal information outside Quebec and concluded, taking into account contractual and technical safeguards, that the information receives adequate protection. <!-- Owner: keep a written copy of this transfer assessment (PIA) on file — Law 25 s.17 requires it to exist, not to be published. -->
7. Retention — how long we keep it
| Data | Retention |
|---|---|
| Account & profile | For as long as your account exists, then deleted or anonymized on account deletion (see §8). |
| Public content (reviews, posts, listings) | Until you delete it or your account is deleted. Note that content removed for moderation reasons may be retained in an internal archive as evidence for a limited period. |
| Chat messages | For as long as the conversation exists; deleted when the account of a participant is deleted, subject to the other participant's copy of the thread context. |
| Orders & tickets | Kept for the period required for accounting, tax, and dispute-resolution obligations (generally up to 7 years for transaction records once payments launch), then deleted or anonymized. |
| Push tokens | Deleted automatically when invalid/expired, and on account deletion. |
| Analytics & crash data | Retained per Firebase defaults (Analytics user-level data: up to 14 months; Crashlytics: 90 days) and in aggregate thereafter. |
| Reports (moderation) | Kept while relevant to enforcement, then archived or deleted. |
| Waitlist | Until launch communications conclude or you unsubscribe. |
8. Deleting your account and your data
You can request deletion of your account and associated personal information at any time:
- In the app: Profile → Delete account → confirm your password → Delete forever. Your account and data are removed immediately. <!-- Shipped 2026-07-13 (Profile row → confirmation sheet →
deleteAccountCloud Function). This bullet is accurate as written. --> - By email: send a request to ircanbusinesshub.support@gmail.com from the email on your account, or use the deletion request page at mahaleh.ca/delete-account. <!-- Page written (firebase/hosting/landing/delete-account.html); goes live with the Hosting deploy — required before Play submission (Data safety form needs a public deletion-request URL). -->
When your account is deleted we permanently delete your profile, your reviews, community posts and comments, marketplace listings, event tickets, and your registered device tokens. Chat messages you sent remain visible to the person you were talking to — that conversation is equally their record — but they are no longer linked to an identifiable account. We may retain limited records where the law requires it (e.g. moderation-enforcement evidence) or to resolve disputes.
9. Your rights
Under PIPEDA (all of Canada) you may:
- Access the personal information we hold about you and ask how it has been used and to whom it has been disclosed.
- Correct inaccurate or incomplete information.
- Withdraw consent (§4) and challenge our compliance with this policy.
Quebec residents additionally have, under Law 25:
- The right to receive computerized personal information you provided to us in a **structured, commonly used technological format** (data portability).
- The right to request de-indexing / cessation of dissemination of personal information in certain circumstances.
- The right to be informed of and complain about decisions based exclusively on automated processing (we do not currently make such decisions about you).
To exercise any right, contact ircanbusinesshub.support@gmail.com. We respond within 30 days. If you are not satisfied, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, in Quebec, the Commission d'accès à l'information du Québec (cai.gouv.qc.ca).
10. Security
We protect personal information with safeguards appropriate to its sensitivity: encryption in transit (TLS) and at rest on Google's infrastructure, per-user database security rules that limit who can read and write each record, role-based admin access, and server-only writes for sensitive fields. No system is perfectly secure — in particular, remember that chat messages are not end-to-end encrypted (§2.1) and anything you post publicly is, by definition, public.
Breach notification: if a breach of security safeguards creates a real risk of significant harm (PIPEDA) or a risk of serious injury (Law 25), we will notify affected individuals and the Office of the Privacy Commissioner of Canada and, where Quebec residents are affected, the Commission d'accès à l'information, and we maintain an internal register of confidentiality incidents as Law 25 requires.
11. Children
Mahaleh is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, contact ircanbusinesshub.support@gmail.com and we will delete it. Users must meet the age requirements in our Terms of Service to buy or sell.
12. Cookies and similar technologies (web)
The web app at mahaleh.ca uses local storage and Firebase SDK identifiers strictly to keep you signed in, remember your language/metro, and provide the analytics and crash reporting described above. We do not use third-party advertising cookies.
13. Changes to this policy
We may update this policy as Mahaleh evolves (for example, when payments launch). We will post the updated policy at mahaleh.ca/privacy with a new effective date and, for material changes, notify you in the app or by email before they take effect.
14. Contact
Mahaleh — Privacy Officer Email: ircanbusinesshub.support@gmail.com (subject "Privacy") Web: mahaleh.ca requirements expect a real point of contact. A registered business address or PO box is fine. -->