Skip to content

Privacy and Personal Data Processing Policy

Revision: 2026-09-14

1. Operator

The personal data operator and seller is sole proprietor Armen Barseghyan Simoni, Republic of Armenia. State registration No. 264.1380700 dated 05.04.2024; ՀՎՀՀ/TIN 73047749.

Postal address: 7 Gabriel Sundukyan Street, Yerevan 0033, Republic of Armenia. Brand: Mushroom Matters, website mushroomatters.com.

2. Data we collect

Orders and enquiries: name, phone number, email if provided, city and delivery address, apartment and entrance, contact channel and handle, order contents, amount, currency, promo code, payment and delivery statuses, and return and claim history. If you arrived via a tagged link, the order also stores the referral channel label (utm_source) — without any visitor identifiers.

Communications: message and review text, attachments, and conversation and profile identifiers in the site chat, Telegram, Instagram or WhatsApp. Telegram Mini App also provides signed launch data and available profile data.

Technical and security data: IP address, user agent, request time, URL, error logs and abuse indicators. These are needed to deliver pages, protect the site and apply rate limits. For service reliability, sanitized server logs, metrics and traces are sent to Grafana Cloud (EU, Germany) independently of the browser analytics choice, without request bodies, contact details, delivery addresses, message contents, URL parameters or secret tokens.

Order-confirmation evidence: Order, revision and protected-link identifiers, date and time, interface language, the exact activated button statement, a SHA-256 hash of the accepted immutable copy, a daily salted network hash and the user-agent string. The raw IP address is not stored in the evidence record.

3. Analytics

Only after you choose “Allow analytics” does the site create a persistent random visitor ID and a 30-minute session ID. We store pages viewed, referrer and its URL, UTM tags, language, device type, country, visit time, engagement time and scroll depth. Google Analytics, Yandex Metrica, Meta (Facebook) Pixel and Meta Conversions API may also be enabled.

We also record the product, value and cart, checkout, order-submission and waitlist events, including the link between an order and its session. IP and user agent provide country and a daily rotating salted hash; the raw IP is not stored in the analytics table.

With consent, the server may send events for an order request, the buyer’s confirmation of the final terms, and verified payment in full through Meta Conversions API. Raw contact details are not sent to Meta: email and phone are first normalized and sent only as SHA-256 hashes. Those hashes remain personal data.

If the corresponding integration is enabled, after separate consent Google Analytics may receive page views and cart and checkout events, and the server may send verified full-payment and refund events. These include the order number, products and quantities, amount, currency, event time and Google client ID/session ID to associate them with a visit. Name, phone, email and delivery address are not included in these Google Analytics events. Order numbers and technical IDs are pseudonymous data.

Grafana browser diagnostics starts only after analytics consent and when the integration is enabled. Grafana Cloud (EU, Germany) receives error types and sanitized stack locations in static JavaScript files, Web Vitals measurements and traces of HTTP requests to this same site. A random diagnostics session identifier is kept only in page memory and resets on reload, page closure or consent withdrawal. Raw error messages, console logs, session replay, page or DOM snapshots, form contents and persistent identifiers are not transmitted; URLs exclude query parameters, fragments and tokens.

This data is pseudonymous, not anonymous: an ID can be linked to an order. Its purpose is site, channel and funnel analysis, audience segmentation, and improvement of products, content, service and offers.

4. Purposes, legal bases and choice

Order and communication data is needed to answer a request, conclude and perform the contract, arrange payment and delivery, provide support, handle returns, maintain records and protect rights. The bases are pre-contractual steps, contract, legal obligations and, where needed, consent.

Confirmation evidence is processed to conclude and perform the contract, prevent disputed or duplicate actions, and protect the Buyer’s and Seller’s rights. It is not used for advertising or analytics segmentation.

Analytics is based on a separate voluntary choice in privacy settings. The order checkbox accepts the offer and acknowledges this policy; it is not analytics consent. Refusing analytics does not affect purchasing, chat, payment or delivery.

The referral channel label on an order is processed to account for sales-channel performance on the basis of the Seller’s legitimate interest. It contains no visitor identifiers and is not combined with analytics profiles without your analytics consent.

5. Cookies and browser storage

When SMS verification is enabled, opening checkout sets the necessary HttpOnly mm_checkout_phone cookie with a signed random identifier for 1 hour. It links phone verification and SMS sending limits to the current session; the phone number is not stored in the cookie. Google reCAPTCHA loads only after you choose SMS verification and may use its own security cookies. You can also place an order without SMS verification.

Necessary: mm_consent stores the choice for 180 days; the HttpOnly mm_chat cookie stores a signed chat key for 180 days; localStorage mm-cart, mm-currency and mm_instagram_shelf_locale store cart, currency and language until browser data is cleared; sessionStorage mm-utm-source keeps the referral channel label and mm-promo the entered promo code until the browser session ends; sessionStorage mm-checkout keeps an unfinished checkout draft (name, phone, e-mail, city and delivery address, preferred contact) so that reloading the page does not wipe what you already typed: the draft lives only until the browser session ends, is removed as soon as the order is submitted and stores no consents — those are given again. Blocking them may break the corresponding feature.

Analytics-only and consent-only: localStorage mm-visitor and mm-session, plus Google Analytics (_ga and others), Yandex Metrica (_ym_ and others) and Meta Pixel (_fbp, _fbc) if enabled. Meta Conversions API runs server-side and does not set a separate cookie, but no server events are sent to Meta without this consent. The “Privacy settings” button changes the choice. Refusal immediately stops analytics on the device. To complete withdrawal on the server, localStorage mm-pending-analytics-withdrawal temporarily stores only the visitor ID and session ID. The request is retried when connectivity returns or the site is opened; the record is removed after server acknowledgement. Until acknowledgement, settings show the pending status and a retry button. If the separate record cannot be stored, the original IDs are retained solely to complete withdrawal, without further analytics use.

6. Recipients and transfers

Phone verification by SMS is optional and uses Google Firebase Authentication and reCAPTCHA. When you request a code, your number is sent to and stored by Google for verification and to prevent spam and abuse across Google services; reCAPTCHA processes technical browser data to protect against automated requests. Before sending the code, we display a separate notice about this processing. The verification result is stored with the order. Declining verification, an error or an undelivered SMS does not prevent ordering: the founders can contact you using the supplied phone number or preferred contact. A repeat request triggers a warning to the founders containing the phone number.

The necessary amount of data may be received by the carrier; ACBA Bank and its payment environment; Telegram, Meta/Instagram and WhatsApp; hosting, database, security and notification providers; and, after consent, Google Analytics, Yandex Metrica and Meta Platforms (Pixel and Conversions API), if enabled. Grafana Cloud (EU, Germany) receives sanitized server telemetry for service reliability independently of the analytics choice, and browser diagnostics only after analytics consent.

External providers may process data outside Armenia and the EAEU under their terms. Choosing a channel or external analytics may result in such transfer. We do not sell personal data.

The full card number and CVC/CVV are entered in the payment provider’s secure environment and are not requested by us in chats.

7. Retention

First-party visit and event records are automatically deleted after 400 days. The browser visitor ID remains until withdrawal or browser clearing; a session ends after 30 minutes of inactivity. On our Grafana Cloud plan, logs and traces are retained for 14 days. Retention of other external-service data follows their policies.

Orders, payments, deliveries, returns and business correspondence are retained while needed to perform and prove the transaction, maintain records, provide warranties, resolve disputes and meet mandatory periods, then deleted or anonymized.

The accepted Order revision and its confirmation record are retained with the Order for the period needed to perform the contract, meet mandatory recordkeeping and defend possible claims; the 400-day analytics period does not apply to them.

Withdrawal immediately stops browser analytics. After acknowledging the request, the server removes the analytics link from saved orders and cancels unsent Meta Conversions API events; until then, only the record needed to retry the request is retained. Server analytics records collected before withdrawal remain for up to 400 days unless deleted earlier following a verified request.

8. Rights

You may request information and a copy, correction, blocking or deletion, object and withdraw consent. Limits may apply by law, to protect rights or resolve a dispute. Withdrawal does not undo lawful processing before withdrawal.

Request via mushroomatters@gmail.com or another contact in Section 10. We may reasonably verify identity. You may complain to the personal-data protection authority of Armenia or another competent authority.

9. Security and automation

Measures include HTTPS, restricted HQ access, signed HttpOnly chat cookies, rate limits and action logs. Absolute transmission or storage security cannot be guaranteed.

Analytics may produce segments and more relevant offers, but we do not make solely automated decisions with legal or similarly significant effects.

10. Contacts and changes

For data questions: +374 44 605058, mushroomatters@gmail.com, Telegram @mushroomatters, Instagram @mushroomatters. Postal address is in Section 1.

The current version is published on mushroomatters.com. If analytics scope or purpose changes, we will ask again. Effective date: 13 September 2026.