التطبيق غير موجَّه للجمهور العام ولا متاح له. الوصول إليه يتطلب حساباً يُنشئه ويديره مدير المتجر؛ لا يوجد تسجيل ذاتي. توضح هذه السياسة: ما هي المعلومات التي يجمعها التطبيق، وكيف تُستخدم، ومع من تُشارَك، وكيف تُحمى، وكيف يمكنك طلب حذفها.
بتسجيل دخولك إلى التطبيق، فإنك تُقر بأنك قرأت هذه السياسة وفهمتها.
2. هويتنا والجهة المسؤولة عن بياناتك
المتجر (التاجر المستخدم لهذا التطبيق) هو الجهة الأساسية المسؤولة عن بيانات عملائه (الاسم، الهاتف، العنوان)، ويحتفظ بتحكّم كامل في هذه البيانات ضمن حسابه.
Babylon Core LTD (بغداد، العراق) هي الجهة المطوِّرة والمشغِّلة للمنصة التقنية التي يعمل عليها هذا التطبيق. تُعد BabylonCore "متحكماً مشتركاً" في البيانات (Joint Controller) إلى جانب المتجر، حصراً في نطاق البيانات التشغيلية المجمَّعة التي تصل تلقائياً إلى منصة BabylonCore المركزية بغرض تحسين الخدمة عبر جميع المتاجر المشتركة — مثل أرقام "بابلون غارد"، وإحصاءات الطلبات اليومية، وأداء شركات التوصيل. هذا الوصول التلقائي منصوص عليه أيضاً كبند صريح ضمن عقد الاشتراك بين BabylonCore والمتجر.
تلتزم BabylonCore، عند استخدامها لهذه البيانات، بالمعايير التالية:
تُستخدَم البيانات لتحسين الخدمة عبر المنصة (أداء شركات التوصيل، جودة الخدمة العامة) — لا لأي غرض تسويقي أو بيعها لطرف ثالث.
الوصول إلى لوحة BabylonCore الإدارية (حيث تظهر هذه البيانات، بما فيها أرقام بابلون غارد الكاملة) محصور بالموظفين المصرَّح لهم داخل BabylonCore فقط، خلف جلسة دخول محمية بكلمة مرور.
كل إجراء تعديل أو حذف (لا الاطلاع وحده حالياً) على بيانات المشتركين داخل لوحة BabylonCore يُسجَّل في سجل تدقيق داخلي.
لأي استفسار يخص هذا التمييز أو ممارسة حقوقك تجاه أي من الطرفين، راسلنا على privacy@babcore.com (تفاصيل التواصل الكاملة في القسم 16).
3. البيانات التي نجمعها
نجمع فقط المعلومات اللازمة لتشغيل التطبيق وتنفيذ الطلبات. تصف الفئات التالية كل البيانات التي يعالجها التطبيق.
3.1 بيانات الحساب والدخول (مستخدمو التطبيق)
اسم المستخدم والاسم المعروض الذي يحدده مدير المتجر، ودورك الوظيفي (مدير، موظف، أو مندوب) مع صلاحيات كل مستخدم.
كلمة المرور، تُخزَّن فقط كقيمة تجزئة تشفيرية مملَّحة (Salted Hash). لا يخزّن التطبيق أو ينقل كلمة مرورك كنص صريح مطلقاً.
رموز تحقق تسجيل الدخول (تُرسَل عبر خدمة مراسلة فورية خاصة بالمتجر)، وسجل دخول يتضمن التاريخ والوقت وعنوان IP ومعرّف المتصفح/الجهاز لكل عملية دخول. يُستخدَم هذا حصراً لتأمين الحسابات وتنبيه المتجر عند الدخول من شبكة أو جهاز جديد.
صورة شخصية اختيارية (أفاتار) وحالة توفر تختارها بنفسك (متاح / مشغول / خارج الدوام).
3.2 بيانات الطلبات والزبائن (سجلات تجارية)
اسم الزبون، ورقم/أرقام هاتفه، والمحافظة، والمنطقة، ومعلَم قريب اختياري، كما يُدخلها موظفو المتجر وقت البيع.
تفاصيل الطلب: المنتجات، الكميات، الألوان، الأرقام التسلسلية، نوع الضمان وتاريخ انتهائه، السعر، طريقة التوصيل، حالة التوصيل، ملاحظات الطلب، الملاحظات الداخلية للموظفين، وسجل تغييرات حالة الطلب.
إثبات الدفع للطلبات المدفوعة مسبقاً: المبلغ المدفوع وصورة إيصال التحويل البنكي/المصرفي التي يقدمها الزبون، وتُستخدَم للتحقق من دفع الطلب مسبقاً.
سجلات شركة التوصيل: رقم الطلب لدى شركة التوصيل، حالة التوصيل الحالية، مشاكل التوصيل، والفواتير وسجلات التسوية المتعلقة بطلباتنا.
3.3 بيانات الموقع الجغرافي
موقع تسليم الزبون: عندما يختار الزبون مشاركة موقعه عبر رابط تتبّع الطلب المُرسَل إليه، يخزّن التطبيق الإحداثيات الجغرافية (خط الطول/العرض والدقة) لمساعدة مندوبنا في الوصول لعنوان التسليم. المشاركة طوعية ومبادرة من الزبون؛ لا يتتبّع التطبيق موقع الزبون في الخلفية إطلاقاً.
موقع المندوب: في طلبات التوصيل الذاتي، قد يُستخدَم الموقع الحالي للمندوب على جهازه الخاص لحساب المسافات واقتراح مسار التوصيل. يُستخدَم هذا الموقع على الجهاز لهذا الغرض فقط، ولا يُسجَّل كسجل حركة مستمر.
موقع يُدخله الموظف يدوياً: قد يُدخل الموظفون إحداثيات تقريبية لطلب ما عندما يتعذّر على الزبون مشاركتها.
3.4 سجلات نشاط التوصيل والتشغيل
سجلات إجراءات المندوب على الطلب (قُبل، سُلِّم، أُلغي، أُجِّل، أُبلِغ عن مشكلة) مع الطابع الزمني وأي سبب أو ملاحظة مرفقة.
تقييمات وتعليقات اختيارية من الزبون تُقدَّم طوعاً عبر صفحة تتبّع الطلب بعد التسليم.
قائمة بأرقام هواتف الزبائن المرتبطة بطلبات راجعة أو ملغاة، تُستخدَم داخلياً لتحذير الموظفين من تكرار الإرجاع قبل إرسال طلب جديد.
3.5 المراسلة الداخلية للفريق
الرسائل والصور والتسجيلات الصوتية (حتى دقيقة واحدة) التي يتبادلها المستخدمون في الدردشة الداخلية للتطبيق، بما في ذلك الإشارات إلى الطلبات.
3.6 البيانات التقنية
ملف تعريف ارتباط الجلسة (Session Cookie) اللازم لإبقائك مسجَّل الدخول.
اشتراك الإشعارات الفورية (Push) (نقطة نهاية ومفاتيح خاصة بجهازك) إن فعّلت الإشعارات على جهازك.
تفضيلات مخزَّنة محلياً على جهازك (مثل السمة، الصوت، وقائمة انتظار الطلبات المدخَلة أثناء انقطاع الاتصال) لا تغادر جهازك إطلاقاً إلا عند إرسال الطلبات المعلَّقة.
التطبيق لا يجمع معرّفات إعلانية، ولا يستخدم أدوات تحليل أو إعلانات (SDKs)، ولا يصل إلى جهات اتصالك أو تقويمك أو ملفاتك أو صورك، باستثناء الصورة الواحدة التي تختار إرفاقها صراحةً (إيصال تحويل، صورة دردشة، أو صورة شخصية).
4. كيف نستخدم بياناتك
نستخدم المعلومات الموصوفة أعلاه حصراً للأغراض التالية:
إدارة الطلبات: تسجيل المبيعات، إصدار وصولات الضمان، تجهيز بوليصات الشحن، إرسال الطلبات لشركة التوصيل، ومعالجة الاستبدال والإرجاع.
المتابعة التشغيلية: تتبّع حالة توصيل كل طلب، معالجة مشاكل التوصيل، تنسيق مندوبي التوصيل الذاتي، وتسوية فواتير التوصيل وحسابات المندوبين.
الأمان: التحقق من عمليات الدخول برموز لمرة واحدة، رصد الدخول من أجهزة أو شبكات جديدة، فرض صلاحيات المستخدمين، وحفظ سجل تدقيق لتغييرات الطلبات.
التواصل مع الزبائن: تجهيز رسائل واتساب وروابط تتبّع يرسلها موظفو المتجر للزبائن من أجهزتهم الخاصة. التطبيق نفسه لا يرسل رسائل للزبائن تلقائياً بأي حال.
لا نستخدم بياناتك لأغراض إعلانية أو تنميط (Profiling) أو أي غرض لا يتعلق بتشغيل متجرنا.
5. ميزة "بابلون غارد المجتمعي" (اختيارية)
يمكن لمدير المتجر تفعيل مفتاح اختياري يجعل المتجر يُرسِل أرقام هواتف الزبائن المرتبطة بطلبات ملغاة أو راجعة إلى منصة BabylonCore المركزية، ويستطيع بالمقابل الاستعلام عن رقم هاتف يُدخله زبون جديد ليرى تحذيراً إن أبلغته متاجر أخرى مفعِّلة لنفس الميزة عن مشاكل سابقة معه.
الرقم يصل BabylonCore كاملاً وصريحاً (بلا تجزئة/Hashing) — راجع القسم 2 حول علاقة BabylonCore بهذه البيانات.
لا يظهر رقم الهاتف نفسه، ولا هوية أي متجر آخر، لمتجرك مطلقاً. عند استعلامك عن رقم زبون جديد، تتلقى فقط: عدد المتاجر الأخرى التي أبلغت عنه، وفئات أسباب البلاغات (مثل "لا يرد" أو "رفض الاستلام") — بلا أي تفصيل يكشف هوية المتجر المُبلِّغ.
هذه الميزة استعلام لا فهرسة: لا يمكن لأي متجر تصفّح أو البحث عن أرقام لم يُدخلها هو نفسه أصلاً في طلب حقيقي.
موافقة المتجر على تفعيل الميزة تكفي لتشغيلها؛ وهذا القسم يشكّل إشعارك — بصفتك زبوناً — بأن رقمك قد يصل منصة BabylonCore المركزية بهذه الصيغة إن فعَّل متجرك هذه الميزة، بصرف النظر عن أخذ موافقتك الصريحة على ذلك تحديداً.
6. مشاركة البيانات وأطراف ثالثة
لا نبيع معلوماتك الشخصية إطلاقاً، ولا نشاركها مع أي طرف ثالث لأغراضه التسويقية الخاصة أو لأي غرض خارج تشغيل متجرنا. يُفصَح عن المعلومات فقط للجهات التالية، وبالقدر اللازم حصراً:
شركة التوصيل المفعَّلة. الشركات النشطة حالياً على المنصة هي "المارد الأمين" (agg-iq.net) و"الوسيط" (alwaseet-iq.net). قد تُضاف شركات توصيل أخرى إلى المنصة مستقبلاً؛ الشركة الفعّالة فعلياً على حساب متجرك تظهر دائماً في إعدادات المتجر. لإتمام التوصيل، نرسل اسم الزبون ورقم/أرقام هاتفه وعنوانه (المحافظة، المنطقة، المعلَم) ووصف البضاعة وكميتها والمبلغ المطلوب تحصيله ورقم طلبنا إلى شركة التوصيل عبر واجهتها الخاصة بالتجار. تعالج شركة التوصيل هذه المعلومات وفق شروطها وسياسة خصوصيتها الخاصة. العلاقة التعاقدية بين BabylonCore وهذه الشركات هي تعاقد تجاري تشغيلي عادي، وليست اتفاقية معالجة بيانات (DPA) رسمية.
خدمة مراسلة فورية لطرف ثالث. يرسل التطبيق إشعارات تشغيلية (طلبات جديدة، تغيّرات حالة التوصيل، رموز تحقق الدخول، تقارير يومية، ونسخاً احتياطية مشفَّرة من قاعدة البيانات) إلى مجموعة خاصة على خدمة مراسلة فورية لطرف ثالث، لا يصل إليها سوى موظفي المتجر المخوَّلين. تمرّ هذه الرسائل عبر بنية هذه الخدمة وتخضع لسياسة خصوصيتها الخاصة.
مزوّد الاستضافة. يُستضاف التطبيق وقاعدة بياناته على خادم نستأجره من مزوّد استضافة أوروبي. يوفر هذا المزوّد البنية التحتية فقط، ولا صلاحية له للاطلاع على محتوى قاعدة البيانات.
خدمة حماية وتوزيع الشبكة. نستخدم خدمة عالمية لحماية الموقع وتسريع الوصول إليه، وهذه الخدمة ترى حركة المرور المارّة عبرها.
خدمات الإشعارات الفورية (Push). إن فعّلت الإشعارات، يُسلَّم محتواها عبر خدمة الدفع الخاصة بمتصفحك أو نظام تشغيلك (مثل Google أو Apple). الحمولات مشفَّرة تماماً من طرف إلى طرف بحيث لا يمكن لخدمة الدفع قراءتها.
المتطلبات القانونية. قد نفصح عن معلومات إذا طُلب ذلك بموجب القانون المعمول به أو أمر قضائي أو طلب مشروع من جهة عامة مختصة (تفاصيل كاملة في القسم 10).
نقل البيانات دولياً: بما أن مزوّد الاستضافة وخدمة حماية الشبكة وخدمة المراسلة الفورية المذكورين أعلاه مقرّهم خارج العراق، فإن جزءاً من بياناتك قد يُنقَل ويُعالَج ويُخزَّن على خوادم خارج الأراضي العراقية. نلتزم بإخضاع جميع عمليات النقل هذه لمعايير أمنية عالية بصرف النظر عن موقعها الجغرافي.
داخل التطبيق، لا تظهر المعلومات إلا للمستخدمين المخوَّلين حسب دورهم وصلاحياتهم. فمثلاً، لا يرى الموظفون بلا صلاحية "الأسعار" أسعار الطلبات، ولا يرى المندوبون سوى الطلبات المسنَدة إليهم. الزبائن الذين يفتحون رابط التتبّع يرون فقط الاسم الأول لطلبهم ورقمه وحالة التوصيل والموعد المتوقّع — ولا يرون مطلقاً الأسعار أو أرقام الهواتف أو بيانات زبائن آخرين.
7. أمان البيانات
نطبّق إجراءات تقنية وتنظيمية تتناسب مع حساسية البيانات:
التشفير أثناء النقل: كل اتصال بين جهازك وخادمنا مشفَّر عبر HTTPS (TLS). يفرض الخادم استخدام HTTPS وسياسة أمان محتوى صارمة (CSP).
المصادقة: تُخزَّن كلمات المرور كقيم تجزئة مملَّحة؛ عمليات الدخول محمية برمز تحقق لمرة واحدة وبآلية إيقاف تدريجي بعد محاولات فاشلة متكررة؛ الجلسات تستخدم ملفات تعريف ارتباط آمنة (Secure, HTTP-only).
التحكم بالوصول: صلاحيات حسب الدور (مدير، موظف، مندوب) وصلاحيات دقيقة لكل مستخدم؛ كل تعديل على طلب يُسجَّل مع المستخدم المسؤول والوقت.
نسخ احتياطية مشفَّرة: تُشفَّر نسخ قاعدة البيانات الاحتياطية بخوارزمية AES-256-GCM بمفتاح يُحفظ على الخادم حصراً قبل مغادرتها له.
المراقبة: تُراقَب جاهزية الخادم، ويُنبَّه المتجر عند الدخول من شبكات غير معروفة.
تقليل جمع البيانات: تكشف الصفحات الموجَّهة للزبائن الحد الأدنى الضروري من المعلومات، ولا يجمع التطبيق بيانات تتجاوز ما ورد في القسم 3.
لا توجد وسيلة نقل أو تخزين آمنة بشكل مطلق. إذا علمنا بحادث أمني يؤثر على معلوماتك الشخصية، سنُبلِّغ المستخدمين المتأثرين دون تأخير لا داعي له (تفاصيل إضافية في القسم 15).
8. مدة الاحتفاظ بالبيانات
سجلات الطلبات والزبائن: تبقى طوال استمرار اشتراك المتجر النشط في المنصة. عند فسخ الاشتراك لأي سبب، أو خروج المتجر من الخدمة، تُحذف جميع البيانات الحساسة، باستثناء إحصاءات بسيطة ومجمَّعة (كأداء شركات التوصيل) تظل محتفَظاً بها لتحسين جودة الخدمة العامة للمنصة.
رموز تحقق الدخول: تنتهي صلاحيتها خلال 10 دقائق.
سجل الدخول الأمني (عنوان IP والجهاز): يُحتفَظ به لمدة 90 يوماً لأغراض أمنية، ثم يُحذَف تلقائياً.
رسائل الدردشة الداخلية ومرفقاتها: تبقى طالما الحساب نشطاً، ويمكن لمدير المتجر إزالتها.
بيانات موقع الزبون: تُحفَظ فقط لغرض إتمام التوصيل، ويمكن لموظفي المتجر مسحها بعد التسليم.
بيانات الحساب: تُحفَظ حتى إزالة الحساب (انظر القسم 9).
بيانات التخبير التشغيلي لدى BabylonCore (مثل إحصاءات "بابلون غارد" اليومية وأداء شركات التوصيل عبر المنصة): لا توجد حالياً مدة احتفاظ محدَّدة لها؛ تُحفَظ لأجل غير مسمى لغرض تحسين الخدمة عبر المنصة ككل.
9. حقوقك وطلب الحذف
نوفّر لك الحقوق التالية:
حق الوصول: يمكنك طلب معرفة البيانات التي نحتفظ بها عنك.
حق التصحيح: يمكنك طلب تصحيح أي بيانات خاطئة.
حق الحذف: يمكنك طلب حذف بياناتك بالكامل.
حق الاعتراض: يمكنك الاعتراض على استخدام بياناتك لأغراض معينة، مثل تحسين الخدمة عبر BabylonCore.
حق التقييد: يمكنك طلب تجميد معالجة بياناتك.
حق نقل البيانات: يمكنك طلب نسخة إلكترونية من بياناتك.
لممارسة أي من هذه الحقوق، تواصل معنا على privacy@babcore.com. سنستجيب لطلبك خلال 72 ساعة، وننفّذه خلال 30 يوماً كحد أقصى.
مستخدمو التطبيق (الموظفون والمندوبون). يمكنك أيضاً طلب إزالة حسابك مباشرة من مدير المتجر عبر شاشة إدارة المستخدمين. عند تنفيذ الطلب، سيُعطَّل حسابك فوراً ويُحذَف ملفك الشخصي وصورتك وسجل دخولك واشتراكات الإشعارات ورسائل الدردشة خلال المهلة أعلاه. يُرجى ملاحظة أن سجلات الطلبات التي أنشأتها أو حدَّثتها أثناء أداء مهامك هي سجلات تجارية للمتجر؛ قد يبقى اسمك مرتبطاً بها في سجل التدقيق حيث يقتضي القانون أو المحاسبة الاحتفاظ بها، لكنها لن تبقى مرتبطة بحساب نشط.
حالة خاصة — بابلون غارد المجتمعي. إذا طلب زبون حذف بياناته وكان رقمه مرتبطاً ببيانات "بابلون غارد المجتمعي" (القسم 5)، يُحذَف رقمه بالكامل من هذه البيانات مع بقية بياناته الشخصية، بصرف النظر عن عدد المتاجر التي أبلغت عنه سابقاً — لا استثناء ولا احتفاظ جزئي.
سنؤكّد إتمام كل طلب حذف بالرد على العنوان الذي أُرسل منه.
10. الإفصاح للجهات الحكومية والقانونية
نلتزم بحماية خصوصية مستخدمينا. لا نكشف عن أي بيانات شخصية لأي جهة حكومية أو أمنية إلا في الحالات التالية حصراً:
وجود قرار قضائي عراقي نافذ يأمرنا بالكشف عن بيانات محددة، وذلك وفقاً للمادة (40) من الدستور العراقي.
وجود طلب رسمي من جهة تنظيمية مختصة (مثل هيئة الإعلام والاتصالات)، بعد مراجعته قانونياً والتأكد من مشروعيته.
وجود خطر وشيك على السلامة العامة أو حياة الأفراد، وبعد استنفاد جميع الوسائل الأخرى.
في جميع الحالات، سنقوم بتوثيق الطلب، ومراجعته مع مستشارينا القانونيين، والرد بالحد الأدنى من البيانات المطلوبة، مع إخطار المستخدم المعني إذا كان ذلك ممكناً قانونياً. نحتفظ بسجل لجميع الطلبات الحكومية، وننشر تقرير شفافية دوري يوضح عددها ونوعها.
11. الإطار القانوني الحاكم
نلتزم بحماية بياناتك الشخصية وفقاً لأحكام الدستور العراقي (المادة 40) التي تكفل حرمة الاتصالات والمراسلات الإلكترونية، وبما يتماشى مع القوانين العراقية النافذة، بما في ذلك قانون العقوبات رقم 111 لسنة 1969 (المادة 438) الذي يجرّم الاعتداء على حرمة الحياة الخاصة.
نلتزم أيضاً بالمعايير الدولية لحماية البيانات، تماشياً مع أفضل الممارسات العالمية، إلى حين صدور قانون عراقي شامل لحماية البيانات الشخصية.
القانون الحاكم عند أي نزاع: تخضع هذه السياسة للقوانين العراقية النافذة والمحاكم العراقية المختصة، مع التزامنا الطوعي أيضاً بمواءمة ممارساتنا مع معايير اللائحة الأوروبية العامة لحماية البيانات (GDPR) كمعيار ثقة إضافي، دون أن يشكّل ذلك التزاماً قانونياً خارج نطاق القانون العراقي.
12. أذونات الجهاز
يطلب التطبيق أذونات الجهاز فقط عند استخدام الميزة المرتبطة بها، ويمكن سحب كل إذن في أي وقت من إعدادات جهازك أو متصفحك:
الموقع الجغرافي — لحساب المسافات والمسارات للمندوبين، ولتمكين الزبون (في صفحة التتبّع) من مشاركة موقع التوصيل طوعاً.
الكاميرا — لمسح رموز QR على بوليصات الشحن، ولالتقاط صورة لرسالة دردشة أو إيصال تحويل.
الميكروفون — لتسجيل الملاحظات الصوتية في دردشة الفريق.
الإشعارات — لتنبيهك بالطلبات الجديدة والمهام والرسائل.
الصور / الملفات — فقط عبر منتقي الملفات القياسي، عند اختيارك صورة لإرفاقها.
13. خصوصية الأطفال
التطبيق أداة عمل موجَّهة للبالغين الموظفين لدى المتجر أو المتعاقدين معه. لا يستهدف الأطفال دون 18 عاماً، ولا نجمع عن قصد أي معلومات شخصية من الأطفال.
14. خطط مستقبلية قد تؤثر على بياناتك
قد نوسّع نطاق خدماتنا مستقبلاً لتشمل خدمات استضافة المواقع والسيرفرات، وبناء المواقع الإلكترونية، وتطبيقات المراسلة. عند إطلاق أي خدمة جديدة، سنحدّث هذه السياسة لتعكس طبيعة البيانات التي تجمعها الخدمة الجديدة.
قد نتعاون مع شركاء خارجيين (مثل بوابات الدفع، وشركات الشحن، ومزوّدي الخدمات السحابية) لتقديم خدماتنا. سنفصح عن أي شراكة جديدة تستلزم مشاركة البيانات في تحديثات لاحقة لهذه السياسة.
نخطط للتوسّع في خدماتنا لتشمل دولاً عربية وأجنبية. عند دخول أسواق جديدة، سنلتزم بالقوانين المحلية لحماية البيانات، وسنحدّث هذه السياسة لتتوافق مع كل سوق.
نعمل على تطوير ميزات جديدة قد تجمع أنواعاً إضافية من البيانات. قبل إطلاق أي ميزة، سنراجع سياسة الخصوصية ونتأكد من أنها تغطي جميع الجوانب.
15. الخروقات الأمنية وتحديثات هذه السياسة
في حال حدوث أي خرق أمني يؤثر على بياناتك، سنخطرك خلال 72 ساعة من اكتشافه، وسنعمل على احتواء الموقف وإصلاحه فوراً.
قد نحدّث هذه السياسة من وقت لآخر لتعكس تغييرات في التطبيق أو المتطلبات القانونية. النسخة الحالية متاحة دائماً على هذا العنوان، ويشير تاريخ "آخر تحديث" أعلى الصفحة إلى آخر مراجعة لها. سنخطرك بأي تغييرات جوهرية عبر البريد الإلكتروني أو إشعار داخل التطبيق، قبل 30 يوماً على الأقل من دخولها حيز التنفيذ.
16. التواصل معنا
لأي استفسار حول هذه السياسة، أو لممارسة حقوقك المتعلقة ببياناتك الشخصية، راسلنا:
المتحكم التشغيلي بالبيانات: إدارة متجر BabylonCare هذا الجهة المطوِّرة والمشغِّلة للمنصة (متحكم مشترك للبيانات المجمَّعة): Babylon Core LTD — بغداد، العراق البريد الإلكتروني لشؤون الخصوصية:privacy@babcore.com البريد الإلكتروني العام:info@babcore.com
هذه السياسة متوفرة بنسختين، عربية وإنجليزية، مع مبدّل لغة فوري أعلى الصفحة. النسخة الإنجليزية ترجمة نصية حرفية من النسخة العربية دون أي فارق في المضمون. عند وجود أي تعارض بين الترجمتين، يُعتمد المرجع تبعاً لصفة الطرف المعترِض: فإن كان مقيماً أو يستخدم الخدمة من خارج العراق وبلغة غير عربية، فالمرجع هو النسخة الإنجليزية؛ وفي غير ذلك، فالمرجع هو النسخة العربية.
Privacy Policy
BabylonCare — internal order & delivery management application Effective date: 28 September 2026 · Last updated: 28 September 2026
1. Introduction & Scope
BabylonCare (the "App") is a private, internal business tool operated by our store (the "Store", "we", "us"), used exclusively by our authorized store employees and by delivery couriers contracted with us, to register, track, and update customer orders and deliveries.
The App is not intended for, and is not available to, the general public. Access requires an account created and administered by the store manager; there is no self-registration. This policy explains what information the App collects, how it is used, with whom it is shared, how it is protected, and how you can request its deletion.
By signing in to the App, you acknowledge that you have read and understood this policy.
2. Our Identity & Who Controls Your Data
The Store (the merchant using this App) is the primary controller of its customers' data (name, phone number, address), and retains full control over this data within its own account.
Babylon Core LTD (Baghdad, Iraq) is the developer and operator of the technical platform this App runs on. BabylonCore is a Joint Controller of data alongside the Store, strictly within the scope of aggregated operational data that automatically reaches the central BabylonCore platform for the purpose of improving the service across all participating stores — such as Babylon Guard numbers, daily order statistics, and delivery-company performance. This automatic access is also stated explicitly as a clause in the subscription agreement between BabylonCore and the Store.
When using this data, BabylonCore adheres to the following standards:
Data is used to improve the service across the platform (delivery-company performance, overall service quality) — never for marketing or sale to a third party.
Access to the BabylonCore admin dashboard (where this data appears, including full Babylon Guard numbers) is restricted to authorized BabylonCore personnel only, behind a password-protected login session.
Every edit or deletion action (not read access alone, at this time) on subscriber data within the BabylonCore dashboard is recorded in an internal audit log.
For any question about this distinction, or to exercise your rights against either party, contact us at privacy@babcore.com (full contact details in Section 16).
3. Information We Collect
We collect only the information necessary to operate the App and fulfil orders. The categories below describe all data the App processes.
3.1 Account and authentication data (App users)
Username and display name assigned by the store manager, and your role (manager, staff, or courier) together with per-user permissions.
Password, stored only as a salted cryptographic hash. The App never stores or transmits your password in plain text.
Sign-in verification codes (delivered via the store's private instant-messaging channel) and a sign-in history consisting of the date and time, IP address, and browser/device identifier of each sign-in. This is used solely to secure accounts and to alert the store about sign-ins from a new network or device.
Optional profile picture (avatar) and an availability status you choose to set (available / busy / off duty).
3.2 Order and customer data (business records)
Customer name, phone number(s), governorate, area, and an optional nearby landmark, as entered by store staff at the time of sale.
Order details: products, quantities, colours, serial numbers, warranty type and expiry, price, delivery method, delivery status, order notes, internal staff notes, and the order's status-change history.
Payment evidence for prepaid orders: the amount paid and an image of the bank/card transfer receipt supplied by the customer, used to verify advance payment.
Delivery-company records: the delivery company's order number, current delivery status, delivery issues, invoices, and settlement records relating to our orders.
3.3 Location data
Customer delivery location: when a customer chooses to share their location through the order tracking link sent to them, the App stores the geographic coordinates (latitude/longitude and accuracy) so our courier can find the delivery address. Sharing is voluntary and initiated by the customer; the App never tracks a customer's location in the background.
Courier location: for self-delivered orders, the courier's current position on their own device may be used to calculate distances and suggest a delivery route. This position is used on the device for that purpose only and is not recorded as a continuous movement history.
Staff-entered location: staff may manually enter approximate coordinates for an order when the customer cannot share them.
3.4 Delivery activity and operational logs
Records of courier actions on an order (accepted, delivered, cancelled, postponed, issue reported) with timestamps and any reason or note supplied.
Customer ratings and optional comments submitted voluntarily through the order tracking page after delivery.
A list of customer phone numbers associated with returned or cancelled orders, used internally to warn staff about repeated returns before dispatching a new order.
3.5 Team messaging
Messages, images, and voice notes (up to one minute) that users exchange in the App's internal team chat, including references to orders.
3.6 Technical data
Session cookie required to keep you signed in.
Push notification subscription (a device-specific endpoint and keys) if you enable notifications on your device.
Locally stored preferences on your device (for example theme, sound, and a queue of orders entered while offline), which never leave your device except to submit the queued orders.
The App does not collect advertising identifiers, does not use analytics or advertising SDKs, and does not access your contacts, calendar, files, or photos except for the single image you explicitly choose to attach (transfer receipt, chat image, or profile picture).
4. How We Use Your Information
We use the information described above strictly for the following purposes:
Order management: registering sales, issuing warranty receipts, preparing shipping labels, sending orders to the delivery company, and handling replacements and returns.
Operational tracking: following each order's delivery status, resolving delivery issues, coordinating self-delivery couriers, and reconciling delivery invoices and courier settlements.
App functionality: signing you in, keeping your session active, delivering notifications about orders assigned to you, enabling team chat, and producing internal operational reports (daily, weekly, and monthly summaries).
Security: verifying sign-ins with one-time codes, detecting sign-ins from new devices or networks, enforcing user permissions, and maintaining an audit trail of order changes.
Customer communication: preparing WhatsApp messages and tracking links that store staff send to customers from their own devices. The App itself never sends messages to customers automatically.
We do not use your information for advertising, profiling, or any purpose unrelated to operating our store.
5. The "Babylon Guard Community" Feature (Optional)
A store manager may enable an optional switch that sends the store's phone numbers associated with cancelled or returned orders to the central BabylonCore platform, and in return lets the store look up a new customer's number to see a warning if other stores with the same feature enabled have reported problems with it.
The number reaches BabylonCore in full, unhashed form — see Section 2 on BabylonCore's relationship to this data.
The phone number itself, and the identity of any other store, is never shown to your store. When you look up a new customer's number, you only receive: how many other stores reported it, and the categories of reasons reported (such as "no answer" or "refused delivery") — with no detail that could reveal the reporting store's identity.
This is a lookup, not a directory: no store can browse or search for numbers it has not itself already entered on a real order.
The store's consent to enable the feature is sufficient to operate it; this section serves as your notice — as a customer — that your number may reach the central BabylonCore platform in this form if your store enables this feature, regardless of obtaining your specific explicit consent for it.
6. Data Sharing & Third Parties
We never sell your personal information, and we never share it with any third party for their own marketing purposes or for any purpose outside operating our store. Information is disclosed only to the following recipients, and only to the extent necessary:
The active delivery company. The companies currently active on the platform are "Al-Mareed Al-Ameen" (agg-iq.net) and "Al-Waseet" (alwaseet-iq.net). Additional delivery companies may be added to the platform in the future; the company actually active on your store's account is always shown in the store's settings. To complete delivery, we transmit the customer's name, phone number(s), address (governorate, area, landmark), goods description and quantity, amount to be collected, and our order number to the delivery company through its merchant interface. The delivery company processes this information under its own terms and privacy policy. The contractual relationship between BabylonCore and these companies is an ordinary commercial operating agreement, not a formal Data Processing Agreement (DPA).
A third-party instant-messaging service. The App sends operational notifications (new orders, delivery status changes, sign-in verification codes, daily reports, and encrypted database backups) to a private group on a third-party instant-messaging service, accessible only to authorized store staff. These messages pass through that service's infrastructure and are subject to its own privacy policy.
Hosting provider. The App and its database are hosted on a server we rent from a European hosting provider. The provider supplies infrastructure only and has no access to the contents of the database.
Network protection & delivery service. We use a global service to protect the site and speed up access to it; this service sees the traffic passing through it.
Push notification services. If you enable notifications, the notification content is delivered through your browser or operating-system vendor's push service (for example Google or Apple). Payloads are end-to-end encrypted so the push service cannot read them.
Legal requirements. We may disclose information if required by applicable law, a court order, or a lawful request by a competent public authority (full details in Section 10).
International data transfer: because the hosting provider, network-protection service, and instant-messaging service mentioned above are based outside Iraq, part of your data may be transferred, processed, and stored on servers outside Iraqi territory. We are committed to subjecting all such transfers to high security standards regardless of their geographic location.
Within the App, information is visible only to authorized users according to their role and permissions. For example, staff without the "prices" permission cannot see order prices, and couriers see only the orders assigned to them. Customers who open a tracking link see only their order's first name, order number, delivery status, and expected delivery window — never prices, phone numbers, or other customers' data.
7. Data Security
We apply technical and organisational measures appropriate to the sensitivity of the data:
Encryption in transit: all communication between your device and our server is encrypted using HTTPS (TLS). The server enforces HTTPS and a strict Content Security Policy.
Authentication: passwords are stored as salted hashes; sign-ins are protected by a one-time verification code and progressive lock-outs after repeated failed attempts; sessions use secure, HTTP-only cookies.
Access control: role-based access (manager, staff, courier) and fine-grained per-user permissions; every change to an order is recorded with the responsible user and time.
Encrypted backups: database backups are encrypted with AES-256-GCM using a key stored only on the server before they leave it.
Monitoring: server availability is monitored and the store is alerted about sign-ins from unrecognised networks.
Data minimisation: customer-facing pages disclose the minimum necessary information, and the App collects no data beyond what is listed in Section 3.
No method of transmission or storage is completely secure. If we become aware of a security incident affecting your personal information, we will inform affected users without undue delay (see Section 15).
8. Data Retention
Order and customer records are retained for as long as the store's subscription to the platform remains active. Upon termination of the subscription for any reason, or the store leaving the service, all sensitive personal data is deleted, except for simple, aggregated statistics (such as delivery-company performance) that remain retained to improve the platform's overall service quality.
Sign-in verification codes expire after 10 minutes.
Security sign-in history (IP address and device) is retained for 90 days for security purposes, then automatically deleted.
Team chat messages and attachments are retained while the account is active and may be removed by the store manager.
Customer location data is kept only for the purpose of completing the delivery and may be cleared by staff once the order is delivered.
Account data is retained until the account is removed (see Section 9).
BabylonCore's operational telemetry data (such as daily "Babylon Guard" statistics and platform-wide delivery-company performance) currently has no defined retention period; it is retained indefinitely for the purpose of improving the service across the platform.
9. Your Rights & Deletion Requests
We provide you with the following rights:
Right of access: you may request to know the data we hold about you.
Right of rectification: you may request correction of any inaccurate data.
Right of deletion: you may request complete deletion of your data.
Right to object: you may object to the use of your data for specific purposes, such as improving the service through BabylonCore.
Right to restriction: you may request that processing of your data be frozen.
Right to data portability: you may request an electronic copy of your data.
To exercise any of these rights, contact us at privacy@babcore.com. We will respond to your request within 72 hours, and complete it within a maximum of 30 days.
App users (employees and couriers). You may also request removal of your account directly from the store manager via the user-management screen. Upon such a request, your account will be disabled immediately, and your profile, avatar, sign-in history, push subscriptions, and chat messages will be deleted within the period above. Please note that order records you created or updated while performing your duties are business records of the store; your name may remain attached to them in the audit trail where retention is required by law or accounting purposes, but the records will no longer be linked to an active account.
Special case — Babylon Guard Community. If a customer requests deletion of their data and their number is linked to "Babylon Guard Community" data (Section 5), their number is deleted entirely from this data along with the rest of their personal data, regardless of how many stores previously reported it — no exception, no partial retention.
We will confirm completion of every deletion request by reply to the address it was sent from.
10. Disclosure to Government & Legal Authorities
We are committed to protecting our users' privacy. We do not disclose any personal data to any government or security authority except in the following cases only:
The existence of an enforceable Iraqi judicial order compelling us to disclose specific data, in accordance with Article 40 of the Iraqi Constitution.
The existence of a formal request from a competent regulatory authority (such as the Communications and Media Commission), after it has been legally reviewed and its legitimacy confirmed.
The existence of an imminent threat to public safety or to individuals' lives, and after all other means have been exhausted.
In all cases, we will document the request, review it with our legal counsel, and respond with the minimum data required, notifying the affected user where legally possible. We keep a record of all government requests, and publish a periodic transparency report indicating their number and type.
11. Governing Legal Framework
We are committed to protecting your personal data in accordance with the provisions of the Iraqi Constitution (Article 40), which guarantees the inviolability of electronic communications and correspondence, and in line with applicable Iraqi law, including Penal Code No. 111 of 1969 (Article 438), which criminalises infringement of the sanctity of private life.
We are also committed to international data-protection standards, in line with global best practice, pending the issuance of a comprehensive Iraqi personal data protection law.
Governing law for any dispute: this policy is governed by applicable Iraqi law and the competent Iraqi courts, alongside our voluntary commitment to aligning our practices with the standards of the EU General Data Protection Regulation (GDPR) as an additional trust standard, without this constituting a legal obligation beyond the scope of Iraqi law.
12. Device Permissions
The App requests device permissions only when you use the related feature, and each permission can be revoked at any time in your device or browser settings:
Location — to calculate distances and routes for couriers, and (on the customer tracking page) to let a customer voluntarily share their delivery location.
Camera — to scan QR codes on shipping labels and to take a photo for a chat message or a transfer receipt.
Microphone — to record voice notes in the team chat.
Notifications — to alert you about new orders, assignments, and messages.
Photos / files — only through the standard file picker, when you choose an image to attach.
13. Children's Privacy
The App is a workplace tool intended for adults employed by, or contracted to, the store. It is not directed at children under 18, and we do not knowingly collect personal information from children.
14. Future Plans That May Affect Your Data
We may expand the scope of our services in the future to include website and server hosting, website-building services, and messaging applications. When we launch any new service, we will update this policy to reflect the nature of the data that new service collects.
We may collaborate with external partners (such as payment gateways, shipping companies, and cloud service providers) to deliver our services. We will disclose any new partnership requiring data sharing in subsequent updates to this policy.
We plan to expand our services into other Arab and foreign countries. When entering new markets, we will comply with local data-protection laws, and update this policy to align with each market.
We are working on developing new features that may collect additional types of data. Before launching any feature, we will review this privacy policy to ensure it covers all aspects.
15. Security Breaches & Policy Updates
In the event of any security breach affecting your data, we will notify you within 72 hours of discovering it, and will work to contain and remedy the situation immediately.
We may update this policy from time to time to reflect changes in the App or in legal requirements. The current version is always available at this address, and the "Last updated" date at the top of the page indicates its most recent revision. We will notify you of any material changes by email or in-app notice, at least 30 days before they take effect.
16. Contact Us
For any question about this policy, or to exercise your rights regarding your personal data, please contact us:
Operational data controller: Management of this BabylonCare store Platform developer & operator (joint controller for aggregated data): Babylon Core LTD — Baghdad, Iraq Privacy email:privacy@babcore.com General email:info@babcore.com
This policy is available in two versions, Arabic and English, with an instant language switcher at the top of the page. The English version is a literal text translation of the Arabic version, with no difference in substance. In case of any conflict between the two versions, the reference version is determined by the nature of the objecting party: if they are located or using the service from outside Iraq and in a language other than Arabic, the English version governs; otherwise, the Arabic version governs.