1. Who we are
MabrookTrack is operated by VM MEDIA LLC (في إم ميديا ذ م م), a limited liability company licensed by Sharjah Media City (SHAMS), UAE. Licence 2322072.01; Formation 2322072. Registered address: Sharjah Media City, Sharjah, United Arab Emirates.
Contact: privacy@mabrooktrack.com, hello@mabrooktrack.com, +971 58 543 9796.
We control data used for our website, enquiries, accounts, support, billing, security and contract records. For a brand's store tracking, we process shopper data on the brand's instructions under our Data Processing Addendum. The brand controls that processing. Agency services have separate terms; agency staff using MabrookTrack remain restricted to the relevant brand's instructions and workspace.
This notice covers mabrooktrack.com and app.mabrooktrack.com. It explains our practices; reading it does not give consent.
2. What we collect
| Activity | Data and source |
|---|---|
| Enquiries and demos | Details you provide: name, work email, store URL, platform, message, language and email-marketing choice. Ad-spend range and WhatsApp number are optional. Resend delivers submissions to our team's mailbox, not our tracking database. We use a supplied WhatsApp number only to arrange the demo. Required form fields are marked; without the necessary contact details we cannot respond. |
| Accounts, support and billing | Business and user details, registration/licence number, login information, invoices, payment records, emails, messages and call notes. We do not receive full payment-card numbers. |
| Contract evidence | Accepted documents and versions, signer's name and role, account email, acceptance time, IP address, browser and document hash. |
| Our website | Hosting requests, IP address, browser/device, referrer and pages visited. Advertising-pixel data is collected only after cookie consent. |
| Brands' stores | Through store integrations and tracking: contact identifiers, advertising click IDs, random visitor/session IDs, consent signals, IP address, user agent, sanitised URLs/referrers, campaign parameters, and order/event details including products, amounts, currency, payment method, shipping, tax, refunds and cancellations. |
Please do not send shopper records, passwords or sensitive information through our enquiry form. Our website and dashboard are for business users, not children. Brands must not submit children's or sensitive personal data; stores presenting those risks need agreed exclusion controls before onboarding.
3. Why we use our own records
We apply the UAE Personal Data Protection Law and, where applicable, Saudi Arabia's Personal Data Protection Law and implementing rules.
| Purpose | UAE basis | Saudi basis |
|---|---|---|
| Answer enquiries and arrange demos | Steps requested by an individual who will personally be party to the contract; otherwise informed consent or a specific applicable legal exception | Legitimate interest in responding to requested business enquiries, subject to the required assessment |
| Provide accounts, support and billing | Contract where the individual is a party; for other users or business contacts, informed consent unless a specific legal exception applies | Agreement with the individual where applicable; otherwise assessed legitimate interest in administering business accounts |
| Keep agreements, invoices and accounting records | Applicable legal obligations and establishing or defending legal claims | Applicable legal obligations and assessed legitimate interest in agreement evidence |
| Protect and monitor the service | Applicable security obligations; consent where required for other processing | Applicable legal obligations and assessed legitimate interests |
| Website advertising and promotional emails | Consent | Consent |
Where we rely on consent, we explain the purpose when requesting it and record your choice. You may withdraw through Cookie settings, an email unsubscribe link or our privacy contact. Withdrawal does not invalidate earlier lawful processing; withdrawing consent needed for an account may prevent us from continuing that account. Contacting us or accepting service terms does not by itself give consent for unrelated uses. Saudi legitimate-interest processing excludes sensitive data and is subject to the required balancing assessment.
We do not sell personal data, use shopper data for our own advertising or other customers, or train models on it. We do not make solely automated decisions with legal or similarly significant effects.
4. How store tracking works
Raw contact identifiers reach our Cloudflare edge servers transiently. Matching records in the tracking database use customer-specific keyed hashes; advertising-compatible hashes are kept separately and encrypted for the period below. These are personal data, not anonymous data. Account and enquiry records contain readable contact details.
We filter URL parameters, redact apparent email/phone values and remove personal contact details from stored webhook logs. We use encryption, restricted access, workspace isolation, administrative MFA and internal security reviews. Detailed controls are in DPA Annex B; no independent certification or penetration test is claimed.
In consent-required mode, advertising identifiers, identity matching and advertising delivery remain disabled until the brand supplies permission. Withdrawal stops future delivery and removes our browser identifiers. The mode is the default for workspaces created from 19 September 2026; older workspaces retain their setting pending review. Brands are responsible for notices, lawful settings and their consent integration. Data already sent to advertising platforms is handled under those platforms' terms.
5. Recipients and international processing
Our provider and recipient list (available to customers in the MabrookTrack app, and on request from privacy@mabrooktrack.com) identifies Cloudflare (global edge and queues), Supabase (database and backups in Mumbai, India), Vercel (hosting; Mumbai functions and global edge, US company), Resend (email, USA) and Anthropic (optional AI, USA), including the data each processes. It also explains brands' optional TikTok, Meta, Snap and Google deliveries. Those advertising platforms' roles depend on their products and agreements; they are not our subprocessors merely because we deliver to them.
For our own enquiries, accounts and communications, Cloudflare, Vercel, Supabase and Resend process the relevant data on our behalf. After you accept, TikTok receives cookies, IP address, browser details, visited pages and a demo-submission event to measure our own advertising. Its processing and international locations are described in its applicable privacy policy. WhatsApp/Meta handles your number, name and messages if you choose WhatsApp contact. Advertising and messaging providers also process data under their own applicable terms; their roles are not universally those of our processor. We may disclose data to confidential professional advisers or authorities where legally required.
Our team accesses data from the UAE; providers may also allow support access from other countries. The service is not GCC-only. For our own processing and brands' data, we document the applicable UAE transfer route under Articles 22–23 and the Saudi transfer route and safeguards for each relevant transfer. Where used for brand-to-MabrookTrack transfers, the completed SDAIA clauses are governed by DPA Annex D. Contract instructions alone are not transfer safeguards. Contact us for details of the safeguards and available copies.
6. Retention and deletion
We delete or anonymise data when no longer needed, subject to applicable retention duties. These are the normal maximum periods:
| Records | Period |
|---|---|
| Encrypted advertising-hash vault | 7 days after that shopper's latest order-related update; a new order restarts the period, but does not renew consent |
| Queued/failed events | 4 days |
| Raw event IP addresses | 30 days; no persistent IP hash |
| Raw tracking events | 60 days |
| Redacted webhook/delivery logs; cached AI summaries | 90 days |
| Consent-signal logs | 13 months |
| Orders, attribution touchpoints and identity links | Rolling 25 months from record date |
| Enquiries and sales correspondence | 24 months from last contact, unless you become a customer |
| Account and support records | Contract term plus 12 months |
| Invoices and accounting | Applicable statutory period, generally 5–7 years from the relevant tax period's end |
| Executed agreements and acceptance evidence | Contract term plus 7 years, with restricted access |
| Security/administrative audit logs | 12 months |
Anthropic applies its own retention: its standard API policy deletes inputs and outputs within 30 days, subject to contract-specific arrangements and legal or safety exceptions; flagged content may be kept up to two years and safety-classification scores up to seven years (see Anthropic's policy).
After a brand's contract ends, it may request an export within 14 days; we deliver it within 7 days of the request. Its personal data is deleted from live systems within 30 days of termination. Backups expire within 30 days of live deletion, are used only for recovery, and previously deleted records are deleted again before restored data is used. Revoking an identity key deletes the matching vault and triggers a recorded batch purge of keyed identities; backup expiry still applies.
7. Cookies and similar storage
Accept and Reject have equal prominence. Advertising pixels load only after Accept. Reject, or Global Privacy Control with no recorded choice, keeps them off. We ask again after 180 days. You can change your choice through Cookie settings; withdrawal removes accessible pixel cookies. We cannot directly remove a platform's own-domain cookies or data already delivered to it.
| Storage | Purpose and duration |
|---|---|
mbt_consent | Necessary record of your choice; cookie and local storage, 180 days |
mb_lang | Language preference; local storage until cleared, set when you choose a language |
_ttp, _tt_enable_cookie, ttcsid, ttcsid_* | TikTok advertising measurement; cookies up to 13 months, only after Accept |
The dashboard uses only storage needed for sign-in and interface preferences.
8. Your rights and updates
Subject to applicable law, you can request information, access and a copy, correction, deletion, portability, restriction or objection, and withdraw consent. Email privacy@mabrooktrack.com. We verify identity proportionately, do not request identity documents by default, and respond within applicable legal deadlines. You may complain to the UAE Data Office or SDAIA in Saudi Arabia, as applicable.
For store purchases, contact the brand first. We forward requests received directly within two business days and assist the brand with linked records and platform-delivery details.
For a breach involving brand data, we notify the brand as soon as aware and within 24 hours at the latest, without extending any shorter legal deadline. For our own data, we notify authorities and individuals where and when the law requires.
We publish dated updates and give additional notice where required. New consent-dependent uses begin only after obtaining the necessary consent. Previous notices remain available through our privacy contact.