About This Policy
This Privacy Policy explains how Manzo Proptech Company ("Manzo", "we", "our", or "us") — a Saudi limited liability company registered under Commercial Registration No. 7041635215 — collects, uses, shares, and protects personal data when you use the Manzo website, our iOS and Android applications, our APIs, and any related services (together, the "Platform").
We process personal data in accordance with the Saudi Personal Data Protection Law (the "PDPL") and its Implementing Regulations issued by the Saudi Data & Artificial Intelligence Authority (SDAIA), together with all other applicable Saudi laws.
For the purposes of the PDPL, Manzo is the controller of the personal data described in this Policy.
Data Protection Officer. Our Data Protection Officer is Abdullah Bader AlOtaishan. To contact the DPO — including for any access, correction, deletion, or complaint request — write to [email protected].
Scope
This Policy applies to
- Visitors to manzo.com.sa and any subdomain we operate
- Users of the Manzo iOS and Android apps
- Users of any Manzo API, dashboard, or admin tooling
- Individuals whose data is uploaded to the Platform by Listers, Agencies, or other users (for example, the team member of an agency)
It does not apply to third-party websites or apps you reach through links on the Platform — review their own policies before sharing personal data.
What Personal Data We Collect
We collect the categories of personal data set out below. Where a field is generated by you (for example a chat message), we collect what you provide. Where a field is provided by an authority (for example Nafath), we collect only what the authority returns to us.
Identity & Nafath verification
- Name, email address, phone number, national ID or Iqama number
- First, father, grand-father, and family names where Nafath returns them
- Date of birth, gender, nationality
- Profile picture, biography, language preference
- Last login, registration date
- A SHA-256 hash of any Nafath JWT received (we never store the raw JWT)
- Apple Sign-In and Google Sign-In identifiers (provider, provider user ID, provider email)
Agency data
- Company name (Arabic and English), trade name where provided
- Commercial Registration number, FAL (REGA marketing licence) number
- Authorized representative name, mobile, and email
- Office phone, email, website, address, latitude/longitude
- Verification status, verification timestamp, subscription tier and end date
- Team members, invitation tokens, roles, statuses, joined/invited timestamps
Property & location data
- Listing title, description, price, area, type, room counts, amenities
- Address (free text + structured), city, coordinates (PostGIS)
- Original (un-offset) coordinates and the location-privacy preference
- REGA ad-licence number and expiry
- Report count, hidden-due-to-reports flag, ownership-verification fields
Offers, contracts, and messaging
- Offer price, move-in/move-out dates, payment reference, contract handler, lifecycle timestamps
- Snapshotted offerer name and profile picture (captured at offer time)
- Message content (free text — anything users type), read receipts, soft-delete flags
Devices and notifications
- Firebase Cloud Messaging device tokens
- Device type (iOS/Android/Web), device name, app version, last used
- Notification delivery records (recipient email/phone, status timeline)
- Per-channel notification preferences (push, email, SMS)
Payments
- Moyasar payment ID and environment marker
- Card brand, last four digits, expiry month/year, cardholder name, Moyasar card token (we do not store full PAN or CVV — these never reach our systems)
- Payment amount, currency, method, Moyasar charge / session / receipt IDs, completion timestamp
- Refund, webhook, and subscription history records
Behavioural & analytics data
- Sessions, property views, clicks, shares, search queries (text), screen views, interaction events
- User or guest ID, device ID, platform, app version, device model, OS version
- Latitude/longitude, city, country, IP address, user agent, referrer, page URL
- Touch coordinates, scroll depth, image-view counts
- Onboarding events, threshold metrics, recommendation outputs
Help center & support
- Contact-form submissions: name, email, phone, message body, IP address, user agent
- Callback requests
- AI assistant memory: previous questions, viewed properties, search preferences, interaction patterns
Viewings & attendance
- Viewing request: property ID, scheduled date/time, optional note, lifecycle status (pending, accepted, rejected, cancelled)
- Attendance confirmation: a single yes/unknown flag and a timestamp, recorded only during the confirmed viewing time window using your device location. We never store GPS coordinates, a location trail, or any background location history — only whether you were there and when.
Moderation & audit
- Property report records: reporter user ID, reason, additional details, reporter IP, status, severity, admin notes, action taken, viewing-admin ID
- Account deletion requests: reason, scheduled deletion timestamp, snapshot of name/email/phone at request time, JSON audit log
In total, the Platform stores personal data across approximately thirty-eight database models. The list above is comprehensive at the category level — if you would like a complete field-level inventory for a specific subject access request, contact [email protected].
How We Collect Personal Data
We collect personal data
- Directly from you — when you register, complete profile fields, list a property, send a message, file a report, contact support, or make a payment
- Automatically — through your interaction with the Platform (device data, analytics, IP address, cookies, push tokens)
- From the Saudi national digital identity service (Nafath / Elm) — when you complete identity verification
- From Apple or Google — when you sign in with Apple ID or a Google account
- From REGA — for licence and registration checks, where required
- From our payment processor (Moyasar) — for transaction confirmations, refunds, and webhook events
- From our SMS and email providers — for delivery status of OTPs and notifications
- From you on behalf of others — for example, when a Lister uploads a property featuring identifiable people, or an Agency adds team members
Why We Use Your Data — Purposes & Legal Bases
Under the PDPL, we may process personal data only for legitimate purposes and on a clear legal basis. Our purposes and bases are:
To operate and provide the Platform — contractual necessity
- Create and authenticate your account
- Verify your identity through Nafath, email, phone, Apple, or Google
- Verify Agency credentials (FAL, CR, representative)
- Publish, search, and display Listings
- Receive and route Offers, messages, and notifications
- Process payments through Moyasar, Apple, or Google
- Issue subscriptions and Featured Listing placements
- Respond to support requests and run the AI assistant
- Confirm attendance at confirmed viewings — by recording a yes/unknown flag and timestamp from your device location, during the viewing window only, for safety (§ Viewings & Location Attendance)
To comply with Saudi law — legal obligation
- Meet REGA's listing, advertising, and brokerage requirements
- Issue ZATCA-compliant tax invoices and retain transaction records for tax-audit purposes (six years per Saudi norm)
- Respond to lawful requests from competent authorities
- Maintain records required by the e-Commerce Law and the Anti-Cyber Crime Law
To protect the Platform — legitimate interest
- Detect, prevent, and investigate fraud, abuse, and bots
- Moderate Listings and reports
- Run admin verification and grant/revoke flows
- Keep audit logs of admin actions
- Maintain security, monitoring, and incident response
To improve and personalize — consent for non-essential, legitimate interest for essential improvement:
- Analyze how the Platform is used (sessions, screens, search queries, interaction events)
- Run A/B tests and product experiments
- Personalize search, recommendations, and notifications
To hear from you and understand our reach — legitimate interest (you can opt out):
- Contact you — by email, SMS, in-app message, or phone — to request feedback, run satisfaction and product surveys, and understand how you discovered Manzo (attribution and marketing-effectiveness research)
- These are relationship and research communications, not promotional marketing. You can opt out at any time in app settings, by telling us during the call or message, or by writing to [email protected] — and, being based on our legitimate interest, you may also object to this processing under § Your Rights
For marketing — consent only
- Send promotional emails, SMS, or push notifications
- You may withdraw consent at any time in app settings or via the unsubscribe link in our emails
International Data Transfers
Our primary infrastructure for everything Manzo controls — application servers, databases, caches, media storage, logs, and the AI assistant — is hosted in me-central2 (Dammam, Saudi Arabia) on Google Cloud Platform. By default your data stays in Saudi Arabia.
The following categories of data are transferred outside Saudi Arabia, by name and purpose:
- Transactional email content — to ZeptoMail in the European Union
- Push notification payloads and device tokens — to Firebase Cloud Messaging (Google, multi-region)
- Sign-in identity tokens — to Apple (United States) and Google (United States)
- Address strings and coordinates for geocoding — to Google Maps Platform (United States)
- Support pings (name, email, phone, message body) — to Slack (United States)
For each transfer, we rely on one or more of the following PDPL-aligned bases
- Contractual necessity — the transfer is required to deliver a service you requested
- Adequacy or safeguards — the recipient operates in a jurisdiction with adequate data protection or under contractual safeguards designed to provide PDPL-equivalent protection
- Your consent — for non-essential transfers, where applicable
You may contact [email protected] for further information about the safeguards in place for any specific transfer.
How We Protect Your Data
We apply technical and organizational measures appropriate to the risk of the processing, including:
- Encryption of personal data in transit (TLS) and at rest
- Strict identity-and-access controls; least-privilege role assignments for staff
- Multi-factor authentication for staff with administrative access
- Continuous logging and monitoring through Google Cloud Logging
- Tokenization of payment instruments (we never receive full PAN or CVV)
- Hashing of Nafath JWTs (we never store the raw JWT)
- Segregation of staging and production environments
- Vendor due diligence on all sub-processors
No security measure is absolute. If you become aware of a security issue, write to [email protected] with subject line "SECURITY".
How Long We Keep Your Data
We retain personal data for as long as necessary to operate the Platform, comply with our legal obligations, and resolve disputes. Specific retention rules — as actually implemented:
- Account data: retained while your account is active. On deletion request, a 60-day grace period applies (see § Account Deletion). After grace, your name is replaced with "Deleted User", email is reassigned to a non-deliverable internal alias, phone is anonymized, and Nafath fields are cleared.
- National ID: retained after anonymization for ZATCA tax-audit compliance, in line with the six-year retention norm under Saudi law.
- Email verification token: 24 hours, deleted on use or expiry
- Social signup token: 10 minutes, deleted on use or expiry
- Nafath verification session: 5 minutes of activity TTL, then status is finalized; the row remains for audit
- Nafath verification record: retained indefinitely as an audit record (only the SHA-256 JWT hash is stored, never the raw JWT)
- Chat messages: retained indefinitely. You may soft-delete messages from your view; the row is retained on the server
- Payments, refunds, and webhook records: retained indefinitely for ZATCA tax-audit compliance
- Saved cards: deleted on account deletion; the underlying Moyasar token is also revoked
- Draft listings: retained until you (or an admin) delete them
- Property reports & admin moderation notes: retained indefinitely as an audit record
- Analytics data: retained while your account is active and as long as we need it to operate and improve the service. On account deletion, our anonymization pipeline scrubs PII from analytics rows tied to the deleted user.
- Server logs: retained per Google Cloud Logging defaults; logs may include redacted PII.
We do not implement an absolute "right to erasure" — instead we follow an anonymize-and-retain model for fields we are required to keep for audit, tax, or legal-defence purposes. Where mandatory law gives you a stronger right than we describe here, that mandatory law prevails.
Your Rights Under the PDPL
As a data subject under the PDPL, you have the right to
- Access — request confirmation of whether we process your personal data and a copy of that data
- Rectification — request correction of inaccurate or incomplete data
- Erasure — request deletion of your personal data, subject to the retention rules above and any mandatory legal obligation we cannot displace
- Restriction — request that we limit processing in certain circumstances
- Withdraw consent — for any processing based on your consent (for example, marketing or location tracking)
- Object — to processing based on our legitimate interests, where your particular situation requires it
- Be informed — about how your personal data is processed, by whom, and on what legal basis (this Policy is part of how we meet that obligation)
To exercise any of these rights, contact [email protected]. We will respond within the timelines required by the PDPL. We may need to verify your identity before responding to your request.
If you are not satisfied with our response, you have the right to lodge a complaint with the Saudi Data & Artificial Intelligence Authority (SDAIA).
Account Deletion
You may request deletion of your account at any time from in-app settings or by writing to [email protected].
How deletion works
- Your request enters a 60-day grace period during which it can be cancelled by signing back in or contacting support
- After the grace period, a daily backend process anonymizes your account: name becomes "Deleted User", email is reassigned to an internal non-deliverable alias, phone is replaced with a placeholder, profile picture, biography, and preferences are cleared, and Nafath identity fields are cleared from the User record
- Your saved cards are deleted and the underlying Moyasar tokens revoked
- Your messages remain in conversation threads with other users (so the other side's view is not broken), but with your sender details anonymized; you may soft-delete individual messages from your own view
- Your Listings remain on the Platform unless you also delete them — they may be transferred or hidden depending on context
- Your national ID is retained in anonymized form to satisfy ZATCA tax-audit requirements (six-year norm)
- Audit records (property reports you filed, agency-verification logs, payment records) are retained for legal, regulatory, and dispute-resolution purposes
Children
The Platform is intended for users aged 18 or above. We do not knowingly collect personal data from children under 18. If we become aware that a minor has provided personal data without verified parental or legal-guardian consent, we will delete it without undue delay.
Viewings & Location Attendance
The Manzo platform allows users to book and accept property viewings between Nafath-verified parties.
What we do with your location
When you have a confirmed viewing (one that has been accepted and is within its scheduled time window), the app may request permission to read your device location — once — to check whether you are at the property. We record only a yes/unknown flag and a timestamp. We never record your GPS coordinates, never build a location trail, and never access your location outside the confirmed viewing window.
Legal basis: contractual necessity (to operate the safety record of a booked viewing between two Nafath-verified users) and, where required by the PDPL, your consent given through the device permission prompt.
Consent and control
- Location access requires you to grant the device location permission when prompted. You may decline or revoke this permission at any time in your device settings (iOS: Settings → Privacy & Security → Location Services → Manzo; Android: Settings → Apps → Manzo → Permissions → Location).
- Declining or revoking permission does not cancel your viewing — it simply means attendance stays "unknown" rather than "confirmed".
- We never request background location (always-on) permission. The single location read is triggered only during the active viewing window.
Purpose limitation
The attendance flag is used solely to create a safety record confirming that a viewing between two Nafath-verified users took place. It is not used for advertising, profiling, or any purpose other than viewing safety. It is not shared with third parties outside of the sub-processors listed in § Who We Share Your Data With.
Retention
The attendance flag and timestamp are retained as part of the viewing record for the same period as other viewing data. See § How Long We Keep Your Data.
Location Data — Nearby Property Alerts
Nearby property alerts (optional). If you turn on Nearby property alerts in the app, Manzo collects your device's approximate location — while you use the app and, if you allow it, in the background — to notify you about rentals available in neighborhoods you visit. We use it only for that purpose and for personalizing property suggestions. We do not sell it, use it for advertising, or share it with third parties. Location samples are kept for 30 days and then deleted. You can turn Nearby property alerts off at any time in Settings → Notifications, or revoke location access in your device settings; the app keeps working without it. Personalized property suggestions are also based on your searches and the listings you view in the app.
Data-collection summary for this feature
- Data type: Location (approximate)
- Purpose: App functionality (nearby alerts), personalisation
- Linked to account: Yes
- Retention: 30 days, then deleted
- Optional: Yes — disabled by default; requires your explicit opt-in
Marketing Communications
We will only send you marketing emails, SMS, or push notifications where you have explicitly opted in.
You may withdraw consent at any time
- In the app, via Notification Preferences
- In any email, via the "unsubscribe" link
- By writing to [email protected]
Withdrawing consent for marketing does not affect transactional and security communications (for example, verification codes, payment receipts, dispute notices), which we send on the basis of contractual necessity or legal obligation.
Third-Party Links
The Platform may contain links to third-party websites, apps, or services. We are not responsible for the privacy practices of any third party. We encourage you to review the privacy policy of any third party before sharing personal data with them.
Changes to This Policy
We may update this Policy from time to time. The latest version is the version published on manzo.com.sa, dated by the "Updated" pill at the top of this page. Where a change is material — for example, a new sub-processor, a new category of data, or a change to retention — we will give reasonable notice by email, in-app message, or both.
How to Contact Us
Data Protection Officer: Abdullah Bader AlOtaishan [email protected]
General inquiries: [email protected]
Manzo Proptech Company Riyadh, Kingdom of Saudi Arabia Commercial Registration No. 7041635215
Questions
Need clarification on anything in this document?
We respond to legal inquiries on Saudi business days.
[email protected]This document forms part of your agreements with Manzo Proptech Company (CR No. 7041635215).