Privacy Policy
Last updated: 20 September 2026
This Privacy Policy explains how the Tiaar platform ("Tiaar", "we", "us") collects, uses, discloses, and safeguards personal data when you use our services: the Tiaar customer and driver mobile applications, the merchant portal, and the platform's operations services. It applies in Arabic and English, wherever Tiaar operates.
01Who we are and how to reach us
The data controller for the data described below is [Operator Legal Name], the company operating the Tiaar platform, with registered address [Registered Address], Egypt. You can contact us at any time through the Contact Us page, or by writing to [Data Protection Email].
02Data we collect
We collect the following categories of personal data, depending on how you use the platform:
- Account data: name, email address, phone number, and authentication credentials (passwords are stored only as bcrypt hashes).
- Location data: customers' delivery addresses; drivers' real-time location while on duty, used for dispatch and live tracking.
- Order and transaction data: orders, rides, and deliveries, their status and lifecycle, wallet balances, top-ups, commissions, and payout records.
- Payments data: card payments are processed by our payment partners (such as Paymob) on their own secure pages; we never store full card numbers.
- Identity documents: government IDs and licence information provided by drivers during onboarding, and prescription information handled by partner pharmacies for regulated orders.
- Device and communications data: device identifiers and push notification tokens, IP address, and messages you exchange with our support team.
- Activity data: audit logs of actions performed in the merchant portal and operations console, recorded with timestamps.
03How we use your data
- Operate the platform: place and deliver orders, dispatch drivers, and keep live order state accurate.
- Process payments, wallet top-ups, commissions, and settlements.
- Verify identity during onboarding of drivers and merchants, for safety and regulatory compliance.
- Send operational notifications: order updates, OTP verification codes, and service notices.
- Provide customer support and resolve disputes.
- Keep the platform secure, prevent fraud, and maintain audit trails.
- Meet legal, regulatory, and accounting obligations.
04Legal bases for processing
Where required by law, we rely on the following bases: performance of a contract (delivering the service you requested), our legitimate interests in operating and securing the platform (dispatch, fraud prevention, audit logging), compliance with legal obligations (record keeping and regulatory requirements), and your consent where explicitly requested (for example, optional marketing communications and continuous location sharing in the driver app), which you may withdraw at any time.
05Sharing and processors
We do not sell personal data. We share it only with service providers that process data on our instructions, including:
- Cloud hosting and infrastructure (Google Cloud, European Union region).
- Payment processors operating card payments and payouts (such as Paymob).
- Map and location services (Google Maps) used for addressing, routing, and ETAs.
- Push notification and SMS providers used for verification codes and service updates.
- Public authorities, where disclosure is required by law or to protect vital interests.
06International data transfers
The platform's primary infrastructure is hosted in the European Union (Belgium). Data may be accessed from Egypt for support and operations purposes. We apply safeguards consistent with the Egyptian Data Protection Law (Law No. 151 of 2020) for such transfers.
07Data retention
We retain your account data for as long as your account is active, location data for the period needed for dispatch, support, and dispute resolution, and transaction, commission, and payout records for the periods required by accounting and tax law. After the applicable periods, data is deleted or anonymised.
08Security
We protect personal data with encryption in transit, hashed credentials, strict role-based access control, signed access to private documents and media, and comprehensive audit logging. Identity documents are stored with restricted access. No method of transmission or storage is completely secure, so we continuously review and improve our safeguards.
09Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion of data we no longer have a lawful basis to keep, subject to our statutory record-keeping duties.
- Object to or restrict certain processing, and withdraw consent where processing relies on it.
- Lodge a complaint with the competent data protection authority.
10Children
Tiaar's services are not directed at children. Accounts are provided only to individuals aged sixteen or older; use by minors of payment or ride services must be arranged by a parent or guardian in accordance with applicable law.
11Changes to this policy
We may update this policy to reflect changes in our practices or the law. The "Last updated" date at the top of this page shows the current version, and material changes will be communicated through the apps and portals.
Questions about this policy? Reach us any time through the Contact Us page.