Privacy Policy
Last updated 12 August 2026
This Privacy Policy explains how Minasat Tarjim Commercial Establishment (Tarjimpro), Commercial Registration No. 7040621802, Kingdom of Saudi Arabia ("Tarjim", "we", "us") collects, uses, shares, and protects your personal data when you use the Tarjim application and services as a client. We process personal data in accordance with the Saudi Personal Data Protection Law (PDPL) and its regulations. By using the Service you acknowledge this Policy.
1. Data controller and contact
The data controller is Minasat Tarjim Commercial Establishment (Tarjimpro). For any privacy request or question, contact contact@tarjim.pro.
2. Personal data we collect
Account and contact data: your mobile phone number (used for sign-in), and your name and profile details where provided.
Order content: the documents and voice notes you upload for translation, order details, and messages exchanged in the in-app chat with your Translator.
Delivery data: for hardcopy delivery, your recipient name, delivery address, contact number, and approximate geolocation used to place a map pin.
Payment data: payment references and transaction status. Your full card number is collected and stored by our payment processor, not by Tarjim.
Device and usage data: device identifiers, app version, language, diagnostics/crash data, and analytics and attribution identifiers.
Security data: sign-in and login-attempt records and related metadata used to protect your account and prevent abuse.
Session records: when you sign in we record the session, the device or browser your software reports, the network address the request came from, and the time. We use these to operate the one-active-session protection described in the Terms, to detect unauthorized access, and to answer your security queries.
3. How we use your data
- To provide the Service: create your account, process orders, enable chat, take payment, and arrange delivery.
- To match your order with a suitable Translator and enable the translation.
- To provide customer support and resolve disputes.
- To protect the Service: fraud and abuse prevention, bot protection (Cloudflare Turnstile) on sign-in, and security monitoring.
- To send you service and order notifications (including push notifications).
- To measure and improve the Service through analytics and to attribute installs to marketing sources.
- To comply with legal obligations.
4. Legal bases (PDPL)
We rely on: performance of our contract with you (to deliver orders you request); your consent (for example, certain analytics or optional features); our legitimate interests (security, fraud prevention, and improving the Service) balanced against your rights; and compliance with a legal obligation.
5. Who we share data with
- Translators: the Translator assigned to your order receives the document(s), order details, and chat necessary to perform the translation.
- Payment processor: PayTabs (and Apple/Google/Samsung Pay where used) to process payments securely.
- Delivery couriers: for hardcopy delivery, a third-party courier receives the recipient name, address, and contact number needed to deliver your order. See Section 6.
- Infrastructure providers: our hosting and backend provider (Supabase, running on Amazon Web Services) stores data on our behalf; analytics and attribution providers (which may include AppsFlyer, Firebase/Google, and others) process device and usage data.
- Authorities: where required by law, regulation, legal process, or to protect rights and safety.
We do not sell your personal data.
6. Delivery and courier data
When you request a hardcopy delivery, we share the minimum data the courier needs to complete the shipment — recipient name, delivery address, and contact number — and, for international shipments, any information required for customs. This data is used solely to fulfil and track your delivery. The courier acts as an independent processor for shipping. The courier's identity is not disclosed to your Translator, and the Translator does not receive your delivery address.
7. Document security
Documents and voice notes you upload are encrypted at rest using strong, industry-standard encryption (AES-256-GCM), with a unique key per document wrapped by a master key that is held only on our servers and never shipped to any client app. Document storage is private by default, and files are served only through authenticated, access-controlled requests. This means that even at the storage layer, your documents are unreadable without the server-held key.
8. Data retention and deleting your account
How to delete your account. Open the app and go to Settings → Delete Account. If you no longer have the app installed, use the deletion request form at tarjim.pro/en/delete-account. You do not need to contact support, and no approval is required.
What happens. We check first whether anything is still outstanding — an open order, an unpaid balance, a hardcopy still with the courier, a refund in progress, or an open support ticket. If something is, we tell you exactly what it is; your request goes through automatically once it clears. Otherwise your account is scheduled for deletion after a 30-day grace period, during which signing in again cancels the request. After that period your personal data is erased automatically.
What is erased. Your name, mobile number, email address, tax ID, addresses, profile photo, the documents and voice notes you uploaded, and the content of your messages and reviews. Your account can no longer be used, and your mobile number is released so it can be registered again in future.
What we must keep, and why. Saudi law requires us to retain certain records irrespective of your request. These are separated from your identity so they no longer identify you:
| What | How long | Why |
|---|---|---|
| Uploaded documents and voice notes | ~90 days after the order is finalized (sooner if you delete your account) | Service delivery. Erased by destroying the encryption key, which makes the data unrecoverable including in backups. |
| Sign-in delivery logs (which channel your code was sent over) | ~7 days | Security and fraud prevention |
| Sign-in attempt log (mobile number, and email where used) | 180 days | Detecting credential-stuffing and account-takeover attempts |
| Order, payment, invoice, VAT and payout records | 10 years | Law of Commercial Books (Royal Decree M/61) and ZATCA VAT record-keeping rules |
| Session records (device or browser reported, network address, timing) | 90 days after the session ends | Operating one-active-session protection and investigating suspected account access |
| A one-way cryptographic digest of your mobile number | Indefinitely | Abuse and ban-evasion prevention. This is a keyed, irreversible digest — your number cannot be recovered from it. |
This retention is permitted under Article 18 of the PDPL, which allows a controller to retain personal data where a legal obligation requires it, and to retain anonymised data.
9. International data transfer
Our infrastructure currently stores data in the European Union (Frankfurt, Germany). Transfers of personal data outside the Kingdom are made in accordance with the PDPL and SDAIA requirements, using appropriate safeguards (such as standard contractual clauses) and a documented transfer risk assessment. The European Union provides a high standard of data protection, and your documents are additionally protected by the encryption described above.
10. Your rights
Subject to the PDPL, you have the right to: access your personal data; request correction of inaccurate data; request deletion of your data; object to or restrict certain processing; and withdraw consent where processing is based on consent.
Deletion is self-service — see section 8. For any other right, contact contact@tarjim.pro. We respond within 30 days, which we may extend by a further 30 days where the request is complex, as permitted by the PDPL. You also have the right to lodge a complaint with the competent authority (SDAIA).
11. Children
The Service is not directed to, and may not be used by, individuals under 18 years of age. We do not knowingly collect personal data from children.
12. Cookies, SDKs, and tracking
Our apps use software development kits (SDKs) and identifiers for analytics, crash reporting, and marketing attribution. Where required, we ask for your consent before non-essential tracking. You can control certain tracking through your device settings and, on the website, through your browser.
13. Security
We apply technical and organizational measures to protect personal data, including encryption in transit (HTTPS/TLS) and at rest, row-level access controls, access logging, and least-privilege administration. No system is perfectly secure, but we work continuously to protect your data.
14. Changes to this Policy
We may update this Policy from time to time. We will publish the updated version and, where the change is material, notify you and, where required, ask for your renewed acceptance.
15. Contact
For any question or request regarding this Policy or your personal data, contact contact@tarjim.pro.