PrivacyUpdated September 4, 2026

Privacy Policy

This Policy explains how Manzo Proptech Company handles your personal data in line with the Saudi Personal Data Protection Law (PDPL). It covers what we actually collect, where we store it (Dammam by default), and every sub-processor we share it with — disclosed by name.

Terms & Conditions
§ 01

About This Policy

This Privacy Policy explains how Manzo Proptech Company ("Manzo", "we", "our", or "us") — a Saudi limited liability company registered under Commercial Registration No. 7041635215 — collects, uses, shares, and protects personal data when you use the Manzo website, our iOS and Android applications, our APIs, and any related services (together, the "Platform").

We process personal data in accordance with the Saudi Personal Data Protection Law (the "PDPL") and its Implementing Regulations issued by the Saudi Data & Artificial Intelligence Authority (SDAIA), together with all other applicable Saudi laws.

For the purposes of the PDPL, Manzo is the controller of the personal data described in this Policy.

Data Protection Officer. Our Data Protection Officer is Abdullah Bader AlOtaishan. To contact the DPO — including for any access, correction, deletion, or complaint request — write to [email protected].

§ 02

Scope

This Policy applies to

  • Visitors to manzo.com.sa and any subdomain we operate
  • Users of the Manzo iOS and Android apps
  • Users of any Manzo API, dashboard, or admin tooling
  • Individuals whose data is uploaded to the Platform by Listers, Agencies, or other users (for example, the team member of an agency)

It does not apply to third-party websites or apps you reach through links on the Platform — review their own policies before sharing personal data.

§ 03

What Personal Data We Collect

We collect the categories of personal data set out below. Where a field is generated by you (for example a chat message), we collect what you provide. Where a field is provided by an authority (for example Nafath), we collect only what the authority returns to us.

Identity & Nafath verification

  • Name, email address, phone number, national ID or Iqama number
  • First, father, grand-father, and family names where Nafath returns them
  • Date of birth, gender, nationality
  • Profile picture, biography, language preference
  • Last login, registration date
  • A SHA-256 hash of any Nafath JWT received (we never store the raw JWT)
  • Apple Sign-In and Google Sign-In identifiers (provider, provider user ID, provider email)

Agency data

  • Company name (Arabic and English), trade name where provided
  • Commercial Registration number, FAL (REGA marketing licence) number
  • Authorized representative name, mobile, and email
  • Office phone, email, website, address, latitude/longitude
  • Verification status, verification timestamp, subscription tier and end date
  • Team members, invitation tokens, roles, statuses, joined/invited timestamps

Property & location data

  • Listing title, description, price, area, type, room counts, amenities
  • Address (free text + structured), city, coordinates (PostGIS)
  • Original (un-offset) coordinates and the location-privacy preference
  • REGA ad-licence number and expiry
  • Report count, hidden-due-to-reports flag, ownership-verification fields

Offers, contracts, and messaging

  • Offer price, move-in/move-out dates, payment reference, contract handler, lifecycle timestamps
  • Snapshotted offerer name and profile picture (captured at offer time)
  • Message content (free text — anything users type), read receipts, soft-delete flags

Devices and notifications

  • Firebase Cloud Messaging device tokens
  • Device type (iOS/Android/Web), device name, app version, last used
  • Notification delivery records (recipient email/phone, status timeline)
  • Per-channel notification preferences (push, email, SMS)

Payments

  • Moyasar payment ID and environment marker
  • Card brand, last four digits, expiry month/year, cardholder name, Moyasar card token (we do not store full PAN or CVV — these never reach our systems)
  • Payment amount, currency, method, Moyasar charge / session / receipt IDs, completion timestamp
  • Refund, webhook, and subscription history records

Behavioural & analytics data

  • Sessions, property views, clicks, shares, search queries (text), screen views, interaction events
  • User or guest ID, device ID, platform, app version, device model, OS version
  • Latitude/longitude, city, country, IP address, user agent, referrer, page URL
  • Touch coordinates, scroll depth, image-view counts
  • Onboarding events, threshold metrics, recommendation outputs

Help center & support

  • Contact-form submissions: name, email, phone, message body, IP address, user agent
  • Callback requests
  • AI assistant memory: previous questions, viewed properties, search preferences, interaction patterns

Viewings & attendance

  • Viewing request: property ID, scheduled date/time, optional note, lifecycle status (pending, accepted, rejected, cancelled)
  • Attendance confirmation: a single yes/unknown flag and a timestamp, recorded only during the confirmed viewing time window using your device location. We never store GPS coordinates, a location trail, or any background location history — only whether you were there and when.

Moderation & audit

  • Property report records: reporter user ID, reason, additional details, reporter IP, status, severity, admin notes, action taken, viewing-admin ID
  • Account deletion requests: reason, scheduled deletion timestamp, snapshot of name/email/phone at request time, JSON audit log

In total, the Platform stores personal data across approximately thirty-eight database models. The list above is comprehensive at the category level — if you would like a complete field-level inventory for a specific subject access request, contact [email protected].

§ 04

How We Collect Personal Data

We collect personal data

  • Directly from you — when you register, complete profile fields, list a property, send a message, file a report, contact support, or make a payment
  • Automatically — through your interaction with the Platform (device data, analytics, IP address, cookies, push tokens)
  • From the Saudi national digital identity service (Nafath / Elm) — when you complete identity verification
  • From Apple or Google — when you sign in with Apple ID or a Google account
  • From REGA — for licence and registration checks, where required
  • From our payment processor (Moyasar) — for transaction confirmations, refunds, and webhook events
  • From our SMS and email providers — for delivery status of OTPs and notifications
  • From you on behalf of others — for example, when a Lister uploads a property featuring identifiable people, or an Agency adds team members
§ 05

Why We Use Your Data — Purposes & Legal Bases

Under the PDPL, we may process personal data only for legitimate purposes and on a clear legal basis. Our purposes and bases are:

To operate and provide the Platform — contractual necessity

  • Create and authenticate your account
  • Verify your identity through Nafath, email, phone, Apple, or Google
  • Verify Agency credentials (FAL, CR, representative)
  • Publish, search, and display Listings
  • Receive and route Offers, messages, and notifications
  • Process payments through Moyasar, Apple, or Google
  • Issue subscriptions and Featured Listing placements
  • Respond to support requests and run the AI assistant
  • Confirm attendance at confirmed viewings — by recording a yes/unknown flag and timestamp from your device location, during the viewing window only, for safety (§ Viewings & Location Attendance)

To comply with Saudi law — legal obligation

  • Meet REGA's listing, advertising, and brokerage requirements
  • Issue ZATCA-compliant tax invoices and retain transaction records for tax-audit purposes (six years per Saudi norm)
  • Respond to lawful requests from competent authorities
  • Maintain records required by the e-Commerce Law and the Anti-Cyber Crime Law

To protect the Platform — legitimate interest

  • Detect, prevent, and investigate fraud, abuse, and bots
  • Moderate Listings and reports
  • Run admin verification and grant/revoke flows
  • Keep audit logs of admin actions
  • Maintain security, monitoring, and incident response

To improve and personalize — consent for non-essential, legitimate interest for essential improvement:

  • Analyze how the Platform is used (sessions, screens, search queries, interaction events)
  • Run A/B tests and product experiments
  • Personalize search, recommendations, and notifications

To hear from you and understand our reach — legitimate interest (you can opt out):

  • Contact you — by email, SMS, in-app message, or phone — to request feedback, run satisfaction and product surveys, and understand how you discovered Manzo (attribution and marketing-effectiveness research)
  • These are relationship and research communications, not promotional marketing. You can opt out at any time in app settings, by telling us during the call or message, or by writing to [email protected] — and, being based on our legitimate interest, you may also object to this processing under § Your Rights

For marketing — consent only

  • Send promotional emails, SMS, or push notifications
  • You may withdraw consent at any time in app settings or via the unsubscribe link in our emails
§ 06

Who We Share Your Data With

We share personal data only with the categories of recipients listed below, only for the purposes stated, and only to the extent necessary.

Other users on the Platform

  • Your name, profile picture, and contact details (where you choose to share them) when you message or send an offer
  • Your Listings and the snapshot fields of any Offer you send

Saudi authorities

• REGA, the Ministry of Justice, the Ministry of Commerce, SDAIA, the Saudi Anti-Cyber Crime authority, and any other competent authority — where required by law, by regulation, or by a lawful order

Payment processors

  • Moyasar — card payments, Mada, Apple Pay over card rails. Saudi-licensed, SAMA-regulated, PCI-DSS certified
  • Apple Inc. — in-app purchases on iOS via the App Store
  • Google LLC — in-app purchases on Android via Google Play

Communications providers

  • Taqnyat — SMS and OTP delivery (Saudi Arabia)
  • ZeptoMail — transactional email delivery (European Union)
  • Firebase Cloud Messaging — push notification delivery (Google, multi-region)

Identity providers

  • Nafath / Elm — Saudi national digital identity (Saudi Arabia)
  • Apple — Apple Sign-In identity service (United States)
  • Google — Google Sign-In identity service (United States)

Mapping & geocoding

• Google Maps Platform — Places, Geocoding, Distance Matrix, Directions APIs (United States)

Cloud infrastructure

  • Google Cloud Platform — Cloud Run, Cloud SQL Postgres, Memorystore Redis, Cloud Storage, Cloud Logging, all hosted in me-central2 (Dammam, Saudi Arabia)
  • Vertex AI Gemini — help-center AI assistant, configured to me-central2 (Dammam, Saudi Arabia)
  • OpenSearch — property search and recommendations

AI / chatbot

• Vertex AI Gemini, hosted in Saudi Arabia, processes user questions and the last ten turns of conversation history to power the help-center assistant

Support tooling

• Slack — internal channel notifications for contact-form submissions, callback requests, and escalations (United States)

Professional advisers

• Lawyers, auditors, accountants, and insurers — where required to defend a claim, respond to an audit, or obtain professional advice

Corporate transactions

• Acquirers, investors, or successors — in case of a merger, acquisition, financing, or sale of all or substantially all of our assets, subject to confidentiality undertakings

We do not sell your personal data, and we do not share your personal data for behavioural advertising on third-party platforms.

§ 07

International Data Transfers

Our primary infrastructure for everything Manzo controls — application servers, databases, caches, media storage, logs, and the AI assistant — is hosted in me-central2 (Dammam, Saudi Arabia) on Google Cloud Platform. By default your data stays in Saudi Arabia.

The following categories of data are transferred outside Saudi Arabia, by name and purpose:

  • Transactional email content — to ZeptoMail in the European Union
  • Push notification payloads and device tokens — to Firebase Cloud Messaging (Google, multi-region)
  • Sign-in identity tokens — to Apple (United States) and Google (United States)
  • Address strings and coordinates for geocoding — to Google Maps Platform (United States)
  • Support pings (name, email, phone, message body) — to Slack (United States)

For each transfer, we rely on one or more of the following PDPL-aligned bases

  • Contractual necessity — the transfer is required to deliver a service you requested
  • Adequacy or safeguards — the recipient operates in a jurisdiction with adequate data protection or under contractual safeguards designed to provide PDPL-equivalent protection
  • Your consent — for non-essential transfers, where applicable

You may contact [email protected] for further information about the safeguards in place for any specific transfer.

§ 08

How We Protect Your Data

We apply technical and organizational measures appropriate to the risk of the processing, including:

  • Encryption of personal data in transit (TLS) and at rest
  • Strict identity-and-access controls; least-privilege role assignments for staff
  • Multi-factor authentication for staff with administrative access
  • Continuous logging and monitoring through Google Cloud Logging
  • Tokenization of payment instruments (we never receive full PAN or CVV)
  • Hashing of Nafath JWTs (we never store the raw JWT)
  • Segregation of staging and production environments
  • Vendor due diligence on all sub-processors

No security measure is absolute. If you become aware of a security issue, write to [email protected] with subject line "SECURITY".

§ 09

How Long We Keep Your Data

We retain personal data for as long as necessary to operate the Platform, comply with our legal obligations, and resolve disputes. Specific retention rules — as actually implemented:

  • Account data: retained while your account is active. On deletion request, a 60-day grace period applies (see § Account Deletion). After grace, your name is replaced with "Deleted User", email is reassigned to a non-deliverable internal alias, phone is anonymized, and Nafath fields are cleared.
  • National ID: retained after anonymization for ZATCA tax-audit compliance, in line with the six-year retention norm under Saudi law.
  • Email verification token: 24 hours, deleted on use or expiry
  • Social signup token: 10 minutes, deleted on use or expiry
  • Nafath verification session: 5 minutes of activity TTL, then status is finalized; the row remains for audit
  • Nafath verification record: retained indefinitely as an audit record (only the SHA-256 JWT hash is stored, never the raw JWT)
  • Chat messages: retained indefinitely. You may soft-delete messages from your view; the row is retained on the server
  • Payments, refunds, and webhook records: retained indefinitely for ZATCA tax-audit compliance
  • Saved cards: deleted on account deletion; the underlying Moyasar token is also revoked
  • Draft listings: retained until you (or an admin) delete them
  • Property reports & admin moderation notes: retained indefinitely as an audit record
  • Analytics data: retained while your account is active and as long as we need it to operate and improve the service. On account deletion, our anonymization pipeline scrubs PII from analytics rows tied to the deleted user.
  • Server logs: retained per Google Cloud Logging defaults; logs may include redacted PII.

We do not implement an absolute "right to erasure" — instead we follow an anonymize-and-retain model for fields we are required to keep for audit, tax, or legal-defence purposes. Where mandatory law gives you a stronger right than we describe here, that mandatory law prevails.

§ 10

Your Rights Under the PDPL

As a data subject under the PDPL, you have the right to

  • Access — request confirmation of whether we process your personal data and a copy of that data
  • Rectification — request correction of inaccurate or incomplete data
  • Erasure — request deletion of your personal data, subject to the retention rules above and any mandatory legal obligation we cannot displace
  • Restriction — request that we limit processing in certain circumstances
  • Withdraw consent — for any processing based on your consent (for example, marketing or location tracking)
  • Object — to processing based on our legitimate interests, where your particular situation requires it
  • Be informed — about how your personal data is processed, by whom, and on what legal basis (this Policy is part of how we meet that obligation)

To exercise any of these rights, contact [email protected]. We will respond within the timelines required by the PDPL. We may need to verify your identity before responding to your request.

If you are not satisfied with our response, you have the right to lodge a complaint with the Saudi Data & Artificial Intelligence Authority (SDAIA).

§ 11

Account Deletion

You may request deletion of your account at any time from in-app settings or by writing to [email protected].

How deletion works

  • Your request enters a 60-day grace period during which it can be cancelled by signing back in or contacting support
  • After the grace period, a daily backend process anonymizes your account: name becomes "Deleted User", email is reassigned to an internal non-deliverable alias, phone is replaced with a placeholder, profile picture, biography, and preferences are cleared, and Nafath identity fields are cleared from the User record
  • Your saved cards are deleted and the underlying Moyasar tokens revoked
  • Your messages remain in conversation threads with other users (so the other side's view is not broken), but with your sender details anonymized; you may soft-delete individual messages from your own view
  • Your Listings remain on the Platform unless you also delete them — they may be transferred or hidden depending on context
  • Your national ID is retained in anonymized form to satisfy ZATCA tax-audit requirements (six-year norm)
  • Audit records (property reports you filed, agency-verification logs, payment records) are retained for legal, regulatory, and dispute-resolution purposes
§ 12

Children

The Platform is intended for users aged 18 or above. We do not knowingly collect personal data from children under 18. If we become aware that a minor has provided personal data without verified parental or legal-guardian consent, we will delete it without undue delay.

§ 13

Cookies & Mobile Tracking

Backend cookies. The Manzo backend may set the following cookies on web flows that interact directly with our Django views:

  • sessionid — Django session identifier; HttpOnly; scoped to manzo.com.sa
  • csrftoken — cross-site request forgery protection; scoped to manzo.com.sa

These are essential for security and for the operation of the Platform; they are not used for advertising.

Mobile apps. Our iOS and Android apps store access and refresh JWTs in the platform's secure storage (Keychain on iOS, Keystore on Android). The mobile apps do not embed third-party trackers (no Sentry, Mixpanel, PostHog, or Google Analytics on mobile) and use only Firebase Cloud Messaging to receive push notification tokens.

Web frontend. Cookies, localStorage entries, and any third-party SDKs set by the manzo.com.sa web frontend are documented separately in our cookie disclosure on the web site. Where applicable, we surface a cookie banner on first visit and respect your preferences for non-essential categories.

§ 14

Viewings & Location Attendance

The Manzo platform allows users to book and accept property viewings between Nafath-verified parties.

What we do with your location

When you have a confirmed viewing (one that has been accepted and is within its scheduled time window), the app may request permission to read your device location — once — to check whether you are at the property. We record only a yes/unknown flag and a timestamp. We never record your GPS coordinates, never build a location trail, and never access your location outside the confirmed viewing window.

Legal basis: contractual necessity (to operate the safety record of a booked viewing between two Nafath-verified users) and, where required by the PDPL, your consent given through the device permission prompt.

Consent and control

  • Location access requires you to grant the device location permission when prompted. You may decline or revoke this permission at any time in your device settings (iOS: Settings → Privacy & Security → Location Services → Manzo; Android: Settings → Apps → Manzo → Permissions → Location).
  • Declining or revoking permission does not cancel your viewing — it simply means attendance stays "unknown" rather than "confirmed".
  • We never request background location (always-on) permission. The single location read is triggered only during the active viewing window.

Purpose limitation

The attendance flag is used solely to create a safety record confirming that a viewing between two Nafath-verified users took place. It is not used for advertising, profiling, or any purpose other than viewing safety. It is not shared with third parties outside of the sub-processors listed in § Who We Share Your Data With.

Retention

The attendance flag and timestamp are retained as part of the viewing record for the same period as other viewing data. See § How Long We Keep Your Data.

§ 15

Location Data — Nearby Property Alerts

Nearby property alerts (optional). If you turn on Nearby property alerts in the app, Manzo collects your device's approximate location — while you use the app and, if you allow it, in the background — to notify you about rentals available in neighborhoods you visit. We use it only for that purpose and for personalizing property suggestions. We do not sell it, use it for advertising, or share it with third parties. Location samples are kept for 30 days and then deleted. You can turn Nearby property alerts off at any time in Settings → Notifications, or revoke location access in your device settings; the app keeps working without it. Personalized property suggestions are also based on your searches and the listings you view in the app.

Data-collection summary for this feature

  • Data type: Location (approximate)
  • Purpose: App functionality (nearby alerts), personalisation
  • Linked to account: Yes
  • Retention: 30 days, then deleted
  • Optional: Yes — disabled by default; requires your explicit opt-in
§ 16

Marketing Communications

We will only send you marketing emails, SMS, or push notifications where you have explicitly opted in.

You may withdraw consent at any time

  • In the app, via Notification Preferences
  • In any email, via the "unsubscribe" link
  • By writing to [email protected]

Withdrawing consent for marketing does not affect transactional and security communications (for example, verification codes, payment receipts, dispute notices), which we send on the basis of contractual necessity or legal obligation.

§ 18

Changes to This Policy

We may update this Policy from time to time. The latest version is the version published on manzo.com.sa, dated by the "Updated" pill at the top of this page. Where a change is material — for example, a new sub-processor, a new category of data, or a change to retention — we will give reasonable notice by email, in-app message, or both.

§ 19

How to Contact Us

Data Protection Officer: Abdullah Bader AlOtaishan [email protected]

General inquiries: [email protected]

Manzo Proptech Company Riyadh, Kingdom of Saudi Arabia Commercial Registration No. 7041635215

Questions

Need clarification on anything in this document?

We respond to legal inquiries on Saudi business days.

[email protected]

This document forms part of your agreements with Manzo Proptech Company (CR No. 7041635215).