Privacy Policy
Al Zaitoon Compound App / IQ Compound
1. Introduction and scope
This Privacy Policy explains how the Al Zaitoon Compound App / IQ Compound platform collects, uses, stores, shares, and protects personal information. It applies to guests, residents and normal registered users, approved service providers inside the compound, approved service providers outside the compound, compound administrators, security users, and other account types supported by the platform.
Resident services are intended for residents of Al Zaitoon Compound. Approved service providers may operate from inside or outside the compound, subject to administrative review and approval. This Policy applies to the mobile application, related APIs, support services, account deletion requests, reporting tools, notifications, and related public web pages.
2. Operator and privacy contact
The platform is operated and technically maintained by TcPedia, a sole proprietorship operated by Muhanad Al Azawi.
NIE: Z3094883P
Address: Calle Italia 20, Entresuelo, 03003 Alicante, Spain
Email: info@tcpedia.com
Support Phone: +964 - 7724488662
Websites: https://alzaitooncompound.com | https://tcpedia.com
3. Information we collect
We collect information directly from users, information generated through use of the platform, limited technical information from devices, information received from compound administration, and information submitted during provider approval.
- Account and identity data: name, phone number, email address when provided, hashed password and authentication credentials or tokens, WhatsApp preference, role, account status, and verification status.
- Resident and compound data: compound membership, role, section, street, building, unit, floor, property number, address labels, gender, profile photo, and related resident profile information.
- Provider data: business name, description, service categories, inside or outside location type, address, latitude and longitude, working hours, business phone, contact email, pickup or delivery options, ordering mode, provider type, approval status, ratings, subscriptions where applicable, identity document, additional document, logo, cover image, and provider gallery or service images.
- Marketplace data: product category, listing type, title, description, price, negotiability, delivery options, contact number, status, published date, item address, and listing images.
- Orders and service requests: resident, provider, category, offering, descriptions, pickup or delivery details, scheduled times, price estimates, final price, status changes, cancellation or rejection reasons, and order events.
- Visitor passes: visitor name, visitor phone, vehicle information, entry date and time, validity period, notes, QR token or QR code image, gate selections, scan/approval/rejection/cancellation status, and related security actions.
- Reviews, ratings, and community content: ratings, comments, provider review details, marketplace content, and other user-submitted content.
- Support, reports, and moderation: support tickets, support messages, report target, report reason, user-written details, attached images, review status, moderation history, and account deletion request records.
- Device and notification data: device ID, platform, app version, locale, device model, device name, FCM token, notification preferences where supported, and last seen time.
- Security and diagnostics: IP address, request metadata, authentication events, security logs, error/diagnostic logs, and abuse-prevention records.
- Location and uploads: approximate or precise location coordinates when provided or selected in the app, and camera or photo-library content uploaded by the user.
4. Why we use information
We process information to provide and protect the platform, including account registration and authentication, phone OTP verification, resident verification, provider application and management, provider profiles and services, marketplace listing publication, order and service request management, visitor pass generation and security processing, push notifications, support, account deletion, moderation and report handling, fraud and abuse prevention, technical diagnostics, service improvement, legal compliance, and dispute resolution.
The platform does not process electronic payments within the application.
5. Legal and operational basis
Depending on the context, processing may be based on providing the requested service, the user's consent where required, legitimate operational and security interests, safety and fraud-prevention needs, or compliance with applicable legal obligations.
6. User-generated content and moderation data
The platform processes marketplace listings, provider profiles, service information, images, reviews, ratings, comments, and reports submitted about products, providers, or reviews. Reports may include the reporter identity, reported target, selected reason, written details, date and time, and administrative review status. Reports are used to investigate possible violations, prevent abuse, and enforce the Terms. Reports are not published to other users as public content.
7. Third-party services and processors
We use service providers only as needed to operate the platform. Current service integrations include Firebase Cloud Messaging for push notification delivery, Otpiq for OTP delivery through WhatsApp/SMS channels when real OTP mode is enabled, Laravel mail transports for email delivery when configured, hosting/infrastructure providers, and secure file storage services for uploaded images and verification documents. Uploaded public profile and business images may be displayed publicly when uploaded for that purpose. Uploaded identity, licence, permit, and verification documents are restricted to authorized administrative access and are not intended to be publicly displayed. These providers may process device tokens, phone numbers, message delivery data, email delivery data, uploaded files, IP addresses, and technical metadata as needed for their services. Their own privacy terms may also apply.
Google Maps and location services may be used to display addresses, provider locations, maps, directions, or other location-related application features. When a user enables or uses a location-related feature, Google and the device platform may process location information, IP address, device information, and technical usage information required to provide that feature. Location permission can be controlled through the device settings, although disabling it may prevent or limit location-dependent features. Google processes relevant information according to its own applicable privacy terms.
For Apple devices, the application uses Apple Push Notification service (APNs), together with Firebase Cloud Messaging and the application's notification infrastructure where applicable, to deliver notifications. Apple may process a device or application push token and technical delivery information necessary to deliver notifications. Users may refuse notification permission or later disable notifications through device settings. Disabling notifications does not delete the account, but may prevent important application updates from being received.
The platform does not currently use advertising networks or advertising-tracking tools. If analytics or diagnostic services are added in the future, this Privacy Policy and the applicable app-store disclosures will be updated accordingly.
8. International processing
The operator is located in Spain, the application serves users in Iraq, and technical providers may operate infrastructure in other countries. Information may therefore be processed outside Iraq where necessary to host the service, deliver OTP or push notifications, provide email delivery, store files, or maintain security. We use reasonable safeguards appropriate to the service and the nature of the information.
9. Data sharing
We may share information with compound administration, authorised security personnel, service providers where needed to fulfil a request or order, technical service providers, legal or regulatory authorities when lawfully required, and professional advisers where necessary. Service providers receive only information reasonably needed to communicate with the resident or complete the requested service. We do not sell personal data and do not share personal data with advertisers.
10. Retention
Active account data is retained while the account is active and as needed to provide the service. Order, service, support, security, report, moderation, visitor pass, provider verification, and transaction-related records may be retained for a reasonable period where needed to resolve cases, prevent repeated abuse, keep audit history, defend legal claims, meet accounting or legal obligations, or protect community safety. Technical logs are retained for a limited security and diagnostic period. Backup copies may remain until routine backup rotation is completed. Data kept after deletion is restricted to the purpose that justifies retaining it.
11. Account deletion and associated data
Users can initiate account deletion inside the application. Users can also use the public account deletion resource and request form at https://alzaitooncompound.com/account-deletion. Valid deletion requests result in deletion, disabling, removal, or anonymisation of the account and associated personal data, subject only to limited legal, security, fraud-prevention, dispute, accounting, audit, or regulatory exceptions. Provider account deletion may also affect provider profiles, listings, orders, subscriptions, and related public visibility according to platform rules.
Some historical records may be retained in restricted form where needed for safety, legal compliance, dispute handling, or abuse prevention. Public content may be removed, anonymised, or retained only where legally or operationally justified. Additional identity verification may be required before completing a deletion request.
12. Security
We use reasonable technical and organisational safeguards, including authenticated APIs, access controls, restricted administrative access, secure transport where configured, logging and monitoring, file access controls, and controlled service-provider access. No digital service can guarantee absolute security. Users should protect their devices, phone numbers, and account access.
13. User rights and choices
Users may access and update profile information in the app where supported, correct inaccurate information, request account deletion, contact support about personal data, withdraw optional device permissions through device settings, disable push notifications through device settings, and contact us about privacy concerns. Some requests may require verification of identity or account ownership.
14. Children and minors
The platform is not directed specifically at children. Users under 18 should use the platform only with supervision from a parent or legal guardian, and the responsible adult remains responsible for the minor's activity.
15. Changes to this Policy
We may update this Privacy Policy when the platform, legal requirements, or operational practices change. Updated versions will be published in the application or on the website. The metadata at the top of this page identifies the current version.