Data Retention Policy
Data intrării în vigoare: 2026-08-20 · v1.0.0
Acest document este publicat în engleză și arabă. Pentru celelalte limbi este afișată versiunea în engleză.
1. Purpose
This policy states how long the current Ramlyon implementation keeps each data class and what the automated retention and closure processes do. The periods below are generated from the same constants used by the running cleanup jobs.
| Data | Who decides | How long | What happens at the end |
|---|---|---|---|
| Menu view/tap events | Ramlyon | 90 days | Deleted |
| Anonymous menu visitors (no order) | Ramlyon | 90 days | Deleted |
| Menu visitors who ordered | Ramlyon | 90 days | Phone number erased; anonymous record kept |
| Orders and order contents | Merchant | 24 months | Name and phone erased; order and amounts kept |
| Delivery address and recipient details | Merchant | 24 months | Address, recipient name/phone and driver notes erased; fee and amounts kept |
| Diner directory | Merchant | Until the merchant deletes it | Erased across orders and sessions too |
| Aggregate daily statistics | — | Indefinite | Anonymous; retained |
| Account and staff records | Ramlyon | 30 days after closure | Operational data purged; account anonymized |
| Sessions / OTPs / login attempts | Ramlyon | 30 days / 24 hours / 90 days | Deleted |
| Change history (audit) | Ramlyon | 365 days | Deleted |
| Invoices and payment records | Law | 5 years | Retained; cannot be deleted on request [EGYPTIAN LAWYER REVIEW REQUIRED] |
| Uploaded images | Merchant | Deleted with the item; orphans after 30 days | Deleted from storage |
| Provider logs (Cloudflare, Zoho, host) | Provider | Provider default | Outside Ramlyon's control |
| Offline browser storage | Device owner | Until logout or the browser clears it | Cleared on logout |
| Backups | — | None exist today | No backup copy exists |
2. Merchant-controlled erasure
The merchant can erase a diner from the customer directory. The erasure flow removes personal data across customer, order, and guest-session records while preserving financial amounts needed for operational and record-keeping purposes.
The merchant can request tenant closure. Closure is reversible for 30 days; after that, operational data is purged and the user account is anonymised where the implementation permits.
3. Billing records
Invoices, subscriptions, and payment-claim records are retained for the period generated above and are not removed through customer erasure or tenant closure.
4. Provider logs and backups
Infrastructure providers apply their own log-retention defaults outside Ramlyon's direct application policy. Their roles are listed on the Sub-processors page.
5. Questions
Questions about retention or a data request can be sent to [email protected].