Privacy policy

Last updated: 18 September 2026

This policy explains what data Tammat collects, why, who it is shared with, how long it is kept, and how you exercise your rights over it under Saudi Arabia's Personal Data Protection Law (PDPL) and its implementing regulations.

Who is responsible, and what this covers

This policy covers the Tammat mobile app, the tammatapp.com website, and the public outing cards that open from a shared link without an account.

Tammat is a Saudi product for discovering places and coordinating group outings. We do not sell or rent your personal data, and we do not use it for third-party targeted advertising.

The data we collect

Account data. When you sign in with Apple, Google or email, we receive a unique identifier from the identity provider along with your email address and display name where the provider supplies one. We never receive or see your password.

Your profile photo and display name. The name you choose, and an optional photo you upload from your device photo library with your permission. We re-encode the photo on our servers into two fixed sizes and strip its metadata (including capture location and time). It is kept in private, non-public storage and served through an authenticated route — it has no permanent link and no public address. You can delete it at any time from the "My profile" screen.

Your ratings of places. Stars from 1 to 5, quick-verdict tags, your answer to "would you repeat it?" (yes/no/maybe), an optional experience note, and optional visit photos. Stars, tags and the repeat answer take effect as soon as you write them; the note and the photos go through human review before they appear publicly, and rejecting a note or a photo alone does not remove your stars.

Visit verification (optional). You can prove you visited a place in one of two ways: a confirmed outing with your group, or a check of your current location at the moment you write the rating. Verification is never required to write a rating, and what is kept from it is only its method and its time, as described in the location paragraph below.

Product usage data. The groups you create, the outing plans with their places and times, voting responses, saved places, and attendance confirmations.

Guest identity on an outing card. Anyone voting from a link without an account is identified by a signed HttpOnly cookie that identifies a browser, not a person, together with the name or nickname they type for the group. We do not store raw IP addresses; where rate limiting is needed we use a short-lived, per-plan salted network fingerprint.

Location. Location permission is requested for "while using the app" only: when you choose "near me" or use your location to select a supported city, and when you choose to verify your visit while writing a rating. The coordinates are used at that moment and then discarded: they are not stored in our database, not linked to your account, and we keep no movement history. City selection converts the reading on your device into a city key that the app sends to the catalogue; "near me" sorting stays on your device. Visit verification stores two values only: the verification method (a confirmed outing, or location) and its time. Refusing the permission does not stop you browsing, or writing an unverified rating.

Technical and operational data. Server logs needed to run and secure the service. When crash reporting is configured, Tammat sends Sentry a minimized crash record containing the exception type and technical stack frames. It removes the user, request URL and headers, breadcrumbs, free-form content, contact details, invitation tokens, authentication tokens and push tokens, and disables performance tracing and session replay.

Push notifications. If you enable notifications, the app sends an Expo push token, platform, app language and an installation identifier to Tammat and links them to your account so relevant group and outing alerts can be delivered through Expo and Apple Push Notification service (APNs). On sign-out or account switch, the app attempts both to disable the token at Tammat and to unregister this installation from the notification service; a token is also disabled when it is found to be invalid. Notifications remain available in the in-app inbox independently of Push.

Reports and personal blocks. A signed-in user can report a published rating, its visibly attributed author, or another member of a shared group using a controlled reason. We keep the reporter internally for abuse control and review, but do not disclose it to the reported person. When the reporter deletes their account, we remove the identity link from the report; the anonymized report record may remain for moderation and audit. A personal block hides each person's published ratings from the other while signed in; it does not remove group membership, votes or plan results.

Account safety and identity continuity. When a moderator takes account action, we keep the suspension state, its reason, and an audit record tied to your internal account identifier. If an identity is explicitly transferred between Clerk instances after both sides are proven, we keep a server-side mapping between the old and new identifiers and a proof digest, not the raw proof. Your internal identifier and product data stay in place, and we do not link accounts because their email addresses look alike.

Support requests and suggestions. If you use “Problem or suggestion”, we save the request type and text and link it to your account, together with the app version, build number, platform and operating-system version needed to diagnose the problem. We do not collect your location, a device identifier, sign-in tokens or push tokens for this request. Full text appears in a protected support dashboard and is sent to support@tammatapp.com; Slack receives only a generic alert and the dashboard link, with neither your text nor your identity.

The "top raters" list — only if you opt in

Each city has a public list of the people who rated the most of its places with a verified visit. You appear on it only if you explicitly opt in: the default is not to appear, and we never add anyone automatically.

If you opt in, three things about you are shown and nothing else: your display name, your profile photo if you have one, and how many places you rated with a verified visit in that city. Your email, your identifier, your ratings and the names of the places you visited are not shown.

You can leave at any time from "Settings → Appearing in top raters", and leaving takes effect immediately for both the list and your photo on it. Leaving does not delete any rating you wrote.

If you apply for a business account

When you apply to manage a business we collect from you: the legal or trade name, a contact email and phone, the commercial registration number, and a proof document you upload, together with the business-terms version you accepted and the moment you accepted it. The document is required before an application can be sent for review: no application is reviewed or approved without one.

The proof document is private and is never published. It is kept in separate private storage, only our review team can open it, and no link to it is issued — not even a temporary one.

What becomes public after approval is what you publish about the business — its name and photos — not your application or its documents. The review decision and its reason reach you alone and are shown to nobody else.

Deleting your account removes your documents from storage and removes your relationship to the business. The details are in the account-deletion section below and in the business terms.

When the first publication is approved, our reviewers record the place’s location (latitude and longitude) in a record about the place, not about you, so that its location stays known after the maps provider data expires. That record is not personal data about you, and it is not deleted with your account because it does not identify you.

Why we use this data, and on what legal basis

To provide the service — creating your account, showing places, running the voting card and locking the time, and keeping your outings archive. Basis: performance of our agreement with you.

To protect the product and its users — preventing abuse, rate limiting, and reviewing reports. Basis: legitimate interest and the protection of others' rights.

For location — based on your explicit consent at the moment the permission is requested; you can withdraw it from your device settings at any time.

For legal compliance — where an applicable law requires us to retain data or provide it to a competent authority.

Who we share data with

Clerk — identity management and sign-in with Apple, Google and email.

Supabase — the database where Tammat's data is stored.

Vercel — hosting for the website and the server layer.

Google Places and Outscraper — the sources of place data. Google display content is fetched at the moment you request it and is not stored by us. The city catalog is collected in advance through Outscraper and is stored by us (place name, coordinates, public rating and a single photo) with a retention period of no more than thirty days. We send neither of them your account or identity, only the place query.

Expo and Apple APNs — delivering optional device notifications. Expo receives the push token and notification payload needed for delivery; Apple APNs delivers it to the selected device.

Sentry — minimized crash diagnostics when a public DSN is configured. Tammat removes account, contact, content, URL and token fields before a JavaScript crash event is sent; session replay and performance tracing are disabled.

Hostinger Email and Slack — support-request text and release metadata go to the approved support inbox, while Slack receives only a generic alert and a link to the protected admin dashboard, with neither the request text nor the sender’s identity.

We share your data with no one else except under a legal order, at the request of a competent authority, or with your consent.

Transfers outside Saudi Arabia

Some of the service providers above run their servers outside Saudi Arabia, so some data is processed abroad. We contract with them under data-protection terms and limit what reaches them to what is necessary to run the service.

Retention periods

Your account data and content are kept for as long as your account exists, then handled as described in the account-deletion section below.

Third-party provider data about places — the name, coordinates, rating and photo in the city catalog — is deleted within thirty days at most, and is not served once it expires. Display data fetched live from Google at request time is never stored by us.

Operational security logs and minimized crash diagnostics are kept only as long as needed for security and fault diagnosis. The exact provider-side period must be set in the approved production configuration before monitoring is enabled.

Your profile photo, your rating photos, your business photos and your business-application documents are kept while your account exists or until you delete them, and are removed from storage when your account is deleted.

Push-token records are linked to the account. Revoked or invalid tokens are excluded from delivery, and the account-deletion process removes them with the account. No fixed additional retention promise is made here.

Your rights

Under the PDPL you have the right to: be informed how your data is processed · access it · obtain a copy in a readable format · correct what is inaccurate or incomplete · request its destruction · withdraw your consent wherever processing is based on consent.

To exercise any of these rights, contact us using the details at the end of this page. You also have the right to lodge a complaint with the competent personal-data authority in Saudi Arabia (the Saudi Data & AI Authority — SDAIA).

Deleting your account

Account deletion starts inside the app: Account → Settings → Delete account. You do not need to write to us.

On deletion: your sessions and tokens are revoked, your profile photo, your rating photos, your business photos and your business-application documents are removed from storage before anything else, your open or pending plans are cancelled, your name is anonymised on what you voted, personal keys are erased from the event records tied to your plans and groups, and your identity link is removed from any report you submitted while the anonymized report may remain for moderation and audit; then your account row is deleted and your identity is deleted at the identity provider.

Deletion does not complete while any of those photos or documents remain: if they cannot be removed, deletion stops at a retryable state and we do not declare it finished.

If you were an approved business owner, your approval ends and the name and photos you published for the business are withdrawn. The business does not transfer to another user, and its data does not automatically revert to a third-party provider; returning it to provider data is a separate decision by our team.

Anything we are legally required to retain is kept only for the period the law prescribes, then deleted.

Children

The service is not directed at anyone under eighteen, and we do not knowingly collect personal data about them. If we learn that we have collected data from a minor without guardian consent, we delete it.

Security

All traffic is encrypted in transit. Neither the browser nor the app holds any administrative database key; every write passes through a trusted server layer, and row-level security rules are enforced in the database itself. No system is perfectly secure, but we treat your data on that footing.

Cookies

We use functional cookies only: the signed guest-identity cookie on an outing card, and a cookie remembering your chosen language. No advertising cookies and no third-party tracking cookies.

Changes to this policy

We may update this policy. The last-updated date appears at the top of this page, and any material change is announced inside the product before it takes effect.

Contact

Responsible entity: Khaled H Al-Mkhlfey

Email: support@tammatapp.com