Privacy Policy
How the tmra.io marketing website collects, uses and protects your personal data.
Legal draft: pending review
This Privacy Policy is an operational first draft prepared for Tmra. It has not yet been reviewed or approved by qualified legal counsel, and must not be relied upon as legal advice, treated as final, or published without that review.
1. About this Policy
This Privacy Policy explains how Misraj Information Technology Company, the company that develops and operates the Tmra platform ("Misraj", "we", "us", "our"), collects, uses, and protects personal data through the tmra.io marketing website (the "Site").
2. Scope: this Policy covers the marketing website only
This Policy covers only the tmra.io marketing website, the pages that describe Tmra's products and let visitors get in touch or request a demonstration. It does not cover, and should not be read as describing, app.tmra.io, Tmra's separate fundraising platform, which processes donations, payment details, and donor data under its own, separate privacy policy. If you are a donor or an organization using the platform, that separate policy, not this one, governs how your data is handled there.
3. What we collect, and why
The Site collects personal data only when you choose to submit the contact form or the demo-request form. We collect:
- Name (required)
- Email address (required)
- Phone number (optional)
- Organization name (optional)
- Your message (optional)
- The language you were browsing in
We use this information solely to respond to your enquiry, follow up about a demonstration, or otherwise communicate with you about Tmra's products, the purpose you submitted the form for. We do not use it for advertising, and we do not sell it.
4. Lawful basis for processing
We process the information you submit through these forms on the basis of your consent, given by voluntarily submitting the form, and our legitimate interest in responding to enquiries from prospective users of Tmra's products. [TMRA TO COMPLETE: confirm the specific lawful basis or bases relied on under the PDPL and, if applicable, the GDPR, with legal counsel. This section describes current practice, not a formal legal determination.]
5. IP addresses and rate limiting
When you submit a form, the Site's server briefly reads the IP address associated with your request (from the cf-connecting-ip or x-forwarded-for header) for one purpose only: to apply a short-lived rate limit that prevents abuse of the form, for example automated spam submissions. This is a form of processing personal data, even though it is limited and short-lived, so we describe it here.
The IP address is held only in the memory of the specific server process handling your request, for the duration of a rate-limiting time window measured in seconds. It is never written to our database, never stored alongside your name, email, or message, and does not persist once that server process ends.
6. Where your information goes
Submitted form data is stored in a database (Cloudflare D1) managed through our content management system, and is then automatically forwarded to Nova Star (api.novasyc.com), a third-party automation service we use to route and act on new enquiries. Whether that forwarding succeeded or failed is recorded against your submission so our team can follow up manually if needed.
We rely on the following processors and infrastructure providers to operate the Site:
- Cloudflare: hosting (Workers), database (D1), and file storage (R2) for the Site and its content management system
- Nova Star (api.novasyc.com): receives submitted form data to route it into our lead-handling workflow
Data processing agreements are in place with both Cloudflare and Nova Star. Any further processors added after this Policy is drafted will be listed here.
7. No tracking, no analytics, no cookies of our own
Unlike most marketing websites, the Site does not use Google Analytics, Google Tag Manager, the Meta/Facebook Pixel, PostHog, Plausible, Hotjar, Segment, Mixpanel, or any comparable analytics or advertising tool. It does not set any cookies of its own for visitors, and it does not use tracking pixels or fingerprinting.
The only cookie associated with the Site is an authentication cookie set by our content management system (Payload) for administrators who log in to manage Site content at /admin. That cookie is for our staff only. It is never set for, or related to, an ordinary visitor browsing the Site.
Fonts used on the Site are self-hosted. The Site does not make requests to Google Fonts or other third-party font services, so no browsing data is shared with a font provider.
8. Third-party links
The Site links out to Tmra's profiles on X/Twitter, LinkedIn, and Instagram. These are plain links you may choose to click. They are not embedded widgets, and no data is shared with those platforms unless and until you click through and interact with them directly, under their own privacy policies.
9. Data retention
Submitted lead data (name, email, phone, organization, message) is retained only for as long as needed to handle your enquiry, and for a limited period afterwards in case you need to follow up. You may request deletion of your data at any time by contacting us at hello@misraj.sa, and we will delete it unless we are required to keep it for a legitimate business or legal reason.
10. Your rights
Depending on where you are located, you may have rights over the personal data we hold about you. Under Saudi Arabia's Personal Data Protection Law (PDPL), individuals generally have rights to access their data, request correction, request deletion, object to processing, and request data portability. If the EU General Data Protection Regulation (GDPR) applies to you as a visitor located in the European Economic Area, you have similar rights, including the right to restrict processing and the right to lodge a complaint with a supervisory authority.
To exercise any of these rights, contact us at hello@misraj.sa. [TMRA TO COMPLETE: confirm the process and timeline for responding to these requests, and designate a privacy contact or Data Protection Officer if one is formally required under the regimes that apply to us.]
11. International data transfers
Cloudflare operates a global network, so the infrastructure that stores and processes Site data may be located in, or route through, countries other than the one you are browsing from. [TMRA TO COMPLETE: confirm which specific countries or regions are relevant, and what transfer safeguards, such as standard contractual clauses, apply, with legal counsel.]
12. Children's data
The Site is not directed at children, and we do not knowingly collect personal data from children through the contact or demo-request forms. If you believe a child has submitted personal data to us, please contact hello@misraj.sa so we can remove it.
13. Security
We rely on Cloudflare's infrastructure and take reasonable technical and organizational measures to protect the personal data submitted through the Site. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
14. Changes to this Policy
We may update this Policy from time to time, for example to reflect changes to the Site or to legal requirements. The version published on this page is the current one, and the "last updated" date below indicates when it last changed.
15. Contact
Questions about this Policy, or requests relating to your personal data, can be sent to hello@misraj.sa, or by post to our registered address in Al Khobar, Saudi Arabia.
Last updated: 31 July 2026.