AmanAuth — Privacy Policy (Draft)
Last updated: 23 July 2026 website legal name: "AmanAuth" Website: www.amanauth.com
1. Who We Are
AmanAuth ("we", "us", "the Platform") is a software-as-a-service platform that lets software vendors ("Merchants") issue, validate, and manage license keys for their own applications. This Privacy Policy explains what personal data we collect, why, and what rights you have over it.
This Policy applies to everyone who interacts with the Platform:
- Merchants — businesses/developers who register an AmanAuth account, buy Points and/or a subscription plan, and generate license keys.
- Resellers — sub-accounts created by a Merchant to distribute/manage a subset of that Merchant's keys.
- Administrators — AmanAuth's own staff who operate the Platform.
- End Users — the Merchant's own customers. End Users never create an AmanAuth account; they interact only through (a) the AmanAuth SDK embedded in the Merchant's app (device activation/validation) and (b) an optional self-service link a Merchant may send them to check or reset their own license.
[LEGAL REVIEW] Because Merchants collect and control data about their own End Users, AmanAuth acts as a data processor for End User data and as a data controller for Merchant/Reseller account data. A specialist should confirm this classification holds under the Saudi Personal Data Protection Law (PDPL) and, if so, whether a separate Data Processing Agreement (DPA) between AmanAuth and each Merchant is required (it currently is not offered).
2. Information We Collect
2.1 Account data (Merchants, Resellers, Administrators)
- Name, username, email address, phone number
- Password (stored as a one-way hash — we never store or can retrieve your plain-text password)
- Preferred language, timezone, and light/dark theme setting
- Public support contact details a Merchant chooses to publish to its own End Users (support email, Telegram handle, WhatsApp number)
2.2 License & device data (collected from End Users, via the Merchant's app)
- License key code and its status (new, activated, reset, expired, frozen, blocked)
- Device identifier and a device fingerprint, generated by the AmanAuth SDK to bind a key to one device
- App bundle identifier, activation/expiry timestamps
- Optional contact details (email/phone) an End User submits when using a Merchant's self-service key-check/reset link
2.3 Billing & payment data
- Purchases of Points and subscription/access plans, including amount, tax, currency, and payment method (card, Apple Pay, or cryptocurrency)
- We do not collect or store full payment card numbers. Card payments are processed by Stripe; AmanAuth only stores the outcome (success/failure), an internal reference, and the invoice line items.
- Cryptocurrency payments are processed by a third-party crypto payment gateway. [LEGAL REVIEW / FILL IN] — name the specific crypto processor once finalized so it can be named here.
- Points balance and full Points transaction ledger (purchases, spend on key generation, transfers between Merchants, admin adjustments, chargeback debits)
2.4 Location data
- IP address of each request
- Approximate location (country and city) resolved from IP address via a third-party geolocation service (Geoapify), cached so each unique IP is only looked up once
- We do not collect GPS or precise device location
2.5 Support & communication data
- Support tickets you open with us and their replies
- In-app notifications generated by account activity (payments, key events, ticket updates)
2.6 Security & anti-abuse data
- Login timestamps, failed-login counts, and account activity/audit logs
- A verification token and an automated bot-likelihood score from Google reCAPTCHA (v3), collected on registration, password reset, public key-reset, and login (only after repeated failed attempts) — see §6 (Third Parties)
2.7 Cookies & similar technology
- A session cookie, required to keep you signed in and to protect forms against cross-site request forgery (CSRF) — strictly necessary, cannot be disabled if you want to use the dashboard
- For visitors who are not signed in, a session-based language preference (English/Arabic) when they use the language switch on our public website
- We do not currently use third-party advertising or analytics tracking cookies. [LEGAL REVIEW] If analytics/ads are added later, a cookie consent banner will be required.
3. How We Use Your Information
We use the data above to: create and secure your account; generate, validate, and enforce license keys; process payments and calculate tax; operate the Points economy (balances, transfers, refund-by-deletion of unused keys); send transactional emails and in-app notifications; detect and prevent fraud, bot activity, and abuse; provide customer support; and comply with our legal and accounting obligations.
We do not sell personal data to third parties, and we do not use End User or Merchant data for advertising.
4. Who We Share Data With
We share data only as needed to run the Platform:
| Recipient | What they receive | Purpose |
|---|---|---|
| Stripe | Card payment details, billing amount | Payment processing |
| [Crypto payment processor — name TBD] | Wallet address, transaction amount | Cryptocurrency payment processing |
| Geoapify | IP address | Country/city lookup |
| Google reCAPTCHA | Browser/device signals, IP address | Bot and abuse prevention |
| [Email delivery provider — name TBD] | Email address, message content | Sending transactional emails (verification, receipts, notifications) |
| [Hosting provider — e.g. Laravel Cloud] | All data described above (data at rest) | Application hosting and database storage |
[LEGAL REVIEW] A full sub-processor list with each provider's own privacy policy link should be finalized and kept up to date here once the hosting/email providers are locked in.
We may also disclose data if required by law, court order, or a lawful request from a Saudi regulatory authority, or to protect the rights, property, or safety of AmanAuth, our Merchants, or others.
5. International Data Transfer
[LEGAL REVIEW — IMPORTANT] AmanAuth's production database is currently hosted on infrastructure located in the United Kingdom/EU region (AWS eu-west-2, London), while the company operates from Saudi Arabia. Transferring personal data of Saudi-based individuals outside the Kingdom is regulated under the Saudi PDPL (transfers require an adequacy decision, appropriate contractual safeguards, or one of the statutory exceptions). A specialist must confirm whether this hosting arrangement satisfies PDPL cross-border transfer requirements, and whether a Riyadh-region hosting option should be used instead, before this Policy is published.
6. Data Retention
- Account data is kept for as long as your account is active, plus a reasonable period afterward for legal, accounting, and dispute-resolution purposes.
- Security, activity, and debug logs are kept for admin-configurable periods (security and activity logs default to 180 days; debug logs default to 30 days), after which they are purged automatically.
- Payment and invoice records are retained as required by Saudi tax and accounting law. [LEGAL REVIEW] confirm the exact statutory retention period (commonly cited as 10 years under Saudi commercial bookkeeping rules) and update this figure accordingly.
- IP-to-location lookups are cached indefinitely to avoid repeat third-party lookups; the underlying IP address itself is retained for as long as the account/request log referencing it is retained.
7. Your Rights
Subject to applicable law (see §9), you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data, subject to our legal retention obligations
- Object to or restrict certain processing
- Receive a copy of your data in a portable format
[LEGAL REVIEW] These rights should be mapped explicitly to the specific rights granted under the Saudi PDPL (right to be informed, right to access, right to request destruction, right to correction, right to withdraw consent) and its Implementing Regulations issued by SDAIA, and a defined contact channel/process and response timeframe (PDPL specifies response deadlines) should be added here.
To exercise any of these rights, contact us at:
- Privacy email:
[FILL IN] - Privacy phone:
[FILL IN]
8. Children's Privacy
The Platform is a business tool intended for use by software vendors, their resellers, and adult account holders. We do not knowingly collect personal data directly from children. [LEGAL REVIEW] If a Merchant's own end-product is used by children, clarify in this section (and in the Terms of Use) that the Merchant — not AmanAuth — is responsible for that product's compliance with children's-privacy laws, since AmanAuth has no direct relationship with or visibility into a Merchant's own End Users beyond device/license data.
9. Governing Law
[LEGAL REVIEW] This Policy is intended to operate under the laws of the Kingdom of Saudi Arabia, including the Personal Data Protection Law (Royal Decree No. M/19) and its Implementing Regulations issued by the Saudi Data & Artificial Intelligence Authority (SDAIA). A specialist should confirm the correct governing-law clause and whether an Arabic-language version of this Policy must be treated as the authoritative/binding text for Saudi users (this English draft should not be assumed sufficient on its own).
10. Changes to This Policy
We may update this Policy from time to time. Material changes will be communicated to Merchants via email or an in-app notification before they take effect.
11. Contact Us
- General support email:
[FILL IN] - General support phone:
[FILL IN] - Postal address:
[FILL IN]
Appendix — Open Questions for the Legal Specialist
A consolidated checklist, so nothing above gets missed in review:
- Confirm AmanAuth's controller/processor classification for Merchant vs. End User data, and whether a standard Data Processing Agreement (DPA) template is needed for Merchants.
- Confirm whether hosting personal data in the UK/EU (
eu-west-2) is compliant for Saudi-resident data subjects under PDPL, or whether KSA-region hosting is required. - Confirm the correct statutory data-retention period for financial/invoice records.
- Confirm whether a Data Protection Officer (DPO) or equivalent contact must be formally designated under PDPL.
- Confirm whether an Arabic-language version must be the legally authoritative version, and by when it must exist.
- Confirm the exact process/timeline for responding to data subject access/deletion requests under PDPL.
- Confirm whether the points/virtual-currency system requires any disclosure calling out its treatment as "not legal tender" / "non-transferable to cash" for consumer-protection clarity.
- Once the crypto payment processor and email delivery provider are finalized, name them explicitly in §4.