Ehdaa Information Technology Company (شركة إهداء لتقنية المعلومات), Commercial Registration 1009070947, operates Masfot and is responsible for the personal data described in this notice.
This notice covers the Masfot website and mobile apps, whether you browse, create an account, support a creator, buy an offering, or receive earnings. It explains our processing under applicable Saudi personal data protection requirements.
01Data we collect
- Account information you supply: name, handle, email, phone, verification information, credentials or linked sign-in identifiers, preferences, and account-security records. We collect identity or bank verification details when needed for a feature such as withdrawals.
- Content and interactions: avatars, covers, bios, posts, uploaded media, comments, quotes, reposts, reactions, follows, support messages, private conversations, reports, blocks, muted words, and the audience settings you choose.
- Commerce and earnings: product and commission details, membership and renewal records, shipping information where required, payment references and status, currency, Coin purchases and transfers, Diamond entries, withdrawals, refunds, disputes, and supporting evidence.
- Technical information: IP address, browser or app version, device and operating system, language, activity times, logs, page or screen visits, interaction events, and identifiers stored on the device. Security checks may include browser fingerprints and device-integrity signals.
- Correspondence you send us and information from payment, banking, sign-in, verification, delivery, or app-store providers needed to operate the service. Reports from other users may contain information about you.
- A profile photo or bio is optional. Contact details needed for sign-in, payment information for a purchase, and verification or bank details for a withdrawal are required for those functions. If you choose not to provide necessary information, we cannot provide the affected function.
02Why we use data
- Provide accounts, publish content to the selected audience, operate search and recommendations, deliver messages and notifications, and apply privacy and safety controls.
- Process purchases and renewals, provide purchased access, fulfil orders, account for Coins and Diamonds, verify withdrawals, reconcile payments, and handle refunds or disputes.
- Protect users and the platform, investigate abuse, prevent unauthorized payments, assess security signals, and maintain records required for legal obligations or claims.
- Answer requests, correct errors, measure product use and reliability, and improve the service. Marketing messages are subject to applicable consent and opt-out requirements; service and security notices are separate.
03Grounds for processing
- We use the legal ground appropriate to each purpose: implementing our agreement with you to operate your account and transactions; meeting legal obligations for records and lawful authority requests; and legitimate interests, where permitted and balanced against your rights, for security, fraud prevention, and service improvement.
- Where consent is required, we obtain it for the specific purpose and you may withdraw it by contacting us or using the relevant control. Withdrawal does not invalidate earlier lawful processing. Acceptance of the Terms is not blanket consent to every use of personal data.
04Payments and app-store purchases
- Card entry and payment approval are handled through the payment provider’s checkout. We record the transaction information needed to confirm payment and reconcile it, such as provider references, amounts, status, and available limited payment-method details; we do not store full card numbers or security codes entered directly into that checkout.
- For PayPal, we may receive payer identifiers, transaction information, and billing-agreement references needed for approved recurring payments. For Apple or Google Play purchases, we validate store transaction or purchase-token information and receive refund or reversal updates. These providers also process information under their own notices.
- Bank-beneficiary details and verification evidence are used for payout review and transfer processing. Do not send passwords, one-time codes, full card numbers, or card security codes in messages or support emails.
05Identity Verification and Compliance
- We may require a Content Creator to provide information or documents to verify identity, tax information, or bank account, particularly before Diamonds become eligible or a payout is approved, or where reverification is required.
- Necessary information may be processed or shared with verification, payment, banking, tax, or compliance service providers or competent authorities where necessary to comply with applicable requirements, prevent fraud, or verify transactions and payout requests.
06Sharing Personal Data
The Platform does not sell personal data.
Personal data may be shared, to the extent necessary to achieve the purposes specified in this Privacy Policy, with:
- Payment service providers, banks, and entities involved in processing payments and transfers.
- Identity verification, fraud-prevention, tax, and compliance service providers.
- Hosting, infrastructure, storage, and technical service providers.
- Messaging and communications service providers.
- Analytics, cybersecurity, and customer-service providers, where used.
- Professional advisers, auditors, and insurers, where necessary.
- Competent governmental, judicial, regulatory, or tax authorities where disclosure is required or permitted by law.
The Platform is committed to taking appropriate measures to ensure that service providers process personal data in accordance with applicable legal and contractual requirements.
07Processing locations and international transfers
Masfot uses infrastructure and service providers that may process data in Saudi Arabia and other countries. We do not promise Saudi-only storage. Our configured PostHog analytics service uses the European Union region; other hosting, storage, payment, communications, security, or app-store services may involve international processing.
International transfers are subject to applicable Saudi data-transfer requirements, including an appropriate legal basis, permitted transfer mechanism, and safeguards where required. You may contact us for information about the providers and safeguards relevant to your data. A provider’s availability or your acceptance of these Terms does not by itself establish that a transfer is lawful.
08Retention and account deletion
- We retain data for the purpose for which it is needed. Relevant criteria include account activity, delivery of an outstanding service, payment or payout reconciliation, refund and dispute periods, security investigations, statutory record-keeping, and legal claims. Different categories can therefore have different retention periods.
- Account deletion is available in settings but may require outstanding balances, purchases, subscriptions, and withdrawals to be resolved first. Deletion closes access; it does not immediately erase every financial record, support case, backup, or copy held by another recipient.
- When the purpose ends and no legal ground requires retention, personal data must be deleted or anonymized. Retained records remain subject to access restrictions. Contact us about access or destruction of particular data, including when self-service account deletion is blocked.
09Data Security
- The Platform implements appropriate organizational and technical measures to protect personal data against unauthorized access, use, disclosure, alteration, loss, or destruction, taking into account the nature of the data and the level of risk associated with processing.
- The Platform may review and update relevant security measures as necessary and in a manner appropriate to the nature of its services.
10Device storage, analytics, and controls
- We use essential cookies or device storage for sign-in, sessions, security, and preferences such as language and appearance. Blocking necessary storage can prevent these functions from working.
- Where analytics is enabled, PostHog receives usage and interaction events to help us understand the service. Events can include account identifiers, page or screen information, device details, and interaction metadata. An account identifier is pseudonymous, not anonymous; page or interaction information may identify a public profile.
- Our web analytics uses local storage and has session recording disabled. Browser Do Not Track or Global Privacy Control signals do not currently disable this first-party analytics integration. This notice does not imply that a cookie-consent or analytics opt-out switch exists where none is offered.
- You can manage browser storage and available notification or privacy controls. Contact us to exercise a relevant data right or withdraw consent where processing relies on it. Required consent must be obtained before the affected optional processing.
11Your rights and how to request them
Subject to applicable law, you may request information about processing, access to your data, a readable copy, correction or completion, and destruction. You may withdraw consent where it is the processing ground.
Contact the address in this notice with your request. We may verify your identity using proportionate information; do not send identity documents unless requested through an appropriate channel. We respond within 30 days, with any permitted extension explained. If a request is restricted by law or others’ rights, we explain the applicable reason where permitted. You may also complain to the competent Saudi data protection authority through the National Data Governance Platform.
12Personal Data of Other Individuals
Users must not provide the Platform with personal data relating to another individual unless they have a lawful basis to do so and have complied with applicable legal requirements.
13External Links and Services
- The Platform may contain links to or services provided by third parties.
- This Privacy Policy does not govern the personal-data processing practices of third parties acting independently from the Platform.
14Who can see your content
- Published profiles and public posts may be visible to visitors, search engines, and people receiving shared links. Membership or other restricted content is shown according to the applicable access rules. Public media links and copies already shared outside Masfot may remain accessible independently of a later privacy change.
- Creators receive information needed to fulfil purchases and manage support or memberships, including delivery details where needed. Public supporter names, rankings, and social lists follow the available visibility settings; hiding a public name does not make a payment anonymous to Masfot, its processor, or all records needed by the creator.
- Private messages are not public posts and are not end-to-end encrypted. Authorized staff may access relevant content and records for support, moderation, security, disputes, or legal obligations. Access is limited by role and purpose.
- Creators who receive customer data for fulfilment must use it lawfully for the transaction. Enabling a third-party integration or public widget can share the information described by that feature with the service or its audience.
15Age requirements
Masfot accounts and transactions are intended for people aged 18 or older with legal capacity. If you believe a child has provided personal data through an account, contact us so we can investigate and take appropriate action.
16Contact and complaints
For privacy and data-rights requests, email [email protected]. Include the relevant account or transaction reference so we can locate your request. You do not need to finish an internal complaint process before exercising a mandatory legal right.
Registered operator: Ehdaa Information Technology Company, CR 1009070947. National address: Building 2996, Al Wafa Street, additional number 8679, Hittin District, Riyadh 13518, Saudi Arabia. Short address: RRHC2996.
17Version and updates
This version applies when published as the current policy on Masfot. Material changes will be explained with their effective date through the website and, where appropriate, account notices or email. Changes do not remove rights relating to earlier transactions. Where new consent is required, we will request it separately.