Same-day delivery in Baku and Absheron

Privacy policy

What data Narçiçək collects, why it collects it, and who it is shared with — in plain language.

Last updated: 2026-08-28

The legal details of this document (operator name, tax ID, address, official contact channel) have not been filled in yet — the company is still being registered. The text below honestly describes how the platform actually works, but it has not been reviewed by a lawyer.

1. What this document is

Narçiçək is a flower and gift ordering platform serving Baku and the Absheron area. This document explains how personal data collected while using the platform is processed.

It applies equally to the website, the mobile app and the florist panel.

2. What we collect

Account data: your name, email address and phone number.

Order data: the recipient's name and phone, the delivery address and (if picked on the map) its coordinates, the delivery date and time, the gift card message, and the sender's name.

Technical security record: the time of each sign-in to your account, the IP address and the device type. This record exists precisely so that you can see if someone other than you has signed in.

Notifications: if you allow notifications in the mobile app, the device's push token.

Content you write: product reviews and messages you send to support.

3. Why we collect it

To accept your order, pass it to the florist you chose and arrange delivery.

To notify you about the status of your order.

To answer your support requests.

To protect account security and prevent abuse.

Your data is not sold to third parties for advertising.

4. Who it is shared with

The florist you ordered from: to fulfil the order they are shown the recipient's name, phone, address and the gift card message. If you mark the order as anonymous, the sender's name is not passed to the florist either.

Supabase: data is stored on its cloud infrastructure in the European Union (Frankfurt) region.

Expo: the device push token, solely to deliver mobile notifications.

Data is not given to any other third party, except where required by law.

5. Payment data

Orders are currently accepted with cash on delivery. Your card details — number, expiry date, CVV — are never collected or stored by the platform.

When online card payment goes live, the transaction will take place in the bank's or payment provider's own environment and this document will be updated.

6. How long it is kept

Account and address data is kept while your account is active.

Order records may be kept for accounting and reporting even after your account is deleted, but their link to your identity is severed.

Sign-in and session records are kept for account security.

7. Your rights

You can view and change your data from the profile page.

You can delete your account from within the app — this removes your profile and personal data.

You can turn notifications off at any time in settings; when you do, the device push token is deleted from the database.

The channel for requesting a copy, a correction or full deletion of your data will be listed at the end of this document.

8. Cookies and browser storage

Only what is necessary for the service to work is stored in your browser: the sign-in session, your chosen language and city, and the contents of your cart.

The platform uses no advertising or behavioural tracking code (analytics pixels, ad network cookies).

9. Security

Connections are encrypted with HTTPS. Database access is restricted by row-level permission rules — each user can only read their own data.

Your password is not stored in readable form.

10. Children

The platform is not intended for people under 18.

11. Changes

When this document is updated, the date above changes. Significant changes will be announced separately on the site.