قاعدة الصدق: كل بندٍ هنا مأخوذ من بنية بياناتنا الفعلية. لا نجمع شيئًا غير مذكورٍ هنا، ولا نذكر شيئًا لا نفعله.
| البيانات | لماذا |
|---|---|
| رقم المعرّف (App-ID)، الاسم المستعار، الدور | هوية حسابك داخل التطبيق |
| رمز الدخول (PIN) ورموز الاستعادة — مشفّرةً بالتجزئة، لا تُخزَّن نصًّا أبدًا | أمان الدخول والاستعادة |
| رقم الهاتف — اختياري | توثيق الحساب برمز نصّي؛ ليس شرطًا للتسجيل |
| البريد الإلكتروني (لحسابات المزوّدين والوكلاء، أو من اختار التسجيل به) | تفعيل الحساب واستعادته |
| رصيد المحفظة والنقاط وحركاتهما | الخدمة نفسها — شراء البطاقات وإعادة المال عند الاسترجاع |
| مراجع الحوالات البنكية التي تُرسلها | مطابقة الشحن — لا يُقيَّد مالٌ إلا عند التطابق التام |
| وثائق التحقق (للمزوّدين والوكلاء فقط) | التحقق القانوني من الأعمال؛ تُحفظ في خزنة خاصة يصل إليها صاحبها ومراجعو المنصة فقط |
| طلباتك وبيانات البطاقات التي أظهرتها | تسليم ما اشتريته وإثبات ملكيتك له |
| نسخة من بطاقاتك على جهازك (خزنة البطاقات) — إن اخترت ذلك | عرض بطاقاتك بلا اتصال؛ تُحفظ في التخزين الآمن لجهازك ولا تُرسل إلينا |
| الشكاوى التي تقدّمها | معالجتها والردّ عليها |
| تفضيلات اللغة والمظهر وحجم النص | تُحفظ على جهازك فقط |
سجلّات المال دائمةٌ بطبيعتها: دفترٌ يمكن الوثوق به هو دفترٌ لا يُعدَّل بصمت. رموز التحقق تنتهي في دقائق وتُخزَّن مجزّأة. وثائق التحقق تبقى ما دامت علاقة العمل قائمة. حركات الاسترجاع والإهداء تُسجَّل كأثرٍ لا يُمحى.
اطلب منّا — عبر شكوى داخل التطبيق أو بريد الدعم — أن نُطلعك على ما نحتفظ به عنك، أو أن نصحّح اسمك المستعار ورقمك، أو أن نُغلق حسابك (تبقى سجلّات المال كما يقتضي القانون وسلامة الدفتر). نجيب ضمن مهلة معالجة الشكاوى المعلنة في التطبيق.
حماية على مستوى الصفّ لكل جدول · بيانات الدخول وأسرار البطاقات مشفّرة عند التخزين · الوصول عبر وظائف خادمٍ مُراقَبة فقط · كل قرارٍ إداريّ حسّاس بعينين اثنتين ويُسجَّل.
The honesty rule: every line below is derived from our actual data model. Nothing is collected that is not listed here; nothing listed here is aspirational.
| Data | Why |
|---|---|
| App-ID, alias, role | Your account identity |
| PIN and recovery codes — hashed, never stored in plain text | Sign-in and recovery security |
| Phone number — optional | Account assurance via a text code; never required to sign up |
| Email (provider and agent accounts, or if you chose to sign up with it) | Account activation and recovery |
| Wallet and points balances and their movements | The service itself — buying cards and returning money on a refund |
| Bank-transfer references you submit | Matching your top-up — money posts only on an exact match |
| KYC documents (providers and agents only) | Legal onboarding of businesses; kept in a private vault reachable by the owner and platform reviewers only |
| Your orders and the card credentials you revealed | Delivering what you bought and proving it is yours |
| A copy of your cards on your device (the card vault) — if you choose it | Showing your cards offline; stored in your device's secure storage, never sent to us |
| Complaints you file | Resolving them |
| Language, theme and text-size preferences | Stored on your device only |
Money records are permanent by design: a ledger you can trust is one that cannot be silently edited. Verification codes expire in minutes and are stored hashed. KYC documents persist while the business relationship stands. Refunds and gifts leave an immutable trail.
Ask us — through an in-app complaint or the support address — to see what we hold about you, correct your alias or phone, or close your account (money records are retained as law and ledger integrity require). We answer within the complaint-handling promise shown in the app.
Row-level security on every table · credentials and card secrets encrypted at rest · access only through audited server functions · four-eyes governance on every sensitive administrative act.