Privacy Policy
This policy explains what the Gareeb and Gareeb Captin apps collect, why, where it is stored, who it is shared with, and how you can control it.
Last updated:
In short
If you read nothing else, read this:
- Your phone number is your account. Gareeb cannot be used without one.
- We run no tracking, no analytics and no advertising. Neither app contains a single library for measuring your behaviour or serving ads, and we do not read your device advertising ID.
- We do not sell your data, and we do not share it with anyone for marketing.
- Location permission is optional and read only on demand. Nothing runs in the background to follow you — we have not even asked for the background location permission.
- We do not track a captain’s route. We keep only the last known position, and each reading replaces the one before it.
- A captain’s national number is encrypted in the database. It is never stored as readable text.
- Passwords, verification codes and session tokens are never stored in their original form — only as a cryptographic hash.
Who we are
Gareeb is a Sudanese delivery platform connecting customers, restaurants and captains. We are responsible for the data collected through the Gareeb customer app, the Gareeb Captin app and the gareeb.net website.
To reach us about anything in this policy: WhatsApp +249 111 162 062 or email gareebsd.net@gmail.com.
What this policy covers
Our two Android apps and this website:
- Gareeb (customer app)
- com.gareeb.customer on Google Play. Android only — there is no iOS build.
- Gareeb Captin
- com.gareeb.captain on Google Play. Android only.
- gareeb.net
- A static brochure site. It sets no cookies, carries no tracking script, and asks you for nothing: every contact link on it opens WhatsApp or your email app directly.
What the customer app collects
- Phone number
- Required. It identifies your account, it is where the verification code goes, and it is how a restaurant or captain reaches you when something about your order needs asking.
- Name and email
- Your name is shown to the restaurant and the captain with your order. Email is entirely optional — an account works without one.
- Preferred language
- Arabic or English, so notifications arrive in the language you read.
- Delivery addresses
- Region, city and district, a nearby landmark, and the street, building number, floor and apartment if you enter them; the coordinates of the pin you place on the map; delivery notes; and a contact number for handover. This is the data that makes an order arrivable.
- Orders
- The items and options you chose and any notes on them, prices and delivery fee, payment method, the order status and the time of every change to it, the restaurant and branch, and the assigned captain.
- Favourites
- The restaurants you add to your list.
- Payment proof
- When paying by bank transfer (Bankak) you upload a picture of the transfer receipt. It is read automatically on our own servers to match the amount and reference against your order, then kept as the record of that transaction. The image is never sent to any outside service.
- Device data
- A push notification token, the platform, the app version, the device model, and a random identifier generated when you install the app. That identifier is not your device’s hardware id and not an advertising id — it is a number with no meaning outside our app, and it disappears when you uninstall.
- Security data
- The IP address and client type when a verification code is requested or a session is created. We keep these to limit abuse and automated attempts, not to work out where you are.
What the captain app collects
The captain app collects the same account data listed above (phone number, name, language, device and security data), and in addition:
- Working area
- The region, city and district you work in, so nearby orders reach you.
- National number
- Required to verify your identity before your account is approved, because a captain handles customers’ orders and customers’ money. It is stored AES-GCM encrypted in the database and is visible only to the review team when needed. It is never shown to customers or restaurants.
- Account status
- Pending review, approved, rejected or suspended, and the reason for a rejection or suspension.
- Availability
- Whether you are currently available to take orders.
- Last known position
- One point (latitude and longitude) with the time it was read. It is read when you toggle availability, so dispatch can rank captains by how close they are to the restaurant. The next reading replaces it; it is not kept as a movement log.
- Trips and earnings
- The orders assigned to you and the timing of each step, your fee per trip, and your settlement history with any documents you upload alongside it.
Your name and phone number are shown to the customer you are delivering to, and theirs — with the address — are shown to you. That exchange is what makes a handover possible, and it is limited to the order in progress.
App permissions, and why we ask
These are every permission the two apps request. There are no others:
- Internet and network state
- To reach our servers and to know whether the device is online. Both are granted automatically and the app cannot function without them.
- Location (precise and approximate) — optional
- In the customer app: when you tap “use my current location” on the address screen, to place the map pin instead of making you drag it. In the captain app: when you toggle availability, to attach your position so nearby orders can reach you. Both apps work fully if you decline — you simply place the pin yourself, and ranking captains by distance is not possible. We do not request background location permission, and neither app contains any background service that reads location.
- Notifications
- To tell you your order status changed, and to alert a captain to a new delivery offer. You can decline it, or turn it off in system settings at any time, and the rest of the app keeps working.
- Permissions added by the notification service
- Google’s notification component (Firebase Cloud Messaging) adds technical permissions to the app: waking the device, running after a restart, running a foreground service, and receiving notification messages. They exist so a notification can reach your device, and are not used to read anything from you.
Choosing a payment-proof picture goes through the Android system photo picker. That is why the app asks for no camera permission and no access to your files or gallery: the system hands us the one image you picked, and nothing else.
To fill the verification code in automatically we use Google’s SMS User Consent service, which asks your permission for one specific message each time. That is why the app asks for no SMS-reading permission and cannot reach any other message on your phone. You can always dismiss the prompt and type the code yourself.
What we do not collect
A list of what an app cannot do is clearer than any general promise. Neither app requests these, and neither can reach them:
- Contacts. We do not read your address book and we do not invite anyone on your behalf.
- Camera or microphone.
- Your gallery or device files. The single exception is the one image you choose as payment proof.
- Text messages. We do not request SMS read permission.
- Call log, IMEI, or network and carrier identifiers.
- Advertising ID.
- Background location, or any tracking while the app is not in use.
- Any analytics about the screens you open or what you tap. Neither app contains an analytics tool.
- Card details. We do not accept card payment and never receive card data at all.
Neither app backs its data up to your Google account either — Android auto-backup is disabled in both.
Why we use this data
- To create your account and confirm the number is yours.
- To carry out your order: getting it to the restaurant, assigning a captain, and directing them to your address.
- To tell you your order status.
- To settle amounts with restaurants and captains, and to keep the record of the transaction.
- To verify a captain’s identity before approving their account.
- To answer a complaint or a question, which means looking at the record of the order concerned.
- To protect the service from abuse: repeated code requests, fake orders, automated sign-in attempts.
- To meet a legal obligation or respond to a lawful official request.
We do not use your data for anything else, and we do not send you marketing you did not ask for.
Location data in detail
Location is the most sensitive data a delivery app touches, so it gets a section rather than a line in a table.
- Neither app contains anything that reads location continuously. A reading happens at one moment, in response to something you did: tapping “use my current location”, or toggling availability.
- What we read is the last position Android already knows, not a fresh GPS fix. That is less precise, but it is faster, it does not drain your battery, and it is accurate enough for the purpose.
- We never requested background location permission, so the app could not read your position while closed even if it wanted to.
- The coordinates of the pin you place are saved with the address because they are part of it: without them a captain does not know where to go.
- A captain’s position is stored in a single row that is overwritten each time. There is no location-history table in our database, and no route can be reconstructed from our data.
- Customers do not see a captain’s position on a map, and we offer no live order tracking. That feature does not exist in the service today.
How we protect your data
- All traffic between the apps and our servers is HTTPS. Unencrypted traffic is blocked at the Android platform level in both apps, not by a setting that could be worked around.
- Session tokens on your device are held in encrypted storage whose key lives in the Android Keystore, not in an ordinary preferences file.
- Passwords, verification codes and refresh tokens are never stored in our database in their original form — only as a hash that cannot be reversed.
- A captain’s national number is AES-GCM encrypted in the database under a separate key. If that key is missing the system refuses to start rather than storing the number as readable text.
- Access to production data is limited to the operations staff who need it.
- We take regular database backups so your data is not lost.
No protection is absolute. If a breach affects your personal data, we will tell you what we know and what you should do — without alarm, and without playing it down.
Where your data is stored
Gareeb’s servers currently run on a private server in France, inside the European Union. That means your data is stored and processed outside Sudan.
We chose that because hosting with the reliability and connectivity a round-the-clock service needs is not available locally at that standard. We state it plainly because you deserve to know where your data actually sits rather than assume it is in Sudan. If we move, we will update this section.
How long we keep it
- Account data
- Kept as long as your account exists.
- Order and financial records
- Kept as a business record after an order completes, because an order is a transaction between three parties that may need reviewing or disputing later.
- Verification codes
- Expire within minutes, and are only ever stored as a hash in the meantime.
- Sessions and device registrations
- Revoked when you sign out. The device registration that receives notifications is deleted from our servers on sign-out.
- A captain’s last known position
- Never accumulated or archived; each reading replaces the previous one.
Your rights, and how to use them
You can ask to see your data, to correct it, or to delete your account and whatever of its data can be deleted.
What you can already do yourself in the app: change your name, email and language; add, edit and delete your addresses; change your phone number; and sign out — which deletes the device registration that receives notifications.
What needs a request: deleting your account. There is no in-app delete button yet, and we would rather say so than point at a feature that does not exist. Send the request by WhatsApp on +249 111 162 062 or by email to gareebsd.net@gmail.com from the number or address on the account, and we will carry it out and confirm it to you. We are working on putting this in the app.
After deletion we may keep the minimum order and financial records required as a business record, with whatever personal data can be stripped from them removed.
Children
Gareeb is for adults. We do not knowingly collect data from anyone under 18. If we learn an account belongs to a child, we delete it and its data.
Changes to this policy
We may update this policy when the service changes — for example when a new feature needs new data. The last-updated date is at the top of this page, and if a change is significant we will tell you in the app before it takes effect.
Contact us
For any question, complaint or request about your data: WhatsApp +249 111 162 062, or email gareebsd.net@gmail.com. We reply as soon as we can during working hours.