Skip to content
Back to home

Privacy Policy

Last updated September 2026

1. Introduction

Mongjee ("we", "us", or "our") operates a personal shopping marketplace available as a mobile app, with this website at mongjee.com. This Privacy Policy explains how we collect, use, store, and protect your personal information. By registering or using Mongjee, you agree to the practices described here.

2. Information We Collect

Account data: Email address, username, and password (stored only as an Argon2 hash, never as text we can read) provided during registration.

Profile data: Profile photo, country, and for Personal Shoppers the brands they specialise in and the countries they travel to.

Content you post: Item listings and their photos, trip details, written updates, comments, and messages you send to other users. Photos are stripped of their EXIF metadata (including any GPS coordinates) on your device before they are uploaded.

Safety data: Reports you submit about content or people, and the accounts you block. A report records who sent it, what it was about, and what we did; the person reported is never told who reported them.

Order and transaction data: Delivery addresses, item prices, transaction amounts, and order status records necessary to fulfil purchases.

Payment data: Payment is processed by Razorpay. We do not store card numbers on our servers, and we retain only transaction identifiers and payout references. Personal Shoppers give us their bank details so they can be paid; only the last four digits are ever shown back in the app.

Identity verification (Personal Shoppers only): The type of document you choose (passport, national ID or driving licence), a photograph of that document, and optionally a selfie. We do not ask you to type your document number, and we do not require an image of the back. These files go to separate, private storage described in section 5.

Usage data: IP address and basic request logs, collected automatically to keep accounts secure and to rate-limit abuse. Your IP address is used when you sign in and when you register, to stop somebody creating accounts in bulk.

What we do not collect: We do not have push notifications, so no device push tokens are collected. We do not use advertising identifiers, we do not track you across other apps or websites, and we do not collect your precise location.

3. How We Use Your Information

We use collected data to create and manage accounts, show you the shoppers, trips and items you have asked to see, facilitate orders and hold payments in escrow, verify Personal Shopper identity, process payouts, deliver notifications inside the app, investigate disputes and reports, keep abusive accounts off the platform, and comply with applicable law.

4. Information Sharing

We do not sell your personal information. We share data only in these circumstances:

Between buyers and shoppers: A buyer's delivery address is shared with the assigned Personal Shopper for fulfilment.

Payment processors: Transaction data is shared with Razorpay to process payments and disburse payouts.

Between users generally: Anything you post publicly (a listing, a trip, an update, a comment, your username, your profile photo and your reviews) is visible to other people using Mongjee.

Infrastructure: Our database, servers and file storage run on DigitalOcean, in Singapore. They host the data on our instructions and do not use it for anything of their own. Images and other public files are served through DigitalOcean's CDN.

Legal obligations: We may disclose data when required by law, court order, or to protect user safety.

5. KYC Data Handling

Identity documents and selfies are kept in separate, private storage with no CDN in front of it and no public address of any kind. They can only be opened through a signed link that expires after five minutes, generated one document at a time when a reviewer actually opens it. They are never served from the same place as your profile photo or your listing photos, and an ordinary request for one is refused outright. They are used solely to verify identity and are not shared with third parties except as required by law or by our payment processor for compliance. These records are retained for a minimum of 5 years from verification to meet anti-money-laundering obligations.

6. Data Retention

Account data is retained while your account is active. You can delete your account from inside the app, under Account. If you have never had an order, the account and everything attached to it is deleted outright. If you have, the account is anonymised instead and the order records are kept: they are also the counterparty's record of a transaction they were part of, and a tax record we are required to hold, typically for up to 7 years. Anonymising replaces your email and username with generated values and clears your personal fields. Reviews you wrote stay attached to the anonymised account, because they are a rating the shopper earned.

7. Cookies

This website uses a cookie only where one is needed to keep an administrator signed in to our internal review tool. We do not use third-party advertising or tracking cookies anywhere. The mobile app does not use cookies; it stores your sign-in token in your device's secure storage.

8. Your Rights

You have the right to access, correct, or delete your personal data, and to withdraw consent for optional data processing. To exercise these rights, contact our Privacy Officer at [email protected].

9. Data Security

We implement industry-standard security measures including encrypted connections (TLS), hashed password storage, access-controlled databases, and short-lived signed URLs for sensitive documents.

10. Contact

For privacy-related enquiries, contact us at [email protected].