LOFUS / Legal
Privacy Policy.
This policy describes the public storefront, customer identity, browser-linked Cart and cash-on-delivery order system as implemented. Public order tracking, review submission, newsletters and marketing systems remain inactive.
1. Who is responsible
The responsible operator must be the legal entity identified on the Legal Information page. Its required identity and privacy contact fields are not published until canonically configured.
2. Data used by the storefront and accounts
The storefront stores a region preference. When an account is created or used, LOFUS processes the normalized email, verification state, sign-in provider, profile name, optional phone, avatar and language, saved addresses and wishlist. A submitted COD order stores the customer name and Algerian phone number, note if provided, exact product configuration and media snapshot, quantities, prices, discounts, delivery destination, home address or selected Stop Desk, carrier and rate snapshots, estimated dates, order status, and applicable policy versions. Security records can include session identifiers, browser, operating system, device, IP address, user agent, timestamps and authentication events.
- Region preference, profile and account settings
- Browser-linked Cart and checkout intent
- Order, product, price and delivery snapshots
- Saved delivery addresses and wishlist items
- Authentication methods, sessions and abuse-prevention records
- Anonymous catalog search queries without personal identifiers
- No card credentials are requested by the COD checkout; public order tracking and review submission remain inactive
3. Why data is used
Account data is used to authenticate the customer, maintain their profile, addresses and wishlist, protect access, prevent abuse and grant administrative capability only to an explicitly linked active Member. Cart and order data is used to calculate canonical prices and delivery, prevent duplicate submission, reserve exact inventory, fulfil the COD sale, provide a receipt, handle after-sales needs and meet applicable legal or audit obligations. Technical request handling serves, secures and diagnoses the website. Anonymous search terms help optimize catalog indexing.
4. Cookies and local storage
lofus_region_code is a one-year preference cookie also stored locally. The HttpOnly lofus_session cookie authenticates the same identity for personal and, where authorized, administrative access. The HttpOnly lofus_cart_id cookie links the browser to an active Cart for up to 30 days; product and quantity data stays in the application database. Local storage also retains recent search queries on your device (up to 8 items) for quick reuse; these remain on your device only and can be cleared directly within the search interface. Supabase may set temporary authentication cookies during email verification, recovery and Google OAuth. No public tracking or advertising cookie was identified.
5. Infrastructure and recipients
Supabase/PostgreSQL provides application and order data infrastructure and Supabase Auth brokers verified email/password authentication and, when enabled, Google authentication. If the Google option is published and chosen, Google supplies openid, email and profile information. Cloudinary serves media, Fontshare serves Panchang font files, and the deployed web host processes ordinary requests. The canonical order identifies the configured delivery company. The customer’s name, phone, destination, address or Stop Desk and necessary order details may be made available to that company only to arrange and complete delivery under the approved operating process. No card processor, SMS or WhatsApp connector is used by this COD checkout.
6. Hosting location and transfers
External infrastructure may process technical data outside Algeria depending on its configured hosting location. The operator must review the actual deployment regions, safeguards and Algerian transfer requirements before launch; this page does not invent them.
7. Retention
The region cookie is configured for one year and the Cart cookie for up to 30 days. Authentication sessions expire or may be revoked by the customer or LOFUS; expired and revoked session records and security events are retained only for security, audit and abuse-prevention needs under the operator's approved schedule. Account profile, address and wishlist records remain while the account is active or until lawfully deleted. Checkout refuses order submission unless an approved order-retention period is canonically configured; each order records its resulting retention date. Deletion remains subject to applicable legal preservation duties.
8. Your choices and rights
Subject to applicable Algerian law, people may have rights to information, access, rectification and objection. Requests must be sent through the official privacy or support channel once published. Identity may need to be verified, and no automated deletion portal is claimed to exist.
9. Security
LOFUS and its providers should apply safeguards proportionate to the data and risk. No internet service can promise absolute security. Never send passwords, one-time codes or full payment credentials through an ordinary support message.
10. Changes to this policy
Material changes to data collection, processors, purposes, rights handling or retention require a deliberate policy review in English, French and Arabic. A configured version and effective date will be shown when approved for production.