1. Introduction
Rizq ("Rizq", "we", "our", or "us") is a charitable donation platform that connects donors, beneficiaries, partner shops, and administrators to facilitate the distribution of assistance.
This Privacy Policy explains how we collect, use, store, share, and protect personal information when you use the Rizq mobile application and related services.
By using Rizq, you agree to the collection and use of information described in this Privacy Policy.
2. Information We Collect
Identity Information
We may collect:
- Full name
- CNIC number
- Date of birth
- Gender
- Phone number
- Account credentials
This information is used to verify identity, prevent fraud, maintain eligibility records, and comply with legal requirements.
Beneficiary Verification Data
For beneficiaries, Rizq may collect and process biometric information in the form of:
- Facial embeddings or facial recognition templates
Rizq does not store biometric information for marketing purposes.
Facial embeddings are used solely for identity verification, fraud prevention, and ensuring that assistance reaches the intended beneficiary.
Location Information
With your permission, Rizq may collect:
- User location
- Shop location
Location data may be used to:
- Display maps and service areas
- Find nearby participating shops
- Verify redemption events
- Prevent fraudulent activity
- Improve service delivery
Location access may be disabled through device settings, although some features may not function properly.
Donation and Transaction Information
We collect information related to:
- Donations
- Redemption activity
- Beneficiary allocations
- Transaction records
- Account balances and points
Payment Information
When processing donations or payments, we may collect:
- Payment details
- Billing information
- Transaction identifiers
Payment information is used solely for processing transactions and preventing fraud.
Device and Technical Information
We may automatically collect:
- Device type
- Operating system
- App version
- IP address
- Device identifiers
- Error logs
- Diagnostic information
3. How We Use Information
We use collected information to:
- Create and manage user accounts
- Verify user identities
- Process donations and redemptions
- Authenticate users using multi-factor authentication (MFA)
- Prevent fraud, abuse, and unauthorized access
- Verify beneficiary eligibility
- Facilitate assistance distribution
- Provide customer support
- Improve and maintain our services
- Generate operational and impact reports
- Comply with legal obligations
4. Legal Basis for Processing
Where applicable, Rizq processes personal information based on:
- User consent
- Contractual necessity
- Legitimate operational interests
- Compliance with legal obligations
5. Sharing of Information
Rizq does not sell personal information.
We may share information with:
Service Providers
Trusted third-party providers that assist with:
- Payment processing
- Cloud hosting
- Authentication services
- Analytics
- Notifications
- Security monitoring
Partner Shops
Limited information necessary to complete authorized redemptions.
Legal Authorities
When required by law or when necessary to protect the rights, security, or safety of Rizq, its users, or the public.
6. Biometric Information
Biometric information, including facial embeddings, is used solely for identity verification and fraud prevention.
Rizq does not:
- Sell biometric information
- Use biometric information for advertising
- Share biometric information except when required by law
Biometric data is protected using industry-standard security measures.
7. Data Security
We implement administrative, technical, and organizational safeguards designed to protect personal information, including:
- Encryption in transit
- Encryption at rest where appropriate
- Role-based access controls
- Audit logging
- Multi-factor authentication
- Security monitoring
Despite these measures, no system can guarantee absolute security.
8. Data Retention
We retain personal information only for as long as necessary to:
- Operate the platform
- Prevent fraud
- Resolve disputes
- Meet legal and regulatory requirements
Information that is no longer required may be deleted, anonymized, or aggregated.
9. User Rights
Subject to applicable law, users may request:
- Access to personal information
- Correction of inaccurate information
- Deletion of information
- Restriction of processing
- Withdrawal of consent where applicable
Requests may be submitted through the contact information below.
10. Children's Privacy
Rizq is not intended for children under the age of 13 and does not knowingly collect personal information from children under 13.
11. International Data Transfers
Your information may be processed and stored in jurisdictions different from your own. Rizq takes reasonable measures to ensure adequate protection of transferred information.
12. Changes to this Privacy Policy
We may update this Privacy Policy periodically. Updated versions will be posted within the application and on our website.
13. Contact Information
For privacy-related inquiries, please contact us through the appropriate channels available on the Rizq platform.