Privacy

Privacy Policy

This policy explains what personal data Muyasir Portal handles, why, where it is kept, who can see it, how long it is kept and what rights people have. We only collect what the Service needs, we do not sell personal data, and we do not use advertising or tracking cookies.

Effective date: Version: 2.0

1. Who we are and who this policy covers

In short: SAAD ICT runs Muyasir Portal. This policy covers website visitors, agency staff who use the portal, and the people whose records agencies keep in it.

Muyasir Portal (the "Service") is provided by SAAD ICT, Mogadishu, Somalia ("we", "us"). This policy applies to:

  • visitors to our website at muyasir.com;
  • staff of Hajj and Umrah agencies who use the Service ("Authorised Users");
  • pilgrims, travellers, applicants, employees, suppliers and other people whose details an agency records in the Service;
  • people who contact us by email or through the website contact form.

Questions and requests about privacy can be sent to info@muyasir.com. This policy is written in English, which is the binding version; Somali and Arabic translations are provided for convenience.

2. Our role: controller or processor

In short: For pilgrim and customer records, the agency decides and is responsible; we process the data for it. For our own website, accounts and support, we are responsible.

Each agency that uses the Service decides which people it records, why and for how long. For that data ("Customer Data") the agency is the data controller and SAAD ICT is its data processor: we store and process it only to provide the Service to that agency and according to its instructions.

SAAD ICT is the controller for the data it handles for its own purposes: website visitors, enquiries, Authorised User accounts, security records, and the agency's subscription and billing records.

If you are a pilgrim, traveller or employee of an agency and have a question about your record, please contact that agency first: it controls your data. We will help the agency respond.

3. What we collect

In short: What we hold depends on how you interact with us. Agencies record identity, travel and payment details about pilgrims; we record account and security details about users.

3.1 Website visitors

  • Our public website sets no cookies and uses no analytics, advertising or tracking tools.
  • Like any website, our hosting provider receives technical information when a page is requested, such as your IP address, browser type and the page requested, and keeps it in short-lived server logs for security and troubleshooting.
  • If you use the contact form, we receive your name, email address and message. To prevent abuse we also store a one-way, salted scrambling (hash) of your IP address and a short description of your browser. We cannot turn the hash back into your IP address.

3.2 Authorised Users (agency staff)

  • Account details: full name, email address, phone number (optional), profile photo (optional), role, permissions and the agency you belong to.
  • Sign-in data: your password, which is stored only as a one-way hash by our authentication service; one-time sign-in codes, which are stored only as a hash and expire after 10 minutes; and records of verified sign-in sessions.
  • Activity records: which records were created, changed or deleted, by whom and when, and administrative actions such as inviting or disabling users. These help agencies keep an audit trail and help us investigate problems.
  • Technical data generated when you use the Service, such as IP address and browser information in security and server logs.

3.3 Records agencies keep (Customer Data)

Depending on how an agency uses the Service, it may record the following about the people it serves or employs:

CategoryExamples
IdentityFull name (including in Arabic), gender, date of birth, nationality, photo
Travel documentsPassport number and expiry date, passport copy, visa number and visa copy, other document numbers
ContactPhone number, email address, emergency contact name and phone number
Travel and pilgrimageBookings, packages, trips, flights, tickets, hotels, rooms, transport, groups and itineraries
PaymentsAmounts, dates, payment method and reference, invoices, receipts, refunds, balances
Health (only if needed)Medical notes, medical status and health documents for Hajj, where the agency needs them for the person's safety and care
ApplicationsName, phone number, passport copy and notes submitted through an agency's own website application form
Employees of the agencyName, nationality, passport number, phone number, photo, salary and employment contract details
Suppliers and driversNames, phone numbers and email addresses

3.4 Public verification pages

When someone scans a QR code on a document issued through the Service, we record the time the record was last checked. We do not identify the person who scanned it. A salted hash of the requesting IP address is kept briefly to prevent automated misuse.

4. Why we use personal data and on what basis

In short: To run the Service, keep it secure, support you, bill agencies and meet legal duties. Never for advertising.

PurposeData usedLegal basis
Providing the Service to an agency: storing and displaying its records, generating documents, invoices, ID cards and manifestsCustomer Data, account detailsPerformance of our contract with the agency; for Customer Data, the agency's own legal basis
Creating and securing accounts: sign-in, two-step verification, permissionsAccount and sign-in dataPerformance of contract; our legitimate interest in security
Protecting the Service against abuse, fraud and attacksSecurity logs, hashed IP addresses, bot-protection signalsLegitimate interest in security; legal obligations
Sending service emails: invitations, sign-in codes, password resets, daily summaries, departure alerts and subscription remindersName, email address, relevant record detailsPerformance of contract; legitimate interest
Answering enquiries and providing support by emailContact details, messagesLegitimate interest in responding; steps before a contract
Managing subscriptions and billingAgency and administrator contact details, payment recordsPerformance of contract; legal obligations (tax, accounting)
Complying with the law and defending legal claimsRelevant recordsLegal obligation; legitimate interest

We do not use personal data for advertising, we do not build marketing profiles, and we do not sell or rent personal data to anyone.

5. Sensitive data

In short: Passport copies and health information need extra care. Agencies should record them only when necessary; we store them privately and restrict access.

Passport and visa copies, dates of birth and especially health information deserve extra protection. Agencies are responsible for recording health information only where it is necessary for a person's safety and care during travel and for having the legal basis and consent the law requires.

  • Uploaded documents and photos are stored in private storage and are never public. They can only be opened by signed-in users of the same agency through temporary links that expire.
  • Public verification pages never show passport copies or health information, and show document numbers only in part.
  • Agencies should grant access to sensitive records only to the staff who need it.

6. Passport scanning (OCR)

In short: Passport scanning happens inside your browser. The image is not sent to any scanning service, and no automated decisions are made.

When a user scans a passport to pre-fill a form, the text recognition runs inside the user's own browser. The passport image is not sent to any external recognition service for this purpose. To run, the browser downloads the recognition engine from a public software distribution network, which receives the user's IP address like any website would.

The result only pre-fills fields that the user must check. The Service does not use it, or any other data, to make automated decisions about any person.

7. Cookies and browser storage

In short: No cookies on the public website. Only essential cookies when you sign in, plus a few settings saved in your browser. No tracking.

We use only what the Service needs to work. We do not use advertising, analytics, social-media or other tracking cookies, so we do not ask for cookie consent.

WhatTypePurposeHow long
Sign-in sessionEssential cookie, set only when you sign inKeeps you signed in securely and proves your identity to the ServiceUntil you sign out, or until the session expires
Theme (light or dark)Browser storageRemembers your display preferenceUntil you clear your browser data
Sidebar layoutBrowser storage (signed-in area)Remembers whether menu groups are open or collapsedUntil you clear your browser data
Sign-in attemptsBrowser storage (sign-in page)Counts failed sign-in attempts on your device to slow down password guessingReset to zero after a successful sign-in; kept until you clear your browser data
Bot protectionThird-party check on the sign-in and password-reset pagesConfirms that a human, not an automated program, is signing in. Provided by Cloudflare, which processes your IP address and browser characteristics for this purposePer page visit

You can block or delete cookies in your browser settings, but you will not be able to sign in without the essential session cookie.

8. Who we share data with

In short: Only with the providers that run the Service, and with authorities when the law requires it. Never sold.

Inside an agency, Customer Data is visible only to that agency's Authorised Users, according to the roles and permissions the agency sets. Agencies cannot see each other's data. Outside the agency, we share personal data only with:

RecipientRoleData involved
Hosting providerRuns the website and application servers and delivers pagesAll data passing through the Service, technical logs
Database and file-storage serviceStores the database, uploaded files and backups, and provides sign-inAll stored data
Email delivery providerSends service emailsRecipient name and email address, email content
CloudflareBot protection on sign-in pagesIP address, browser characteristics
Public software distribution networkDelivers the passport-scanning engine to the browserIP address, browser information
Professional advisersLegal, accounting or audit advice, under confidentialityOnly what is necessary
AuthoritiesWhere required by law, court order or to protect rights and safetyOnly what is legally required
  • Our providers may process data only on our instructions and must protect it.
  • We do not send data to any government, embassy, airline or visa system. Agencies make such submissions themselves, outside the Service.
  • If SAAD ICT or the Service is reorganised, merged or sold, personal data may be transferred to the new owner under the same protections, and we will inform agencies.

9. Where data is stored

In short: The database and files are stored in the European Union. The application servers run in the United States. Data therefore leaves Somalia.

  • The database, uploaded files and backups are stored in a data centre in Stockholm, Sweden, in the European Union.
  • The application servers that process requests run in the United States, and pages may be delivered through a global content network closer to the visitor.
  • Our email delivery provider and Cloudflare may process data in other countries.

This means personal data is transferred outside Somalia and outside the country of the agency. We use providers that apply strong security and contractual commitments to protect data wherever it is processed, and all data travels over encrypted connections.

10. How long we keep data

In short: Security records are cleaned automatically within days. Agency records are kept while the subscription is active, then deleted within 90 days.

DataHow long
One-time sign-in codesValid for 10 minutes; deleted automatically 1 day after they expire
Verified sign-in sessionsValid for 12 hours; deleted automatically 7 days after they expire
Invitation linksValid for 15 minutes
Anti-abuse records (hashed IP addresses and phone identifiers)Deleted automatically after 7 days
Public verification linksPilgrim and traveller links expire after 180 days by default and can be revoked earlier by the agency
Customer DataFor as long as the agency's subscription is active and the agency keeps the record, then as described below
Records deleted in the ServiceHidden immediately and kept only so that mistakes can be undone and the audit trail stays complete; permanently deleted with the rest of the agency's data at the end of its subscription, or earlier on request
Activity and audit recordsFor the life of the agency's account
After a subscription endsThe agency may request an export for 90 days; after that its Customer Data is deleted
BackupsOverwritten automatically on a rolling basis within 7 days
Contact-form and email enquiriesAs long as needed to handle the enquiry and any follow-up; you can ask us to delete them
Subscription and billing recordsAs long as tax, accounting and legal requirements require

11. How we protect data

In short: Encryption, separation between agencies enforced by the database, two-step sign-in, private files and activity logs.

  • Encrypted connections (HTTPS) for all traffic, and encryption of stored data by our infrastructure providers.
  • Separation between agencies is enforced by rules inside the database itself, so one agency's users cannot read or change another agency's records.
  • Two-step sign-in: a password plus a one-time email code, with limits on attempts and on how often codes can be requested.
  • Bot protection on the sign-in and password-reset pages, and rate limits on public pages and forms.
  • Private file storage: documents and photos are never public and open only through temporary signed links.
  • Role-based permissions, so each user sees and changes only what their role allows.
  • Activity logging of changes to records and of administrative actions.
  • Masked document numbers on public verification pages, and strict browser security rules that limit which external services the site can contact.

12. Your rights

In short: You can ask to see, correct, delete or export your data, or object to how it is used. Pilgrims should contact their agency first.

Depending on the law that applies to you, you may have the right to:

  • access the personal data held about you and receive a copy;
  • have inaccurate or incomplete data corrected;
  • have your data deleted, or its use restricted;
  • object to certain uses of your data;
  • receive your data in a portable format;
  • withdraw consent, where processing is based on consent;
  • complain to the data protection authority in your country.

If your data is held by an agency (for example as a pilgrim, traveller or employee), please contact that agency, which is responsible for your record. For data we control, or if you cannot reach the agency, email info@muyasir.com. We may need to confirm your identity first, and we aim to respond within 30 days. We do not charge for reasonable requests.

13. Children

In short: Only adults use the Service. Agencies may record children who travel, with their guardian's consent.

Authorised Users must be at least 18 years old. Agencies may record details of children who travel with their families; the agency is responsible for obtaining any consent required from a parent or guardian. Our website is not directed at children.

14. Security incidents

In short: If a breach affects your data, we act quickly and tell the agencies concerned.

If we become aware of a security incident that affects personal data, we will act promptly to contain it, investigate it and reduce its effects. We will inform affected agencies without undue delay, and where possible within 72 hours of confirming the incident, with the information they need to meet their own obligations. Where the law requires, we or the agency will also inform the authorities and the people affected.

15. Changes to this policy

In short: We update this page when the Service changes, and tell agencies about important changes.

We will update this policy when our practices or the Service change. The effective date and version at the top of this page show the latest update. We will notify agencies' administrators of material changes by email or in the Service before they take effect.

16. Contact

In short: How to reach us about privacy.

SAAD ICT, Mogadishu, Somalia. Privacy and data requests: info@muyasir.com. Website: muyasir.com.

© 2026 Muyasir