Data Retention Policy

発効日: 2026-08-20 · v1.0.0

この文書は英語とアラビア語で公開されています。その他の言語では英語版が表示されます。

1. Purpose

This policy states how long the current Ramlyon implementation keeps each data class and what the automated retention and closure processes do. The periods below are generated from the same constants used by the running cleanup jobs.

DataWho decidesHow longWhat happens at the end
Menu view/tap eventsRamlyon90 daysDeleted
Anonymous menu visitors (no order)Ramlyon90 daysDeleted
Menu visitors who orderedRamlyon90 daysPhone number erased; anonymous record kept
Orders and order contentsMerchant24 monthsName and phone erased; order and amounts kept
Delivery address and recipient detailsMerchant24 monthsAddress, recipient name/phone and driver notes erased; fee and amounts kept
Diner directoryMerchantUntil the merchant deletes itErased across orders and sessions too
Aggregate daily statisticsIndefiniteAnonymous; retained
Account and staff recordsRamlyon30 days after closureOperational data purged; account anonymized
Sessions / OTPs / login attemptsRamlyon30 days / 24 hours / 90 daysDeleted
Change history (audit)Ramlyon365 daysDeleted
Invoices and payment recordsLaw5 yearsRetained; cannot be deleted on request [EGYPTIAN LAWYER REVIEW REQUIRED]
Uploaded imagesMerchantDeleted with the item; orphans after 30 daysDeleted from storage
Provider logs (Cloudflare, Zoho, host)ProviderProvider defaultOutside Ramlyon's control
Offline browser storageDevice ownerUntil logout or the browser clears itCleared on logout
BackupsNone exist todayNo backup copy exists

2. Merchant-controlled erasure

The merchant can erase a diner from the customer directory. The erasure flow removes personal data across customer, order, and guest-session records while preserving financial amounts needed for operational and record-keeping purposes.

The merchant can request tenant closure. Closure is reversible for 30 days; after that, operational data is purged and the user account is anonymised where the implementation permits.

3. Billing records

Invoices, subscriptions, and payment-claim records are retained for the period generated above and are not removed through customer erasure or tenant closure.

4. Provider logs and backups

Infrastructure providers apply their own log-retention defaults outside Ramlyon's direct application policy. Their roles are listed on the Sub-processors page.

5. Questions

Questions about retention or a data request can be sent to [email protected].