Skip to main content

Privacy Policy

العربية

Last updated: 2026-06-24 Changelog · privacy-v3-2026-06

Privacy Policy

Introduction

Nashr ("we," "us," "our") is committed to protecting your privacy. This Privacy Policy describes how we collect, use, disclose, and safeguard your personal information when you use the Nashr platform for social media account management ("the Service").

Information We Collect

Information You Provide

When you create an account, we may collect:

  • Your business name and email address
  • Profile information (store name, category, description)
  • Communications you send us (support inquiries, feedback)

Information Collected Automatically

When you use the Service, we automatically collect:

  • Device and browser information (device type, operating system, browser version)
  • Usage data (pages visited, actions taken, timestamps)
  • IP address (truncated for storage, not logged in raw form)

Information from Third Parties

When you connect social media accounts:

  • We receive profile information from the platforms you authenticate
  • Engagement metrics and analytics from your posts
  • Data about users who interact with your content (comments, likes, followers)

How We Use Your Information

We use your information to:

  • Provide and maintain the Nashr service
  • Schedule and publish content to your connected social media accounts
  • Generate AI-powered content suggestions and captions
  • Provide engagement analytics and performance insights
  • Send weekly performance reports (at your option)
  • Communicate with you regarding updates, security, and support

Where data protection law requires a legal basis, we rely on:

  • Consent: when you grant us explicit permission (e.g., connecting social media accounts).
  • Contract Performance: processing necessary to deliver the Service to you.
  • Legitimate Interests: for service improvement, security, and fraud prevention, balanced against your rights.

By accepting the Terms and this Privacy Policy when you create an account, you consent to the processing necessary to provide the Service — including the cross-border transfer of your data described in International Data Transfers below and the optional AI features used to generate content suggestions and captions.

Marketing communications are separate. We send marketing messages only with your separate, optional opt-in, which you can give or decline independently of accepting the Terms and this Privacy Policy, and which you can withdraw at any time without affecting your use of the Service.

Cookies and Similar Technologies

We use cookies and similar technologies for two main purposes:

  • Essential cookies needed to run the Service (e.g., authentication, security).
  • Analytics cookies that help us understand usage and improve the Service.

For analytics we rely on privacy-friendly, behavioral analytics providers; the authoritative, current list of these providers and their locations is maintained on our Subprocessors page. You can accept or reject non-essential cookies through our cookie banner, and you can change your choice at any time. Rejecting non-essential cookies does not affect access to the core Service. For more detail on the categories of cookies we use, see our Cookie Policy.

Data Sharing and Disclosure

We may share your information with:

  • Service Providers (Subprocessors): third-party vendors that help operate the Service. We use third-party subprocessors to operate the Service; our current subprocessors, their purpose, and their location are listed on our public Subprocessors page, which we update with at least 30 days' notice before adding a new subprocessor.
  • Social Media Platforms: when publishing content through the Service, on your instruction.
  • Payments: Paddle, our Merchant of Record, which processes payments and acts as an independent controller for payment data.
  • Legal Obligations: when required by law or in response to valid legal requests.

We never sell your personal information.

International Data Transfers

Your data is processed outside your country. Our infrastructure and service providers are located in the European Union (Frankfurt), the United States, and other countries. Where we transfer personal data across borders, we rely on appropriate safeguards — such as Standard Contractual Clauses — consistent with applicable data protection law. You can see each provider and its location on our Subprocessors page.

Data Retention

We retain your information for as long as your account is active or as needed to provide you the Service. Upon account deletion:

  • Personal information is deleted or anonymized within 60 days
  • Backups may be retained for up to an additional 90 days
  • Social media platform tokens are revoked immediately

Data Security

We implement industry-standard security measures including:

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Strict access controls and authentication
  • Regular security monitoring and auditing

Data Breach Notification

If a personal-data breach occurs that may harm your data or your rights, we will notify the relevant supervisory authority without undue delay (generally within 72 hours where required), and we will inform affected users without undue delay, with enough detail for you to understand the risk and take protective action. We maintain a written incident-response process and an internal record of incidents.

Your Rights

Depending on where you live, you may have the right to access, correct, update, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent at any time. To exercise any of these rights, contact us at [email protected]. You can also exercise many of these rights, including deleting your account, from within the Service settings.

If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local data protection authority.

Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect data from children.

Contact Us

The data controller responsible for your personal data is Millennium Techno Computer Consultancy Co. W.L.L (operating as Nashr), a limited liability company registered in the Kingdom of Bahrain (Commercial Registration No. 124175), Muharraq, Kingdom of Bahrain.

For privacy-related questions or to exercise your data privacy rights:

Changes to This Policy

We will notify you of material changes to this Privacy Policy via email or through the Service before the changes become effective.

changelog

privacy-v3-2026-06 (2026-06-24) — DRAFT, counsel-review pending

  • Fixed: removed the dead #sub-processors anchor; the Data Sharing and International Data Transfers sections now point to the public /legal/subprocessors page (with the 30-day advance-notice commitment).
  • Changed: "Your Rights" is now a general baseline plus an EEA/UK callout only; removed named-regime references (GDPR/UK GDPR) so no specific country regime is named.
  • Added: "Your Consent" section explaining that accepting the Terms and Privacy Policy covers the processing needed to provide the Service (including cross-border transfer and optional AI features), and that marketing is sent only with a separate, optional, withdrawable opt-in.
  • Added: Cookie Policy reference (/legal/cookie-policy) and a general, privacy-friendly behavioral-analytics note pointing to the Subprocessors page for the authoritative provider list.
  • Note: The Arabic version is pending a counsel-reviewed translation of these changes.

privacy-v2-2026-06 (2026-06-23) — DRAFT, counsel-review pending

  • Added: International Data Transfers section; Data Breach Notification section; Cookies section; per-region rights note.
  • Fixed: the broken "Sub-Processor List" link now points to the public /subprocessors page (with a 30-day advance-notice commitment).
  • Changed: payment disclosure names Paddle as Merchant of Record / independent controller for payment data.
  • Framing: generalized — no country-specific data-protection regime named; GDPR used as the international benchmark.

privacy-v1-2026-05 (2026-05-01)

  • Initial privacy policy release
  • Covers data collection, use, sharing, retention, and user rights

Sub-Processors

Third-party service providers and sub-contractors we use to operate Nashr.

Last updated: 2026-06-24

Sub-processor list
NamePurposeLocationCategoryDPA
SupabaseDatabase hosting, authentication, and file storageFrankfurt, Germany (eu-central-1)InfrastructureDPA
PaddlePayment processing and subscription management (Merchant of Record)United KingdomPaymentsDPA
ResendTransactional email delivery (primary)United States (us-east-1)CommunicationsDPA
AyrshareSocial media publishing API (Facebook, Instagram, etc.)United StatesInfrastructureDPA
OpenRouterAI transport broker — routes requests to Mistral, Qwen, and other models (cutover gate, default-OFF)United StatesAIPending
Mistral AIAI content generation (primary — Saba model)European UnionAIDPA
Qwen (Alibaba Cloud)AI content generation (fallback)Saudi Arabia / UAEAIDPA
SentryError monitoring and performance trackingUnited StatesAnalyticsDPA
AxiomLog aggregation and observabilityEuropean UnionAnalyticsDPA
PostHogProduct analytics and user behavioral event trackingEuropean Union (eu.i.posthog.com, Frankfurt)AnalyticsDPA
PlausiblePrivacy-friendly, cookieless website analyticsEuropean UnionAnalyticsDPA
FirecrawlMerchant website content extraction (text and metadata) for AI content generationUnited StatesInfrastructurePending
SerwistWeb push notification infrastructure (client library)n/a (client-side library, no data processing)InfrastructurePending