Skip to main content
Privacy Policy

Privacy Policy

Last Updated: April 3, 2026

1. Introduction

Qudoom ("we," "us," or "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, disclose, retain, and protect information when you use our visitor management platform ("Service"), including the web dashboard, the check-in application, and all related services.

This Privacy Policy applies to all users of the Service, including organization staff and visitors who check in through our platform. By using the Service, you acknowledge that you have read and understood this Privacy Policy.

We comply with applicable data protection laws, including the General Data Protection Regulation (GDPR), the Saudi Arabia Personal Data Protection Law (PDPL), the UAE Data Protection Law, and other relevant regional and international privacy regulations.

2. Information We Collect

We collect information in several ways depending on your role and interaction with the Service.

2.1 Organization Account Data

When an organization registers for the Service, we collect: organization name, administrator name and email address, billing information, selected subscription plan, and language preferences.

2.2 Authorized User Data

For team members, we collect: full name, email address, assigned role, and account activity logs.

2.3 Visitor Data

When visitors check in through the Service, the following data may be collected based on the organization's configuration: full name, email address, phone number, check-in and check-out timestamps, and any additional visit details the organization chooses to collect during check-in.

2.4 Device & Technical Data

We automatically collect: IP addresses, browser type and version, device identifiers for paired check-in devices, operating system information, access timestamps, and referral URLs.

2.5 Usage & Analytics Data

We collect aggregated usage data including: visitor traffic patterns, feature usage statistics, check-in volume metrics, and performance monitoring data.

3. How We Use Your Information

We process personal information for the following purposes:

  • Providing and operating the Service — processing visitor check-ins, managing user accounts, and delivering core functionality
  • Communicating with you — sending service notifications, security alerts, billing information, and support responses
  • Analytics and improvements — generating visitor analytics dashboards, identifying usage trends, and improving the Service
  • Security and fraud prevention — detecting unauthorized access, preventing abuse, and enforcing our Terms of Service
  • Legal compliance — fulfilling legal obligations, responding to lawful requests, and protecting our legal rights
  • Billing and payments — processing subscription payments, managing invoices, and handling billing inquiries

5. How We Share Information

We do not sell, rent, or trade personal information to third parties. We may share information in the following limited circumstances:

  • Service Providers — we use industry-leading cloud infrastructure providers for hosting, data storage, authentication, and serverless operations. These providers process data on our behalf under strict contractual obligations
  • Within Your Organization — visitor data is accessible to authorized users within the organization that collected it, based on their assigned roles and permissions
  • Legal Requirements — we may disclose information when required by law, legal process, or government request, or when we believe disclosure is necessary to protect our rights, safety, or property
  • Business Transfers — in the event of a merger, acquisition, or sale of assets, personal data may be transferred as part of the transaction, subject to the same privacy protections

6. Data Security

We implement comprehensive security measures to protect your information:

  • Encryption in transit using TLS 1.2+ for all data communications
  • Encryption at rest for all stored data on our cloud infrastructure
  • Server-enforced access control rules that prevent unauthorized data access
  • Role-based access control with distinct permission levels
  • Server-side rate limiting on critical operations to prevent abuse
  • Regular security audits and monitoring of infrastructure

While we implement industry-standard security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data.

7. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required by law.

Active account data is retained for the duration of your subscription. Visitor check-in records are retained in accordance with your organization's data retention settings and applicable legal requirements.

Upon account termination, we retain Customer Data for thirty (30) days to allow for data export. After the retention period, data is permanently deleted from our systems, including all backups, within a reasonable timeframe.

Automated maintenance processes handle routine data cleanup, including auto-checkout of remaining visitors and cleanup of expired records.

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Right of Access — request a copy of the personal data we hold about you
  • Right to Rectification — request correction of inaccurate or incomplete personal data
  • Right to Erasure — request deletion of your personal data, subject to legal retention requirements
  • Right to Restriction — request that we limit processing of your personal data in certain circumstances
  • Right to Data Portability — receive your personal data in a structured, machine-readable format (CSV export is available through the dashboard)
  • Right to Object — object to processing of your personal data based on legitimate interests
  • Right to Withdraw Consent — withdraw consent at any time where processing is based on consent

To exercise any of these rights, please contact us through the support form on our website. We will respond to your request within thirty (30) days, or within the timeframe required by applicable law.

9. Visitor-Specific Privacy

As a platform that processes visitor personal data on behalf of organizations, we want visitors to understand the following:

Organizations using our Service are the data controllers for visitor information. They determine what data is collected during check-in, how long it is retained, and how it is used. We act as a data processor on their behalf.

If you are a visitor and wish to exercise your data protection rights, you should contact the organization you visited directly. They can access, modify, or delete your visitor records through their dashboard.

Organizations are responsible for providing appropriate privacy notices to visitors at the point of data collection and for obtaining any necessary consents. Our platform supports displaying custom messages during the check-in flow to facilitate this.

10. Cookies & Local Storage

We use minimal cookies and browser local storage to operate the Service:

  • Authentication cookies — essential session cookies to keep you logged in securely
  • Language preference — stored in local storage to remember your language selection (Arabic/English)
  • Backend SDK cookies — necessary for real-time data synchronization and authentication

11. International Data Transfers

Our Service infrastructure is hosted on enterprise-grade cloud platforms. Your data may be processed in data centers located in different regions. When data is transferred across borders, we ensure appropriate safeguards are in place, including standard contractual clauses and compliance with applicable data transfer regulations.

Our cloud infrastructure providers maintain compliance with international standards including SOC 2, ISO 27001, and GDPR requirements for data processing.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by posting a notice on our website or sending an email to account administrators at least thirty (30) days before changes take effect.

We encourage you to review this Privacy Policy periodically. Your continued use of the Service after any changes constitutes acceptance of the updated Privacy Policy.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Qudoom Data Protection Office

To reach us, please use the contact form at the bottom of our main page. Go to the main page