Data Safety
At a glance
- Data sold: none. Ever.
- Data shared for advertising: none. There are no ad networks, ad IDs, or trackers in the app.
- Encryption: all data is encrypted in transit (TLS) and at rest.
- Deletion: you can delete your account and data from inside the app, or from the web form — no email request needed.
- Optional by default: location, camera, photos, and notifications are all refusable, and the app still works.
1. How to read this page
App stores require a short, standardised summary of what an app collects. This page is the long version of that summary — the same disclosures, with the reasons attached. It is a companion to the Privacy Policy, which is the binding document.
- Collected means the data leaves your device and reaches our servers.
- Shared means it is passed to a company that is not acting purely as our processor.
- Optional means you can use the app without providing it.
2. Data the app collects
2.1 Personal information
| Data type | Collected | Shared | Optional | Purpose |
|---|---|---|---|---|
| Phone number | Yes | With travel suppliers for your booking only | No — it is your sign-in | Account creation, sign-in, booking contact |
| Name | Yes | With travel suppliers for your booking only | Optional for profile; required per traveller on a booking | Addressing you, ticketing and visa processing |
| Passport number, date of birth, nationality, gender | Yes | With airlines, visa agents, and destination authorities | Only if you make a booking | Visa, ticketing, and pilgrimage registration |
| Email address | No | — | — | Not used by the consumer app |
| Alternate contact number | Yes | No | Optional | Backup contact for urgent travel matters |
2.2 Financial information
| Data type | Collected | Shared | Optional | Purpose |
|---|---|---|---|---|
| Payment proof / receipt image | Yes | No | Only if you pay for a booking | Confirming your payment against your booking |
| Wallet ledger, holds, refunds | Yes | No | Only if you use the wallet | Tracking what you paid and what is owed |
| Card number, CVV, bank password, banking OTP | Never | — | — | The app takes no card payments and has no field for these |
2.3 Location
| Data type | Collected | Shared | Optional | Purpose |
|---|---|---|---|---|
| Precise location (while using the app) | Used on device; not stored on our servers | No | Optional | Qibla direction and prayer times, computed locally |
| Approximate location (~1 km grid) | Yes, transiently | Coordinates only, to the weather provider | Optional | Local weather. Coordinates are rounded before caching so the record cannot pinpoint you, and carry no account identifier |
| Background location | Never | — | — | The app does not track you when closed |
2.4 Photos, files, and camera
| Data type | Collected | Shared | Optional | Purpose |
|---|---|---|---|---|
| Profile photo | Yes | No | Optional | Shown to you and to staff on your booking |
| Passport and document images | Yes | With visa agents and authorities as your booking requires | Only if you make a booking | Visa and ticket processing, document verification |
| Camera stream (AR Qibla, document scanning) | No | No | Optional | The live camera feed stays on your device. Text recognition runs on-device; only the still image you confirm is uploaded |
| Photo library contents | No | — | — | We receive only the individual file you pick |
2.5 App activity and diagnostics
| Data type | Collected | Shared | Optional | Purpose |
|---|---|---|---|---|
| Crash logs | Yes | Processed by Firebase Crashlytics on our behalf | No (release builds) | Diagnosing and fixing crashes |
| App interactions, screen views, session data | Yes | Processed by Google Analytics for Firebase on our behalf | No | Aggregate product measurement — never used for advertising or sold |
| Device model, OS version, app version, language | Yes | No | No | Compatibility, update gating, correct-language messaging |
| Push token and installation ID | Yes | To Google FCM and Apple APNs for delivery | Tied to the notification permission | Delivering booking notifications to your device |
| Active-day counters | Yes | No | No | Counting active users. A list of dates, not a log of your actions |
| Problem reports you submit | Yes | No | Optional | Support and bug fixing |
| Advertising ID | Never | — | — | The app contains no advertising SDK |
3. Data we do not collect
- Contacts, address book, or call logs
- SMS message contents (the sign-in code is read only as a one-time code, on supported devices)
- Microphone audio, or any recording
- Health, fitness, or biometric data
- Browsing history from outside the app
- Installed-app inventory
- Advertising identifiers, or any cross-app tracking identifier
- Race, religion-as-a-profiling-attribute, political opinions, or any similar profiling category
4. Sharing
We do not sell data and we do not share it for advertising. Data leaves our systems in exactly three situations:
- Processors acting for us — Google Firebase and Google Cloud host the service; Crashlytics and Analytics process diagnostics; FCM and APNs deliver notifications; WeatherAPI.com returns forecasts for approximate coordinates.
- Travel fulfilment — airlines, hotels, transport and ziyarat operators, visa agents, insurers, and the Saudi authorities receive the traveller details needed to deliver the trip you booked.
- Legal obligation — where a regulator, tax authority, court, or law enforcement lawfully requires it.
The full list, with what each recipient receives, is in Privacy Policy §9.
5. Security practices
- Data is encrypted in transit with TLS.
- Data is encrypted at rest in Google Cloud storage and databases.
- Passwordless sign-in by verified phone number — no password database exists to be stolen.
- Per-record access rules: your data is readable only by you and by authorised staff, enforced server-side.
- App Check attestation rejects requests that do not come from the genuine app.
- Uploaded files are validated by content type and scanned before they are accepted; rejected files are deleted automatically.
Detail: Security.
6. Deletion and retention
- In the app: Settings → Delete account.
- On the web: aomadinah.com/privacy — verify your phone number by SMS and delete, without needing to install the app.
Deletion removes your account, profile, traveller records, passport and receipt images, wallet history, devices, and activity counters. Booking and accounting records that we must keep are stripped of your name and phone number. The retention table is in Privacy Policy §11.
7. Permissions the app requests
| Android / iOS permission | When it is asked for |
|---|---|
| INTERNET | Always — required for any online feature |
| POST_NOTIFICATIONS | When you opt in to booking updates |
| CAMERA | AR Qibla, profile photo, passport or receipt capture |
| ACCESS_FINE_LOCATION / ACCESS_COARSE_LOCATION | Qibla direction and local weather, while the app is open |
| Photo library (iOS) / media selection (Android) | Only when you pick an existing image |
The app declares no background-location, contacts, microphone, SMS-read, or call-log permission.
8. Families and children
The app is rated for a general audience and is intended for adults arranging travel. It contains no ads, no in-app purchases of digital content, and no user-to-user social features. A child's traveller details may be entered by their parent or guardian for a booking; see Privacy Policy §15.
9. Questions
If anything here does not match what you see in the app, tell us — support@aomadinah.com. We would rather correct this page than leave it inaccurate.