Aman Fix
العربية

Privacy Policy

Version 2026-07-25 · Effective date 25 July 2026

This Policy explains how we collect your personal data on the Aman-Fix platform, how we use, retain, and share it, what rights you have over it, and how you exercise them.

This Policy forms an integral part of the Terms of Use and is accepted by both the Customer and the Provider. It addresses the "User" generally and sets out Provider-specific provisions where needed.

Read it in full before using the Platform; using the Platform after its effective date constitutes your agreement to the processing described in it.

1) Introduction and Scope

1.1 This Policy applies to every processing of personal data carried out through the Aman-Fix mobile application, its website, its control panels, and the related services.

1.2 This Policy addresses the User generally, meaning both the Customer and the Provider, and sets out provisions applying to the Provider alone where that is expressly stated.

1.3 This Policy does not apply to processing carried out by a Provider on its own account outside the Platform, nor to third-party websites or applications you reach through links inside the Platform.

1.4 The currently active country is the Arab Republic of Egypt and the currency in use is the Egyptian Pound (EGP); this Policy is read in light of the laws of the Arab Republic of Egypt.

2) Definitions

2.1 "Platform" means the Aman-Fix application, its website, its panels, its programming interfaces, and every digital service we provide through them.

2.2 "User" means any person who creates an account on the Platform or uses it, whether a Customer or a service Provider.

2.3 "Provider" means the independent technician or maintenance center that performs the service as an independent contractor, not as our employee and not as our subordinate.

2.4 "Personal Data" means any information relating to an identified or identifiable natural person, including name, phone number, address, location, and image.

2.5 "Processing" means any operation performed on personal data, including collection, recording, organization, storage, alteration, retrieval, use, disclosure, erasure, or anonymization.

2.6 "Processor" means a third party that processes data on our behalf, on our instructions, and under a contract restricting its use to the purpose of the service.

3) Who We Are and the Data Controller

3.1 Aman-Fix is a digital intermediary platform connecting Customers with independent service Providers; it is not the service provider and it is not the Provider's employer.

3.2 We are the data controller in respect of user accounts, orders, payments, fraud prevention, and support inside the Platform.

3.3 The Provider is an independent controller of the data it collects itself outside the Platform, and bears sole responsibility for the lawfulness of that processing.

3.4 You may contact us on any matter relating to this Policy through the official support channels inside the application.

4) Identity Data and Contact Data

4.1 We collect from every User their full name, phone number, preferred language, and the role selected at registration.

4.2 We collect the date of birth to verify eligibility; registration is not accepted for anyone under 19 years of age, nor for anyone above 80 years of age.

4.3 We collect additional verification data from the Provider, including gender, national identification number, images of identity documents, and details of trade, specialty, and service area.

4.4 Phone verification is performed with a one-time code sent by the channel you select, and we send no code before you select the channel and request the send.

4.5 We may collect an alternative contact provided by the Provider for operational emergencies, and the Provider represents that it has obtained that person's consent.

5) Address Data and Location Data

5.1 We collect the address you enter for an order, its coordinates on the map, and any access notes you add.

5.2 We collect your device location, approximate or precise, when you request a service, so the order can be broadcast to nearby Providers and time and distance can be estimated.

5.3 We collect the Provider's location during an active visit to enable arrival tracking, distance calculation, and dispute resolution, and collection stops when the visit ends.

5.4 We do not collect location without your operating-system level permission, and you may withdraw that permission at any time from your device settings.

5.5 Withdrawing location permission does not cancel your existing orders, but it may prevent features that depend on it, such as geographic broadcast and arrival tracking.

6) Media: Images and Video

6.1 We collect the images and video you upload to describe a fault, to evidence condition before and after performance, or to verify the Provider's identity.

6.2 Uploaded media may contain metadata and background details you did not intend to reveal; we strip metadata as set out in Section 14, but responsibility for what appears in the image itself remains yours.

6.3 Do not upload media containing another person's personal data without their consent, nor documents unrelated to the order or to verification.

6.4 Media is stored on cloud storage (Cloudflare R2) behind time-limited links and is not publicly browsable.

7) Order Data and Fault Descriptions

7.1 We collect the details of every order: the service type, the fault description, the requested time, and the notes you write.

7.2 We collect the full order trail: broadcast or selection, acceptance, the visit, the on-site estimate, your approval or refusal, performance, and closure.

7.3 We collect in-app chat content and in-app call metadata, namely times, parties, and duration, to evidence the dealing, resolve disputes, and protect user safety.

7.4 We collect your ratings, your complaints, and any evidence you attach to them.

7.5 For finishing services performed by the company itself, we also collect the visit, stage, and installment data associated with the project.

8) Financial Data and Wallet Data

8.1 We collect the record of order amounts, visit fees, the published commission, the Provider's net amount, wallet movements, and withdrawal requests.

8.2 We keep a double-entry accounting record of every financial movement; that record is legally binding and is not deleted when an account is deleted.

8.3 We do not store your full bank card details on our systems; payment processing occurs with a licensed payment service provider, and we receive from it only the transaction reference, its outcome, and limited identifying digits where available.

8.4 We collect from the Provider the account or wallet details to which it asks its dues to be transferred, and we use them for that purpose and to evidence disbursement only.

8.5 We use financial data to detect and prevent fraud and money laundering, and to meet our accounting and tax obligations.

9) Device Data, Technical Data, and Usage Data

9.1 We collect automatically the device type and its operating system, the application version, the device language, the notification token, the internet address (IP), and the country inferred from it.

9.2 We collect technical logs including sign-in and sign-out times, active sessions, the screens you open, and the errors the application encounters.

9.3 We keep a security log of sensitive events such as failed sign-in attempts, password changes, enabling two-step verification, and blocking and unblocking events.

9.4 We use this data to secure your account, keep the service stable, and detect abusive use, not to build an advertising profile about you.

10) How We Collect Your Data

10.1 We collect data directly from you when you create an account, place an order, upload a document, or contact support.

10.2 We collect data from your use of the Platform, that is, from what your transactions, messages, ratings, and order trail generate.

10.3 We collect data automatically from your device when the application runs, according to the permissions you have granted to the operating system.

10.4 We receive limited data from our processors, such as the outcome of a payment, the delivery status of a message, or the result of a notification send.

10.5 We receive data from the other party to a transaction where necessary, such as the Customer's address for the Provider whose offer was accepted, or the Provider's name for the Customer.

11) Purposes of Processing

11.1 We process your data to create and administer your account, and to verify the Provider's identity before activation.

11.2 We process your data to operate the service model: broadcasting or routing the order, arranging the visit, conveying the on-site estimate, recording your approval or refusal, and closing the order.

11.3 We process your data for financial settlement: computing the published commission, updating the Provider's wallet, executing withdrawals, and reconciling records.

11.4 We process your data for security and to prevent fraud, impersonation, and abusive use, and to protect users' lives and property.

11.5 We process your data to improve the service through aggregated analytics, for support and dispute resolution, and to comply with a legal obligation or an order of a competent authority.

12) Legal Bases for Processing

12.1 Performance of contract: all processing necessary to deliver the service you requested, or to enable the Provider to work on the Platform.

12.2 Legitimate interests: Platform security, fraud prevention, service quality measurement, product improvement, and protection of our legal rights, provided they do not override your rights and freedoms.

12.3 Legal obligation: retention of financial and tax records, and response to orders of law-enforcement and regulatory authorities.

12.4 Explicit consent: access to location, camera, photos, and notifications, marketing communications, and processing of the verification video.

12.5 Where consent is the basis of processing, you may withdraw it at any time, and withdrawal does not affect the lawfulness of processing carried out before it.

13) Location and Tracking During the Visit

13.1 We collect the Customer's location only when the order is created or its address is changed, and we do not track that location afterwards.

13.2 We collect the Provider's location during the active visit only: collection begins when the Provider accepts the order and sets out, and ends when the visit is closed or cancelled.

13.3 Provider location collection may operate with the application in the background during an active visit, to show arrival to the Customer and evidence arrival time, and the operating system indicator for this is displayed.

13.4 We do not use location data to track the Provider outside active visits, nor to build a map of the Provider's personal movements.

13.5 You may disable location access entirely from your device operating system settings; that is the decisive control and it does not depend on any in-application setting.

14) Metadata Stripping and Encryption of Sensitive Documents

14.1 We strip metadata (EXIF) from uploaded images, including location data, device model, and capture times, before storing them or making them available to the other party to the transaction.

14.2 Sensitive verification documents are encrypted at rest, and access to them is limited to a small number of authorized staff by reason of their role.

14.3 All transfer of data between your application and our servers occurs over an encrypted connection.

14.4 Metadata stripping does not erase what appears inside the image itself, so review the content of an image before uploading it.

15) The Provider Verification Video

15.1 The Provider is required to record a short verification video as one step of identity verification, its purpose being to establish that the person submitting the documents is their holder and a real person.

15.2 The video is recorded without audio, and we do not request microphone permission for this step.

15.3 The verification video is not shown to Customers or to any Provider other than the one who submitted it, is not published anywhere, and is viewable only by the authorized review team.

15.4 The video is reviewed by a human before the Provider's account is activated, and is retained for as long as needed as set out in Section 21.

15.5 Refusing to provide the verification video prevents completion of verification, and therefore prevents activation of the Provider's account and receipt of orders.

16) Sharing Between the Customer and the Provider

16.1 When your order is accepted we share with the Provider only what is necessary to perform it: your name, a contact channel, the address and its coordinates, and the fault description with attached media.

16.2 We share with the Customer the Provider data necessary for trust and communication: name, professional photo, rating, verification status, and an in-application contact channel.

16.3 We never share your national identification number, your verification documents, or your verification video with the other party to the transaction.

16.4 Each party undertakes to use the other party's data for the purpose of the order alone; using it for marketing, for contact outside the purpose of the order, or transferring it to a third party is prohibited.

16.5 Availability of direct contact details is limited to the duration of the order and to the period following it only so far as necessary for warranty or dispute.

17) Processors and Service Providers

17.1 We engage processors that act on our behalf and on our instructions, for the following purposes: - Cloud storage of media and documents. - Maps, route and distance calculation, and address geocoding. - Push notifications to devices. - Sending text messages and messaging-application messages for phone verification and operational alerts. - Payment and transfer processing. - Hosting, technical monitoring, and error logging.

17.2 We bind every processor by a contract restricting use of the data to the purpose of the service, prohibiting use for its own account, and imposing appropriate security measures.

17.3 We share with each processor the minimum amount of data sufficient to perform its task, and no more.

17.4 Our engagement of a processor does not make our liability for its acts absolute; our liability rests on due care in its selection and on binding it to the contracted measures.

18) Legal Disclosure and Business Transfers

18.1 We disclose your data to judicial, law-enforcement, or regulatory authorities upon receipt of a valid legal request, or where disclosure is necessary to protect life or prevent a crime.

18.2 We disclose your data to our legal advisers or auditors where necessary to establish or defend a right or to meet a regulatory obligation.

18.3 On a merger, acquisition, or transfer of all or part of our business, data may be transferred to the successor provided it commits to protection no lower than that of this Policy, and we notify you of this.

18.4 We notify you of a legal request where notice is legally permitted and does not endanger an investigation or any person's safety.

19) What We Do Not Do With Data

19.1 We do not sell your personal data, we do not rent it, and we do not barter with it.

19.2 We do not share your data with data brokers or advertising networks for third-party behavioral marketing purposes.

19.3 We do not read your chat content except within a defined scope: a complaint, a dispute, an abuse report, a legal obligation, or a security investigation, and only so far as necessary.

19.4 We do not take purely automated decisions producing serious legal effects on you without the possibility of human review on your request.

20) Cross-Border Transfers

20.1 Your data may be stored or processed on servers located outside the Arab Republic of Egypt, with processors acting on our behalf.

20.2 We apply appropriate safeguards to every transfer, including contractual data protection terms, purpose limitation, and security measures and encryption.

20.3 In selecting storage locations we observe the requirements applicable law imposes on data of high sensitivity.

20.4 By using the Platform you acknowledge that operating a cross-border digital service entails such transfers within the limits we have described.

21) Retention Periods

21.1 Account data is retained for the life of your account, then anonymized on account deletion as set out in Section 23.

21.2 Order, chat, and media data is retained for a period sufficient for warranty, dispute, and audit, then deleted or anonymized.

21.3 Provider verification documents and the verification video are retained for the validity period of the verification, and for the period afterwards necessary to evidence that we verified as the law requires, then deleted.

21.4 Financial, accounting, and tax records are retained for the period applicable law imposes, and are not subject to a deletion request conflicting with that.

21.5 Security logs and error logs are retained for a limited period sufficient to investigate incidents and detect abusive patterns, then deleted or aggregated.

22) Data Subject Rights and How to Exercise Them

22.1 You have the right to access your data, to know the purposes of its processing, and to know with whom we have shared it.

22.2 You have the right to correct inaccurate data and complete incomplete data; some fields may require re-verification before amendment.

22.3 You have the right to request deletion, the right to object to processing based on legitimate interests, and the right to request restriction of processing while your objection is examined.

22.4 You have the right to port the data you provided in a machine-readable format, and the right to withdraw any consent you granted.

22.5 These rights are exercised from the account settings page inside the application or by a request through the official support channels inside the application; we respond within 30 days of verifying your identity, and we may extend that period once by the same length for complex requests, notifying you of the reason.

22.6 We may refuse a request in whole or in part where it conflicts with a legal obligation on us, prejudices the rights of others, or is repetitive without cause, and we will state the reason for refusal.

23) Account Deletion and Anonymization

23.1 You may request deletion of your account from inside the application, and we do not ask you for a reason.

23.2 Deletion is carried out by anonymization: your personal identifiers are severed from the records and replaced or erased, so the account is no longer attributable to you.

23.3 Legally binding financial records remain after deletion, stripped of your identifiers so far as the law permits, because erasing them would breach our accounting and tax obligations.

23.4 Records necessary to establish or defend a right in an existing or potential dispute likewise remain until that dispute ends.

23.5 Deletion does not cancel an existing order or any financial obligation owed by you or to you, so settle what you owe and collect what is owed to you before requesting deletion.

23.6 An account cannot be restored once anonymization is complete, and any later use requires a new registration.

24) Minors and Eligibility Age

24.1 The Platform is not directed to anyone under 19 years of age, and we do not knowingly accept such a registration.

24.2 If we learn that an account belongs to a person under 19 years of age, we suspend it and delete their data except what the law requires us to retain.

24.3 A guardian should contact us through the official support channels inside the application if they believe a person in their care registered without permission.

24.4 Misstating the date of birth does not relieve the User of responsibility, and creates no liability on us for an account opened on an untrue statement.

25) Information Security

25.1 We apply technical and organizational measures including transport encryption, encryption of sensitive documents at rest, and access control on a least-privilege basis.

25.2 We record sensitive events in an audit log, allow you to enable two-step verification on your account, and display your active sessions so you can end them.

25.3 No system is absolutely secure, so we give no warranty that data will never be subject to any breach, however strong the measures.

25.4 You are responsible for the confidentiality of your password and the verification codes sent to you, for the security of your device, and for all activity occurring from your account by reason of your default in that.

25.5 Notify us immediately through the official support channels inside the application if you suspect unauthorized access to your account.

26) Data Breach Notification

26.1 If a personal data breach occurs that is likely to create a risk to you, we notify you and notify the competent authority as applicable law requires and without undue delay.

26.2 The notice states the nature of the breach, the categories of data affected, the expected impact, the measures we have taken, and what we recommend you do.

26.3 We investigate every incident, limit its impact, remedy its cause, and update our measures according to what the investigation reveals.

26.4 We require your cooperation in the investigation where the breach arises from your account, your device, or your disclosure of your sign-in credentials.

27) Identifiers, Tracking Technologies, and Analytics

27.1 We use technical identifiers, cookies, and local storage technologies on the web to operate the session, provide security, and remember your language.

27.2 In the application we use an installation identifier and a notification token, and we do not use the advertising identifier to build an advertising profile about you.

27.3 We use aggregated usage analytics to understand service performance and where users encounter difficulty, and we endeavor to aggregate or anonymize that analytics data.

27.4 You may manage non-essential cookies from your browser settings, noting that disabling essential cookies prevents sign-in and operation of the service.

28) Notifications and Marketing Communications

28.1 We send operational notifications necessary to the service: order status, Provider arrival, the estimate, payment, and security alerts.

28.2 Operational notifications are part of the service and cannot be switched off entirely while the account remains active; if you disable them at the operating system level you may miss information concerning your order.

28.3 We send marketing communications only with your consent, and you may stop them at any time from account settings or by the means stated in the message itself.

28.4 Stopping marketing communications does not stop operational notifications or legal messages such as notice of amendment of this Policy.

29) User Responsibility for Third-Party Data

29.1 If you enter another person's personal data, such as a relative's address, a resident's phone number, or an image containing people, you represent that you have a lawful basis for doing so.

29.2 You are solely responsible for notifying the data subject and obtaining their consent where required, and we process that data to perform your own order.

29.3 Uploading sensitive data unrelated to the order is prohibited, such as health records or religious, political, or financial data belonging to another person.

29.4 On the request of the data subject we delete what you entered about them where it is established that it was entered without a lawful basis, so far as this does not conflict with a legal obligation on us.

30) Limits of Our Liability and Exclusions

30.1 We are a digital intermediary, so we bear no liability for a Provider's or a Customer's use of the other party's data outside the purpose of the order; that liability rests on whoever committed the act.

30.2 We bear no liability for harm arising from your disclosure of your sign-in credentials, your use of a compromised device or an insecure network, or your own publication of your data.

30.3 We bear no liability for any indirect or consequential damage, loss of profit, loss of opportunity, or reputational harm arising from data processing, to the extent applicable law permits.

30.4 We bear no liability for a failure or breach occurring at a processor, a network operator, or an operating system beyond our reasonable control, and no liability for force majeure.

30.5 Our aggregate liability for any claim relating to data processing is limited, to the extent the law permits, to the equivalent of the commission we collected from you in the twelve months preceding the incident, or the value of your transactions in that period, whichever is lower.

30.6 This Policy does not limit our liability for fraud or gross fault, nor for anything whose exclusion may not lawfully be agreed.

31) Indemnity and Release

31.1 You undertake to indemnify us against every loss, claim, fine, or expense, including reasonable legal fees, arising from your breach of this Policy or from your processing of another person's data without a lawful basis.

31.2 This undertaking covers third-party claims arising from your uploading of media or documents to which you have no right.

31.3 You release us, our staff, and our processors from every claim arising out of a dispute between you and the other party to a transaction concerning use of data, while your right to hold the actual wrongdoer accountable remains intact.

31.4 We may assume the defense of any claim covered by this Section, you may participate with your own counsel at your expense, and you shall not settle a claim affecting us without our written consent.

32) Complaints, Governing Law, and Arbitration

32.1 If you have a grievance relating to the processing of your data, submit it first through the official support channels inside the application, and we will seek an amicable resolution within 30 days.

32.2 This Policy is governed by and construed in accordance with the laws of the Arab Republic of Egypt.

32.3 Every dispute not resolved amicably is referred to arbitration before the Cairo Regional Centre for International Commercial Arbitration (CRCICA) in Cairo, under its rules, by a sole arbitrator, in the Arabic language, and its award is final and binding.

32.4 Your right to any claim relating to the processing of your data lapses if it is not brought within one year from the date you became aware of the event giving rise to it, to the extent the law permits.

32.5 This Section does not prevent you from lodging a complaint with the competent data protection supervisory authority where the law confers that right.

33) Amendment of the Policy and Notice of It

33.1 We may amend this Policy as the service develops or upon a legal or regulatory change, and we publish the amended version inside the Platform with a version number and an effective date.

33.2 We notify you of a material amendment inside the application a reasonable time before it takes effect, and we may require your acceptance of the new version before you continue using the Platform.

33.3 The current version displayed inside the Platform is the reference, and your acceptance is recorded with its version and time to evidence the agreement.

33.4 This operational template requires the approval of a licensed lawyer in every active country before final adoption.

34) Precedence and Effectiveness

34.1 This Policy is issued in two versions, Arabic and English, and in the event of any conflict or difference in interpretation the Arabic version prevails.

34.2 This Policy takes effect from the effective date displayed with its version inside the Platform, and replaces every earlier privacy policy for the same service.

34.3 Your continued use of the Platform after you are notified of the new version and after its effective date constitutes your acceptance of it.

34.4 The invalidity or unenforceability of any clause of this Policy does not affect its remaining clauses, and the invalid clause is replaced by the nearest valid clause achieving its purpose.