Skip to content
enDo
For businessesImpactAboutHelp
BenDo

Privacy Policy

Last updated: July 1, 2026

This policy explains what personal data BenDo collects, why, how long we keep it and what rights you have. We collect as little as we can, and we don't sell it.

1. Who is responsible

[Legal Entity Name], the company operating BenDo and registered in Morocco, is the controller of the personal data described here. Processing is carried out in accordance with Moroccan Law 09-08 on the protection of individuals with regard to the processing of personal data, under the supervision of the CNDP.

2. What we collect

Account data: your name, email address, phone number, password (stored hashed) and language preference.

Transaction data: the bags you reserve, the amounts you pay, payment status, refunds, credits and promotional codes used. Card details are handled by our payment providers. We never store your full card number.

Location data: your approximate or precise location, only while you use the map or search nearby, and only with your permission. You can turn it off in your device settings and enter an address instead.

Device and usage data: device type, operating system, app version, IP address, crash reports and basic usage events, used to keep the service working and secure.

Communications: messages you send to support, reviews you leave, and your notification preferences.

Partner data: for business accounts, company details, location, bank details for payouts and the identity of authorised users.

3. Why we use it

To provide the service: creating your account, showing what's available near you, taking payment, issuing pickup codes and confirming collection.

To support you: answering questions, investigating problems with an order, handling refunds and disputes.

To keep the platform safe: detecting fraud, abuse and misuse, and enforcing our terms.

To improve BenDo: understanding which features are used, diagnosing errors, and measuring impact in aggregate.

To communicate: service messages you can't opt out of (such as reservation confirmations), and marketing messages you can, at any time.

To meet legal obligations: accounting, tax and responding to lawful requests.

4. Legal bases

We process data because it is necessary to perform the contract between us, because we have a legitimate interest in running and securing the service, because the law requires it, or because you have given consent, which you can withdraw at any time, for example for location access or marketing.

5. Who we share it with

Partner businesses: the minimum needed to prepare and hand over your reservation, typically your first name and the reservation code.

Couriers: where you choose delivery, the details needed to complete it.

Service providers: payment processors, hosting, email and messaging, analytics and crash reporting, each bound to process data only on our instructions.

Authorities: where we are legally required to disclose information.

We do not sell personal data, and we do not share it with advertisers for their own purposes.

6. International transfers

Some of our service providers operate outside Morocco. Where data is transferred abroad, we do so in accordance with Law 09-08, including obtaining CNDP authorisation where required, and we put contractual safeguards in place.

7. How long we keep it

Account data: while your account is open, and for a limited period afterwards to handle disputes.

Transaction records: for the period required by accounting and tax law.

Support messages: normally up to three years after the matter is closed.

Technical logs: normally up to twelve months.

When a retention period ends, data is deleted or irreversibly anonymised.

8. Your rights

You have the right to access your data, to correct it, to object to certain processing, to have data deleted where there is no overriding reason to keep it, and to withdraw consent you have given.

You can exercise most of these directly in the app, or by contacting us. We respond within the time limits set by law.

If you are not satisfied with our response, you may lodge a complaint with the CNDP.

9. Security

Data is transmitted over encrypted connections, passwords are stored hashed, sensitive fields are encrypted at rest, and access is restricted to staff who need it for their role. No system is perfectly secure, but we treat a breach as an emergency and will notify you and the authorities where the law requires it.

10. Cookies and similar technologies

This website uses only what is necessary to serve pages, remember your language and keep the site secure. Where we use analytics, we do so in a form that does not track you across other websites, and we ask for consent where the law requires it.

11. Children

BenDo is not intended for children under 16. We do not knowingly collect their data; if you believe we have, contact us and we will delete it.

12. Changes and contact

We will update this policy as the service evolves; the date at the top shows the latest version, and we will tell you about material changes.

For any privacy question, or to exercise your rights, use the privacy contact address on this site.

This page is written to be readable and accurate. It is not legal advice. Have it reviewed by qualified counsel, and confirm your CNDP declarations, before you rely on it.