Back to the site

Privacy Policy

Last updated 28 July 2026

This policy explains what personal data the platform handles, why, where it sits and who else touches it. It covers two different groups of people: the pilgrims whose permits are processed, and the staff at an agency who use the platform.

1Who is responsible for what

For pilgrim data, your agency is the controller and we are a processor: you decide whose documents are uploaded and why, and we act on your instructions. Our contract with you sets those instructions.

For the accounts of your own staff, and for our billing records, we are the controller.

2What we handle about pilgrims

Extracted from the documents you upload: full name, passport number, visa number, application number, permit number, nationality and date of birth.

Set by you: the travel window for the group, the group name, and the guide’s name and phone number where you provide one.

Created by the platform: a mailbox provisioned for the pilgrim, a Nusuk account, the verification codes received in that mailbox, appointment details, the entry QR issued by Nusuk, and a timeline of every action taken.

3What we handle about your staff

Name, email address, the agency they belong to and their role, through our authentication provider. We also log which operator performed which action, so that an entry in a pilgrim’s timeline can be attributed to a person rather than only to the platform.

4Why we handle it

Solely to deliver the service you have asked for: obtaining a Rawdah or Umrah appointment for a named pilgrim and delivering their pass. We do not use pilgrim data to train models, we do not sell it, and we do not share it for anyone’s marketing.

5Where it is held

Pilgrim records are held inside the Kingdom of Saudi Arabia, on infrastructure in the Jeddah region. The database is partitioned by agency so that one agency cannot reach another’s records, and uploaded documents and rendered passes are stored on the same infrastructure under the same partitioning.

Two things leave the Kingdom, and only these two: encrypted database backups, and optional monitoring data that has personal data stripped from it before it is sent. Both are set out in the sections below.

6Who else touches it

We use a small number of providers to run the service. Each receives only what its function requires.

ProviderPurposeWhat it sees
NusukPermit registration and appointment bookingPilgrim identity and permit details, as required to make the booking
Oracle Cloud (Jeddah)Hosting the platform, its database and its stored documentsAll pilgrim records and documents, held inside the Kingdom
QeexProvisioning mailboxes and receiving verification codesThe mailbox and its messages; no passport or visa data
ClerkSigning in your staffStaff name, email, agency and role. No pilgrim data
CloudflareDNS, the tunnel that reaches our origin, and protecting the platformEncrypted traffic in transit
Cloudflare R2Off-site encrypted database backupsA full encrypted copy of the database, held outside the Kingdom
Datadog (optional)Error and performance monitoringOperational metrics and logs, stripped of personal data before they leave the platform. Held outside the Kingdom
Network egress providerRouting our requests to NusukEncrypted traffic only; no stored personal data

We name every provider that receives personal data. The one exception is the network egress provider, which carries encrypted traffic in transit and stores nothing; we describe it by function because naming it would disclose operational detail without telling you anything further about who holds your pilgrims’ data.

7Pass links

Each pilgrim receives a private link. The link itself is the credential: anyone holding it can open that pass, which is why the page shows masked names and partial permit numbers rather than full records, refuses to be indexed by search engines, and does not pass the link on to any third party when the pilgrim taps away from it.

A link can be protected with a passcode you set, and can be revoked at any time. When a passcode is used, the pilgrim’s device stores a small signed cookie so that they are not asked again on that device. That cookie contains no personal data.

The pass page caches itself on the pilgrim’s device so that it still opens at the gate without a network connection. That copy sits on their phone and is cleared with their browser data.

8How long we keep it

Pilgrim records are retained for the season they belong to and then deleted on your instruction, or after 12 months by default.

Documents you upload and passes we render are deleted on the same schedule as the records they belong to.

Diagnostic records of upstream responses are retained for 30 days and then deleted. The audit timeline is retained for 12 months, on the same schedule as the record it describes, so that nothing about a pilgrim outlives the record we told you we had deleted.

Where an agreement ends, records remain available for export for 90 days and are then deleted on the schedule above. Encrypted backups are rotated and a deleted record leaves the backup set as that rotation completes.

9Security

Pass link tokens are encrypted at rest, so a database read alone does not open anyone’s pass. Passcodes are stored only as slow hashes, never in a readable form. Access to the platform is limited to your own agency’s data and every action is attributable.

Data in transit is encrypted. Monitoring data that leaves the platform is stripped of personal data first.

10Rights

Pilgrims have rights over their personal data, including access, correction and deletion. Because you are the controller, a pilgrim should approach your agency, and you should ask us — we will help you answer within the time the law allows.

You can export a batch in full at any time, and request deletion at any time.

11Transfers outside the Kingdom

Pilgrim records, documents and passes are processed inside the Kingdom and are not transferred out of it in the ordinary course of the service.

Two limited transfers do occur. Encrypted database backups are stored with Cloudflare R2 outside the Kingdom; they are encrypted, held solely so that the service can be restored after a failure, and are never used for any other purpose. Where monitoring is enabled, operational metrics and logs are sent to Datadog outside the Kingdom, after personal data has been stripped from them at source.

Both transfers are made to serve the continuity and security of the service you have asked us to provide, and each provider is bound by its own contractual data protection commitments. If you require that no data whatsoever leaves the Kingdom, tell us before you begin: monitoring can be disabled, and backup arrangements can be discussed.

12Changes and contact

We will post any change here and, where it materially affects you, tell you directly.

Data protection contact: privacy@rawdahpass.com.