سياسة الخصوصية — منصة مسند
آخر تحديث: 28 أغسطس 2026
تنطبق هذه السياسة على منصة مسند عبر الموقع misnaad.com وعلى تطبيقي أندرويد التابعين لها: مسند الفني (com.misnaad.technician) ومسند المالك (com.misnaad.owner). تشرح هذه الصفحة، بدقة وبما يطابق ما يفعله النظام فعلاً، البيانات التي نجمعها وسبب جمعها وكيفية التصرف فيها، وفقًا لنظام حماية البيانات الشخصية في المملكة العربية السعودية.
من نحن وأدوار الأطراف
منصة مسند خدمة برمجية تستخدمها منشآت الخدمات الميدانية لإدارة أعمالها. حسابات الفنيين والموظفين تُنشئها وتديرها المنشأة الموظِّفة (صاحب العمل) — فهي الجهة التي تقرر أغراض معالجة بيانات فريقها وعملائها، بينما تعالج منصة مسند تلك البيانات لتشغيل الخدمة لصالح المنشأة.
البيانات التي نجمعها
- بيانات الحساب: الاسم ورقم الهاتف والبريد الإلكتروني. تُدخل هذه البيانات المنشأةُ الموظِّفة عند إنشاء الحساب.
- الموقع الجغرافي الدقيق للفني (بموافقته): يجمع تطبيق مسند الفني موقع الفني ويشاركه مع منشأته فقط، بعد موافقة صريحة داخل التطبيق تُمنح لكل منشأة على حدة. يستمر الجمع ما دام الفني مسجلاً للدخول وما دامت موافقته قائمة، وفي تطبيق أندرويد حتى عندما يكون التطبيق مغلقًا أو غير مستخدم. عند استخدام النسخة المتصفحية (PWA) يتوقف الجمع بمجرد إغلاق الصفحة. سحب الموافقة من داخل التطبيق يوقف الجمع فورًا. تطبيق مسند المالك لا يجمع الموقع إطلاقًا (لا يملك صلاحية الموقع أصلاً).
- رموز الإشعارات: رمز جهاز خدمة Firebase Cloud Messaging في تطبيقات أندرويد، واشتراك Web Push في المتصفح، لتوصيل إشعارات المهام.
- أحداث تشخيصية: أسماء أحداث قصيرة مع توقيتها (مثل «نجح تحديد الموقع» أو «تعذّرت المزامنة») لتشخيص أعطال التتبع. هذه الأحداث لا تتضمن أي إحداثيات، والخادم يرفض أي محتوى خارج قائمة أسماء الأحداث المسموحة.
- سجلات العمل التي تُدخل في التطبيق: صور المهام، توقيع العميل عند إنجاز العمل، الملاحظات، سجلات الحضور والانصراف، وصورة التحقق عند تسجيل الحضور.
غرض المعالجة
تُعالج بيانات الموقع لغرض واحد: توزيع المهام وتنسيق الفريق الميداني للمنشأة الموظِّفة. يظهر موقع الفني الموافِق على خريطة المتابعة الحية التي يراها مشغّل منشأته. تُعالج بقية البيانات لتشغيل الحساب وتوثيق الأعمال المنجزة وتوصيل الإشعارات.
الأساس النظامي
جمع الموقع يقوم على الموافقة الصريحة: لا يُخزَّن أي موقع دون موافقة الفني المسبقة داخل التطبيق، والموافقة لكل منشأة على حدة، ويمكن سحبها في أي وقت من داخل التطبيق فيتوقف الجمع فورًا — ويتحقق الخادم من قيام الموافقة عند استلام كل نقطة موقع قبل تخزينها. تُعالج بيانات الحساب وسجلات العمل في إطار علاقة العمل بين الفني ومنشأته وبتوجيه منها. لا تدّعي المنصة أي شهادة أو تسجيل أو اعتماد؛ والتزامها هو العمل وفق أحكام نظام حماية البيانات الشخصية.
مدة الاحتفاظ
تُحدد مددَ الاحتفاظ ببيانات الموقع المنشأةُ الموظِّفة لكل مصدر تتبع، وتُحذف السجلات الأقدم من المدة المحددة تلقائيًا بعملية حذف دورية يومية. بيانات الموقع التي فقدت مصدرها المُهيّأ تُحذف تلقائيًا بعد 30 يومًا كحد أقصى. يعمل الحذف الدوري حتى لو عُطّلت ميزة التتبع نفسها.
حقوقك: الاطلاع والتصحيح والحذف
يوفر النظام أدوات مدمجة لتصدير نسخة من البيانات الشخصية المرتبطة بحسابك (بما فيها سجل المواقع وأحداث المناطق الجغرافية وسجلات الإشعارات وسجلات شؤون العاملين) ولمحوها محوًا كاملاً عند طلب صاحب الشأن. لتقديم طلب اطلاع أو تصحيح أو حذف، تواصل عبر: [PRIVACY-CONTACT-EMAIL]، أو عبر منشأتك الموظِّفة بصفتها المتحكمة في بيانات فريقها.
المشاركة مع الغير
لا نبيع البيانات الشخصية، ولا نشاركها مع أي طرف ثالث لأغراضه الخاصة. تقتصر المشاركة على مزوّدي خدمات يعالجون البيانات لتشغيل المنصة:
- Google Firebase Cloud Messaging: لتوصيل الإشعارات إلى تطبيقات أندرويد.
- خدمات دفع الإشعارات في المتصفحات (Google وMozilla وMicrosoft): لتوصيل إشعارات الويب، ومحتوى الإشعار فيها مشفّر بحيث لا يستطيع مشغّل الخدمة قراءته.
- خدمة البريد الإلكتروني المُهيّأة للمنصة: لإرسال رسائل الإشعارات البريدية.
- خدمة الترميز الجغرافي للعناوين: يُرسل عنوان موقع الخدمة (نص العنوان فقط، دون اسم أو هاتف) إلى خدمة ترميز جغرافي لتحديد موقع المهمة على الخريطة — الخدمة الافتراضية هي OpenStreetMap Nominatim وهي قابلة للتغيير من إعدادات المنصة.
- مزوّد الاستضافة الذي تعمل عليه المنصة.
إضافة إلى ذلك، قد تربط المنشأة الموظِّفة بنفسها تكاملات اختيارية بمفاتيحها الخاصة — مثل حساب واتساب للأعمال (Meta) أو بوابة رسائل، أو مزوّد ذكاء اصطناعي، أو خدمة تتبع مركبات أو توجيه طرق. لا تعمل هذه التكاملات إلا إذا فعّلتها المنشأة، وتخضع معالجتها لاتفاقيات المنشأة مع تلك الجهات.
أمن البيانات
تنتقل البيانات عبر HTTPS المشفّر حصرًا. تطبيقا أندرويد مقفلان على الاتصال بخادم المنصة وحده (لا يمكن توجيه بياناتهما إلى أي مضيف آخر)، ويتحقق الخادم من الجلسة والموافقة عند كل نقطة موقع يستلمها قبل تخزينها.
التغييرات على هذه السياسة
عند أي تغيير جوهري في هذه السياسة سيُحدَّث تاريخ «آخر تحديث» أعلاه وتُنشر الصيغة الجديدة على هذه الصفحة.
التواصل
لأي استفسار يتعلق بالخصوصية: [PRIVACY-CONTACT-EMAIL]
Privacy Policy — Misnad Platform
Last updated: 28 August 2026
This policy applies to the Misnad platform at misnaad.com and its two Android applications: Misnad Technician (com.misnaad.technician) and Misnad Owner (com.misnaad.owner). It describes — accurately, and matching what the system actually does — what data we collect, why, and how it is handled, in accordance with the Saudi Personal Data Protection Law (PDPL).
Who we are and the roles involved
Misnad is software used by field-service businesses to run their operations. Technician and employee accounts are created and managed by the employing business (the employer) — the business decides the purposes for processing its team’s and customers’ data, while Misnad processes that data to operate the service on the business’s behalf.
Data we collect
- Account identity: name, phone number, and email address, entered by the employing business when it creates the account.
- Precise technician location (with consent): the Misnad Technician app collects the technician’s location and shares it only with their own company, after explicit in-app consent given separately per company. Collection continues for as long as the technician is signed in and their consent stays on — and in the Android app, even when the app is closed or not in use. In the browser version (PWA), collection stops when the page is closed. Withdrawing consent in the app stops collection immediately. The Misnad Owner app collects no location at all (it holds no location permission).
- Push tokens: a Firebase Cloud Messaging device token in the Android apps, and a Web Push subscription in the browser, used to deliver job notifications.
- Diagnostic events: short event names with timestamps (such as “location fix succeeded” or “sync failed”) used to troubleshoot tracking. These events never contain coordinates, and the server rejects anything outside its allow-list of event names.
- Work records entered in the app: job photos, the customer’s completion signature, notes, attendance (shift) records, and the clock-in verification photo.
Purpose of processing
Location data is processed for one purpose: dispatch and field-team coordination for the employing business. A consenting technician’s position appears on the live team map seen by their own company’s operator. Other data is processed to operate the account, document completed work, and deliver notifications.
Legal basis
Location collection is based on explicit consent: no position is stored without the technician’s prior in-app consent, consent is granted per company, and it can be withdrawn at any time inside the app — collection stops immediately, and the server re-verifies consent on every position it receives before storing it. Account data and work records are processed within the employment relationship between the technician and their business, at the business’s direction. The platform claims no certification, registration, or accreditation; its commitment is to operate in line with the PDPL.
Retention
Retention periods for location data are configured by the employing business per tracking source, and records older than the configured period are deleted automatically by a daily purge. Location data whose configured source has been removed is automatically deleted after at most 30 days. The purge keeps running even if the tracking feature itself is turned off.
Your rights: access, correction, and deletion
The system includes built-in tools to export a copy of the personal data linked to your account (including the location trail, geofence events, notification records, and workforce records) and to erase it completely on a data subject’s request. To make an access, correction, or deletion request, contact [PRIVACY-CONTACT-EMAIL], or your employing business as the controller of its team’s data.
Sharing
We do not sell personal data and do not share it with any third party for that party’s own purposes. Sharing is limited to service providers that process data to run the platform:
- Google Firebase Cloud Messaging — to deliver notifications to the Android apps.
- Browser push services (Google, Mozilla, Microsoft) — to deliver web notifications; the notification content sent through them is encrypted so the push service cannot read it.
- The email delivery service configured for the platform — to send notification emails.
- An address geocoding service — the service-site address text (address only; no name or phone) is sent to a geocoding service to place the job on the map. The default is OpenStreetMap Nominatim, configurable in platform settings.
- The hosting provider the platform runs on.
In addition, the employing business may itself connect optional integrations using its own credentials — such as a WhatsApp Business (Meta) account or messaging gateway, an AI provider, or a vehicle-tracking / routing service. These operate only if the business enables them, and their processing is governed by the business’s own agreements with those providers.
Data security
Data travels exclusively over encrypted HTTPS. Both Android apps are pinned to communicate only with the platform’s own server (their data cannot be redirected to any other host), and the server verifies the session and consent on every position it receives before storing it.
Changes to this policy
Any material change to this policy will update the “Last updated” date above, and the new version will be published on this page.
Contact
For any privacy inquiry: [PRIVACY-CONTACT-EMAIL]