سياسة الخصوصية لمنصة كاشف

Privacy Policy for Kashif Al-Arqam (كاشف الأرقام): how we collect, use, and protect data under GDPR, CCPA/CPRA, and Saudi PDPL — bilingual EN/AR.

Privacy Policy (English)

Last updated: August 2026 — This Policy applies to all services of Kashif Al-Arqam (“Kashif”, “we”, “us”, “the Platform”) available at https://kashif-alarqam.com/.

We operate a community-oriented phone lookup and reporting platform focused primarily on Yemen and related public-interest safety use cases. This Policy explains what information we collect, how we use it, the legal bases we rely on, and the rights available to you under international and regional privacy frameworks, including the EU/UK GDPR, California CCPA/CPRA, and Saudi Arabia PDPL (Personal Data Protection Law).

1. Who we are & contact

Controller of personal data processed through the Platform:

If you are in the EEA/UK, you may also contact us to exercise GDPR rights. If you are in Saudi Arabia, you may exercise PDPL rights through the same channel.

2. Scope

This Policy covers browsing, phone search (Kashef), reports, objections, contact forms, account/admin access (if any), cookies/similar technologies, analytics, security logs, and advertising integrations where enabled.

It does not cover third-party websites, apps, or telecom operators we do not control. Results shown in search may originate from community contributions and/or external public sources and should be treated as assistive information, not an official government registry.

3. Categories of data we process

3.1 Data you provide

  • Phone numbers you search or submit in reports/objections (and related country codes).
  • Report details: type, channel, description, optional message content, optional evidence images.
  • Objection details: selected Kashef name/report targets, proposed display name, reasons, evidence.
  • Contact form fields: name, email, subject, message.
  • OTP verification data when phone ownership verification is enabled (one-time codes / verification status).

3.2 Data collected automatically

  • Technical logs: IP address (often hashed/truncated where feasible), user-agent, timestamps, pages/paths, security events.
  • Approximate geo/city statistics derived from visits/searches for aggregate analytics.
  • Device/browser identifiers, cookies, local storage, App Check / anti-abuse tokens when enabled.
  • Rate-limit and fraud-prevention signals.

3.3 Data we generally do not sell

We do not sell personal information for money in the traditional sense. Under CCPA/CPRA, some advertising/analytics disclosures may be considered a “sale” or “sharing” for cross-context behavioral advertising. See Section 9.

4. Purposes of processing

  • Provide phone lookup results and related platform pages.
  • Accept, store, review, and display reports/objections and evidence for safety/moderation.
  • Verify phone ownership when required (OTP) and reduce abuse.
  • Respond to contact messages and support requests.
  • Secure the Platform (rate limits, App Check, logging, incident response).
  • Measure aggregate usage (visits/searches) to improve reliability and content.
  • Comply with legal obligations and enforce our Terms.
  • Show advertising (where enabled) to fund free public access.

5. Legal bases (GDPR) & similar principles

  • Contract / service delivery: processing needed to provide the features you request (search, report, objection, contact).
  • Legitimate interests: security, abuse prevention, aggregate analytics, product improvement, defending legal claims — balanced against your rights.
  • Consent: non-essential cookies/ads where required by law; optional marketing if ever offered.
  • Legal obligation: responding to lawful requests, retaining records where required.

Under Saudi PDPL, we process personal data for legitimate purposes disclosed here, with appropriate safeguards, and respect data subject rights (access, correction, deletion where applicable, withdrawal of consent when processing is consent-based).

6. Phone search, community data & sensitive context

Search results may include names/labels associated with a number from community reports and external sources. We aim to offer objection/correction mechanisms for disputed names. You should not use the Platform to harass, stalk, dox, or unlawfully identify individuals. Misuse may lead to blocking and/or legal action.

Do not upload evidence containing unnecessary sensitive data (IDs, full bank statements, medical data) unless strictly required for a legitimate objection/report and permitted by law.

7. Cookies, App Check & similar technologies

We use essential cookies/session storage for CSRF protection, sessions, and security. We may use analytics and advertising cookies/SDKs. Where Firebase App Check / reCAPTCHA-like protections are enabled, third-party security providers may process device/browser signals to distinguish humans from bots.

You can control cookies via browser settings. Blocking essential cookies may break forms and search.

8. Advertising

The Platform may display ads from third-party vendors and ad networks, including Google (Google AdSense). These ad partners use cookies or similar IDs to measure ad performance and, where permitted, serve personalized ads based on your prior visits to our Platform or other websites on the Internet. Specifically, Google uses advertising cookies to enable it and its partners to serve ads tailored to your interests. Users may opt out of Google's personalized advertising at any time by visiting Google's [Ads Settings]. We encourage partners that support privacy-compliant modes. See partner policies for further details.

9. CCPA/CPRA notice (California)

California residents may have rights to know/access, delete, correct, and opt out of sale/sharing of personal information, and to limit use of sensitive personal information where applicable. Categories we may collect include identifiers (IP, cookie IDs), internet activity, and user-submitted content related to phone reports.

Do Not Sell or Share: submit a request via the Contact page with subject “CCPA Opt-Out”. We will not discriminate against you for exercising CCPA/CPRA rights.

10. International transfers

Servers, CDN, analytics, email, security, or ad vendors may process data outside your country (including regions with different data-protection standards). Where required, we use appropriate safeguards (contractual clauses / vendor terms) and limit access on a need-to-know basis.

11. Retention

  • Security/rate-limit logs: typically short-term (days to months), longer if investigating abuse.
  • Reports/objections/evidence: retained while needed for moderation, disputes, legal defense, and platform integrity; may be anonymized or deleted after review policies.
  • Contact messages: retained as needed to respond and keep a support record.
  • Aggregate statistics may be kept longer without identifying individuals.

12. Security

We implement technical and organizational measures such as HTTPS, access controls, CSRF protection, rate limiting, and least-privilege admin access. No method of transmission or storage is 100% secure; please avoid submitting secrets (passwords, OTPs for other services, full card numbers) through forms.

13. Your rights

Depending on your location, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. Use the Contact page and specify your request type and enough detail to locate your data (without sending unnecessary sensitive attachments).

You may lodge a complaint with a supervisory authority (e.g., an EU DPA, or the competent Saudi authority under PDPL) if you believe processing violates applicable law.

14. Children

The Platform is not directed to children under 16 (or the age required by local law). We do not knowingly collect personal data from children. If you believe a child provided data, contact us to request deletion.

15. Changes

We may update this Policy to reflect legal, technical, or operational changes. The “Last updated” date will change; material updates may be highlighted on the site.

16. Governing notes

This Policy should be read together with our Terms of Use. If translations differ, the English version may be used for international compliance review, while the Arabic version is provided for clarity to Arabic-speaking users.


--- النسخة العربية (Arabic Version) ---


سياسة الخصوصية (العربية)

آخر تحديث: أغسطس 2026 — تسري هذه السياسة على جميع خدمات منصة كاشف الأرقام («المنصة»، «نحن») عبر الموقع https://kashif-alarqam.com/.

تصف هذه السياسة أنواع البيانات التي نجمعها، وكيف نستخدمها ونحميها، وحقوقك وفق أطر الخصوصية الدولية والإقليمية بما في ذلك GDPR (الاتحاد الأوروبي/المملكة المتحدة)، وCCPA/CPRA (كاليفورنيا)، ونظام حماية البيانات الشخصية السعودي PDPL.

1. الجهة المسؤولة ووسائل التواصل

2. نطاق التطبيق

تشمل التصفح، بحث الكاشف، البلاغات، الاعتراضات، نماذج التواصل، سجلات الأمان، الإحصاءات المجمّعة، وتقنيات ملفات تعريف الارتباط/الحماية من الإساءة، والإعلانات عند تفعيلها.

لا تغطي مواقع أو تطبيقات الغير أو شركات الاتصالات. نتائج البحث مساعدة ومجتمعية وليست سجلاً حكومياً رسمياً.

3. البيانات التي نعالجها

3.1 بيانات تقدّمها أنت

  • أرقام الهواتف التي تبحث عنها أو تدرجها في بلاغ/اعتراض مع رمز الدولة.
  • تفاصيل البلاغات والاعتراضات والمرفقات الاختيارية.
  • بيانات نموذج التواصل (الاسم، البريد، الموضوع، الرسالة).
  • بيانات التحقق بـ OTP عند تفعيل توثيق ملكية الرقم.

3.2 بيانات تُجمع تلقائياً

  • سجلات تقنية (عنوان IP وقد يُجزَّأ/يُهش، المتصفح، الوقت، المسار، أحداث أمنية).
  • إحصاءات زيارات/بحث تقريبية حسب المدينة لأغراض تحليل مجمّع.
  • ملفات تعريف الارتباط ومعرّفات الجهاز وإشارات مكافحة الإساءة (مثل App Check) عند التفعيل.

4. أغراض المعالجة

  • تشغيل خدمة البحث وعرض المحتوى.
  • استقبال ومراجعة البلاغات والاعتراضات والأدلة.
  • توثيق ملكية الرقم وتقليل الإساءة والاحتيال.
  • الرد على رسائل التواصل.
  • تأمين المنصة وقياس الاستخدام بشكل مجمّع وتحسين الخدمة.
  • الامتثال للالتزامات القانونية وعرض إعلانات لتمويل الخدمة المجانية عند التفعيل.

5. الأسس النظامية (باختصار)

نعتمد على تقديم الخدمة التي طلبتها، والمصلحة المشروعة للأمن ومنع الإساءة والتحليل المجمّع، والموافقة عند الحاجة (مثل بعض ملفات تعريف الارتباط غير الضرورية)، والالتزام النظامي عند الاقتضاء — بما يتوافق مع مبادئ GDPR وPDPL حسب انطباقها.

6. البحث المجتمعي والاعتراض

قد تظهر أسماء أو تصنيفات مرتبطة برقم من بلاغات المستخدمين أو مصادر عامة. نوفر آليات اعتراض/تصحيح للأسماء المتنازع عليها. يُحظر استخدام المنصة للمضايقة أو التتبع غير المشروع أو إفشاء بيانات شخصية بشكل مخالف للقانون.

7. ملفات تعريف الارتباط والحماية

نستخدم جلسات ضرورية لحماية النماذج (مثل CSRF) وقد نستخدم أدوات تحليل/إعلانات. أدوات الحماية من الروبوتات قد ترسل إشارات للجهاز/المتصفح إلى مزوّدين خارجيين. يمكنك التحكم عبر إعدادات المتصفح مع العلم أن حظر الكوكيز الأساسية قد يعطل بعض الوظائف.

8. الإعلانات

قد تُعرض إعلانات من شبكات طرف ثالث، بما في ذلك شركة جوجل (Google AdSense)، والتي تستخدم ملفات تعريف الارتباط (Cookies) أو معرّفات الجهاز لقياس الأداء أو تخصيص الإعلانات بناءً على زياراتك السابقة لمنصتنا أو للمواقع الأخرى على الإنترنت. يمكن للمستخدمين في أي وقت إيقاف استخدام ملفات تعريف الارتباط للإعلانات المخصصة من قِبل جوجل عن طريق زيارة [إعدادات الإعلانات الخاصة بجوجل]. يُرجى مراجعة سياسات الشركاء للمزيد.

9. إشعار CCPA/CPRA (سكان كاليفورنيا)

قد تشمل حقوقك المعرفة/الوصول والحذف والتصحيح وإلغاء بيع/مشاركة البيانات لأغراض الإعلان السلوكي عبر السياقات. لطلب «عدم البيع/المشاركة» راسلنا عبر صفحة التواصل بعنوان واضح يوضح الطلب.

10. النقل عبر الحدود

قد تُعالَج البيانات لدى مزوّدي استضافة أو شبكة توصيل محتوى أو تحليلات أو أمان في دول أخرى. نسعى لاختيار مزوّدين بضمانات مناسبة والحد من الوصول بقدر الحاجة.

11. مدد الاحتفاظ

نحتفظ بالسجلات الأمنية لفترات قصيرة عادةً، وبالبلاغات/الاعتراضات طالما لزم للمراجعة والنزاهة والدفاع النظامي، وبرسائل التواصل للرد والمتابعة، وبالإحصاءات المجمّعة لفترات أطول دون تحديد هوية الأفراد قدر الإمكان.

12. الأمن

نتخذ تدابير مثل HTTPS وضوابط الوصول وحماية النماذج وتحديد المعدل. لا يوجد نظام آمن بنسبة 100٪؛ لا ترسل أسراراً أو بيانات بطاقات عبر النماذج.

13. حقوقك

بحسب موقعك، قد يحق لك الوصول أو التصحيح أو الحذف أو التقييد أو الاعتراض أو سحب الموافقة. قدّم الطلب عبر صفحة التواصل مع تفاصيل كافية لتحديد بياناتك. كما يمكنك التظلّم لدى جهة إشراف مختصة عند الاقتضاء.

14. الأطفال

الخدمات غير موجّهة لمن هم دون 16 عاماً (أو السن النظامي المحلي). إذا علمت بجمع بيانات طفل، تواصل معنا لطلب الحذف.

15. التعديلات

قد نحدّث هذه السياسة مع تغيير التاريخ أعلاه. يُفضَّل مراجعتها دورياً.

16. العلاقة مع الشروط

تُقرأ مع شروط الاستخدام. النسخة الإنجليزية مفيدة لمراجعة الامتثال الدولي، والنسخة العربية لتوضيح الحقوق للمتحدثين بالعربية.