رجوع

سياسة الخصوصية

آخر تحديث: October 2, 2026

توضح سياسة الخصوصية هذه البيانات التي يجمعها هذا التطبيق، وكيفية استخدام تلك البيانات، والخيارات المتاحة لك. وتُطبَّق على كل تطبيق من تطبيقات PantaLabs يشترك في ملف الإفصاح هذا على مستوى المجموعة التقنية. ونظراً لاختلاف الميزات بين التطبيقات، تظهر بعض الأقسام أدناه فقط عند استخدام حزمة التطوير (SDK) أو السلوك المعني فعلياً.

جهة التحكم في البيانات

تُعدّ PantaLabs ("المشغّل") جهة التحكم المسؤولة عن البيانات الشخصية التي تُعالَج فيما يتصل بهذا التطبيق. للاستفسارات المتعلقة بالخصوصية أو الشروط أو الحقوق، يُرجى التواصل عبر admin@pantalabs.net. وحيثما تنطبق اللائحة العامة لحماية البيانات في الاتحاد الأوروبي (GDPR) أو اللائحة العامة لحماية البيانات البريطانية (UK GDPR) ولم يكن المشغّل مؤسَّساً في المنطقة الاقتصادية الأوروبية أو المملكة المتحدة، يمكن إرسال الطلبات بموجب تلك القوانين إلى العنوان نفسه؛ وسيرد المشغّل ضمن المهل النظامية المقررة.

البيانات المخزَّنة على جهازك

The trips you create in the app (itineraries and related content such as packing lists and expenses) are stored in a local database on your device. To manage the links you share, the app also keeps an anonymous owner key in the device's secure storage (Keychain on iOS, Keystore-protected storage on Android); on iOS, if iCloud Keychain is on, this key can follow your Apple ID to a new iPhone. Deleting the app removes the on-device data. Backups made by the operating system (iCloud, Google One, etc.) follow each platform's privacy policy. The sections below describe the only data that leaves your device.

Shared links and encrypted backup (trip organizer)

The app has no accounts. The first time you share a trip, the app asks our server for an anonymous owner key. It is a random value that is not linked to your name, email address, phone number or store account; it only proves that later changes to your links come from you. - Shared links: your itinerary is encrypted on your device before it is uploaded. The key needed to read it exists only in the part of the link after "#", which is never sent to our server, so we cannot read your itinerary. To run the link, the server stores the encrypted document together with the link token, the anonymous owner ID, a random trip identifier created by the app, the trip's end date (to know when to delete the link), whether the link is a snapshot or live, its version, the times it was created and updated, and how many times it has been opened. The server also records when your owner key was last used. - Encrypted backup (on by default; you can turn it off in the app's Settings): your trips are encrypted on your device with a recovery code that only you hold. The server stores only the encrypted file, its size and version, and an identifier derived from the recovery code. We cannot read the backup or restore it without your code. This data is used only to provide sharing, live updates and backup.

People who open a shared link (companions)

Opening a trip that someone shared with you does not require an account either. When you join a shared trip in the app, you choose a nickname (1–12 characters), and our server stores: that nickname, your app language, a push notification token (if notifications are allowed), the time you last used the shared features, and a random companion key that identifies your app installation. Checks and comments you leave on an itinerary are stored with that link; comments are encrypted on your device with the link's key, so we cannot read them. The trip organizer and anyone else who has the same link can see your nickname together with your checks and comments. The list of trips shared with you is stored only on your device and is not sent to our server. - Retention: a companion record is deleted after 90 days without use once it is no longer connected to any shared link (links themselves are deleted 90 days after the trip ends), and in any case after 12 months without use. Checks and comments are deleted together with the link or with your companion record, whichever comes first. - Deletion: "Delete my data" in the app's settings immediately deletes your companion record on our server together with your checks and comments, and clears the list of trips shared with you on your device.

Shared link web page

When a shared link (pantalabs.net/t/…) is opened in a web browser, the page helps you open the trip in the app or install it. The decryption key in the part of the link after "#" is read only inside your browser to pass the full link on to the app; it is not sent to our server, to the app stores or to anyone else. The page loads no analytics, advertising or other third-party scripts, and tells the browser not to send the link as a referrer. As with any website, our hosting provider (Vercel) processes the request, including your IP address, in order to deliver the page.

الإعلانات (Google AdMob)

يعرض هذا التطبيق إعلانات عبر Google AdMob، وهي خدمة تقدّمها Google LLC. ولعرض الإعلانات وقياسها ومنع الاحتيال فيها، يجوز لـ Google جمع: معرّف الإعلانات القابل لإعادة الضبط الخاص بالجهاز (IDFA على iOS، وAAID على Android)، وعنوان IP، والموقع الجغرافي التقريبي المستنتج من عنوان IP، ونوع الجهاز، وإصدار نظام التشغيل، وحجم الشاشة، واللغة والمنطقة الزمنية، وتفاعلات الإعلانات داخل التطبيق، ومعرّفاً فريداً للتثبيت لكل تطبيق. في المناطق التي تشترط الموافقة المسبقة على الإعلانات المخصَّصة - المنطقة الاقتصادية الأوروبية والمملكة المتحدة وسويسرا - يعرض التطبيق عند التشغيل الأول مربع حوار الموافقة الخاص بمنصة Google لإدارة الرسائل للمستخدم (UMP). ويمكنك تغيير اختيارك في أي وقت عبر رابط "تخصيص الإعلانات" داخل التطبيق، أو من إعدادات النظام في جهازك. راجع صفحة تخصيص الإعلانات للاطلاع على التفاصيل.

Rewarded ads and live link unlock

If you watch a rewarded ad to unlock live updates for a trip, Google AdMob confirms the reward directly to our server (server-side verification). The confirmation contains your anonymous owner ID, the trip identifier, the number of days unlocked and an ad transaction ID. We store these to know until when that trip's live link is unlocked. Your owner key itself is never included.

Analytics, remote configuration and push (Firebase)

The app uses the following Firebase services provided by Google LLC: - Firebase Analytics: aggregates anonymous events (app launches, session length, key actions, in-app purchases, etc.). Your itineraries, nicknames, comments and link keys are not sent to Firebase Analytics. - Firebase Remote Config: adjusts app settings without an app update. - Firebase Cloud Messaging: delivers companion notifications (see "Notifications"). Firebase data is processed under Google's data processing terms. More: https://firebase.google.com/support/privacy

المشتريات داخل التطبيق

All in-app purchases are processed by Apple (App Store) or Google (Google Play Billing). We never see your payment method, billing address or store account credentials. On iOS, the app sends the signed purchase record for the Pro upgrade to our server. The server checks Apple's signature and stores only the result and the purchase's original transaction ID with your anonymous owner key. This is used only to decide whether your live links can stay live without a time limit. Refund eligibility, cancellations and disputes follow the published policies of the platform that processed the payment. - Apple: https://support.apple.com/en-us/HT204084 - Google: https://support.google.com/googleplay/answer/2479637

Notifications

Companion notifications are on by default. When you open a shared link in the app, you are subscribed to that trip and are notified when the organizer changes it, at most once every 10 minutes per link. After you choose a nickname, the app asks once for the system notification permission. If you allow it, your device's push token is sent to our server, and notifications are delivered through Firebase Cloud Messaging (Google) and, on iOS, Apple Push Notification service. A notification carries no itinerary content, only a signal that the trip changed; the app composes the text on your device. You can turn notifications off at any time with the toggle in the app's settings (this deletes your push token from our server) or in your device's system settings: iOS: Settings → Notifications → the app; Android: Settings → Apps → the app → Notifications.

حزم التطوير والخدمات الخاصة بجهات خارجية

The app relies on the following third-party services, each governed by its own privacy policy: - Google AdMob (ads and rewarded ad verification): https://policies.google.com/privacy - Google Firebase Analytics, Remote Config and Cloud Messaging: https://firebase.google.com/support/privacy - Apple Push Notification service and Apple In-App Purchase (iOS): https://www.apple.com/legal/privacy/ - Google Play Billing (Android): https://policies.google.com/privacy - Amazon Web Services (hosting of our server): https://aws.amazon.com/privacy/ - Vercel (hosting of the shared link web page): https://vercel.com/legal/privacy-policy We have no read access to personal data these services may collect independently. Data sent to each service is limited to what the features described above need.

الأساس القانوني للمعالجة (GDPR / UK GDPR)

Where the EU General Data Protection Regulation (Regulation (EU) 2016/679) or the UK GDPR applies, we process personal data on the following legal bases: - Performance of a contract (Art. 6(1)(b)): shared links, companion reactions and comments, live update notifications, and verifying a purchase or rewarded unlock, all of which you request by using those features. - Consent (Art. 6(1)(a)): personalised AdMob ads, where consent is given through the in-app UMP consent screen, and the notification permission you grant on your device. You may withdraw consent at any time; withdrawal does not affect the lawfulness of prior processing. - Legitimate interests (Art. 6(1)(f)): the encrypted backup, which is on by default so your trips are not lost with your phone (it is encrypted on your device so we cannot read it, and you can turn it off in the app's Settings at any time), non-personalised ads, aggregated analytics, protecting the service against abuse, and automatically deleting inactive records. You may object at any time via the email above. - Compliance with a legal obligation (Art. 6(1)(c)): retaining transaction records to meet tax or consumer protection law, where applicable.

نقل البيانات عبر الحدود الدولية

We are located in the Republic of Korea. Our server, which stores shared links, companion records and encrypted backups, is hosted by Amazon Web Services in Seoul, Republic of Korea. The third-party services listed above (Google, Apple, Vercel) may process personal data in other jurisdictions, including the United States. Where data is transferred out of the European Economic Area, the United Kingdom or Switzerland, the transfer relies on the safeguards adopted by the receiving provider - typically the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum (IDTA), or, where applicable, the EU–US Data Privacy Framework. Each provider's transfer safeguards are described in the privacy policies linked above.

Retention and deletion

- On your device: until you delete it in the app, delete the app or clear its storage. - Shared links (with the encrypted itinerary, checks, comments and notification subscriptions): deleted automatically 90 days after the trip's end date, or immediately when you stop sharing the link or delete the trip in the app. - Encrypted backup: deleted 2 years after the last upload, or immediately with "Delete my data". - Owner key: deleted after 180 days without use if it has no shared links, no rewarded unlock record and no verified purchase. A key with a rewarded unlock record or a verified purchase is kept so that the unlock or purchase keeps working, until you delete it with "Delete my data". - Companion record: see "People who open a shared link (companions)" above. "Delete my data" in the app's settings deletes the server copies immediately: it removes all your shared links, your owner key together with its rewarded unlock and purchase records, your encrypted backup, and your companion record with your checks and comments. If your device is offline at that moment, the on-device data is still deleted and any server copies that could not be reached are removed by the retention periods above. Personal data handled by third-party services (AdMob, Firebase, store platforms, hosting providers) is retained according to their own policies linked above. Where you have a statutory right to erasure, you can exercise it directly with those providers or ask us for help.

الأمان

Shared itineraries, companion comments and backups are end-to-end encrypted (AES-GCM) on the device. The keys stay in the part of the link after "#" or in your recovery code and never reach our server, so a copy of our database would reveal only encrypted content plus the plain items listed above (nicknames, languages, push tokens, anonymous IDs, trip end dates, transaction IDs, times and counts). This also means we cannot recover a trip or a backup for you. Notifications contain no itinerary text. All traffic between the app and our server is encrypted with HTTPS/TLS. Our server necessarily receives your device's IP address with each request; we use it only to deliver the response and to limit abusive request rates, and technical logs are rotated and overwritten automatically. On-device data is protected by the operating system's standard safeguards (iOS Data Protection, the Android app sandbox). Operator-side secrets such as API keys are kept out of public source control. No system is perfectly secure, so we cannot guarantee absolute protection against unauthorised access, but we commit to reasonable technical and organisational measures proportionate to the sensitivity of the data.

خصوصية الأطفال

هذا التطبيق غير موجَّه إلى الأطفال. ولا يجمع المشغّل عن علم بيانات شخصية من أطفال دون الحدود العمرية التي يقررها القانون المعمول به: - 13 عاماً في الولايات المتحدة (قانون حماية خصوصية الأطفال على الإنترنت، COPPA). - 14 عاماً في جمهورية كوريا (قانون حماية المعلومات الشخصية، المادة 22-2). - 16 عاماً في الاتحاد الأوروبي (GDPR، المادة 8، مع مراعاة الحدود الأدنى التي تقررها الدول الأعضاء منفردةً). إذا علم أحد الوالدين أو أولياء الأمور بأن طفلاً قدَّم بيانات شخصية، يمكنه التواصل مع المشغّل عبر عنوان البريد الإلكتروني أعلاه لطلب حذفها. ولا تُقدَّم الإعلانات السلوكية أو القائمة على الاهتمامات إلى المستخدمين المحدَّدين كأطفال.

حقوقك

بحسب مكان إقامتك، قد تتمتع بالحقوق التالية، والتي يمكنك ممارستها بالتواصل عبر admin@pantalabs.net. يُرجى وصف طلبك، والإشارة إلى نطاقك القضائي عند الاقتضاء. - المنطقة الاقتصادية الأوروبية والمملكة المتحدة وسويسرا (GDPR / UK GDPR / FADP): حق الاطلاع (Art. 15)، والتصحيح (Art. 16)، والمحو (Art. 17)، وتقييد المعالجة (Art. 18)، ونقل البيانات (Art. 20)، والاعتراض (Art. 21)، والحق في تقديم شكوى إلى سلطة إشرافية. - كاليفورنيا، الولايات المتحدة (CCPA / CPRA، Cal. Civ. Code §§ 1798.100–1798.199.100): الحق في المعرفة، والحق في الحذف، والحق في التصحيح، والحق في عدم بيع أو مشاركة المعلومات الشخصية، والحق في تقييد استخدام المعلومات الشخصية الحساسة، والحق في عدم التمييز بسبب ممارسة هذه الحقوق. - جمهورية كوريا (قانون حماية المعلومات الشخصية، المواد 35-37): حق الاطلاع والتصحيح والحذف وتعليق المعالجة. - اليابان (قانون حماية المعلومات الشخصية): حق الإفصاح والتصحيح ووقف الاستخدام. - أستراليا (Privacy Act 1988، مبادئ الخصوصية الأسترالية): حق الاطلاع على المعلومات الشخصية وتصحيحها. - كندا (PIPEDA، المبدأ 4.9): حق الاطلاع على المعلومات الشخصية وتصحيحها. "عدم بيع أو مشاركة معلوماتي الشخصية" (CCPA / CPRA): لا يبيع المشغّل المعلومات الشخصية مقابل عوض مالي. غير أن استخدام معرّف إعلاني لأغراض الإعلانات المخصَّصة قد يُصنَّف بوصفه "مشاركة" بموجب CCPA/CPRA. ويمكن لسكان كاليفورنيا رفض ذلك باختيار الإعلانات غير المخصَّصة عبر رابط تخصيص الإعلانات داخل التطبيق، أو بإعادة ضبط المعرّف الإعلاني على أجهزتهم.

التغييرات على هذه السياسة

يجوز تحديث هذه السياسة عند تغيّر ممارسات التطبيق المتعلقة بالبيانات، أو عند إضافة خدمات جديدة من جهات خارجية، أو عند تغيّر القانون. ويعكس تاريخ "آخر تحديث" أعلى هذه الصفحة دائماً أحدث تغيير. وستُبرَز التغييرات الجوهرية داخل التطبيق حيثما كان ذلك معقولاً. ويُعدّ استمرار استخدام التطبيق بعد سريان أي تغيير قبولاً بالسياسة المحدَّثة.

التواصل

للاستفسارات المتعلقة بالخصوصية أو الشروط أو الحقوق، يُرجى التواصل مع PantaLabs عبر admin@pantalabs.net.