# Privacy Policy — Concierge+
This Privacy Policy explains how **Concierge+** ("the App," "we," "us," or "our"), operated by **[LEGAL ENTITY NAME — e.g., Sanabil Technologies]** ("Company"), collects, uses, discloses, and protects information when you use the Concierge+ mobile application on iOS and Android, and the associated backend services.
If you do not agree with this Policy, please do not use the App.
---
## 1. Who We Are
Concierge+ is a personal concierge service. You gain access either through an invitation/concierge code issued by a partner company or bank, or by subscribing as an individual member. Once inside the App, you can submit requests (dining, travel, errands, events, and more), track their status, pay invoices, and chat with your concierge team.
**Data controller:** [LEGAL ENTITY NAME]
**Contact email:** [PRIVACY CONTACT EMAIL — e.g., privacy@sanabiltechnologies.com]
**Registered address:** [COMPANY ADDRESS]
---
## 2. Information We Collect
### 2.1 Information you provide directly
| Category | Examples | Why |
|---|---|---|
| Account & identity | Full name, phone number, email address (optional) | Create and secure your account; phone number is your login identifier, verified via OTP |
| Profile photo | Image from your camera or photo library | Set an optional profile picture (`avatar_url`) |
| Membership details | Concierge/invitation code, membership tier (Gold, Platinum, Diamond), affiliated company/bank | Determine which service categories, pricing, and priority apply to you |
| Language preference | English or Arabic | Display the App and communications in your preferred language |
| Optional demographic details | Age range, gender, nationality | If you choose to provide these in your profile, used to help your concierge tailor recommendations |
| Service requests | Dates, times, guest counts, locations, notes, and any fields specific to the service category you request (e.g., destination for travel, restaurant preferences for dining) | Fulfil and track the concierge request you submit |
| Support communications | Messages, subject lines, and optional file attachments you send in Support Chat (in-app, email, or WhatsApp channel) | Provide customer support and resolve your tickets |
| Payment-related records | Invoice line items, amounts (EGP), payment status, and — if you complete a payment — a transaction reference from our payment processor | Show you invoices, track payment status, reconcile transactions |
**We do not collect full payment card numbers.** When Paymob payments are enabled, card entry happens on Paymob's own secure hosted payment page (opened inside the App); Concierge+ only receives the transaction status and a reference ID, never your card number, expiry, or CVV.
### 2.2 Information collected automatically
| Category | Examples | Why |
|---|---|---|
| Push notification token | Firebase Cloud Messaging (FCM) device token | Deliver push notifications about request updates, invoices, and messages |
| Device & log data | IP address, app version, device type, timestamps of API requests | Operate, secure, and troubleshoot the service (standard server access logs) |
We do **not** use analytics or advertising SDKs, and we do **not** request location, contacts, or microphone access. The App only requests camera and photo-library access (to let you attach or set an image), and notification permission (to deliver push alerts).
### 2.3 Information from third parties
If you join via a concierge code, your affiliated bank/company may provide us your name, phone number, and tier eligibility as part of onboarding you into their corporate program.
---
## 3. How We Use Your Information
We use the information above to:
- Create, authenticate, and maintain your account (phone + OTP login)
- Process and track your concierge requests from submission to completion
- Generate, display, and process invoices and payments
- Enable communication between you and your concierge team (in-app chat, and — if you choose — email or WhatsApp)
- Send push and in-app notifications about status changes, invoices, and messages
- Localize the App into your preferred language (English/Arabic, including RTL layout)
- Maintain the security, integrity, and proper functioning of the App and backend
- Comply with legal obligations (e.g., financial record-keeping for payments)
We do **not** sell your personal information, and we do **not** use it for third-party advertising.
---
## 4. How We Share Your Information
We share information only as needed to operate the service:
- **Your concierge team / the Company** — to fulfil your requests and respond to support tickets.
- **Your affiliated bank or company** (if you joined via a corporate concierge code) — limited to what is necessary for billing and tier administration, such as your name, request activity, and usage against the plan they fund.
- **Paymob** (payment processor, Egypt) — to process payments you initiate. Paymob handles your card details directly; see [Paymob's privacy policy].
- **Firebase Cloud Messaging (Google)** — to deliver push notifications to your device.
- **Google Docs Viewer** — invoice PDF attachments you open in-app are rendered via Google's document viewer service; the PDF's URL is sent to Google for this purpose.
- **WhatsApp (Meta)** — only if you choose to continue a support conversation via the WhatsApp channel, which opens WhatsApp directly; messages sent there are subject to WhatsApp's own privacy policy.
- **Legal & safety** — where required to comply with law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of the Company, our users, or others.
We do not share your information with third parties for their own marketing purposes.
---
## 5. Data Retention
We retain your account and request data for as long as your account is active, and for a reasonable period afterward to comply with legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. You may request deletion of your account as described in Section 7.
---
## 6. Data Security
We use industry-standard measures to protect your information, including encrypted transport (HTTPS/TLS) for all App–server communication, JWT-based authentication, and secure storage of credentials on-device (`flutter_secure_storage`). No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
---
## 7. Your Rights and Choices
Depending on your location, you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your account and associated data
- Withdraw consent for optional data (e.g., profile photo, demographic details)
- Opt out of push notifications at any time via your device settings
To exercise any of these rights, contact us at **[PRIVACY CONTACT EMAIL]**. We will respond within a reasonable timeframe and in accordance with applicable law.
---
## 8. Children's Privacy
Concierge+ is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, please contact us and we will delete it.
---
## 9. International Users
Concierge+ operates primarily in Egypt, and all payments are processed in Egyptian Pounds (EGP). If you access the App from outside Egypt, your information may be transferred to and processed in Egypt or other countries where our service providers operate.
---
## 10. Changes to This Policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date above and, for material changes, provide notice through the App or by other reasonable means.
---
## 11. Contact Us
If you have questions about this Privacy Policy or how we handle your information, contact us at:
**[LEGAL ENTITY NAME]**
Email: **[PRIVACY CONTACT EMAIL]**
Address: **[COMPANY ADDRESS]**
---
### Platform-specific notes (for App Store / Google Play submission — not part of the public policy text)
- **Apple App Privacy (nutrition label):** Based on the data flows above, expected categories: *Contact Info* (name, phone, email) — linked to identity; *User Content* (photos, request details, support messages); *Identifiers* (device push token); *Financial Info* (payment status/reference only, not collected by app). No *Usage Data* or *Diagnostics* is collected since no analytics/crash SDK is integrated. No tracking (no IDFA/ATT usage).
- **Google Play Data Safety form:** Same categories apply — declare *Personal info* (name, email, phone), *Photos/Files* (avatar, chat attachments), *App activity* (request/support content), and *Device/other IDs* (FCM token). Declare data is encrypted in transit and users can request deletion.
- This document must be hosted at a **public, stable URL** (e.g., `https://conciergeapp.online/privacy`) — Apple and Google both require a live link, not a PDF upload or mailto: link.