Last updated: May 2026. Questions? hello@mesraq.com
Mesraq is an Ethiopian business directory built by and for the Habesha community. This policy explains what information we collect, how we use it, and what choices you have. We've written it in plain language — if something is unclear, email us.
What we collect. When you sign up for Mesraq, we ask for your city. This is the only location data we store — a city name (e.g. "Washington DC", "Addis Ababa"). We do not collect GPS coordinates, IP-derived location, or any fine-grained location information.
Why we collect it. We use your city to power our community map, which shows city-level aggregate counts (e.g. "234 members in Washington DC"). We also use it to understand where the community is growing and, in the future, to suggest locally relevant content and businesses near you when you visit Ethiopia.
What we show publicly. We show only aggregated counts per city. We never display your individual location on any public page. Your name is never associated with a city label anywhere on the platform.
What we don't do. We never sell location data. We never share it with third parties for advertising or data brokering. We never use it to build profiles for targeting.
Your control. You can update or remove your city at any time in Settings → Profile. If you remove it, you are removed from the community map immediately.
We do not send marketing email without your explicit opt-in. We do not use your data to train AI models.
Photos attached to reviews are stored in Supabase Storage and are publicly accessible via URL — anyone who visits the business page can see them. Your display name appears as attribution next to your photos.
Business owners can upload photos to their highlight reels, which are similarly public. If you want a photo removed, contact us at hello@mesraq.com and we'll handle it promptly.
Mesraq uses Supabase for database and authentication, hosted on AWS infrastructure. Data is stored in the EU (Frankfurt) region by default. Supabase maintains SOC 2 compliance and encrypts data at rest and in transit.
Row-level security policies in our database ensure that users can only read and write their own private data. All API access requires authentication.
You can:
If you are in the European Economic Area, you have additional rights under GDPR. We honour all GDPR data subject requests regardless of your location.
Mesraq is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has created an account, contact us and we will delete it.
If we make material changes to this policy, we will notify signed-in users by email at least 14 days before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.
Questions, concerns, or data requests: hello@mesraq.com
We are a small team and we read every message.