Privacy Policy
This policy explains what personal data the platform handles, why, where it sits and who else touches it. It covers two different groups of people: the pilgrims whose permits are processed, and the staff at an agency who use the platform.
1Who is responsible for what
For pilgrim data, your agency is the controller and we are a processor: you decide whose documents are uploaded and why, and we act on your instructions. Our contract with you sets those instructions.
For the accounts of your own staff, and for our billing records, we are the controller.
2What we handle about pilgrims
Extracted from the documents you upload: full name, passport number, visa number, application number, permit number, nationality and date of birth.
Set by you: the travel window for the group, the group name, and the guide’s name and phone number where you provide one.
Created by the platform: a mailbox provisioned for the pilgrim, a Nusuk account, the verification codes received in that mailbox, appointment details, the entry QR issued by Nusuk, and a timeline of every action taken.
3What we handle about your staff
Name, email address, the agency they belong to and their role, through our authentication provider. We also log which operator performed which action, so that an entry in a pilgrim’s timeline can be attributed to a person rather than only to the platform.
4Why we handle it
Solely to deliver the service you have asked for: obtaining a Rawdah or Umrah appointment for a named pilgrim and delivering their pass. We do not use pilgrim data to train models, we do not sell it, and we do not share it for anyone’s marketing.
5Where it is held
Pilgrim records are held inside the Kingdom of Saudi Arabia, on infrastructure in the Jeddah region. The database is partitioned by agency so that one agency cannot reach another’s records, and uploaded documents and rendered passes are stored on the same infrastructure under the same partitioning.
Two things leave the Kingdom, and only these two: encrypted database backups, and optional monitoring data that has personal data stripped from it before it is sent. Both are set out in the sections below.
6Who else touches it
We use a small number of providers to run the service. Each receives only what its function requires.
| Provider | Purpose | What it sees |
|---|---|---|
| Nusuk | Permit registration and appointment booking | Pilgrim identity and permit details, as required to make the booking |
| Oracle Cloud (Jeddah) | Hosting the platform, its database and its stored documents | All pilgrim records and documents, held inside the Kingdom |
| Qeex | Provisioning mailboxes and receiving verification codes | The mailbox and its messages; no passport or visa data |
| Clerk | Signing in your staff | Staff name, email, agency and role. No pilgrim data |
| Cloudflare | DNS, the tunnel that reaches our origin, and protecting the platform | Encrypted traffic in transit |
| Cloudflare R2 | Off-site encrypted database backups | A full encrypted copy of the database, held outside the Kingdom |
| Datadog (optional) | Error and performance monitoring | Operational metrics and logs, stripped of personal data before they leave the platform. Held outside the Kingdom |
| Network egress provider | Routing our requests to Nusuk | Encrypted traffic only; no stored personal data |
We name every provider that receives personal data. The one exception is the network egress provider, which carries encrypted traffic in transit and stores nothing; we describe it by function because naming it would disclose operational detail without telling you anything further about who holds your pilgrims’ data.
7Pass links
Each pilgrim receives a private link. The link itself is the credential: anyone holding it can open that pass, which is why the page shows masked names and partial permit numbers rather than full records, refuses to be indexed by search engines, and does not pass the link on to any third party when the pilgrim taps away from it.
A link can be protected with a passcode you set, and can be revoked at any time. When a passcode is used, the pilgrim’s device stores a small signed cookie so that they are not asked again on that device. That cookie contains no personal data.
The pass page caches itself on the pilgrim’s device so that it still opens at the gate without a network connection. That copy sits on their phone and is cleared with their browser data.
8How long we keep it
Pilgrim records are retained for the season they belong to and then deleted on your instruction, or after 12 months by default.
Documents you upload and passes we render are deleted on the same schedule as the records they belong to.
Diagnostic records of upstream responses are retained for 30 days and then deleted. The audit timeline is retained for 12 months, on the same schedule as the record it describes, so that nothing about a pilgrim outlives the record we told you we had deleted.
Where an agreement ends, records remain available for export for 90 days and are then deleted on the schedule above. Encrypted backups are rotated and a deleted record leaves the backup set as that rotation completes.
9Security
Pass link tokens are encrypted at rest, so a database read alone does not open anyone’s pass. Passcodes are stored only as slow hashes, never in a readable form. Access to the platform is limited to your own agency’s data and every action is attributable.
Data in transit is encrypted. Monitoring data that leaves the platform is stripped of personal data first.
10Rights
Pilgrims have rights over their personal data, including access, correction and deletion. Because you are the controller, a pilgrim should approach your agency, and you should ask us — we will help you answer within the time the law allows.
You can export a batch in full at any time, and request deletion at any time.
11Transfers outside the Kingdom
Pilgrim records, documents and passes are processed inside the Kingdom and are not transferred out of it in the ordinary course of the service.
Two limited transfers do occur. Encrypted database backups are stored with Cloudflare R2 outside the Kingdom; they are encrypted, held solely so that the service can be restored after a failure, and are never used for any other purpose. Where monitoring is enabled, operational metrics and logs are sent to Datadog outside the Kingdom, after personal data has been stripped from them at source.
Both transfers are made to serve the continuity and security of the service you have asked us to provide, and each provider is bound by its own contractual data protection commitments. If you require that no data whatsoever leaves the Kingdom, tell us before you begin: monitoring can be disabled, and backup arrangements can be discussed.
12Changes and contact
We will post any change here and, where it materially affects you, tell you directly.
Data protection contact: privacy@rawdahpass.com.