Privacy and data governance
العربيةPrivacy Policy
We treat privacy as part of the trust on which Saudi Memory Map depends. This policy explains, in direct language, the personal data we process, where it comes from, why we use it, and the choices and rights available to you. We do not sell personal data or use behavioural advertising or device fingerprinting.
- Effective
- 2026-08-16
- Operator
- PurityTech — Kingdom of Saudi Arabia
- Privacy and official correspondence
- info@saudimemory.com
- Platform status
- Independent cultural platform, not a government body
Scope and controller
This policy applies to the Saudi Memory Map website, applications, accounts, synchronization, notifications, contributions, and related support requests. It does not govern independent websites or apps reached through an external link.
The service is operated under the name PurityTech, which controls the personal data described here and is referred to as the “operator”, “we”, or “us”. Saudi Memory Map is an independent cultural platform. It does not represent a government body or claim official approval or partnership unless a documented announcement expressly says so.
For privacy rights and official correspondence, use info@saudimemory.com. For technical help and account issues, use support@saudimemory.com. Never email a password, verification code, or access key.
Data we collect and its sources
We process the minimum reasonably needed to deliver and protect the service. What we collect depends on how you use it and the features you choose.
- Data you provide: name, email, language, support messages, account preferences, and content, images, sources, or licence details you submit.
- Account and security data: verification status, role and membership, approximate device names and classes, session creation and last-use times, and redacted security events. Passwords are stored as secure hashes, not recoverable plain text.
- Data you choose to save: favourites, visits, routes, preferences, synchronization, notification read state, and the consent and legal-document versions you accepted.
- External sign-in: if you choose Google or a similar provider, we may receive the provider identifier, name, email, profile image, and email-verification status within the permissions you approve. We do not receive your provider password.
- Limited technical data: public route, language, device or surface class, bucketed performance metrics, stable error codes, and a random journey identifier not linked to your account.
- We do not ask you for national identity, health, financial, biometric, or other sensitive data. Do not place such data in contributions or support messages unless the service expressly requests it with a clear lawful reason.
Purposes and legal bases
We use data for the stated purposes and under an appropriate legal basis. We do not reuse it for an incompatible purpose without notice or renewed consent when required.
- Performing our relationship with you: account creation and verification, sign-in, synchronization, favourites, visits, export, deletion, and requested support.
- Your consent: marketing, nearby alerts, and any separately presented optional purpose. Withdrawal applies to future processing and does not invalidate earlier lawful processing.
- Legitimate interests where permitted: protecting accounts and the service, preventing fraud and abuse, limited quality measurement, protecting intellectual-property rights, and preserving review and source integrity after balancing the impact on your rights.
- Legal obligations and claims: responding to binding requests, managing disputes, retaining legally required records, and investigating incidents.
Location, maps, and visits
We request device location only after a clear action, such as finding nearby places or checking proximity for a heritage-passport stamp. Coordinates are used momentarily for that action and are not stored precisely or tracked in the background. A visit record may store the place identifier and whether proximity verification succeeded, not the coordinates.
Loading a map or opening directions may contact an external map, image, or routing provider, such as services built on OpenStreetMap, CARTO, OpenFreeMap, OSRM, Google Maps, or Apple Maps. The provider may receive ordinary network data under its policy, and we do not control its independent processing.
Messages and notifications
We send account, security, and service communications as needed to fulfil a request or protect the account. Marketing and nearby notices are optional, off by default, and require separate consent where available.
If you enable push, the device token is stored as authenticated ciphertext plus a hash and is excluded from exports and operations views. Minimum delivery data may pass through Expo or the operating-system store. You may disable optional channels in preferences or device settings while essential security messages remain available.
Contributions and published material
Suggestions, images, and source records may include optional attribution or contact details. We use them for moderation, communication, rights checks, and provenance. Contact details are not published as public content unless you request it or attribution is required by the licence.
Accepted cultural material, source information, and licence evidence may remain after account deletion to preserve scholarly integrity, copyright compliance, and the review chain. Account identity and contact details are detached or de-identified to the extent reasonably and legally possible.
Retention and deletion
We retain data only as long as reasonably needed for the stated purpose, then erase or de-identify it unless law, a dispute, or protection of a right requires longer retention. Current operating periods are:
- Account and saved-service data: for the active account lifetime, followed by the deletion process below.
- Account deletion: a 7-day cancellation period, after which account, sync, session, device, and notification data is erased and records that must remain are de-identified.
- Account-export artifact: available for 7 days, then its downloadable content is removed.
- First-party account-unlinked analytics: an operating retention target of up to 14 months.
- De-identified security or editorial evidence: ordinarily up to 12 months, or longer for a legal obligation, dispute, or legitimate investigation.
- Rotating backups: 14 controlled daily copies. A deletion ages out as backups rotate, and deleted data is not restored except through a controlled recovery process.
- Accepted contributions, sources, and licence evidence: may remain as a cultural or rights record after personal data is detached, depending on purpose, licence, and legal obligation.
How we protect data
We use proportionate organisational and technical measures, including transport encryption, password and token hashing, role-based access, secure sessions, data minimisation, log redaction, encrypted backups, and review of sensitive operations. Internal access is limited by role and need.
No digital service can be absolutely secure. If an incident affects your data, we will investigate and notify the competent authority and affected people when required by law. Help by using a unique password, protecting your device, and reporting unauthorised use to support@saudimemory.com.
Your rights and how to exercise them
Subject to statutory conditions and exceptions, you may have the right to be informed, access your data and receive a copy, request correction or completion, request destruction, withdraw optional consent, and complain. Additional rights may apply depending on the legal basis and processing.
- Account centre: manage sessions and preferences, request a readable JSON export, request account deletion, or cancel deletion during the cooling period.
- Email: send a clear request to info@saudimemory.com from the address linked to the account. We may reasonably verify identity to protect your data and will never ask for your password or access code.
- We respond within the statutory period, ordinarily 30 days. A permitted extension may apply for complex or multiple requests, with advance notice and reasons.
- If a complaint remains unresolved, you may contact the Saudi authority competent for personal-data protection.
Children and people lacking legal capacity
The general cultural service is not directed at a child creating an independent account or submitting personal data without supervision. If you lack full legal capacity, use account and contribution features with guardian or lawful-representative approval where required.
If you believe a child’s data was collected inappropriately, contact us promptly so we can restrict or erase it in accordance with law and the child’s interests.
Changes and complaints
We review this policy when the service, providers, purposes, or legal requirements change. The effective date and version appear above. We provide prominent notice or seek renewed consent when a material change requires it.
For a question, objection, or complaint, use info@saudimemory.com. For technical help, use support@saudimemory.com. Nothing in this policy waives a mandatory right available to you under applicable law.
This operating document is grounded in the platform’s current functionality and official Saudi guidance. Qualified Saudi counsel should validate the operator’s legal identity and address, international-transfer arrangements, and final wording before it is treated as final legal advice.