Privacy policy
How Basket Bee handles personal data across basketbee.app and the Basket Bee Intelligence client portal.
The short version
You can read this website without an account and without telling us who you are. If your organization licenses the Basket Bee Intelligence portal, we collect the minimum needed to run those accounts — a work identity, sign-in credentials, and a record of use. We do not sell personal data, and we do not build advertising profiles.
The price data itself is not personal data. It is public retail listings collected from stores' own pages — information about products, not about people.
Who we are
"Basket Bee" is the trading name of the team that operates basketbee.app and the Basket Bee Intelligence client portal at intelligence.basketbee.app. In this policy, "we" and "us" mean Basket Bee, and "you" means anyone using those services.
The entity behind that trading name is BasketBee, founded in 2026. Its address for service of legal notices is 6th of October City, Cairo, Egypt.
For any question about this policy or about your data, write to [email protected].
What this policy covers
This policy covers the public website at basketbee.app and the Basket Bee Intelligence portal for business clients.
Other Basket Bee services, where they exist, carry their own notices and are governed by those. If you were given a separate notice when you were given access to something, that notice governs it.
It does not cover other companies' websites. When we link to a retailer, that retailer's own privacy policy applies once you are on their site.
What we collect, and why
We collect only what a given function needs. Reading this website needs no account and creates no record we can tie to you by name — but it is not invisible: our host serves every page and a page-view counter runs on all of them. What each of those sees is set out below.
| What | Why | When |
|---|---|---|
| No name, email or account, if you are only reading this website | The public pages need no account and ask for no identity | Always |
| What you type into a contact form — your name, email, organization, the intent you pick, and your message | To answer you. Routed to the relevant inbox and sent by our email provider | Only when you submit one |
| Portal account details — a work email address, a display name, the client organization you belong to, and your role in it | To create and secure your access, and to scope what your licence entitles you to see | Only for licensed client users |
| Portal usage records — sign-ins, the reports and views you open, and exports you request | Security and abuse detection, support, and honouring the licence terms your organization agreed to | While you use the portal |
| Website analytics — the page address you opened, the search or campaign parameters in it, the page that referred you, your device type, operating system and browser, and the country you are in | To find what is broken and what people cannot find. Counted in aggregate, with no cross-site tracking cookie and no profile of you | On every page you open |
| Your network address | Seen by our host on every request because that is how a page reaches you, and used by us to rate-limit sign-in and contact forms and to run the anti-bot security check. The analytics counter derives your country from it. Not built into a profile | On every request, and again on sign-in and form submissions |
What we never do
- We do not sell your personal data, and we do not rent or trade it.
- We do not run third-party advertising trackers or build advertising profiles.
- We do not share one person's individual behaviour with a retailer, a brand, or any business client. What business clients see is aggregate market data.
- We do not record labels or inferences about your health, religion, politics, or finances, and we do not want them.
- We do not ask for your national ID, your payment card, or your home address. Nothing we do needs them.
Cookies and what we keep on your device
This website keeps almost nothing. What it does keep sits on your own device, and clearing your browser storage clears it.
| Name | What it is for | Type |
|---|---|---|
| bb_locale | Remembers whether you read the site in Arabic or English so the first page you see is in the right language and reading direction | Cookie, one year |
| Sign-in session | Keeps you signed in. Set by our authentication provider | Cookie, only when signed in |
| Security check | The anti-bot challenge on sign-in and contact forms | Set by Cloudflare Turnstile at the moment of the check |
| Usage analytics | Counts page views and feature use. Designed to work without cross-site tracking cookies | Vercel Analytics |
Who processes data for us
We use a small number of established service providers. They act on our instructions and may not use your data for their own purposes.
- Supabase — the database and the sign-in system.
- Vercel — website hosting and usage analytics.
- Cloudflare — the security check on forms, network protection, and encrypted backups.
- Resend — sending the email replies to messages you send us.
- A mobile network provider — delivering the one-time sign-in code by SMS.
- Google and Apple — only if you choose to sign in with one of them.
How long we keep it
We keep personal data only as long as the purpose it was collected for still applies, and then delete or irreversibly aggregate it.
Removing an account removes its account data. That action is immediate and cannot be undone.
Your rights
Egypt's Personal Data Protection Law No. 151 of 2020 gives you rights over your personal data. You can:
- ask what we hold about you, and get a copy of it;
- have anything wrong corrected;
- have your data deleted;
- restrict or object to a particular use;
- withdraw a consent you gave, at any time, without affecting what was lawful before you withdrew it;
- complain to the Personal Data Protection Centre.
Write to [email protected] and say what you want. Portal users can also raise it with their organization's administrator, who can remove an account directly. We aim to respond within 30 days.
Security
Sign-in sessions are held in cookies scoped to this site and marked Secure, so your browser sends them only over an encrypted connection. Because the app reads your session in the browser, those cookies are readable by scripts running on this site — they are not http-only. Sign-in and contact forms are rate-limited and protected by an anti-bot check. Access to the production database is restricted, and backups are encrypted.
If a breach of personal data occurs, we intend to notify the Personal Data Protection Centre within 72 hours of becoming aware of it, and to tell affected people where the law requires it.
No system is perfectly secure, and we will not claim otherwise.
Children
Basket Bee is a business service and is not directed to children. Accounts are held by adults acting for an organization, and we do not knowingly collect personal data from a child.
The price data itself
Basket Bee collects publicly listed retail prices from stores' own public pages. That information is about products, not about people, and it does not come from you.
We read only what any member of the public could read, at a pace that does not burden a retailer's website, and we do not bypass sign-in screens or security controls to obtain it.
Changes to this policy
When this policy changes we will update the version line at the top of the page. If a change materially affects how we use your data, we will tell you before it takes effect.
