Aoaj
Privacy policy
What we collect, why we collect it, and what you can ask us to do with it. We collect only what an order or an account actually requires.
Last updated 6 October 2026
Who is responsible for your data
Aoaj, the Bangladesh-based retailer operating this website, is the data controller for the information described here. Questions about your data go to the contact details at the foot of this page.
What we collect when you order
Placing an order — as a guest or signed in — requires your name, mobile number, email address, delivery address, district or city, area, and the items themselves. We also record the payment method you chose, any discount applied, and anything you write in the order notes field.
We ask for a mobile number because the courier must be able to call you. We do not treat it as an identity: it is not used to sign you in, and it does not grant access to an account.
What we collect if you create an account
An account stores your name and email address. If you choose a password, we store a scrypt hash of it — never the password itself — so a copy of our database cannot be used to sign in as you. If you sign in with Google, we store Google's stable account identifier so we recognise you next time; we do not store your Google password.
You can sign in with a one-time code emailed to you instead of a password. Only a SHA-256 hash of each code is stored, along with an expiry and a use counter, so an expired, guessed or already-used code cannot work and a database copy cannot be turned back into a working code.
A verified email address is what links orders you placed as a guest to your account. Without a verified address, guest orders stay reachable only by order reference and mobile number.
Cookies
This site sets two cookies, both strictly necessary and neither used for advertising or profiling:
awaj_user— keeps you signed in. Holds an opaque session identifier and a signature, is marked HttpOnly so scripts cannot read it, and is scoped to same-site requests.awaj_admin— the same idea for staff, and only set after a staff sign-in.
Short-lived cookies are also used while you sign in with Google or a one-time code, to carry the return-to page and to prevent a forged sign-in attempt. They expire quickly and do not identify you.
We run no advertising, analytics or cross-site tracking scripts, and we do not sell or share personal data with advertising networks.
Why we are allowed to hold it
To perform the contract you enter into when you order — delivering the goods, taking payment, handling a return — and to meet legal obligations such as accounting and tax records. Where we send you a one-time sign-in code or an order confirmation, that is on the basis of performing the contract or taking steps at your request prior to entering into it.
Who can see your information
The delivery courier receives your name, address and mobile number, because they cannot deliver without them. Our email provider receives your address and the contents of any message we send you. Our hosting and database providers hold the data on our instruction, under the same confidentiality obligations.
We do not sell your data, and we do not share it for anyone else's marketing. Staff can see the orders assigned to them in the admin panel, and staff actions are recorded in an internal audit log. We will disclose data where the law requires it, and will tell you unless legally prohibited from doing so.
How long we keep it
Order records are retained for as long as we need them for accounting, tax and customer disputes — in practice, the period Bangladeshi tax and business record-keeping requires. Sign-in codes are deleted once they expire or are used. Sessions end when they expire or you sign out. Unused one-time codes and expired rate-limit counters are swept from the database automatically.
Your rights
You can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, or object to how we use it. Contact us and we will respond within 30 days.
You can close your account at any time. Closing it removes your profile and ends your sessions. Orders already placed are kept, as our sales records have to be, and stay available to you by order reference and mobile number.
We do not send marketing email unless you ask for it, and every message we do send includes a way to stop. Declining marketing does not affect order confirmations or anything else needed to run your order.
Security
Data is sent over HTTPS. Passwords are hashed with scrypt, sign-in codes are stored only as hashes, sessions are revocable server-side so signing out or blocking an account takes effect immediately, and sign-in attempts are rate limited to make guessing impractical. No system is perfect: if a breach affects your data we will tell you and the relevant authority without undue delay.
Children
This store is not intended for anyone under 18. We do not knowingly collect information from children, and if we learn that we have, we delete it.
Changes to this policy
If this policy changes materially we will update the date at the top and, for anything significant, tell you by email before the change takes effect.
