Privacy Policy
This policy describes how Medyaf · مضياف ("we", "us", or "the platform") collects, uses, and protects your personal information when you use our services.
1. Information we collect
- Account information: Your name, email, and phone number — used to create your account and send notifications.
- Sign in with Apple: When you choose "Sign in with Apple," we receive a unique Apple identifier and, if you choose to share them, your email and name. We support Apple's "Hide My Email" feature and never see your Apple password.
- Occasion details: The information you enter about your event (date, venue, names of the people being celebrated) and the invitation-card images you design or upload.
- Guest list: Names and phone numbers of guests you add for invitations. If you choose to import them from your contacts, that access is used only for this purpose and with your consent.
- Device & notification data: A device identifier and push token (to send RSVP notifications), and anonymized crash data to improve app stability.
- Usage data: Sign-in history, in-app activity, and invitation delivery status — to improve your experience.
- Payment information: In-app purchases on iOS are processed by Apple (App Store In-App Purchase); we never receive or store your card details. Payments made through other channels (e.g. the web) are processed securely by Moyasar for local payments and Paddle.com as Merchant of Record for international payments.
2. How we use your information
- Send invitations and reminders to your guests over WhatsApp.
- Manage guest attendance and RSVP confirmations.
- Generate unique QR codes per guest and log check-ins on scan.
- Notify hosts when guests confirm or decline.
- Improve platform features and run anonymized internal analytics.
3. Information sharing
We do not sell your data or share it with advertisers. We only share information in the following cases:
- Service providers: Apple for sign-in and in-app purchases, Meta WhatsApp for message delivery, Firebase for notifications and crash data, Supabase for data storage, and Moyasar and Paddle.com for payments made through other channels — all bound by strict data-protection standards.
- Legal compliance: When required by an official government request.
4. Data security
We use SSL/TLS encryption for all communications and store data on protected servers. Passwords are hashed and phone numbers are stored securely. That said, no system is 100% secure — we commit to prompt disclosure of any potential breach.
5. Your rights
- Access and update: You can update your account information at any time from within the app.
- Deletion: You can delete your account and all your data directly in the app via Settings → Delete Account; this permanently removes your data and revokes your Sign in with Apple grant. You can also request deletion by emailing hello@medyaf.me.
- Opt-out: You can disable notifications at any time from the app's settings.
6. Data retention
We retain your account and event data for as long as you use the platform. Upon account deletion, personal data is removed within 30 days, unless the law requires us to retain it longer (e.g. billing records).
7. Children
Our platform is not directed at children under the age of 13, and we do not knowingly collect any information from them.
8. Changes to this policy
We may update this policy from time to time. We will notify you via the app or email of any material changes.
9. Contact us
For any privacy inquiry or to exercise your rights:
📧 hello@medyaf.me
📍 Riyadh, Saudi Arabia