This Privacy Policy explains how Yallla handles personal information when you use the Yallla mobile app and the public surfaces at yallla.club and my.yallla.club (together, the "Service"). The Service is provided by Fondry Company for Custom Software Design and Programming (شركة فوندري لتصميم وبرمجة البرمجيات الخاصة), a one-person company registered in Kuwait under Commercial Register No. 516831 ("Fondry", "Yallla", "we", "us").
The Service is intended for users who are 18 or older. We do not knowingly collect information from anyone under 18. If you believe a child has signed up, contact us at support@yallla.club and we will remove the account.
1. INFORMATION YOU PROVIDE
Account information. When you sign up we collect your email address and a password (stored only as a hash). During onboarding you choose a display name, a username, an account type (Talent, Client, or Both), a country, and — for Client and Both accounts — an optional company name and logo.
Profile content. You can add an avatar, a short biography, skills, a portfolio of images and video links, and contact methods you choose to expose (for example, phone number, WhatsApp number, Instagram handle, public email). Anything you mark as a contact method is visible to other Yallla users you transact with, in the contexts described below.
Marketplace activity. When you post a listing, send a proposal, send or receive an offer, mark a listing complete, or file a report, we store that activity along with timestamps. Listings and public profiles are visible to other Yallla users and, in the case of profile pages, to anyone who visits my.yallla.club/<your-username>.
Communications. If you contact us at support@yallla.club we keep the email exchange for service and abuse-prevention purposes.
2. INFORMATION WE COLLECT AUTOMATICALLY
Push tokens. If you grant the iOS push permission, we store the Apple-issued push token so we can deliver notifications about your proposals, offers, and account events. You can revoke this in your device settings at any time.
Language and locale. The app remembers whether you prefer English or Arabic so it can render the correct strings.
Diagnostics. When the app crashes or hits an unhandled error we send anonymised diagnostic information (device model, OS version, crash stack) to Sentry to help us fix bugs. We do not include the contents of your messages, listings, or contact details in crash reports.
Server logs. Our backend records standard request metadata (timestamp, request path, approximate IP-derived country, response code) to operate and secure the Service. These logs age out within 30 days.
3. HOW WE USE YOUR INFORMATION
We use the information we collect to:
- operate the marketplace — let you discover talent and projects, post listings, send and receive proposals and offers, and complete transactions;
- keep accounts and content safe — detect spam, scams, fraud, and abuse, and act on reports;
- communicate with you about the Service — confirm sign-up, reset your password, deliver push notifications you have asked for, and respond to support requests;
- provide multilingual support — translate listing text on demand using Google Cloud Translation, and cache the translation so we do not have to call the third-party API again for the same text;
- comply with legal obligations and protect our rights.
We do not use your information for marketing or to build advertising profiles. We do not sell your personal information.
4. WHO WE SHARE WITH
We use a small number of vendors to run the Service. These vendors only process information on our behalf and under contracts that require them to protect it:
- Supabase — our primary database, authentication system, file storage, and real-time messaging. Data is stored in Supabase's Mumbai region (ap-south-1).
- Google Cloud Translation — translates listing text on demand when you tap "Translate". We send only the text being translated; no account identifier is attached.
- Resend — delivers transactional email (sign-up confirmation, password reset). Operated from Ireland.
- Apple Push Notification service — delivers push notifications to your iPhone.
- Sentry — collects crash diagnostics. Data processed in the EU (Germany).
- Vercel — serves my.yallla.club (public profile pages and legal pages) and our admin web panel from a global content-delivery network.
- Expo (EAS) — distributes over-the-air JavaScript updates to the installed app.
We may also share information when required by law, when needed to investigate suspected fraud or abuse, or as part of a corporate transaction (for example, if Yallla is acquired or restructured).
Other Yallla users see what you publish: your public profile, your listings, the proposals and offers you exchange with them, and the contact methods you have chosen to expose for accepted matches.
5. WHERE DATA IS STORED
User accounts, listings, proposals, offers, profiles, and uploaded images are stored in Supabase's Mumbai region (ap-south-1), the region closest to the GCC. Email delivery, crash reports, push delivery, and web hosting run on the international networks of the vendors listed above. Where data leaves your country, we rely on the vendor's standard transfer safeguards.
6. RETENTION
We keep your information for as long as your account is active. When you delete your account from Settings → Account & Security:
- your profile, listings, portfolio images, proposals, offers, and reports are removed from the live database immediately;
- our encrypted database backups, which exist for disaster recovery, age out within 30 days, after which the deleted data is no longer recoverable;
- we may retain a small amount of information for legitimate purposes — for example, abuse logs, evidence relating to reports filed against you, and the minimum records needed for tax or accounting — in anonymised or aggregated form.
7. YOUR RIGHTS
You can:
- access and update most of your information directly inside the app at Settings → Edit profile;
- export a copy of your account data by emailing support@yallla.club;
- delete your account at Settings → Account & Security → Delete account, or by emailing support@yallla.club;
- object to a specific use of your information by emailing support@yallla.club.
If you are in a jurisdiction that grants additional rights (for example, the EU or UK), you can exercise those rights by contacting us at the same address. We will respond within 30 days.
8. SECURITY
We use Supabase Row-Level Security (RLS) to make sure each user can only read and write their own data through our APIs. Passwords are stored only as hashes. Transport is encrypted in transit using HTTPS / TLS. No system is perfectly secure; if we learn of a breach that affects you, we will notify you promptly and tell you what we know.
9. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent change. If we make a material change, we will let you know in-app or by email before it takes effect.
10. CONTACT
Questions, complaints, or data-rights requests:
Yallla — Fondry Company for Custom Software Design and Programming, Kuwait support@yallla.club