Privacy Policy and Data Protection
Jeetak Delivery — Wait for me at your doorstep
1. Scope and controller
This policy explains how Jeetak Delivery accesses, collects, uses, shares, protects, retains and deletes personal and device data when you use the customer app, website or support channels.
It applies to the customer app and website. It does not automatically apply to the store/vendor app or delivery-man app, which may process additional data categories and need separate policies or addenda.
Jeetak Delivery platform management is the controller for processing within this policy. Contact privacy requests at info@jeetak.store or +963998864185.
2. Data sources
- Data you provide directly when registering, updating your profile, adding an address, placing an order, uploading an image or contacting support.
- Data the app or device sends automatically as needed, such as IP address, device type, OS, app version, install ID, notification token and crash/security logs.
- Data from stores, restaurants, pharmacies, delivery partners, payment providers and social login providers to fulfil orders, verify accounts, take payment or handle complaints.
3. Categories of data we process
- Account and contact: name, phone, email if provided, profile photo, account status and user ID.
- Login and verification: verification codes, access tokens and login identifiers. With Google, Facebook or Apple sign-in we may receive name, email (or private relay), account ID and photo per your choices and the provider’s settings.
- Address and location: delivery address, description, coordinates you set, access notes and delivery zone.
- Orders: items, quantities, store, amounts, fees, discounts, status, history, ratings and notes.
- Payments and wallet: wallet balance, transaction history, amount, time, status and reference. Jeetak does not store full card numbers or CVV.
- Support: messages, chats, complaints, attachments and images.
- Images and files: profile, prescription, chat, damage proof, refund evidence or other files you choose to upload.
- Device/technical: device type, OS, app version, language, IP, install IDs, notification tokens, connection/crash/performance/security logs.
- Interaction: screens/features used, app events, session duration and diagnostics needed to understand performance.
- Security and fraud: login attempts, unusual activity, fake/repeat orders and verification logs.
4. Device permissions and use
- Location (precise or approximate) while in use: to determine service areas, show the map, add an address and improve delivery accuracy. The customer app does not request continuous background location in the current behaviour.
- Notifications: order/account/operational alerts via Firebase Cloud Messaging. You can disable them in device settings.
- Camera, photos and files: for profile, chat, prescription or order/refund images. Access opens when you start the action; the app does not pick photos for you.
- Microphone and speech recognition: for voice search only when you enable the feature. OS speech services may process audio under their own policies.
- Bluetooth on Android: the customer app does not use Bluetooth permissions and they are not declared for any customer-app function.
- Internet: to reach Jeetak services for orders, login, maps, notifications, chat and realtime updates.
Permissions are requested when the related feature is needed. You may refuse or revoke them in system settings; the related feature may then stop working.
5. Purposes of use
- Create and verify accounts, sign in and manage profiles.
- Determine service coverage, show stores, add addresses, create/prepare/track/deliver orders.
- Complete payments, manage wallet, refunds, compensation, offers and loyalty.
- Send order updates, communicate with you and handle support, complaints and disputes.
- Run voice search, uploads, chat and features you choose.
- Operate realtime updates, improve stability, measure crashes/performance and understand feature use.
- Protect accounts/systems and prevent fraud, abuse and fake orders.
- Meet legal, financial and accounting obligations and respond to valid legal requests.
- Send Jeetak marketing messages where consent or another lawful basis exists, with an opt-out.
6. Location
Location is requested when choosing an address on the map, checking the delivery zone or using a place-based feature. Approximate location may set the zone; precise location may pin the delivery address. The customer app does not continuously collect location in the background in the current version and does not use precise location for personalised ads. You may refuse location and enter an address manually when available; refusal may break the map or reduce delivery accuracy.
7. Images, files and prescriptions
You upload images/files by choice (profile, chat, prescription, order issue or refund). Prescriptions are sent to the relevant licensed pharmacy for pharmacist review. Jeetak is a technical/logistics intermediary and does not diagnose or recommend treatment. Prescription images and health information are not used for advertising, marketing or commercial profiling. Images/files are kept for the purpose they were uploaded for, complaints/disputes and legal duties, then deleted or isolated under retention procedures.
8. Payments and e-wallet
Sensitive payment data is processed by the chosen payment provider. Jeetak may receive amount, status, time, reference and channel without storing full card numbers or CVV. Wallet balance and top-up/spend/refund/compensation records are kept to settle orders, prevent fraud and meet financial duties. Providers remain subject to their own policies.
9. External login
The app may allow Google, Facebook or Sign in with Apple. The provider authenticates you and may share account data you approve. Jeetak does not receive your password at that provider. Use of the provider is subject to its privacy policy and terms. You may unlink external login where available; an alternative login method may be required first.
10. Technology providers and SDKs
- Firebase Core, Authentication and Cloud Messaging
- Google Maps / geolocation / Geolocator / Location
- Google Sign-In, Facebook Login and Sign in with Apple (when chosen)
- Image Picker and File Picker
- Speech-to-Text and Permission Handler
- Pusher Channels for realtime features where enabled
- Laravel Passport access tokens on Jeetak servers for API auth
These services may process technical data such as IP, device info, install IDs, notification tokens, connection/crash logs and data needed for the feature. Jeetak is responsible for configuring them and disclosing practices in store forms.
11. Analytics, ads and tracking
Limited technical/operational data may be used to understand performance, diagnose crashes and improve features, consistent with Google Play Data Safety and Apple App Privacy disclosures. Prescription images and full payment data are not used for analytics or ads. The current build does not include a third-party behavioural ad network. If advertising identifiers or cross-app tracking are added later, this policy and store disclosures will be updated and required consent (including App Tracking Transparency on Apple when applicable) will be obtained. The website may use necessary cookies and analytics when enabled, with consent options where required.
12. Notifications and marketing
Notifications are used for order, account, security and offers you allow. You can disable notifications in device settings. Marketing can be stopped in app settings or via support; opting out does not stop operational messages needed for orders, account or security.
13. Sharing
- Delivery partners: name, phone, address, access notes and delivery details needed to fulfil the order
- Store/restaurant: name and order details needed for preparation
- Licensed pharmacy: prescription and order data needed for dispensing/delivery
- Payment providers: transaction data needed to pay or refund
- Login providers: data needed for authentication when you choose social login
- Hosting, maps, notifications, realtime, diagnostics and security providers: limited data needed for their services
- Professional advisers when needed for disputes or rights protection under confidentiality
- Public authorities when legally required
Jeetak does not sell personal data and does not allow processors to use data for undeclared independent purposes.
14. Storage and international transfers
Data is processed on Jeetak servers and technology providers’ services. Some providers may host outside Syria. When data is transferred or processed outside Syria, Jeetak limits it to what is needed and uses appropriate technical and contractual measures.
15. Retention
Retention depends on data type, purpose and operational/financial/legal duties. Account deletion does not always mean every historical record is erased at the same moment if limited retention is required for accounting, fraud prevention, disputes or law. Jeetak reviews retention periodically. When the purpose or duty ends, data is deleted, anonymised or isolated from operational/marketing use.
| Data type | Retention / action |
|---|---|
| Account and profile | Deleted from core user records when deletion succeeds, after ongoing orders finish and the request is verified |
| Access tokens / sessions | Revoked on account deletion, logout or expiry |
| Ongoing orders | Deletion blocked until orders from pending through pickup/delivery complete |
| Completed orders and transactions | May remain up to 24 months, then PII is anonymised; not reused for marketing after account deletion |
| Addresses, favourites, cart (local) | Cleared on device after successful deletion; order-linked data may remain in necessary order history |
| Chat, refund images, support files | Kept up to 12 months after related order closure or deletion request, then deleted/isolated |
| Prescriptions | Kept up to 24 months for dispensing/delivery/disputes/legal duty, then deleted; never for marketing |
| Notification tokens | While account/device is registered; cleared on invalidation or account deletion |
| Crash/security/connection logs | Up to 90 days, then deleted/anonymised |
| Backups | May retain deleted data until normal backup rotation (≤ 90 days); not used to restore a deleted account except security/disaster recovery where lawful |
16. Security
- HTTPS/TLS between app and APIs when correctly deployed
- Access tokens, revoked on account deletion, least-privilege access
- Protection of databases, files and backups; monitoring unusual access
- Limiting access to prescriptions, transaction and location data to those who need it
- Reviewing SDKs, login, notifications and permissions and keeping components updated
- Containment, investigation, remediation and notification for material incidents when required
Absolute security of internet transmission cannot be guaranteed; Jeetak applies measures reasonable for the data and risks.
17. Your rights and choices
- Request access to or a copy of account data where legally and technically available
- Correct inaccurate data or update profile and addresses
- Manage location, camera, photos, microphone and notification permissions in device settings
- Withdraw marketing consent without affecting prior processing
- Object to direct marketing and complain about processing
- Request account and related data deletion as below
Jeetak may ask for information reasonably needed to verify identity.
18. Account and related data deletion
Start deletion in the customer app via Profile → Delete account, then confirm. If you have an ongoing order (pending through pickup/delivery), deletion is temporarily refused until that order finishes — this is not a permanent refusal.
On success, access tokens are revoked, core user and profile records are deleted, and the app clears local session/cart/account data and returns to splash/location.
Completed orders and transactions are not always deleted with the account row if needed for operations, accounting, fraud prevention, disputes or law. They are restricted and not used for marketing after deletion, and direct linkage to the user is reduced where possible.
You can also start deletion outside the app at https://jeetak.store/delete-account without reinstalling.
Uninstalling the app or signing out is not account deletion. Temporary disable/freeze is not a substitute for permanent deletion. Deleted data may remain in backups until rotation and is not used to restore the deleted account except for security/disaster recovery.
19. Children’s privacy
The service is intended for persons aged 18+ with legal capacity. Jeetak does not knowingly collect a minor’s data contrary to the terms. If inappropriate collection is discovered, processing stops and non-legally-required data is deleted. A guardian may contact us for review.
20. Policy updates and store disclosures
This policy is updated when data categories, permissions, SDKs, uses or retention change. Google Play Data Safety, Apple App Privacy and iOS privacy manifest information are kept consistent with actual app behaviour and this policy. Updated versions are published on a public HTTPS URL and available in-app. Material changes may show an in-app notice.
21. Complaints, contact and language
Send privacy questions, complaints or data requests to info@jeetak.store or +963998864185.
This policy was prepared in Arabic. If a translation is provided, the Arabic text prevails on conflict unless law requires otherwise. Read it with the Terms of Use; terms do not reduce mandatory privacy rights or app-store requirements.
Contact: info@jeetak.store · +963998864185