Project Thunder

Privacy Policy

A clear account of the information Project Thunder uses, why it is needed, who may receive it, and the controls available to you.

Version
privacy-2026.09.1
Effective
2026-09-14

On this page

  1. 1. Who is responsible for your data
  2. 2. Brand and Iraqi operational affiliate
  3. 3. Scope and international customers
  4. 4. Data categories we collect
  5. 5. Where data comes from
  6. 6. Why we use data
  7. 7. Processing grounds
  8. 8. Accounts and authentication
  9. 9. Adult confirmation
  10. 10. RFQs, orders, service, returns and refunds
  11. 11. Optional marketing
  12. 12. Administrator CRM records
  13. 13. Cookies and browser storage
  14. 14. Turnstile and click-to-load maps
  15. 15. Service providers and recipients
  16. 16. International data transfers
  17. 17. Retention schedule
  18. 18. Short-lived files and message content
  19. 19. Security
  20. 20. Your choices and requests
  21. 21. Customer data exports
  22. 22. Account closure and data anonymization
  23. 23. Children
  24. 24. No data-broker sale or behavioral advertising
  25. 25. Policy changes
  26. 26. Contact, complaints and legal framework

1. Who is responsible for your data

Project Thunder is a trading brand fully owned, operated and managed by JIDAR AL JANNAH DWC-LLC, Registration No. 13774, at Business Centre, 3rd Floor, Building A3, Business Park, Dubai South, Dubai, United Arab Emirates. The UAE company decides how and why Project Thunder processes personal data.

2. Brand and Iraqi operational affiliate

An affiliated Iraqi Jidar Al-Jannah company may act only as a warehouse operator, fulfilment provider, local delivery coordinator, returns-handling location, or collection and operational agent when stated. It receives only information reasonably required for those functions. It is not the store owner, seller, joint seller, or controller of Project Thunder customer data.

3. Scope and international customers

This Policy applies to Project Thunder websites, accounts, inquiries, quotations, orders, delivery, service, spare-parts, returns, refunds and customer communications. We may receive international inquiries, with most anticipated purchasers in Iraq. Availability and service are confirmed for each destination and order.

4. Data categories we collect

We may process identity and contact details, company information, account preferences, addresses, adult-status evidence, authentication state, consent history, notifications, customer messages, RFQs and quotations, orders and fulfilment, transactions, service and spare-parts requests, returns, inspections, refunds, exports, closure requests, and security or audit metadata. If you choose Google sign-in, this can include the name, email address and basic profile information Google provides, such as a profile image URL. We do not need or request your full date of birth.

5. Where data comes from

Data comes from you, your authorized representatives, account and form activity, Project Thunder staff, order and service operations, authentication and infrastructure providers, delivery or fulfilment partners, and security controls. If you select Google sign-in, basic account information also comes from Google through Supabase Auth. We may derive account status, eligibility, totals and operational timelines from those records.

6. Why we use data

We use data to create and secure accounts, respond to inquiries, prepare quotations, form and perform contracts, deliver products, provide service, administer returns and refunds, meet legal and accounting duties, prevent abuse, protect rights and safety, keep reliable records, and provide customer-requested exports and closure. Marketing is optional and is handled separately.

7. Processing grounds

Depending on the activity, processing is necessary to take requested steps or perform a contract, comply with law, protect legitimate operational and security interests, respond to legal claims, or act on clear consent. Acknowledging this Policy is not consent to every processing purpose.

8. Accounts and authentication

Supabase Auth handles account credentials and sessions. If you choose Google sign-in, Google authenticates you and sends your name, email address and basic profile information to Supabase Auth to create or link your Project Thunder account. We do not receive your Google password. Project Thunder does not display or export passwords, password hashes, sessions, security tokens, recovery evidence or CAPTCHA secrets. Verification, password recovery and secure email changes use expiring, single-use controls.

9. Adult confirmation

Commercial activity requires confirmation that the customer is at least 18 years old. We store the attestation version, time, method, locale and source. Legacy accounts previously validated from a qualifying date of birth are marked by the distinct method “legacy DOB validation”; the date itself is removed.

10. RFQs, orders, service, returns and refunds

We use submitted contact and business details, product selections, messages, addresses and operational records to quote, confirm, fulfil and support transactions. Financial records retain amounts and payment status, but customer exports do not include private settlement references, operator identities, product costs or internal profit data.

11. Optional marketing

Marketing is off by default. A verified, active and unsuppressed account becomes eligible only after an affirmative opt-in under the recorded wording version. Withdrawal is immediate and append-only, and does not stop transactional account, security, order or service messages. Email unsubscribe links are expiring and safe to reuse without duplicate events.

12. Administrator CRM records

Authorized administrators may keep private notes, tags, risk reviews, suspension reasons and audit history for support, safety, fraud prevention and account administration. These records are permission-scoped, are not placed in customer HTML, and are excluded from customer exports where disclosure would undermine security, legal duties or the rights of others.

13. Cookies and browser storage

Essential Supabase authentication cookies keep signed-in sessions secure. Google sign-in also uses a short-lived, first-party security cookie for the return to Project Thunder; it expires after five minutes. Google may use its own cookies on its sign-in pages when you choose that option. First-party storage remembers language, currency and cart contents until you clear it. The current site does not use advertising cookies, behavioral tracking pixels or analytics cookies. Disabling essential storage can prevent sign-in or cart functions.

14. Turnstile and click-to-load maps

Cloudflare Turnstile is an essential anti-abuse control on protected forms. Browser, network and challenge information is sent to Cloudflare for security, not Project Thunder advertising. Protected forms cannot be submitted without successful verification. Google Maps is not loaded until you choose “Load map”; activation connects to Google and may share browser and network information.

15. Service providers and recipients

Supabase provides our production database, account authentication and private storage, with the production project configured in Central EU (Frankfurt). Hostinger provides website hosting and transactional email for sales@projectthunders.com. Cloudflare provides Turnstile security. Google receives sign-in requests only if you select Google sign-in, and Google Maps connects only if you choose to load the map. Carriers, fulfilment, delivery, installation and return-handling providers, professional advisers and public authorities may receive information when needed for their roles or legal duties.

16. International data transfers

Project Thunder is operated by a UAE company with fulfilment activities in Iraq. The production Supabase project is configured in Frankfurt, Germany; Hostinger, Google, Cloudflare and other providers may process information in their own service regions as needed to provide their services. A Frankfurt database setting does not mean every email, login or browser-security request stays in Germany. International transfers must use an applicable legal basis and appropriate contractual, technical or organizational safeguards.

17. Retention schedule

Commerce and accounting records are retained for seven years after the relevant accounting period, or longer where required. Policy acceptances are retained for seven years after supersession or closure. Unsuccessful RFQs and ordinary service correspondence are retained for three years after closure; notifications for two years; marketing history for five years; and security or audit metadata generally for two years. CRM, risk, suspension and profile/address revision records are retained while active and for two years after closure.

18. Short-lived files and message content

Customer export files are private and expire after 24 hours; minimal request metadata is retained for one year. Transactional email bodies are minimized after 90 days following final delivery or failure where operationally safe, while delivery metadata is retained for two years. Unverified registrations without protected activity are eligible for cleanup after seven days. Specific legal holds pause only the records within their documented scope.

19. Security

We use ownership checks, row-level security, server authorization, permission-scoped administration, private storage, hashed expiring tokens, request-origin controls, CAPTCHA, idempotency and audit trails. No system can guarantee absolute security. We investigate and respond to incidents according to applicable duties.

20. Your choices and requests

Subject to applicable law and lawful exceptions, you may ask to access, correct, obtain a copy of, restrict, object to, or erase or anonymize relevant personal data. You can edit supported profile fields, manage addresses, withdraw marketing, request PDF/XLSX exports and request account closure. Contact us for corrections not available in the portal or to raise a complaint.

21. Customer data exports

Exports contain customer-visible account, adult evidence, addresses, policy and marketing history, notifications, commerce, service, return, refund, closure and safe security history. They exclude credentials, tokens, raw IP or user-agent evidence, private administrator notes, internal risk logic, internal identifiers, provider settlement details, product costs, profit data and information about other people.

22. Account closure and data anonymization

Closure starts a 30-day review. Active orders, payments, returns, refunds, disputes, safety or support duties can delay anonymization. When eligible, authentication is disabled and current profile and address identifiers are scrubbed. Required transaction, invoice, refund, warranty, dispute, fraud and accounting evidence may remain in minimized or pseudonymized form. Closure is not a promise of total deletion.

23. Children

Project Thunder commercial accounts and purchasing activity are intended for people aged 18 or older. We do not knowingly invite children to create commercial accounts. Privacy, safety and support contact routes remain available where needed.

24. No data-broker sale or behavioral advertising

Project Thunder does not sell personal information to data brokers and does not use customer information for third-party behavioral advertising. External social and directions links open services controlled by those providers.

25. Policy changes

Published versions are immutable. Clarifications may be announced without forced reacceptance when they do not materially affect your position. A material change is published as a new version, is notified where appropriate, and requires fresh acceptance before future commercial activity. Earlier evidence is not rewritten.

26. Contact, complaints and legal framework

Email sales@projectthunders.com or telephone +964 773 401 6894. Operational correspondence may also be handled at Dist. 710, St. 20, H. 178 Ishtar Building, 2nd Floor, Palestine Street, Zayouna, Baghdad, Iraq. This Policy is intended to operate under applicable UAE federal and Dubai law, including UAE personal-data, consumer and electronic-commerce rules, without removing mandatory rights available in another applicable jurisdiction.

Contact Project ThunderReturn Policy
Project Thunder Logo
PROJECT THUNDER

Dist. 710, St. 20, H. 178 Ishtar Building, 2nd Floor, Palestine Street, Zayouna, Baghdad, Iraq

Email:sales@projectthunders.com
Mobile:+964 773 401 6894

CUSTOMER SERVICE

  • Track Your Order
  • Spare Parts Request
  • Return Request
  • Return Policy

RESOURCES

  • About Us
  • My Account
  • Account Log-In
  • Collaboration Request
  • Privacy Policy
  • Terms of Use
  • Privacy Choices

FOLLOW US

© 2026 Project Thunder. All rights reserved.