Privacy Policy
The Arabic version is the binding version. This English text is a courtesy translation.
Draft pending legal review. It should be reviewed by a data protection specialist before public launch, particularly on transfers of data outside Egypt and on the licensing requirements of Law No. 151 of 2020.
1. Who is responsible for your data
The data controller is Shattably. For privacy matters: [email protected].
This policy is written to comply with Law No. 151 of 2020 on Personal Data Protection and its executive regulations.
One important exception: for technician data an engineer enters in their roster, and for participants a primary client adds to their project, the engineer (or the client) is the controller, and Shattably acts as a data processor on their behalf and on their instructions.
2. What we collect, why, and on what basis
Account data — phone number, email, name, password (stored hashed; we never keep it in plain text), role (client/engineer), language, numeral-format preference. Purpose: creating your account, sign-in, verification. Basis: performance of our contract with you.
Project data — property address and location (coordinates where entered), type, area, entry point, phases, progress photos, files (invoices, receipts, contracts, drawings). Purpose: running and documenting the project. Basis: performance of contract.
Financial data — quotations and their line items, recorded payments and their confirmations, expenses and categories, custody balances, funding plans. Purpose: the project record and settling any dispute. Basis: performance of contract and legal obligation.
Support data — your messages and reports to us. Purpose: user support. Basis: legitimate interest.
Technical data — push token (FCM), device model and OS, app version, IP address, error and crash logs, and usage events anonymised as far as possible. Purpose: delivering notifications, diagnosing faults, account security, improving the service. Basis: legitimate interest, and your consent where the law requires it.
Legal consent records — the document you accepted, its version number, the time of acceptance, the IP address, and the app version. Purpose: proving consent. Basis: legal obligation and legitimate interest.
We do not collect payment card data (there are no online payments in the current version), health, religious or political data, and we do not track your location in the background.
3. Data about people who are not users
Client invitation by phone number: an engineer enters a client's phone number to invite them, and we keep that number in order to connect the invitation when the number's owner registers. The engineer confirms they have that person's permission before entering it.
Technician roster: an engineer records a technician's name, phone, trade, day rate and notes. We host this on the engineer's behalf and use it for no other purpose.
If you are not a user and your details were entered, write to [email protected] and we will delete them or refer you to the controller.
4. Who sees what inside the app
- The engineer sees only the primary client, never the other participants in the project.
- The client sees their project's expenses line by line, and never files marked engineer-internal (such as supplier invoices).
- Self-managed projects: a client's spending record from before handing the project to an engineer is never shown to that engineer.
- The Shattably team accesses data only where needed: offering a request to an engineer, technical support, investigating a report, or a legal obligation.
5. Who we share data with
We do not sell or rent your data, and we do not use it for third-party advertising. We share it only with:
- Cloudflare R2 — storage of photos and files. Processed outside Egypt.
- Google Firebase (push notifications, crash reporting) — processed outside Egypt.
- Resend — verification and security emails. Processed outside Egypt.
- Sentry — software error tracking. Processed outside Egypt.
- PostHog — anonymised usage analytics. Processed outside Egypt.
- Our hosting provider (Hostinger) — running the servers and database. Processed outside Egypt.
We also share data with judicial or regulatory authorities on a lawful request, with our professional advisers where needed, and with an acquirer on a merger or sale of the business (with notice to you).
6. Transfers outside Egypt
The providers above process data outside the Arab Republic of Egypt. Law No. 151 of 2020 requires a licence or permit from the Personal Data Protection Centre to transfer data abroad. We are working to satisfy that requirement, and we conclude agreements with each provider containing data-protection obligations and restricting use to the stated purpose.
7. How long we keep data
- Account and profile: for as long as the account exists, then deleted or anonymised within 90 days of your deletion request.
- Financial and contractual project records (quotations, phase sign-offs, payments, expenses, activity log and the files attached to them): kept for 10 years from the date the project ends, even if you delete your account — because they concern another party, may be relied on in a dispute, and because the law requires us to retain financial documents.
- Legal consent records: for the same period as above.
- Error and security logs: up to 12 months.
After that period, a generic marker takes the place of your name in project records and your account details (name, email, phone number) are erased, wherever that is possible without destroying the record's evidential value.
8. Your rights
Under Law No. 151 of 2020 you have the right to know what we hold about you, to access it, to correct or complete it, to request its erasure, to withdraw consent where consent is the basis, to object to a particular processing, and to receive your data in a machine-readable form (Excel export is available in the app).
Send requests to [email protected]; we respond within 30 days. We may refuse an erasure request in whole or in part where it conflicts with a legal obligation or with a record concerning another party (clause 7), and we will tell you why.
You may also complain to the Personal Data Protection Centre of the Arab Republic of Egypt.
9. Deleting your account
Deletion is available in the app: Settings → Delete account. Immediate deletion may not be possible while you have a live project; the app explains why in that case.
10. Security
We use encryption in transit (HTTPS), password hashing, short-lived access tokens with a single active session per user, server-side permission checks on every file and every operation, short-lived signed download links for photos and documents, and daily encrypted backups. No system can be guaranteed absolutely secure.
If a breach puts your data at risk, we notify the competent authority and affected people within the periods set by law.
11. Children
The service is not intended for anyone under 18 and we do not knowingly collect their data. If we learn of such an account, we delete it and its data.
12. Changes to this policy
We notify you in the app of any change, and ask you to accept again where the change is material. We keep previous versions and a record of your acceptance of each.