Privacy Policy
Not approved for final publication
The technical data-flow disclosure below is ready for review, but the owner and legal decisions listed here are still required. Release packaging is blocked until every item is approved in English and Arabic.
- Data-controller legal identity
- Controller contact and legal address
- Governing jurisdiction and applicable privacy framework
- Exact retention schedule by data category
- Approved recipients, service roles, subprocessors, and transfer locations
- Analytics notice, consent, and opt-out model
- Tracking, advertising, and cross-context use classification
- Minimum age and child-account rule
- Payment flow, provider, and payment-data handling
- Account-deletion request completion timeline
This policy covers the Kelshi website and Kelshi mobile applications. It describes the data flows observed in the current products, including account, location, marketplace, booking, pharmacy, and analytics features.
The sections below combine observed technical data flows with the approved legal and product decisions recorded for this release.
Controller and scope
Kelshi provides marketplace, service-discovery, booking, ordering, saved-item, search, notification, and account features across web and mobile.
- Data-controller legal identity: Pending owner and legal approval.
- Controller contact and legal address: Pending owner and legal approval.
- Governing jurisdiction and applicable privacy framework: Pending owner and legal approval.
Account, contact, authentication, and uploaded content
We process information you provide to create, authenticate, support, and maintain an account or to contact a provider.
- Name, email address, phone number, profile information, address, city or area, account identifiers, and authentication/session records.
- Google, Apple, or other enabled sign-in providers may return a provider identifier, name, email address, and authentication credential needed to sign in or link an account. Kelshi does not infer or guess email ownership from a social identity. After verified account deletion, provider email and provider metadata are removed; where technically required to prevent reassignment of a retired social identity, Kelshi retains only a non-reversible keyed hash of the former provider identifier.
- Profile photos, listing images, support messages, reports, reviews, and other content you choose to submit.
Precise location and maps
When you permit a location feature, the reviewed clients can obtain latitude and longitude to show nearby results, calculate distance, open maps, resolve a city or address, and support delivery.
- Coordinates may be held temporarily in browser session storage or in mobile-device preferences and may be sent to Kelshi APIs with search, listing, healthcare, delivery, or filtering requests.
- Mobile location flows may send coordinates to configured external reverse-geocoding or region-resolution services. Embedded maps or map actions may also contact an external map provider.
- The reviewed mobile permission text says location is used while the app is in use and not for background tracking; final store disclosures must remain aligned with the shipped binary.
Orders, delivery, bookings, and health-related information
Kelshi processes the details needed to operate carts, orders, bookings, appointments, pharmacy requests, and related support.
Health-related booking fields are used to submit the requested appointment, test, pharmacy order, or supporting document to the Kelshi workflow. The final approved recipient classification and retention schedule govern any further access and storage.
- Cart contents, quantities, saved items, provider or service selection, booking date and time, traveler names or seats, order notes, and order or booking status.
- Delivery or billing contact details such as name, email, phone, street, city or area, and delivery coordinates.
- Healthcare-provider appointments, selected tests or services, pharmacy products, and prescription images when a product requires a prescription. These actions can reveal health-related interests and must be handled as sensitive data.
- Radiology and healthcare booking forms can collect a birth date, national number, and an insurance card or medical image, together with name, phone, email, selected service, and appointment details.
- These sensitive fields support the requested booking or pharmacy workflow. Which selected healthcare provider, fulfillment party, or other recipient may receive them remains bound to the approved recipients decision; their exact storage period remains bound to the approved retention schedule.
- The current reviewed clients expose order and billing-address flows. The approved payment decision below identifies any payment provider and payment-data handling for released products.
- Payment flow, provider, and payment-data handling: Pending owner and legal approval.
- Approved recipients, service roles, subprocessors, and transfer locations: Pending owner and legal approval.
- Exact retention schedule by data category: Pending owner and legal approval.
Saved items, search, usage, and analytics
We process marketplace choices and technical usage information to provide requested features, keep sessions working, and diagnose failures. Optional analytics collection starts only after explicit opt-in and can be disabled afterward; core features do not require analytics consent.
- Saved or favorite items, cart activity, search terms, result counts, filters, categories, listings and providers viewed, and contact, map, share, banner, or navigation interactions.
- Website analytics can include the full page URL (including its query string), page path, referrer, campaign parameters, browser user agent, language, direction, timestamps, error signals, and a session or guest identifier. The Backend does not retain or persist a raw visitor IP address in analytics records.
- When mobile analytics is enabled, an event can include a generated device identifier, app version and build, platform and operating-system version, screen or route, timestamps, error signals, and notification receipt or open interactions.
- Only when a device registers for push notifications can registration send a push token, generated device identifier, app version/build, platform or operating-system label, locale, and timezone needed to address and diagnose that device registration.
- Analytics events may include a session or guest identifier and, for signed-in mobile users, an account identifier. Reviewed analytics code removes email-, phone-, password-, token-, authorization-, and secret-named metadata fields.
- Analytics transport is configuration-gated and disabled by default in the reviewed clients. In production, collection remains off until the user explicitly opts in and stops after the user withdraws that choice.
- Analytics notice, consent, and opt-out model: Pending owner and legal approval.
- Tracking, advertising, and cross-context use classification: Pending owner and legal approval.
Why we use information
- Provide and secure accounts, authentication, profiles, search, saved items, carts, bookings, appointments, orders, delivery, notifications, and support.
- Return nearby or relevant results, calculate distance, resolve location labels, and open requested maps or contact actions.
- Prevent abuse, investigate errors, protect the service, meet applicable obligations, and improve reliability and accessibility.
- Measure product and campaign interactions only under the final approved analytics model.
Storage, retention, and deletion
Data may be stored in Kelshi backend systems and, depending on the feature, in browser local/session storage or mobile preferences, secure session storage, offline databases, and bounded analytics queues.
You can use the localized Delete Account page for the current in-product and manual request steps. Deletion may not remove records that must be retained for a valid legal, security, fraud-prevention, or transaction reason.
- The approved retention periods for accounts, transactions, health-related uploads, support/security records, and analytics appear below.
- Exact retention schedule by data category: Pending owner and legal approval.
- Account-deletion request completion timeline: Pending owner and legal approval.
External services and recipients
A requested feature may involve an authentication provider, map or geocoding service, region-resolution service, hosting or storage service, communications channel, or another service needed to operate Kelshi. Each external service may process the data sent to it under its own terms.
- The technical review observed social sign-in integrations, external map content, and configurable external reverse-geocoding and region-resolution endpoints.
- The recipient decision below records the approved contractual and legal classifications; no company is assigned a role outside that decision.
- Approved recipients, service roles, subprocessors, and transfer locations: Pending owner and legal approval.
Security
Kelshi uses technical and organizational safeguards intended to reduce unauthorized access, loss, alteration, or disclosure. Reviewed clients use HTTPS API origins and authenticated sessions for protected operations. No system can guarantee absolute security.
- Do not share verification codes or account credentials. Contact [email protected] if you suspect misuse of your account.
Your choices, rights, and contact
Depending on applicable law, you may ask to access, correct, delete, restrict, or object to certain processing of your personal data. You may also withdraw a device permission through browser or operating-system settings.
- Use Profile or Settings for available account controls and the localized Delete Account page for deletion instructions.
- For privacy questions or requests, contact [email protected]. Identity verification may be required before acting on a request.
Children
The approved minimum age and child-account treatment appear below.
- Minimum age and child-account rule: Pending owner and legal approval.
Policy changes
We will update this page when the products or approved disclosures change. The policy version and effective date are recorded with each approved release.