On this page
Cart Code
Privacy Notice
This notice explains how Cart Code processes information about anonymous visitors, learners and staff.
Different purposes have different legal bases, choices and retention rules. Data collected for security, service operation or exception-only statistics is not automatically reused for personalised opportunity tracking or direct marketing.
1. Controller and contact
The controller is CartCode Marketing Agency (شركة كارت كود – CART CODE), Egyptian registration number 131457, with its registered office at Al Yasmeen 5, First Settlement, New Cairo, Cairo, Arab Republic of Egypt. The representative of the controller is Dr Hassan El Maraghy, General Manager. Privacy requests may be made through the Contact page or [email protected].
UK Representative: Dr Hassan El Maraghy, 61 Hornbeam Road, Cumbernauld, Glasgow, G67 2QE, United Kingdom. Telephone: +44 7591 978728. Email: [email protected].
2. Who this notice covers
This notice covers public visitors, account holders and learners, prospective and current customers, contacts, and staff or operational users. The service is not intended for children.
3. Information we process
- Account, contact, legal-acceptance, communication and support information.
- Order, payment-status, entitlement and consultation information; payment-card details are handled by the payment provider.
- Course, lesson, video, assignment, submission, feedback, progress, completion and achievement records needed to deliver learning services.
- Server and security records including trusted IP address, encrypted exact-IP observations where enabled, IP hash, masked prefix, country, city, ASN, network and proxy/VPN/fraud signals.
- First-party visitor/session events, source, campaign, UTM, CTA, conversion and preference evidence according to the active analytics mode and your choices.
- Staff sign-in, session, operational presence, administrative actions and audit records that are necessary and proportionate.
4. Purposes and lawful bases
- Security and fraud prevention: legitimate interests, legal obligations and, where strictly applicable, a recognised legitimate interest for qualifying crime prevention.
- Service operation and authenticated learning: contract, steps at your request, legal obligations and legitimate interests in reliable delivery.
- Statistical analytics: consent unless the configured collector qualifies for the narrow statistical storage/access exception, provides clear notice and free objection, remains solely for service improvement and is promptly aggregated.
- Personalised opportunity journeys: explicit consent. This is default-off and separate from statistics.
- Direct marketing: consent or another channel-specific basis only where lawfully available, with a simple opt-out. It is separate from opportunity consent.
- Staff audit: legitimate interests and legal obligations, subject to necessity, transparency, proportionality and no unrelated HR-performance reuse.
5. IP, location and risk processing
The trusted proxy path supplies the application with a client IP that visitor-supplied forwarding headers cannot override. Local MaxMind databases may derive country, city and ASN. Where configured and permitted, third-party fraud, VPN or proxy providers may return risk indicators. These signals support security, service region, abuse investigation and separately authorised analytics; they are not a substitute for human review where a decision has significant effect.
This product includes GeoLite Data created by MaxMind, available from https://www.maxmind.com.
6. Cookies, analytics and opportunity choices
Necessary first-party storage supports security, sessions and saved preferences. Optional personalised opportunity tracking requires affirmative consent. Statistical analytics follows the configured consent or exception-with-objection mode. Exception-only data is session-bounded, not linked to an account, not used by OperTrack for individual scoring and not reused for advertising or individual commercial decisions.
7. Anonymous-to-account linkage
We link an anonymous journey to an account only when that journey was already collected with valid personalised-opportunity consent and the same first-party preference evidence. We do not relabel security, service-operation, staff-audit or exception-only statistical records as marketing data. We do not use device fingerprinting.
8. Learner and staff activity
Authenticated learner activity is processed to deliver access, progress, video, assignments, feedback and support. Staff activity is processed for access control, operational presence, accountability, security and support. Staff monitoring is not based on blanket consent and must not become covert productivity or performance scoring.
9. Communications and payment support
Contact requests, payment-support cases, authenticated conversations, delivery status and related evidence are processed to answer requests, perform contracts, protect the service and maintain appropriate records. Promotional email preferences are channel-specific and may be withdrawn independently.
10. Recipients, processors and transfers
Depending on the service and configuration, recipients or processors may include hosting and infrastructure providers, Cloudflare, Clerk, Stripe, Bunny Stream, email and Communications delivery providers, MaxMind local data, and approved risk providers. Some providers may process data outside the UK. We use applicable contractual, adequacy or other transfer safeguards, maintain a processor and transfer register, and minimise the data supplied.
11. Retention
We apply purpose-specific periods and starting points. Exact/raw sensitive network data is short-lived; security and audit history is retained only as justified; exception-only raw statistics is promptly aggregated or anonymised; consented opportunity history has its own bounded period; operational learning and Communications records follow their service and legal needs; consent and legal evidence is retained to demonstrate the relevant choice or contract. We do not retain telemetry indefinitely just in case.
12. Your rights and choices
Depending on the circumstances you may have rights of access, correction, erasure, restriction, portability and objection, and the right to complain to the ICO. You may withdraw consent at any time without affecting earlier lawful processing. You may object free of charge to exception-only statistics through Privacy preferences and opt out of direct marketing through the relevant channel.
13. Decisions and future services
Current OperTrack opportunity interpretation remains read-only and does not itself send messages. No automated intervention or visitor chat is activated. Google Analytics is not active; any future integration requires a separate assessment, notice and control before use.
14. Changes to this notice
We identify the notice version and effective date. A Privacy or cookie update normally uses notice or acknowledgement rather than pretending to be contractual consent. A material Terms change is handled separately and may require fresh acceptance.
15. Protected video security processing
For protected video, Cart Code processes short-lived playback leases and signing authority, a frozen learner-specific watermark snapshot, trusted server and network context, bounded integrity and delivery evidence, temporary video-only restrictions, case history and reviewer actions. The values used for a playback session are frozen from the authoritative account, course, lesson and trusted-network domains; the video service does not create a second email, phone, identity or IP-verification authority.
Bunny Stream acts as a video-delivery processor and may process the bounded technical information needed to deliver and protect video. Cart Code minimises provider evidence used in review, masks network presentation, and does not place learner watermark identity in provider URLs. Signed URLs, tokens, credentials and raw provider payloads are not shown in the protected-video review surface.
This processing supports service delivery, content and account security, abuse prevention, rights protection and accountability. It does not depend on optional analytics, personalised-opportunity or direct-marketing consent, and a security or provider result does not by itself create a punitive decision. Confirmed evidence and human review govern temporary restriction and restoration; broader account action remains separately authorised.
Protected-video records follow the approved purpose-specific security, learning, case and legal-evidence retention schedules, subject to authorised legal holds and applicable rights. The protected-video system does not display date of birth and does not use passive device fingerprinting such as canvas, fonts, audio, plugin lists or hardware-like identifiers.
