Privacy Policy
Last updated August 26, 2026
Privacy Policy
Draft for legal review. The processing described here matches what the platform actually does, checked against the database schema and the code. It has not been reviewed by counsel, and the controller's legal name, registered address and Data Protection Officer contact are pending.
Mahsool is an Egyptian fractional farm-investment platform. This policy explains what we collect, why, how long we keep it, and what you can ask us to do. It is written to Egypt's Personal Data Protection Law (Law 151 of 2020).
Controller: [Operating entity — legal name, commercial register number and registered address to be inserted before launch.]
1. What we collect, and why
To open and secure your account Email address, full name, a password (stored only as an Argon2id hash — we never hold your password), your language preference, and the timestamps of email verification and the suitability quiz. We keep session records (refresh tokens) and one-time email codes so sign-in works and so we can end sessions when you ask.
To verify your identity (KYC) Where the law and our own controls require it — before you withdraw, and for investing where the setting requires it — we collect your identity document type and number, images of the document front and back, and a selfie. A reviewer records a screening note and a decision. We collect this because we cannot pay money out to an unverified person.
To move money Your wallet reference, balances and full transaction ledger; for deposits, the amount you declare, the method, the sender name, the transfer reference, the transfer date and the receipt image you upload; for withdrawals, the IBAN and account name. Egyptian rules and our own controls require withdrawals to go to an account in your own name.
To run your investments Orders, payment plans, instalments and their status, distributions paid to you, and the offers you favourite.
To keep you informed Your notification preferences per category, and — if you allow it — a device token so we can send push notifications.
To operate and improve the platform Product analytics events (which screens are used, which steps are completed), technical logs, and the IP address attached to security-relevant actions.
Administrative actions Every action our staff take on your records — approvals, rejections, adjustments — is written to an append-only audit log that names the person who acted.
2. Files you upload
Identity documents and deposit receipts go to a private store that is not publicly reachable; access is only through short-lived signed links issued to an authorised reviewer. Before any file is stored we check that its contents match the type it claims to be, and we strip embedded metadata — camera and GPS data from images, author and revision history from PDFs, and location and device atoms from video — so information you did not intend to share does not travel with the file. Offer photography sits in a separate public store.
3. How long we keep it
- One-time email codes and expired or revoked sessions are deleted on a scheduled sweep shortly after they expire.
- Duplicate-request keys used to stop double charges are swept on the same schedule.
- Financial records — your ledger, orders, instalments and distributions — are retained for the periods Egyptian accounting and financial regulation require, and are technically immutable: they can be added to but not edited or deleted, including by us. A correction is a new compensating entry, never a rewrite.
- Identity documents are retained for the period anti-money-laundering rules require after your relationship with us ends.
- The audit log is retained as the record of who did what.
4. Who else sees your data
We share only what is necessary, and we do not sell personal data.
- Infrastructure and email providers who host the platform and deliver transactional mail on our behalf.
- Push notification services operated by Apple and Google, which receive a device token and the notification content in order to deliver it.
- Operators of the projects you invest in receive aggregate investor information needed to run the project and make distributions — not your identity documents.
- Regulators, banks and law enforcement where we are legally required to respond.
Some of these providers process data outside Egypt. Where they do, we rely on the transfer conditions PDPL permits.
5. Your rights
Under PDPL you may ask us to: confirm what we hold about you and give you a copy; correct anything inaccurate; erase data where we have no legal reason to keep it; restrict or object to certain processing; and withdraw a consent you gave.
Two honest limits. We cannot erase financial records or the audit log while retention rules apply — those are legal obligations, and the ledger is append-only by design. And you can close your account from the app, but not while you hold a wallet balance or have a review in flight; settle or withdraw first.
6. Security
Passwords are hashed with Argon2id. Traffic is encrypted in transit. Administrative actions that move money require a second factor at the moment they are performed, not just at sign-in. Suspending an account cuts its access immediately rather than at token expiry. The financial ledger and the audit log are append-only in the database itself, and the credential the application runs with cannot alter them or the rules that protect them.
No system is perfectly secure. If a breach affects your personal data we will notify you and the regulator as PDPL requires.
7. Children
Mahsool is not for anyone under 18. We do not knowingly collect data from children, and we delete such an account if we find one.
8. Changes
We will post material changes here and, where the change matters to you, notify you directly. The date below records the last revision.
9. Contact
[Data Protection Officer contact and the controller's registered address to be inserted before launch.] Until then, reach us through the support address shown in the app.