Template — to be reviewed when the company is registered. Rawad is an online service in beta and is not a registered company yet.

Privacy Policy

Version: 2026-10-08 · Rawad (رواد) — online service, beta

What we collect, why, where it is kept and your rights.

1. Who processes your data

If you are an employee or user of a company that uses Rawad, your company is the controller of your data and Rawad processes it on its behalf. Rawad is an online service in beta and is not a registered company yet.

2. What we collect

Account data (name, email, hashed password, two-step secret, sessions and known devices); what the company enters about its employees, customers and suppliers; check-in location only with your consent; feedback you send from the app (text, page and your role, and a screenshot if you attach one); technical security records (internet addresses, attempt counters); and aggregate usage counts with no content.

3. Why we use it

Only to provide the service, support and security. We do not sell data, use it for advertising or set trackers; cookies are essential only (session, language, theme, country choice).

4. Where it is kept and who receives it

Data is hosted in Germany with Hetzner (EU), encrypted, backed up daily and isolated per company. Regional hosting is planned, with no date set. Cloudflare receives requests in transit; Resend (Ireland) receives recipients' names, addresses and the notification text to send email; browser push services receive a notification's title and link only. The password check (Have I Been Pwned) receives no personal data.

5. Check-in location

Your location at check-in is recorded only with your explicit consent inside the app, given once and kept with its date and text version, in addition to the browser permission. You can withdraw it at any time from “My space”; check-in works without location, and your company then sees “no location consent”.

6. How long we keep it

Payroll and accounting records: 10 years by default, a period the company sets. Sessions 7 days; failed sign-ins 24 hours; known devices and attempt counters for short periods; error reports 90 days; feedback and pilot requests until handled, then 12 months; usage counts 12 months.

7. Your rights

To see your data and download a copy (from “My account”), to ask your company to correct or delete it, and to withdraw your consent to location and notifications, under your country's personal data protection law. Requests that reach us directly are passed to your company, the controller.

8. Breaches

If a breach affects your data we notify your company without delay; it informs you and the authority where its law requires.

9. Contact

For any privacy question: [email protected] (email only).

Sub-processors

WhoCountryRoleWhat it receives
Hetzner Online GmbHGermanyHostingAll data: the database, files and the on-server backups
Cloudflare, Inc.Global network (United States)Network edge: protection and passing the encrypted connectionRequests in transit and internet addresses; no content is stored there
ResendIrelandSending emailRecipients' names, email addresses and the notification text
Google · Apple · MozillaDepends on the user's browserBrowser push servicesThe notification's title and link only — never amounts or personal details
Have I Been Pwned—Leaked-password checkNo personal data: only the first 5 characters of the password's hash
Beta