Legal
Privacy Policy
Last updated: September 16, 2026
This policy explains the information used by the current Yanaar storefront and its integrated services, and how to contact us about your information.
Information We Collect
We process information you provide when creating an account, ordering or asking for help. Depending on your interaction, this includes your email, authentication user ID and provider information, and any name or profile information returned by your chosen sign-in provider or supplied in a contact request.
Order information includes selected products, quantities, prices, currency, discounts/referral codes, payment provider and transaction identifiers, status and timestamps. Fulfillment information may include a contact email, delivery email, Instagram username or URL, and Telegram channel/group URL. Support records include subjects, messages, replies, order references and timestamps.
The site and integrated services also process technical information such as your IP address, browser/device information and page interactions as described below. We do not ask for precise GPS location.
How We Use Information
We use information to operate your account, process payments, deliver orders, apply eligible discounts, communicate status, respond to questions, investigate problems and limit abusive checkout activity. Analytics helps us understand site use. Approximate location and exchange-rate information help us display a currency.
Information needed for a particular order or account function may be required to provide that function. Product-specific checkout fields indicate the information needed for delivery.
Account Authentication
Supabase provides account authentication and stores associated user and session information. Email/password registration, sign-in and password resets use Supabase authentication. Google sign-in is also offered; information supplied by Google depends on that sign-in flow and your settings.
Authentication cookies or session information keep you signed in. Guest checkout is available without a Yanaar account. The support ticket area currently requires sign-in; you can also contact us by email.
Order Fulfillment
We store the contact and product-specific delivery details supplied with an order. A delivery email may be different from your contact email. Authorized personnel use order information to process and support the purchase.
Where delivery involves a third-party account, channel, group or service, the relevant destination details are used to arrange that delivery. Provide only information you have authority to use. Do not submit unrelated sensitive information or your personal Instagram password.
Payments
Whop handles card and eligible wallet checkout, and Cryptomus handles cryptocurrency checkout. Payment credentials are entered through those providers rather than stored directly by Yanaar. Our application does not store full card numbers, card security codes or wallet private keys.
We do store payment-related records, including order and transaction/session identifiers, provider, amount, currency, payment status and timestamps. Order references and payment details needed to initialize or reconcile the purchase are exchanged with the provider. Your contact email can be passed to the card checkout to prefill it.
The providers process information under their own privacy policies. Cryptocurrency transactions may also be recorded on public blockchain networks.
Customer Support
We store support tickets and replies linked to the account and order references you provide. Contact submissions may include your name, email, subject and message. Order and support notifications are sent through Resend and may include relevant order or message details.
If you choose the WhatsApp contact link, your communication takes place through WhatsApp and is subject to its privacy practices. Avoid including payment credentials, private keys or unrelated sensitive information in any support message.
Security
The application uses account authentication, access controls and server-side validation to restrict access and validate submitted information. These measures do not guarantee that every transmission or storage system is free from risk.
Keep your account and delivered credentials private. Contact us if you believe someone has used your account or order information without permission.
Fraud Prevention
The checkout uses information derived from an IP address and contact email to limit repeated checkout attempts. Payment identifiers and order records help us reconcile payments, investigate duplicate submissions and address suspected misuse. Payment and authentication providers may perform their own security checks.
Service Providers
- Supabase: authentication, database storage, account, order and support records.
- Whop and Cryptomus: payment checkout, processing and transaction status.
- Resend: order and support email delivery.
- Google: Analytics, signup reCAPTCHA where shown, and Google sign-in when selected.
- ipapi.co: approximate location and currency detection from a browser request.
- ExchangeRate-API: exchange-rate requests used for currency display and conversion. Browser requests disclose connection information such as IP address to that service.
Hosting and infrastructure providers process requests needed to serve the site. Providers receive information relevant to their function, and may process it under their own terms and privacy notices. We may also disclose relevant information when required by law or to address a valid legal request.
Data Retention
Retention depends on the purpose of the record, including an ongoing account or order, support and warranty requests, payment reconciliation, dispute resolution and applicable recordkeeping requirements. This policy does not promise a single deletion period for every category of data.
Contact us to ask about retention or request deletion. Some records may need to be retained for legal obligations, unresolved transactions or claims even after an account is closed.
Cookies, Local Storage and Analytics
Authentication uses browser session storage mechanisms such as cookies. The cart is saved in local storage. The site also stores a currency/location cache and may temporarily save pending order information or refresh flags to support checkout and order navigation.
Google Analytics is loaded on the site to measure visits and interactions. It may use cookies and process online identifiers, browser/device information and page activity. These records may be associated with online identifiers. Google reCAPTCHA on signup forms processes browser/device and interaction information to assess automated activity.
You can clear or restrict cookies and local storage through your browser settings. This may sign you out, clear the cart or affect site functions. Google also provides an Analytics opt-out browser add-on at https://tools.google.com/dlpage/gaoptout.
Location and Currency Detection
Your browser requests approximate location information from ipapi.co using your IP address. The application uses returned country, region, city and currency information for currency display and stores the resulting currency/location data in a local cache with a 24-hour reuse window.
Exchange rates are requested from ExchangeRate-API. Location detection does not use a GPS permission prompt. If usable location or rate information is unavailable, the site falls back to USD where needed.
International Processing
Yanaar and its providers may process information in countries other than the one where you live. Applicable protections and rights can vary by location. Contact us for information about the providers and processing relevant to your request.
Customer Rights
Depending on the law that applies to you, you may have rights to access or correct your information, request deletion or restriction, object to certain processing, receive a portable copy, or withdraw consent where processing relies on consent. You may also have a right to complain to a data protection authority.
Email yanaarstore@gmail.com to make a request. We may ask for information needed to verify your identity and locate the records. We will assess the request under applicable law, including any exceptions or recordkeeping obligations.
Policy Changes
We may update this policy to reflect changes to the site or data practices and will revise the date shown above. Where applicable law requires additional notice or consent, those requirements still apply.
Contact
For privacy questions or requests, email yanaarstore@gmail.com. You may also open a support ticket at /support. Include enough information to identify your account or order without sending passwords or payment credentials.