Privacy Policy
Last updated 6 September 2026 · Applies to my-idara.com and the Idara platform
This policy explains what personal information Idara collects, why we collect it, who we share it with, how long we keep it, and what you can ask us to do about it. Sections 5, 6 and 7 cover Google, Meta and TikTok data in turn — each written to meet that platform's own developer policy, including Google's Limited Use requirements.
1. Who we are
Idara is an operations platform for restaurant groups, operated by Mawrid al Usul Company for Investment (شركة مورد الأصول للاستثمار), a company registered in the Kingdom of Saudi Arabia under commercial registration 7033946281, with its registered address at Building 7448, Al Andalus Branch Street, Al Hamra District, Jeddah 23212, Kingdom of Saudi Arabia.
For anything in this policy, including requests to access or delete your information, contact systems@mao-sa.org. We answer within 30 days.
2. Who this policy covers
Three different groups of people appear in Idara, and our role differs for each. This distinction matters, because it determines who you should ask about your information.
| Who | Our role | What it means for you |
|---|---|---|
| Visitors to my-idara.com People who read our website or join the waitlist | We decide | We are responsible for this information. Ask us directly. |
| Idara account holders Staff at a restaurant group that uses Idara | We decide, jointly with your employer | Your employer controls your account and your role. We hold the account itself. |
| People whose details are entered into Idara Restaurant staff records, guests who complain, people on a waiting list | We only process on instruction | The restaurant group decides what is stored and for how long. Ask them first; we will help them answer you. |
3. Information we collect
3.1 When you use our website
- Waitlist form. Your name, work email address, company name, roughly how many branches you operate, and your phone number if you choose to give it.
- Rate-limiting record. When the waitlist form is submitted we store a one-way keyed digest derived from the sending IP address, and keep it for one hour, so that one sender cannot flood the form. We do not store the address itself. The digest is pseudonymised rather than anonymous: it cannot be turned back into an address, but the same address always produces the same digest.
- Technical records. Our hosting provider records the IP address, browser type and page requested for each visit, in order to serve the site and defend it against abuse.
- Performance measurement. We use Vercel Speed Insights, a service from our hosting provider that records anonymous page-timing data so we can see which pages load slowly. It sets no cookies, builds no profile of you, and is not used for advertising.
- We do not use advertising cookies or third-party tracking pixels on my-idara.com.
3.2 When you hold an Idara account
- Identity. Your name and email address, and an identifier from Google or Microsoft if you sign in with one of those. Access is by invitation only; we never create accounts from public sign-ups.
- Authentication. Session records, and tokens issued by your sign-in provider.
- Activity records. Idara keeps an audit log of actions taken in the system — who changed what, and when — because a shared operations system is unusable without one.
- Fault records. When something fails, we record what failed and where. Secrets and credentials are stripped from these records before they are stored.
3.3 Information a restaurant group enters into Idara
Our customers use Idara to run their operations, and in doing so store information about other people. Depending on which parts of Idara they use, this can include:
- Their employees — names, roles, positions, assessments, disciplinary records, identity document numbers, and health cards. Health cards contain medical information, which is sensitive.
- Their guests — names, phone numbers, and the substance of complaints, together with any message sent in reply.
- People on a waiting list — a name, a phone number and a party size, given in order to hold a table.
We hold this information on the customer's behalf and act on their instructions. We do not use it for our own purposes, and we do not sell it.
3.4 Information from services a customer connects
An administrator at a restaurant group may connect Idara to services that group already uses. Nothing is connected without that deliberate act, and each connection can be revoked at any time.
| Service | What Idara reads | What Idara writes |
|---|---|---|
| Google Business Profile | Business locations and their addresses; reviews, including the star rating, the review text, the reviewer's display name, the time it was posted, and any photo or video attached; the published star rating | Replies to reviews, posted as the business |
| Meta (Facebook, Instagram) | Pages and connected Instagram business accounts, their posts, comments, messages and audience statistics | Posts, comments and message replies, as the connected account |
| TikTok | Basic account profile, video list and account statistics; advertising statistics where the ads permission is granted | Nothing |
| HungerStation | Outlets on the merchant account, and guest reviews | Nothing — this connection is read-only, permanently |
| Localyser | Published star ratings per branch | Nothing |
| Foodics (point of sale) | Menu items, branches, and sales transactions | Nothing |
| Odoo (accounting) | Supplier bills, product costs and recipes | Nothing |
| JISR (human resources) | Employee records for the customer's own staff | Nothing |
| Unifonic, Msegat (SMS) | Delivery reports for messages sent | Text messages to guests, sent at the customer's instruction |
4. Why we use information, and on what basis
| Purpose | Information used | Basis |
|---|---|---|
| Answering waitlist enquiries and opening early access | Waitlist form | Your consent, and our legitimate interest in responding |
| Providing the platform and keeping accounts secure | Account and authentication records | Performance of our contract with the customer |
| Keeping an audit trail of who did what | Activity records | Legitimate interest in accountability and security |
| Diagnosing and fixing faults | Fault records | Legitimate interest in a working service |
| Operating features the customer switched on | Whatever that feature needs | Instruction of the customer, who is responsible for their own basis |
We do not use any information described in this policy for advertising, for building profiles about people, or for training generalised artificial-intelligence models.
5. Google user data
This section applies to information Idara obtains through Google APIs, and it takes precedence over anything more general written elsewhere in this policy.
5.1 What we ask for and why
Idara requests a single Google API permission:
https://www.googleapis.com/auth/business.manage
This is granted by an administrator at a restaurant group, for that group's own Google Business Profile. It is never requested from members of the public and never from people who leave reviews.
We use it for exactly three things:
- Matching branches to locations. We read the business locations on the connected profile so an administrator can say which Idara branch corresponds to which Google location.
- Bringing reviews into one queue. We read reviews for the connected locations so a customer-service team can see and answer them alongside complaints from other sources, rather than logging into several dashboards.
- Replying to reviews. When a member of the team writes or approves a reply, we post it to Google as the business. Google stores one reply per review; posting again replaces the previous one.
Signing in to Idara with a Google account is separate from the above. That gives us your name, email address and Google account identifier, and nothing else.
5.2 Limited Use
Idara's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
In plain terms, and without exception:
- We use Google data only to provide and improve the features described in 5.1, which are the features the user granting access asked for.
- We do not transfer Google data to anyone except as set out in section 5.3, and never to a data broker, an advertising network or an information reseller.
- We do not use Google data for advertising of any kind, including retargeting or personalised advertising.
- We do not sell Google data.
- We do not use Google data to develop, improve or train generalised artificial-intelligence models. Section 5.3 explains the narrow, feature-specific model use that does occur, and how it is contractually restricted.
- No human reads Google data except: with the explicit consent of the customer whose profile it came from; where it is necessary for security purposes such as investigating abuse; to comply with applicable law; or where the data has been aggregated and made anonymous.
5.3 Automated processing of review content
Two optional features send review text to an artificial-intelligence provider — Anthropic or OpenAI, whichever the customer selects. A customer who leaves these features switched off has no review content sent anywhere.
- Classification. The review text is sent so it can be labelled by subject — food, service, speed and so on — for reporting.
- Draft replies. The review text is sent so a reply can be drafted. Whether that reply is posted automatically or held for a person to approve is a setting the customer controls.
We send the review text and its star rating. We do not send account credentials or access tokens. These providers act on our instructions, are contractually prohibited from using the content to train their models, and retain it only as long as needed to return a result.
5.4 Keeping and deleting Google data
- Reviews we have retrieved are stored in our database so they can be displayed, searched and reported on. A nightly reconciliation compares what we hold against Google; a review deleted at Google is marked as removed on our side.
- An administrator can disconnect the Google connection at any time from System → Integrations → Google. Doing so stops all further access immediately.
- Access can also be revoked directly at myaccount.google.com/permissions, which we honour immediately because our tokens stop working.
- Disconnecting destroys the stored credential and the cached list of locations. Reviews already retrieved — their text, the reviewer's display name, any attached media and our replies — stay until you ask us to erase them. Write to systems@mao-sa.org and we erase them within 30 days, other than anything we must keep to meet a legal obligation.
- Access tokens are encrypted before storage. Where no encryption key is configured, the system refuses to store the credential rather than storing it unprotected.
6. Meta (Facebook and Instagram) data
This section applies to information Idara obtains through Meta's APIs for Facebook Pages and Instagram professional accounts, and it takes precedence over anything more general written elsewhere in this policy.
6.1 What we ask for and why
Access is granted by an administrator at a restaurant group, through Facebook Login for Business, for that group's own Pages and Instagram accounts. The permission set is fixed by our login configuration rather than chosen per sign-in, so an administrator sees the same list every time. It is never requested from members of the public and never from people who comment on a post.
Pages: pages_show_list, pages_read_engagement, pages_read_user_content, pages_manage_posts, pages_manage_engagement, pages_messaging, read_insights
Instagram: instagram_basic, instagram_content_publish, instagram_manage_comments, instagram_manage_insights
We use them for exactly four things:
- Listing what was granted. We read which Pages and Instagram accounts the administrator granted, so they can point each one at the right brand inside Idara.
- Publishing what the team writes. When a member of the team publishes a post through Idara, we send it to the Page or Instagram account they chose. Nothing is ever published without a person asking for it.
- Reading and answering engagement. We read comments and messages on the connected accounts so a customer-service team can see them beside complaints from other sources, and post the replies that team writes.
- Reporting. We read the insights Meta publishes for the connected accounts so a manager can see how a brand is performing without opening a second dashboard.
Advertising accounts are a separate grant, made separately, and used only to read and manage the campaigns of the group that granted it.
6.2 What we never do with it
Idara's use of information received from Meta's APIs adheres to the Meta Platform Terms and the Meta Developer Policies.
In plain terms, and without exception:
- We use Meta data only to provide the features described in 6.1, which are the features the person granting access asked for.
- We do not sell Meta data, and we never transfer it to a data broker, an advertising network or an information reseller.
- We do not use Meta data for advertising of any kind, including retargeting or building audiences from it.
- We do not use Meta data to develop, improve or train generalised artificial-intelligence models.
- No human reads Meta data except with the explicit consent of the customer whose account it came from, where it is necessary to investigate abuse or a security problem, to comply with applicable law, or where it has been aggregated and made anonymous.
6.3 Keeping and deleting Meta data
- Posts, comments and messages we have retrieved are stored in our database so they can be displayed, searched and reported on.
- An administrator can disconnect the connection at any time from System → Integrations → Social media. Doing so stops all further access immediately and destroys the stored credential.
- Access can also be revoked directly at facebook.com/settings → Business integrations, which we honour immediately because our tokens stop working.
- Disconnecting stops access; it does not by itself erase what was already retrieved. Our data deletion page is the route for that, and it is the address we give Meta as our deletion instructions.
- Access tokens are encrypted before storage. Where no encryption key is configured, the system refuses to store the credential rather than storing it unprotected.
7. TikTok data
This section applies to information Idara obtains through TikTok's APIs, and it takes precedence over anything more general written elsewhere in this policy.
7.1 What we ask for and why
Access is granted by an administrator at a restaurant group, for that group's own TikTok account. It is never requested from members of the public and never from people who comment on a video.
user.info.basic, user.info.profile, user.info.stats, video.list
These are read permissions. Idara does not request permission to publish to a public audience on TikTok.
We use them for exactly three things:
- Naming the account that was granted. We read the account's display name, handle and avatar so an administrator can confirm which account they connected and point it at the right brand.
- Reporting. We read the account's follower and video counts so a manager can see how a brand is performing beside its other channels.
- Listing the account's own videos. We read the list of videos the connected account has published, so its performance can be reported on inside Idara.
TikTok for Business — the advertising side — is a separate application with a separate sign-in, granted separately, and used only to read and manage the campaigns of the group that granted it.
7.2 What we never do with it
Idara's use of information received from TikTok's APIs adheres to the TikTok Developer Terms of Service.
In plain terms, and without exception:
- We use TikTok data only to provide the features described in 7.1, which are the features the person granting access asked for.
- We do not sell TikTok data, and we never transfer it to a data broker, an advertising network or an information reseller.
- We do not use TikTok data for advertising of any kind, including retargeting or building audiences from it.
- We do not use TikTok data to develop, improve or train generalised artificial-intelligence models.
- No human reads TikTok data except with the explicit consent of the customer whose account it came from, where it is necessary to investigate abuse or a security problem, to comply with applicable law, or where it has been aggregated and made anonymous.
7.3 Keeping and deleting TikTok data
- Profile figures and the video list we have retrieved are stored in our database so they can be displayed and reported on.
- An administrator can disconnect the connection at any time from System → Integrations → Social media. Doing so stops all further access immediately and destroys the stored credential.
- Access can also be revoked directly in the TikTok app, under Settings and privacy → Security and permissions → Manage app permissions, which we honour immediately because our tokens stop working.
- Disconnecting stops access; it does not by itself erase what was already retrieved. Our data deletion page is the route for that, and it is the address we give TikTok as our deletion instructions.
- Access tokens are encrypted before storage. Where no encryption key is configured, the system refuses to store the credential rather than storing it unprotected.
8. Who we share information with
We do not sell personal information, and we do not share it for anyone else's marketing. We use the following providers to run the service, each bound to act only on our instructions:
| Provider | What it does | Where |
|---|---|---|
| Vercel | Hosts and serves the application, and measures how quickly its pages load (Speed Insights) | United States and global edge network |
| Supabase | Hosts the database and stored files | United States |
| Anthropic, OpenAI | Optional classification and reply drafting | United States |
| Unifonic, Msegat | Send text messages to guests | Saudi Arabia and region |
| Google, Meta, TikTok, HungerStation, Localyser, Foodics, Odoo, JISR | Connected only when a customer connects them; see 3.4 | Varies by provider |
We also disclose information where the law requires it, and where it is necessary to establish or defend a legal claim.
9. Where information is held
Idara is operated from the Kingdom of Saudi Arabia, and some of our providers are outside it, including in the United States. Where information moves across borders we rely on the safeguards those providers offer, including standard contractual clauses where applicable.
10. How long we keep information
| What | How long |
|---|---|
| Waitlist entries | Until early access opens to you and is resolved, or until you ask us to delete them |
| Waitlist rate-limiting digests | One hour, then deleted |
| Account and audit records | For as long as the account exists, and for a reasonable period afterwards for security and accountability |
| Fault records | 90 days, then deleted automatically |
| Data connected from a third-party service | Until you ask us to erase it, then within 30 days. Removing the connection stops further collection and destroys the credential |
| Data a customer entered | For as long as the customer instructs; deleted or returned when their agreement ends |
11. Security
- All traffic is encrypted in transit.
- Credentials for connected services are encrypted before storage, using a dedicated key. If no key is configured, storage is refused rather than performed unprotected.
- Every page and every action in Idara is checked against the acting person's permissions, individually. Hiding a menu entry is never treated as a security control.
- Actions are recorded in an audit log, including refused attempts.
- Database tables deny access by default to anything other than the application's own server-side connection.
No system is perfectly secure. If we discover a breach affecting your information, we will notify you and the relevant authority as the law requires.
12. Your rights
Subject to the law that applies to you, you can ask us to give you a copy of your information, correct it, delete it, restrict or object to how we use it, or provide it in a portable form. You can also withdraw consent at any time, which does not affect what we did before you withdrew it.
Write to systems@mao-sa.org. We may need to verify who you are before acting. If your information was entered into Idara by a restaurant group, we will pass your request to that group, because the decision is theirs.
If you are unhappy with our answer, you may complain to your local data protection authority.
13. Children
Idara is a tool for businesses and is not directed at children. We do not knowingly collect information from anyone under 18. If you believe a child's information has reached us, write to systems@mao-sa.org and we will delete it.
14. Changes to this policy
When we change this policy we update the date at the top. Where a change materially affects how we use information, we will tell affected customers directly before it takes effect.
15. Contact
Mawrid al Usul Company for Investment (شركة مورد الأصول للاستثمار) · Building 7448, Al Andalus Branch Street, Al Hamra District, Jeddah 23212, Kingdom of Saudi Arabia · systems@mao-sa.org

