Privacy Policy
Last updated 13 August 2026
This Policy explains how HEYLIM handles personal data when you use the HEYLIM website (“the Website”), the HEYLIM mobile applications for iOS and Android (“the Mobile Application”; together, “the Services”), and HEYLIM locations. It covers the Services only. HEYLIM is one global service operated by local HEYLIM entities: the entity responsible for your personal data (the controller), the data protection law that applies to it, and the supervisory authority for your market are identified in the Country-specific provisions at the end of this Policy. Those provisions state, for each market, when they apply; they supplement this Policy and prevail over it for the matters they address.
1. Acceptance and Changes
1.1 By using the Services you accept this Policy. The version in force at the time you use the Services applies. When we publish a new version, we post it here; a material change is announced in the Services before it takes effect.
2. Who Processes Your Data
2.1 The controller is the HEYLIM entity identified for your market in the Country-specific provisions. Because your HEYLIM account is one global account, other HEYLIM group entities may process account data where necessary to operate the shared platform, under arrangements consistent with the data protection law identified for your market.
3. What We Process
3.1 We process the following data, and nothing beyond it:
- your mobile phone number — it is your login; one-time login codes are delivered to it via WhatsApp or SMS (these channels deliver codes only and are not support channels);
- your name or nickname, if you set one;
- your email address, if you set one (used for receipts if you enable that option);
- your orders and payments: order history, payment status, and — if you choose to save a card — the payment token, card brand, expiry, and last four digits held via our payment processor (never the full card number or CVC; you can delete saved cards in account settings at any time);
- your messages to our support;
- device information, IP address, and app usage events;
- your device’s location, only if you turn location access on.
3.2 Web “quick buy”: to take a payment without registration we create a technical guest account for that purchase. The same data categories apply to it; promotions are not available on guest purchases.
4. Why, and on What Basis
4.1 We process data for the following purposes:
| Purpose | Basis |
|---|---|
| Account, login codes, orders, dispensing, payment | Performance of your contract with us |
| Tax and accounting records | Legal obligation |
| Fraud prevention, chargebacks, abuse, security of the Services | Contract and legal obligation |
| Customer support | Performance of your contract with us |
| Marketing messages (SMS, email, push) | Your separate opt-in only |
| Optional geolocation; non-essential analytics | Your separate opt-in |
4.2 Where the law of your market treats account processing as consent-based, you give that consent by tapping “Get Code” after entering your phone number.
4.3 Marketing is never implied: logging in does not subscribe you to anything. You receive marketing messages only if you enable the marketing opt-in in your account, and you can turn it off there at any time or by writing to hey@heylim.com.
5. Who Receives It
5.1 Personal data is disclosed only to: (a) the payment processor identified for your market in the Country-specific provisions; (b) our hosting and infrastructure providers, under data-processing agreements; (c) processors that help us operate support tooling, under contracts binding them to confidentiality and our instructions; (d) Google LLC, for the analytics in Section 4.1 — only where enabled; (e) other HEYLIM group entities (Section 2.1); and (f) state authorities, where the law requires disclosure. We do not sell personal data.
5.2 Data may be stored or processed outside your market (our infrastructure may be located in the European Union). Cross-border transfers rely on the grounds identified for your market in the Country-specific provisions.
6. How Long
6.1 We keep: (a) account and profile data for the life of your account, deleted or anonymized within 30 days after account deletion, except as set out below; (b) order, payment, and tax records for five years from the transaction, as required by the accounting and tax legislation of our markets; (c) support conversations for 24 months after your request is closed; and (d) analytics data for 14 months. Data may be kept longer where required by law or where necessary to establish, exercise, or defend legal claims.
7. Your Duties
7.1 The data you give us must be accurate and yours. You are responsible for anyone who uses your phone number or account. If data you provide is false, we may refuse to open or may close the account.
8. Withdrawing Consent
8.1 Marketing and the optional tools (geolocation, analytics): you can withdraw at any time, and the Services continue to work.
8.2 If you withdraw the processing the account itself needs, we can no longer take your orders; we then delete or anonymize your data on the timelines in Section 6, except what the law requires us to keep. To withdraw, write to hey@heylim.com or use in-app support.
9. Security
9.1 Access to personal data is limited to those who need it to provide the Services; processors are bound by confidentiality and data-processing agreements. Card payments are handled by PCI-DSS-certified processors; we never store full card data. No transmission over the public internet can be guaranteed absolutely secure, which is why we hold only the data listed in Section 3.
10. Your Rights and the Supervisory Authority
10.1 Your rights (access, correction, deletion, objection, and the further rights your market’s law provides), the applicable law, and the supervisory authority you can complain to are set out in the Country-specific provisions for your market. To exercise a right or delete your account, use in-app support or write to hey@heylim.com.
11. App Permissions
11.1 The Mobile Application asks for permissions only where a feature needs them, and each is optional: location (finding nearby pillars), camera (scanning a pillar’s QR code; nothing is stored or transmitted), and NFC (identifying the pillar you tap). You can revoke any of them in your device settings; the pillar number can always be entered manually.
12. Cookies
12.1 The Website uses cookies needed to operate it (such as session and login cookies) and, separately, analytics cookies as described in Section 4.1 — the latter only with your consent where the law of your market requires it. You can restrict cookies in your browser settings.
13. Contact
13.1 Questions about this Policy: hey@heylim.com.
Country-specific provisions
HEYLIM is one global service, and every HEYLIM location operates in a market. Each section below states when it applies to you.
United Arab Emirates
Last updated 13 August 2026
These provisions apply where HEYLIM TRADING L.L.C is your data controller — in particular where you purchase from a HEYLIM location in the United Arab Emirates or otherwise use HEYLIM services there.
Controller. HEYLIM TRADING L.L.C (هيليم للتجارة ش.ذ.م.م), Office F101, Belshalat Building, Naif, Dubai, United Arab Emirates. Contact: hey@heylim.com.
Applicable law. The UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, “PDPL”).
Legal bases. We process the data needed to operate your account, take and fulfil your orders, and process payment because that processing is necessary to perform your contract with us; we retain transaction records to comply with UAE tax and accounting law; and we rely on your consent for marketing communications, optional geolocation, and non-essential analytics, which you may refuse or withdraw without affecting your ability to order.
Your rights. Under Articles 13–18 of the PDPL, and subject to its conditions and exceptions, you may: request access to the personal data we hold about you and obtain a copy of it in a structured, machine-readable format (data portability); request correction or completion of inaccurate data; request erasure; request that processing be restricted or stopped, including objecting to processing for direct marketing; object to decisions based solely on automated processing that produce legal effects for you; and withdraw consent at any time. To exercise these rights, use in-app support or hey@heylim.com.
Supervisory authority. The UAE Data Office, the federal data protection authority established under Federal Decree-Law No. 44 of 2021.
Payments. Payment transactions are processed by Stripe, Inc. under PCI-DSS. As Stripe operates cross-border, your payment data may be processed outside the United Arab Emirates under appropriate contractual safeguards, consistent with the cross-border transfer provisions of the PDPL (Articles 22 and 23).
International transfers. Our infrastructure may be located outside the UAE (including in the European Union); transfers are protected by safeguards consistent with the cross-border transfer provisions of the PDPL (Articles 22 and 23).
Armenia
Last updated 13 August 2026
These provisions apply where «ՍՈՒՐՃԻ ԱՋԱԿՑՈՒԹՅՈՒՆ» ՍՊԸ (“Coffee Support” LLC) is your data controller — in particular where you purchase from a HEYLIM location in the Republic of Armenia or otherwise use HEYLIM services there.
Controller. «ՍՈՒՐՃԻ ԱՋԱԿՑՈՒԹՅՈՒՆ» ՍՊԸ (unofficial English translation: “Coffee Support” LLC), 21/2A, Nor Aresh 11th Street, Erebuni administrative district, Yerevan 0041, Republic of Armenia. Contact: hey@heylim.com.
Applicable law. The Law of the Republic of Armenia “On Protection of Personal Data” (HO-49-N, adopted 18 May 2015, as amended).
Acceptance. Use of the Services constitutes acceptance of this Policy.
Marketing. Marketing messages are sent only if you enable the marketing opt-in in the app; logging in does not subscribe you to marketing.
Your rights. Subject to the conditions and exceptions in that law, you may access the personal data we hold about you, request its correction, blocking, or destruction, object to its processing, and withdraw consent — via in-app support or hey@heylim.com. We respond to requests within the time limits set by that Law.
Supervisory authority. The Personal Data Protection Agency of the Ministry of Justice of the Republic of Armenia, to which you may also submit complaints about the processing of your personal data.
Payments. Payment transactions are processed by our acquiring bank in the Republic of Armenia, currently Ardshinbank CJSC, under PCI-DSS. HEYLIM does not store your complete card details.
International transfers. Our infrastructure may be located outside Armenia (including in the European Union). Where personal data is transferred outside the Republic of Armenia, we rely on the grounds permitted by Article 27 of the Law “On Protection of Personal Data”: transfer to states ensuring an adequate level of protection (per the adequacy list maintained by the Personal Data Protection Agency, which includes the EU/EEA states), your consent, a ratified international treaty, or the prior permission of the Personal Data Protection Agency.