Moshtare LP privacy

Moshtare LP creates a random membership for each store. It does not store your email address, Aqmar account, raw Apple or Google identifier, or a shared cross-store customer identity. Before redemption, you provide a missing contact phone for that store. A name is not required. Authorized merchant users can view these details to handle your redemption. You can edit or delete contact details; transaction and points-ledger records remain for audit.

If you continue with Apple or Google, the identity provider may send standard identity claims. Moshtare LP requests and saves a supplied name for recognition within that store, preserves it when later sign-ins omit it, and discards email addresses. It keeps a one-way identifier cryptographically scoped to the current merchant. A name does not prove ownership or authorize a transaction; unnamed customers can continue using their member reference.

Contact numbers are unverified and never used to merge accounts or grant access. Where SMS sign-in is available, a verification code proves access to a separate phone login identity. The SMS provider receives the destination number and message; delivery records and verification attempts support retries and abuse prevention.

Android browser credentials are random, stored only as hashes on our servers, placed in Secure HttpOnly cookies, and expire after 180 days. Google Wallet cards are optional and contain the points balance, configured point value, merchant branding, and a signed store-membership recovery link. They contain no QR code, barcode, name, email, or phone number.

Apple Wallet device push tokens are encrypted at rest. Transaction records and an immutable points ledger are retained for merchant audit. Deleting a membership revokes credentials and Wallet registrations, detaches retained aggregate transactions, and makes any Google Wallet object inactive. Google may retain that inactive card under expired passes until you remove it manually.


خصوصية Moshtare LP

ينشئ Moshtare LP عضوية عشوائية خاصة بكل متجر. لا نخزن البريد الإلكتروني أو حساب أقمار أو معرّف Apple أو Google الأصلي أو هوية مشتركة بين المتاجر. قبل الاستبدال، تضيف رقم تواصلك لهذا المتجر إن لم يكن محفوظاً. نحتفظ بالاسم الذي يقدمه Apple أو Google إن توفر، ولا نطلب منك إدخال اسم. يمكن للمستخدمين المخولين في المتجر الاطلاع عليهما لمعالجة طلبك. يمكنك تعديل بيانات التواصل أو حذفها مع بقاء سجل النقاط والعمليات للتدقيق.

قد يرسل Apple أو Google بيانات الهوية المعتادة عند المتابعة. نهمل الاسم والبريد الإلكتروني فوراً ونحتفظ فقط بمعرّف أحادي الاتجاه مرتبط بالمتجر الحالي، ولا يمكن استخدامه لربط عضويتك بين المتاجر.

رقم التواصل غير موثق ولا يستخدم لدمج الحسابات أو الدخول إليها. عند توفر الدخول برسالة نصية، يثبت رمز التحقق الوصول إلى هوية هاتف منفصلة. يتلقى مزود الرسائل رقم الوجهة والرسالة، وتدعم سجلات التسليم ومحاولات التحقق إعادة المحاولة ومنع إساءة الاستخدام.

تستخدم جلسة أندرويد ملف تعريف ارتباط آمن خاصاً بالمتجر لمدة ١٨٠ يوماً. بطاقة Google Wallet اختيارية ولا تحتوي على اسم أو بريد إلكتروني أو هاتف أو رمز QR أو باركود. عند حذف العضوية تُلغى بيانات الدخول وتصبح البطاقة غير نشطة، وقد تبقى ضمن البطاقات المنتهية حتى تحذفها يدوياً.