1.Introduction & Legal Roles
This Privacy Policy outlines how Ya Marhba QR ("Platform", "we", "us") collects, uses, protects, and handles personal data.
Data Controller
Determines event objectives and manages guest lists and contact numbers, bearing legal responsibility for obtaining guest consent.
Data Processor
Processes guest data strictly on behalf of and per instructions of the Host to issue entry passes, deliver invitations, and record check-ins.
2.Personal Data We Collect
We practice data minimization, collecting only information necessary to deliver invitation and digital gate check-in services:
- Host Data: Full name, email address, phone number, organization/family name, and encrypted login credentials.
- Guest Data: Full name, mobile phone number (for WhatsApp/SMS invitation and entry pass delivery), email address (if provided), table assignment, guest allowance count, and RSVP confirmation status.
- Check-in & Gate Data: Timestamp and date of QR scan at the venue, authorized scanner terminal ID, and remaining admission balance.
- Technical Data: IP address, browser type, device details, and security access logs to prevent fraudulent duplicate admissions.
3.Purpose of Processing & Commitment
We process personal data solely for operational fulfillment under contract and consent:
- Generating bespoke digital invitations and cryptographically secured QR passes.
- Dispatching invitations, reminders, and RSVP confirmations via WhatsApp and email.
- Verifying passes in real-time at venue gates to prevent duplicate entry.
- Providing hosts with post-event attendance reports and analytics.
- Zero Monetization Pledge: We never sell, rent, or trade personal guest data to any third party for marketing or commercial advertising.
4.Third-Party Sub-Processors
To maintain high reliability, we partner with industry-leading infrastructure providers:
- Meta Platforms (WhatsApp Cloud API): Dispatches invitations and entry passes via WhatsApp.
- Transactional Email Providers (Resend / AWS SES): Delivers email confirmations and invitations.
- Cloud Infrastructure (Vercel / PostgreSQL): Hosts application logic and encrypted database storage.
5.Security & Encryption
We employ state-of-the-art security measures:
- In-Transit Encryption: All communications are secured using modern TLS 1.3 encryption.
- At-Rest Encryption: Database records are encrypted using AES-256.
- Encrypted QR Passes: QR codes do not expose raw personal records; they utilize cryptographic verification tokens verified securely on our servers.
- Role-Based Access: Gate scanners only see the minimal confirmation necessary to authorize physical entry.
6.Retention & Right to Erasure
We retain event and guest records only for the operational duration required to execute the event and deliver audit reports to the host.
Hosts can request full event deletion at any time. Guests may also request immediate erasure of their contact details and attendance records from our databases.
7.Your Rights Under the PDPL
Under the Saudi Personal Data Protection Law, you enjoy the following rights:
8.Cookies and Local Storage
Ya Marhba QR utilizes strictly necessary cookies and local storage mechanisms to provide and secure our services:
- Essential & Session Cookies: Required to maintain secure host authentication, validate CSRF tokens, and verify digital QR pass signatures.
- Preference Cookies: Storing language preferences (Arabic or English) and banner consent acknowledgements in your local browser storage.
- No Third-Party Ad Tracking: We firmly pledge that we do not deploy third-party advertising cookies or monetize user behavioral data.
Contacting our team:
To exercise your rights or submit a privacy inquiry, please contact our team at:
Email: info@yamarhbaqr.com
Looking for our Terms of Service?
Learn about the platform usage terms and mutual commitments.

