Tazbeat Privacy Policy
1. About This Policy
This Privacy Policy describes how Tazbeat (“we,” “us,” or “our”) collects, uses, shares, retains, and protects personal data when you use the Tazbeat Platform — including the mobile application, website, APIs, and related services (collectively, the “Platform”).
For Egyptian users, this Policy is issued in compliance with Egyptian Personal Data Protection Law No. 151 of 2020 (PDPL) and its Executive Regulations. By using the Platform, you agree that your personal data may be processed as described in this Policy.
The Arabic-language version of this Policy is the governing version for Egyptian users. The English version is provided for convenience and information only.
If you do not agree with this Policy, you must not use the Platform.
2. Who Is the Data Controller?
The data controller responsible for your personal data is:
Tazbeat
[Legal entity name]
[Registered address, Cairo, Arab Republic of Egypt]
Email: [privacy@tazbeat.com]
If you have questions about how we handle your data or wish to exercise your rights under the PDPL or applicable law, please contact us at the details above.
3. What Personal Data We Collect
We collect personal data you provide directly, data generated through your use of the Platform, and data from third parties.
3.1 Data You Provide Directly
| Category | Examples |
|---|---|
| Identity data | Full name, profile photo, national ID (where required for verification) |
| Contact data | Email address, phone number |
| Account credentials | Hashed password, linked social sign-in tokens (Google, Facebook, Apple) |
| Location / address data | Country of residence, service address, booking location |
| Profile data | Bio, service history, personal preferences, communication preferences |
| Financial data | Payment method tokens (stored with payment processor — we do not store raw card numbers), bank account details for Provider payouts, payout history |
| Booking data | Service requests, booking details, images uploaded, notes, scheduling preferences |
| Communications | In-app chat messages, support tickets, review and rating content |
| Verification documents | Identity documents, licences, certifications, and background check results submitted for Provider verification |
| BNPL transaction data | Booking amount and Consumer identity data shared with BNPL providers (valU, Shahry) when a BNPL method is selected at checkout |
3.2 Data We Collect Automatically
| Category | Examples |
|---|---|
| Device and technical data | Device model, operating system, app version, IP address, device identifiers |
| Usage data | Pages viewed, features accessed, search queries, clicks, session duration, error logs |
| Location data | Approximate location inferred from IP address; precise GPS location only where you grant permission. For Providers: when you accept and are travelling to or performing a booked job, we may collect real-time GPS location data to enable Consumer tracking of arrival status — this requires explicit in-app permission and can be revoked at any time |
| Log data | Server logs, authentication logs, payment event logs |
| Push notification tokens | FCM or APNs tokens for in-app notifications |
3.3 Data From Third Parties
| Source | Data Received |
|---|---|
| Social sign-in providers (Google, Facebook, Apple) | Name, email, profile photo, unique identifier |
| Payment processors (Paymob, Fawry) | Transaction status, masked payment method details, refund/chargeback events |
| BNPL providers (valU, Shahry) | Credit approval outcome, instalment status, transaction reference |
| IP geolocation service | Approximate country derived from IP address (used for country-of-residence detection on first sign-in) |
| Identity / background check services (if used) | Identity verification outcome, background check result (pass/fail — underlying report not stored beyond legal requirement) |
| Firebase (Google LLC) | Authentication tokens, push notification delivery status, analytics events |
4. Why We Process Your Data (Legal Basis)
Under the PDPL and applicable law, we process personal data only where we have a lawful basis to do so.
| Purpose | Legal Basis | Data Categories Used |
|---|---|---|
| Create and manage your account | Contract performance | Identity, contact, credential data |
| Enable booking and payment flow | Contract performance | Booking, financial, location data |
| Process payments and manage escrow | Contract performance + legal obligation | Financial data, booking data |
| Provider payout and bank verification | Contract performance | Financial data, identity data |
| Provider GPS location during jobs | Contract performance + consent (explicit in-app permission) | Precise location data (collected only during active job, with Provider consent) |
| Provider background checks | Public interest / legitimate interest + legal obligation | Verification documents, identity data — processed only with Provider explicit consent during onboarding |
| BNPL payment facilitation | Contract performance + consent | Booking amount, Consumer identity data shared with selected BNPL provider |
| Fraud detection and prevention | Legitimate interest + legal obligation | Usage data, device data, financial data |
| Trust and safety, content moderation | Legitimate interest | Communications, booking data, usage data |
| Customer support and dispute resolution | Contract performance + legitimate interest | All relevant data |
| Legal compliance and regulatory obligations | Legal obligation | Identity, financial, booking data |
| Personalised recommendations and search ranking | Legitimate interest (can opt out of personalisation) | Usage data, booking history, preferences |
| Platform improvement and analytics | Legitimate interest | Anonymised/aggregated usage data |
| Marketing communications (opt-in only) | Consent | Contact data, preference data |
| Verification of Provider credentials | Contract performance + public interest | Verification documents |
| Detecting and enforcing Terms/Conditions violations | Legitimate interest | All relevant Platform data |
5. How We Share Your Personal Data
We do not sell your personal data. We share it only as described below.
5.1 Between Consumers and Providers
When a Consumer books a service, we share the Consumer’s first name, booking address, contact details (where necessary), and booking details with the confirmed Provider. When a Provider accepts or confirms a booking, we share the Provider’s profile, shop information, and contact number with the Consumer. Both parties receive only what is reasonably necessary for service delivery.
5.2 Third-Party Service Providers (Processors)
We share data only with processors under a data-processing agreement or equivalent legal instrument:
| Processor | Purpose | Transfer Jurisdiction |
|---|---|---|
| Google Firebase (Google LLC) | Authentication, database, push notifications, analytics, storage | USA (adequacy mechanism: contractual safeguards) |
| Paymob | Card payment processing in Egypt | Egypt |
| Fawry | Cash payment processing in Egypt | Egypt |
| Vodafone Cash / Orange Money | Mobile wallet payments in Egypt | Egypt |
| InstaPay | Instant bank transfer payments in Egypt | Egypt |
| valU (EFG Finance) | BNPL instalment credit — receives booking amount and Consumer identity | Egypt |
| Shahry | BNPL instalment credit — receives booking amount and Consumer identity | Egypt |
| Google Maps Platform | Address autocomplete, geolocation display | USA (adequacy mechanism: contractual safeguards) |
| Apple / Google / Facebook (sign-in) | Identity federation for social sign-in | USA (adequacy mechanism: contractual safeguards) |
| MaxMind / IP geolocation provider | Country detection on sign-in | [confirm processor country] |
| Background check / identity verification provider | Provider vetting (name, ID document, background check result) | [confirm provider and country before launch] |
| Cloud hosting and infrastructure | App hosting and CDN | [confirm provider and country] |
| Email / SMS provider | Transactional and notification delivery | [confirm provider and country] |
5.3 Legal and Regulatory Disclosure
We may disclose personal data to:
- Egyptian or foreign law enforcement, courts, or regulatory authorities where required by Applicable Law, court order, or official government request;
- the Egyptian Information and Decision Support Center (IDSC) / NTRA in connection with PDPL compliance obligations;
- the Central Bank of Egypt (CBE) where required by payment regulation;
- our lawyers, auditors, and compliance advisers under professional confidentiality.
5.4 Business Transfers
If Tazbeat undergoes a merger, acquisition, asset sale, or restructuring, personal data held by us may be transferred as part of such transaction. We will notify affected users as required by law.
5.5 With Your Consent
We may share your data with third parties for other purposes where you have given explicit, informed consent.
6. Cross-Border Data Transfers
Tazbeat’s primary operations are in Egypt. Some of our third-party processors, including Google Firebase, process data in the United States and other countries outside Egypt.
Where personal data is transferred outside Egypt, we ensure that appropriate safeguards are in place as required by PDPL Article 31 and its Regulations, including:
- standard contractual clauses (model contract terms approved by the relevant authority);
- adequacy determinations where applicable; or
- other transfer mechanisms permitted under the PDPL.
7. How Long We Keep Your Data
We retain personal data only as long as necessary for the purposes for which it was collected, or as required by law.
| Data Category | Retention Period |
|---|---|
| Account and identity data | Duration of account + 5 years after closure (or as required by law) |
| Booking and transaction records | 7 years (Egyptian commercial records / tax law requirement) |
| Payment and financial records | 7 years (Egyptian tax and accounting law) |
| Chat messages | 2 years from message date (or open dispute resolution, whichever is later) |
| Support tickets | 3 years from ticket closure |
| Audit logs | 5 years |
| Marketing consent records | 3 years from last opt-in/opt-out action |
| Verification documents | Duration of Provider account + 2 years |
| Anonymous / aggregated analytics | Indefinite (no personal data) |
We may retain data for longer periods where required by a legal obligation, regulatory requirement, ongoing dispute, or enforcement action.
8. Security
We implement technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction, including:
- encryption in transit (TLS/HTTPS for all data transmission);
- encryption at rest for sensitive data fields;
- Firebase Security Rules to enforce data access at the database level;
- tokenised storage of payment credentials (no raw card data stored by Tazbeat);
- access controls limiting employee access to personal data on a need-to-know basis;
- audit logging of sensitive data operations.
No system is completely secure. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware, as required by the PDPL, and will notify affected individuals without undue delay where required.
9. Your Rights Under the PDPL and Applicable Law
If you are subject to the Egyptian PDPL or applicable law in another Supported Country, you have the following rights regarding your personal data:
| Right | Description |
|---|---|
| Right of access | Request a copy of the personal data we hold about you |
| Right to rectification | Request correction of inaccurate or incomplete data |
| Right to erasure | Request deletion of data where no longer necessary or where consent is withdrawn (subject to legal retention obligations) |
| Right to restriction | Request restriction of processing in certain circumstances |
| Right to data portability | Receive your personal data in a structured, machine-readable format |
| Right to object | Object to processing based on legitimate interests, including direct marketing |
| Right to withdraw consent | Withdraw consent at any time where processing is based on consent; withdrawal does not affect prior lawful processing |
| Right to lodge a complaint | File a complaint with the Egyptian data protection supervisory authority (IDSC/NTRA or the designated PDPL authority) |
To exercise any of these rights, contact us at [privacy@tazbeat.com]. We will respond within 30 days (or within any shorter period required by applicable law). We may need to verify your identity before processing a request.
We will not discriminate against you for exercising your privacy rights.
10. Children’s Privacy
The Platform is not intended for, and may not be used by, persons under 18 years of age. We do not knowingly collect personal data from children under 18. If you believe a minor has provided us with personal data, please contact us at [privacy@tazbeat.com] and we will delete the relevant data as soon as reasonably practicable.
11. Cookies and Tracking Technologies
The Tazbeat mobile application may use the following tracking technologies:
| Technology | Purpose |
|---|---|
| Firebase Analytics | App usage analytics to improve the product |
| Firebase Crashlytics | Crash and error reporting (no personally identifiable crash data) |
| FCM push tokens | Delivery of in-app push notifications (no cross-app tracking) |
| Local device storage / shared preferences | Storing session state, cached data, and user preferences locally on your device |
We do not currently deploy cross-site tracking cookies or use third-party advertising networks that track users across other apps or websites.
Where we introduce cookies or new tracking technologies, we will update this Policy and, where required by PDPL or applicable law, request your consent beforehand.
12. Marketing Communications
We will send you marketing messages only with your explicit consent. You may opt out at any time by:
- using the “unsubscribe” link in any email; or
- updating your notification preferences in app settings.
Opting out of marketing does not affect transactional messages (booking confirmations, payment receipts, security alerts), which you may not opt out of while your account is active.
13. Changes to This Policy
We may update this Policy from time to time to reflect changes in our data practices, legal requirements, or product development.
For material changes, we will notify you via in-app notice or email at least 14 days before the change takes effect. The date of the most recent revision is shown at the top of this Policy.
Your continued use of the Platform after the effective date of an updated Policy constitutes acceptance, except where applicable law requires explicit consent.
14. Contact and Complaints
For privacy questions, rights requests, or data-related concerns:
Tazbeat Privacy
[Legal entity name]
[Registered address, Cairo, Arab Republic of Egypt]
Email: [privacy@tazbeat.com]
For Egyptian users: if you are not satisfied with our response, you have the right to lodge a complaint with the Egyptian data protection supervisory authority (currently operating under the IDSC / NTRA framework as the regulatory body overseeing PDPL implementation).
This Privacy Policy is subject to regular review. Please check the “Last Revised” date above. The Effective Date will be inserted upon final counsel review and publication approval. Before publication, the following items still require finalisation: (a) exact legal entity and address; (b) confirm all third-party processor locations and transfer mechanisms; (c) Arabic translation; (d) PDPL-designated supervisory authority details once formally designated; (e) DPO appointment decision.
Status: Draft — pending qualified legal-counsel review before publication
Version: 0.1
Last Revised: 2026-04-27
Effective Date:[TO BE FILLED — insert launch date]
Data Controller:[Tazbeat legal entity name],[registered address, Cairo, Arab Republic of Egypt]
Data Protection Contact:[privacy@tazbeat.com]
Related Documents: Terms of Use · Booking and Service Conditions · Egypt Country Addendum