Skip to content

Privacy and data governance

العربية

Privacy Policy

We treat privacy as part of the trust on which Saudi Memory Map depends. This policy explains, in direct language, the personal data we process, where it comes from, why we use it, and the choices and rights available to you. We do not sell personal data or use behavioural advertising or device fingerprinting.

Effective
2026-08-16
Operator
PurityTech — Kingdom of Saudi Arabia
Privacy and official correspondence
info@saudimemory.com
Platform status
Independent cultural platform, not a government body

Scope and controller

This policy applies to the Saudi Memory Map website, applications, accounts, synchronization, notifications, contributions, and related support requests. It does not govern independent websites or apps reached through an external link.

The service is operated under the name PurityTech, which controls the personal data described here and is referred to as the “operator”, “we”, or “us”. Saudi Memory Map is an independent cultural platform. It does not represent a government body or claim official approval or partnership unless a documented announcement expressly says so.

For privacy rights and official correspondence, use info@saudimemory.com. For technical help and account issues, use support@saudimemory.com. Never email a password, verification code, or access key.

Data we collect and its sources

We process the minimum reasonably needed to deliver and protect the service. What we collect depends on how you use it and the features you choose.

  • Data you provide: name, email, language, support messages, account preferences, and content, images, sources, or licence details you submit.
  • Account and security data: verification status, role and membership, approximate device names and classes, session creation and last-use times, and redacted security events. Passwords are stored as secure hashes, not recoverable plain text.
  • Data you choose to save: favourites, visits, routes, preferences, synchronization, notification read state, and the consent and legal-document versions you accepted.
  • External sign-in: if you choose Google or a similar provider, we may receive the provider identifier, name, email, profile image, and email-verification status within the permissions you approve. We do not receive your provider password.
  • Limited technical data: public route, language, device or surface class, bucketed performance metrics, stable error codes, and a random journey identifier not linked to your account.
  • We do not ask you for national identity, health, financial, biometric, or other sensitive data. Do not place such data in contributions or support messages unless the service expressly requests it with a clear lawful reason.

Purposes and legal bases

We use data for the stated purposes and under an appropriate legal basis. We do not reuse it for an incompatible purpose without notice or renewed consent when required.

  • Performing our relationship with you: account creation and verification, sign-in, synchronization, favourites, visits, export, deletion, and requested support.
  • Your consent: marketing, nearby alerts, and any separately presented optional purpose. Withdrawal applies to future processing and does not invalidate earlier lawful processing.
  • Legitimate interests where permitted: protecting accounts and the service, preventing fraud and abuse, limited quality measurement, protecting intellectual-property rights, and preserving review and source integrity after balancing the impact on your rights.
  • Legal obligations and claims: responding to binding requests, managing disputes, retaining legally required records, and investigating incidents.

Cookies and first-party measurement

The service uses necessary secure cookies to maintain sessions and apply your preferences. Local storage may hold a random journey identifier that rotates within 30 days to measure product journeys and performance quality.

The analytics contract excludes your email, account number, stored IP address, search text, precise location, advertising identifiers, and fingerprinting. Browser measurement is disabled when Do Not Track is enabled. We do not use ad trackers, sell audiences, or fingerprint devices.

Location, maps, and visits

We request device location only after a clear action, such as finding nearby places or checking proximity for a heritage-passport stamp. Coordinates are used momentarily for that action and are not stored precisely or tracked in the background. A visit record may store the place identifier and whether proximity verification succeeded, not the coordinates.

Loading a map or opening directions may contact an external map, image, or routing provider, such as services built on OpenStreetMap, CARTO, OpenFreeMap, OSRM, Google Maps, or Apple Maps. The provider may receive ordinary network data under its policy, and we do not control its independent processing.

Messages and notifications

We send account, security, and service communications as needed to fulfil a request or protect the account. Marketing and nearby notices are optional, off by default, and require separate consent where available.

If you enable push, the device token is stored as authenticated ciphertext plus a hash and is excluded from exports and operations views. Minimum delivery data may pass through Expo or the operating-system store. You may disable optional channels in preferences or device settings while essential security messages remain available.

Contributions and published material

Suggestions, images, and source records may include optional attribution or contact details. We use them for moderation, communication, rights checks, and provenance. Contact details are not published as public content unless you request it or attribution is required by the licence.

Accepted cultural material, source information, and licence evidence may remain after account deletion to preserve scholarly integrity, copyright compliance, and the review chain. Account identity and contact details are detached or de-identified to the extent reasonably and legally possible.

Disclosures, processors, and international transfers

We do not sell personal data. We disclose the minimum needed to providers supporting hosting, databases, email, security, external sign-in, notifications, app distribution, maps, and images, or to competent authorities where legally required or necessary to protect a lawful claim.

Technical categories may include Google when you select Google sign-in, Expo for push delivery, an enabled email provider, Apple and Google stores, and public map and image providers. Each acts under its role and terms and is contractually and instructionally restricted where it processes on our behalf.

Some processing or support may occur outside Saudi Arabia. International transfer takes place only for a legitimate purpose, with data minimisation and the requirements and safeguards prescribed by the Saudi Personal Data Protection Law and its regulations, including adequacy or appropriate contractual safeguards where required.

Retention and deletion

We retain data only as long as reasonably needed for the stated purpose, then erase or de-identify it unless law, a dispute, or protection of a right requires longer retention. Current operating periods are:

  • Account and saved-service data: for the active account lifetime, followed by the deletion process below.
  • Account deletion: a 7-day cancellation period, after which account, sync, session, device, and notification data is erased and records that must remain are de-identified.
  • Account-export artifact: available for 7 days, then its downloadable content is removed.
  • First-party account-unlinked analytics: an operating retention target of up to 14 months.
  • De-identified security or editorial evidence: ordinarily up to 12 months, or longer for a legal obligation, dispute, or legitimate investigation.
  • Rotating backups: 14 controlled daily copies. A deletion ages out as backups rotate, and deleted data is not restored except through a controlled recovery process.
  • Accepted contributions, sources, and licence evidence: may remain as a cultural or rights record after personal data is detached, depending on purpose, licence, and legal obligation.

How we protect data

We use proportionate organisational and technical measures, including transport encryption, password and token hashing, role-based access, secure sessions, data minimisation, log redaction, encrypted backups, and review of sensitive operations. Internal access is limited by role and need.

No digital service can be absolutely secure. If an incident affects your data, we will investigate and notify the competent authority and affected people when required by law. Help by using a unique password, protecting your device, and reporting unauthorised use to support@saudimemory.com.

Your rights and how to exercise them

Subject to statutory conditions and exceptions, you may have the right to be informed, access your data and receive a copy, request correction or completion, request destruction, withdraw optional consent, and complain. Additional rights may apply depending on the legal basis and processing.

  • Account centre: manage sessions and preferences, request a readable JSON export, request account deletion, or cancel deletion during the cooling period.
  • Email: send a clear request to info@saudimemory.com from the address linked to the account. We may reasonably verify identity to protect your data and will never ask for your password or access code.
  • We respond within the statutory period, ordinarily 30 days. A permitted extension may apply for complex or multiple requests, with advance notice and reasons.
  • If a complaint remains unresolved, you may contact the Saudi authority competent for personal-data protection.

Children and people lacking legal capacity

The general cultural service is not directed at a child creating an independent account or submitting personal data without supervision. If you lack full legal capacity, use account and contribution features with guardian or lawful-representative approval where required.

If you believe a child’s data was collected inappropriately, contact us promptly so we can restrict or erase it in accordance with law and the child’s interests.

Changes and complaints

We review this policy when the service, providers, purposes, or legal requirements change. The effective date and version appear above. We provide prominent notice or seek renewed consent when a material change requires it.

For a question, objection, or complaint, use info@saudimemory.com. For technical help, use support@saudimemory.com. Nothing in this policy waives a mandatory right available to you under applicable law.

This operating document is grounded in the platform’s current functionality and official Saudi guidance. Qualified Saudi counsel should validate the operator’s legal identity and address, international-transfer arrangements, and final wording before it is treated as final legal advice.