Privacy policy

This policy describes how Sharik processes personal data, in accordance with Law 09-08 on the protection of individuals with regard to the processing of personal data.

Last updated : 2026-09-20

Site publisher

Company :
Sharik
Email :
contact@sharik.ma
Phone :
+212 661 00 00 00

Data controller

The data controller is the publishing company identified above. The processing described here is subject to the formalities required by Law 09-08 before the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP).

Data we process

Account data: your email address, and the one-time sign-in codes, which are stored as a hash and never in clear text. Card data: the name, title, company, contact details, links and images you enter. Contact data: details third parties send you through the exchange form, with the date and — only where the visitor explicitly consents — the place you met. Order data: name, delivery address and phone when you order an NFC card. Measurement data: how often your cards are viewed and shared, in aggregate.

What we do not process

We collect no banking data: orders are paid in cash on delivery or by transfer from your own bank, and no card number passes through or is stored by our systems. We use no advertising trackers and carry out no profiling.

Purposes and legal bases

Account and card data are processed to perform our contract with you: without them the service cannot be provided. Order data are processed to complete the sale and to meet our accounting and tax obligations. Measurement data serve our legitimate interest in providing usage statistics and maintaining the service. Contact data are processed on your behalf, as the user, for purposes you determine.

Cards are public by nature

A published card is accessible to anyone holding its address or the matching NFC card. Put on it only what you are content to make public. Your contacts, your statistics and your sign-in address are never public.

Recipients

Data are not sold, rented or transferred. They are accessible to authorised Sharik staff strictly within their duties, and to our technical processors: the host, the email delivery provider and the courier handling delivery, who receives only what is needed to deliver the parcel. Each processor is bound by confidentiality and acts only on our instructions.

Transfers outside Morocco

Where hosting or email delivery involves transferring data to another country, that transfer is made only to a country ensuring an adequate level of protection, or under prior authorisation from the CNDP, in accordance with articles 43 and 44 of Law 09-08.

Retention

Account and card data are kept while the account exists. On deletion the public card stops resolving immediately and the data are erased within thirty days, except accounting records relating to orders, which are kept for ten years as the regulations require. Sign-in codes expire after ten minutes. Contacts you saved are deleted with your account; export them first if you want to keep them.

Security

Traffic is encrypted in transit. Sign-in codes are stored as a hash, are single-use, short-lived and limited in the number of attempts. Access to production data is restricted to authorised personnel.

Your rights

You have the rights of access, rectification and objection set out in articles 7, 8 and 9 of Law 09-08, and the right to have your data erased. Most of these can be exercised directly from your dashboard: editing the card, exporting contacts, deleting the account. For anything else write to the address above; we reply within thirty days at the latest. You may also refer the matter to the CNDP.

Minors

The service is not intended for anyone under eighteen. We do not knowingly collect their data; any such account reported to us is deleted.

Changes

Any substantial change to this policy will be notified to you by email or on your next sign-in, before it takes effect.