Privacy Policy
What Warsha collects, why it collects it, who can see it, how long it is kept, and what you can do about all of that.
العربية1. Scope
This policy covers the Warsha application and platform, for customers and for workers. It is the document that governs; where any other Warsha text describes data handling, this one prevails.
It describes what Warsha does today. Where a capability has been approved but is not yet in use, this policy says so explicitly and names the version that would introduce it. Warsha does not describe processing it does not perform.
2. What Warsha collects
Account and identity. Your name, phone number, and email address if you provide one. Workers additionally provide National ID images, the identity fields printed on them, and an official criminal-record certificate.
Location. The addresses you save, and the map pin you confirm for each. A pin is required before a real booking because an approximate address sends someone to the wrong building. Device location is optional; you can always place the pin by hand, and Warsha never collects location in the background or while the application is closed.
Bookings and work. What you booked, from whom, when, for how much, what happened, and the messages exchanged about it.
Payments. Amounts, methods, ledger entries, payouts and refunds. Warsha does not store your full card number.
Reviews and reports. Ratings and reviews you write or receive, and any report you make or that is made about you.
Support. Your conversations with support, and the case record.
Device and diagnostics. Application version, platform, and crash reports if you have not turned them off. These contain no message content and no addresses.
3. Why Warsha collects it, and on what basis
To provide the service you asked for: your account, your bookings, your messages, your payments. Without this there is no product.
To keep people safe: verifying workers before they enter a home, investigating reports, detecting fraud, and enforcing the Trust and Safety Policy.
To meet obligations: keeping the financial and dispute records that operating a marketplace requires, and responding to lawful requests.
With your consent, and only where you have given it: optional marketing messages, referral notifications, diagnostics and device location. Each is a separate choice in the privacy centre, each is off until you turn it on, and turning one off does not turn off anything else.
A note on lawful basis. Egyptian data protection law and its executive regulations continue to develop. This policy describes Warsha's actual purposes honestly rather than asserting a legal characterisation that has not been settled by advice. The Data Processing Register records the basis proposed for each activity and marks it as pending legal review where it is. Warsha would rather tell you what it does and say that the legal classification is unsettled than tell you a classification and be wrong.
4. Identity documents and criminal-record certificates
This is the most sensitive information Warsha holds, and it is handled differently from everything else.
You obtain your criminal-record certificate yourself from the competent Egyptian authority and upload it. Warsha has no integration with the Ministry of Interior, no access to any government system, and no ability to look your record up. It sees what you upload and nothing else.
Documents are stored in private storage. There is no public link. They are never included in a data export, because a copy of your identity document sitting in your downloads folder is a copy outside anyone's control.
Only staff holding the specific capability to review them can open them. Every access is recorded — who, when, under which capability — and that log is kept whether or not anything was found. Opening a certificate requires a stronger capability than opening an ID, and re-authentication.
Offence detail from a certificate is never stored alongside your account record. It exists only in a separate reviewer assessment that no client application can read and that is never returned to any device.
No machine decides anything here. Text extraction helps you fill in a form; the OCR Usage Policy explains it in full. No automated system determines whether a document is genuine, whether an identity is yours, or whether a record makes you eligible to work. Those are human decisions, and an adverse one always requires a person to confirm it.
Your documents are not used to train machine-learning models. See the AI Usage Policy for the governance that would have to be completed before that could ever change, and for the consent that would be required.
5. Who can see what
Other users. A customer sees a worker's profile, trades, area, ratings and reviews. A worker sees the customer's first name, the booking, and the address detail needed to reach them — released at the point in the booking where they need it, not before. Neither sees the other's full contact details outside an active booking.
Warsha staff. Access follows capability, not job title. A support agent handling your case sees your case; they do not see your identity documents. Every staff view of sensitive information is logged and reviewable.
Service providers. Warsha uses a small number of suppliers to run the platform. Every one is listed in the Subprocessor Register with what it processes and where. The register also lists suppliers that have been approved but are not yet in use, marked as such, so you can see what is coming before it arrives.
Nobody else. Warsha does not sell your information, does not share it for advertising, and does not allow third parties to track you across other applications.
Legal requests. Warsha will disclose information where the law requires it. It will tell you when it is permitted to.
6. How long it is kept
The Data Retention Register lists each category with its trigger and period.
Where a period has not yet been settled, the register says so and the item is marked for manual review rather than automatic deletion. Warsha would rather hold something a while longer under review than delete a record it turns out to be required to keep, or claim a statutory period that does not exist.
Booking, payment and dispute records outlive an account, because they concern two people and one of them may still need them.
When you close your account, your personal identifiers are removed or replaced and the records that must survive are anonymised. What that means in practice for each category is in the register.
7. What you can do
From the privacy centre in the application you can:
Warsha will not degrade your experience, hide functionality, or ask you repeatedly to reverse a privacy choice you have made.
- See what is stored about you.
- Correct it.
- Export it, in a machine-readable form. Identity documents and certificates are excluded, and the export tells you so.
- Change any optional consent, at any time, without giving a reason.
- Deactivate your account temporarily.
- Ask for your account to be deleted, with a cooling-off period during which you can change your mind.
- Clear your local history.
8. Security
Access to data is enforced in the database itself, on every table, so that a mistake in an application cannot expose a record the database would refuse to return.
Sensitive documents are in private storage reached only through short-lived links issued to a reviewer with the right capability.
Staff actions on sensitive data are audited.
No system is perfect. If Warsha discovers a breach affecting you it will tell you what happened, what it concerns, and what to do, under the Incident Response Policy. Warsha does not claim to have undergone penetration testing or any security certification, and will not until it has.
9. Children
Warsha is not for anyone under 18. Warsha does not knowingly collect information from children, and will delete it if it learns it has.
10. Changes to this policy
Every version of this policy is numbered, dated and kept. The Version History lists all of them.
A change to what is collected, why, who it is shared with, how long it is kept, whether documents are used for machine learning, or which suppliers process it is a material change: it requires a new version and your acceptance before the affected functionality continues.
Editorial changes do not require you to accept again. They still appear in the Version History.
Adding a subprocessor is always treated as material. You will be told who, for what, and where, before it takes effect.
11. Contact
Privacy requests go through the privacy centre, which routes them to the people who can act on them and records them.
The Legal Contact document lists the routes and the response expectations for privacy, legal and security matters.