Privacy Policy
Effective 29 August 2026
This policy explains how Bawadir collects, uses, and protects your personal data, in line with the Saudi Personal Data Protection Law (Royal Decree No. M/19) and its regulations.
1. Who controls your data
The data controller is Bawadir. For any privacy request or question, contact hello@bawadir.io.
2. What we collect
Your email address; your preferences (language, and the regulators you choose to follow); your optional answer about how you first heard about Bawadir; account and usage data (sign-in events, and basic technical logs needed to run and secure the Service); and website measurement data — page views and a fixed list of interaction counts — described in full in section 4. If you take part in the referral programme, we also record the referral code issued to you or used by you, the resulting link between the referring and the referred account, and the status of any reward — so that we can operate the programme, review rewards before applying them, and enforce its limits. We also record, from the service that delivers our emails, whether a message we sent you could not be delivered at all or was reported as unwanted, so that we stop sending to that address.
We do not collect or store your full payment-card details — card payments are handled directly by our payment processor, Stripe. When you request a sign-in code, sign in, or suggest a regulator, we count the attempts coming from your network address (IP), solely to stop brute-force and abuse. We do not store the address itself: it is converted, as the request arrives, into a scrambled value that cannot be turned back into an address, and only that value is kept. These records are swept automatically every night and never survive more than about two days. They are never used for measurement or profiling.
3. Why we use it, and our legal basis
To provide your account and deliver the digest (basis: performance of our contract with you); to send the email digest and service messages (basis: your consent — withdraw any time via the unsubscribe link or settings); to secure, maintain, and improve the Service (basis: our legitimate interests); to measure how our website is used and which campaigns bring readers to it (basis: our legitimate interests — the measurement described in section 4 is aggregate and identifies no one); to keep our mailing list clean by stopping delivery to addresses that permanently reject our mail or report it as unwanted (basis: our legitimate interests); and to take payment for paid tiers (basis: performance of our contract and compliance with law).
4. Website measurement
What we record. We measure our own traffic, on our own servers. For each page view we record: the page path (the address without its query string); the domain of the site you came from, if any (the domain only, never the full address); the campaign tags carried by the link you clicked (utm_source, utm_medium, utm_campaign, utm_term); your country; a coarse device class (mobile, tablet, desktop, automated crawler, or unknown); the page language; whether the request was signed in or not; the response status; and the moment the request arrived.
What we deliberately do not record. We do not store your IP address in this measurement — in any form, including hashed. We do not store your browser's user-agent string. Your country and device class are derived when the request arrives and the originals are discarded. We set no measurement cookie, and we create no visitor identifier, session identifier, or link to any account. Two visits by one person are indistinguishable from two visits by two people. Pages that belong to your account — confirming a subscription, verifying a sign-in code, your settings, your personalised digest, and the unsubscribe link — are excluded from this measurement entirely.
Interaction counters. Alongside page views we count a short, fixed list of interactions, so that we can tell whether a page is read rather than only opened. This is the complete list: the subscribe card was shown; it was dismissed without subscribing; a subscription was completed through it; the page was scrolled to halfway; the page was scrolled to near its end; the language was switched; a link to another website was followed; a link in the main menu was followed; a link inside a result row was followed; and a search was submitted from one of the filter bars we use for browsing. We record which of these happened and on which page, as counts, carrying the same country, device class, page language and signed-in flag as a page view, plus the moment the interaction was received — and nothing else. We do not record what you typed into the search box, only that a search was submitted. These records carry no campaign tags and no referring domain; those belong to the page-view record alone. The account pages listed above are excluded here too.
We do not follow a visitor from page to page. The interaction counters above are counts, not a trail: there is no visitor identifier and no measurement cookie behind them, so the interactions counted on one page cannot be joined to those counted on any other. The interactions that reach us together are stored in a fixed alphabetical order, not in the order you performed them; where one page view sends more than one batch — because you switched away from the page and came back — we can see that one batch arrived after another, but never beyond that single page view. A deeper measurement that followed a single visitor across pages, and reconstructed the path of their clicks, would need a visitor identifier, and we do not operate one — not in the page-view measurement and not in the interaction counters. If we ever introduce it, it will be optional: we will ask you for that consent separately and in advance, and it will run only for people who agree. Nothing described in this policy depends on it.
When you subscribe. If you subscribe, the campaign details of the visit that brought you here are attached to your subscriber record — the same campaign tags listed above, the referring domain, and, if you arrived from one of our advertisements, that advertisement's click identifier. This is how we know which campaigns are worth running. The click identifier is stored only on your subscriber record and never in the page-view measurement above.
Cloudflare Web Analytics. Alongside our own measurement we use Cloudflare Web Analytics, a service of our hosting provider. It reports page views and page-loading performance. It sets no cookie, does not fingerprint your browser, and does not track you across other websites.
5. Who we share it with
We share the minimum necessary with service providers who process data on our behalf: Stripe (payment processing), Resend (sending emails — confirmation, sign-in codes, the digest — and reporting back to us when a message cannot be delivered or is reported as unwanted), and Cloudflare (hosting, security, and the Cloudflare Web Analytics service described in section 4). We do not sell your personal data.
No one else receives your data. In particular, our pages serve their typefaces from our own servers, so reading Bawadir sends no request to any third party for fonts and no font provider ever sees your IP address.
6. Processing outside the Kingdom
Bawadir runs on infrastructure located outside the Kingdom, and your data is processed there. Our database is hosted by Cloudflare in its Eastern European region. The code that serves each page runs at Cloudflare locations worldwide, including inside the Kingdom, and stores nothing itself. Cloudflare, Stripe and Resend are established in the United States and may process data there and in other countries.
Where we transfer personal data outside the Kingdom, we do so under the conditions of the Personal Data Protection Law and its transfer regulation, and rely on appropriate safeguards (such as data-processing agreements / standard contractual clauses) with each provider.
7. How long we keep it
Account and subscription data: for as long as your account is active, and afterwards only as long as needed for the purposes above or as required by law. Website measurement: individual page-view records are deleted after 90 days. What remains after that is a daily tally — for each day, a count of how many views shared the same page, country, device class, campaign tags, referring domain, signed-in flag and response status. It keeps no timestamp, so it cannot place a visit at a moment in the day; but where a combination was rare, its count may be as low as one, and a count of one describes a single visit. That tally is deleted after 13 months. The interaction counters described in section 4 are kept on exactly the same schedule and swept by the same nightly job: individual interaction records are deleted after 90 days, and what remains is a daily tally — for each day, a count of how many interactions of the same kind shared the same page, page language, country, device class and signed-in flag. It too keeps no timestamp, and the same caveat applies: where a combination was rare, its count may be as low as one. That tally is deleted after 13 months. Abuse-prevention records (section 2): swept nightly, never more than about two days. Records of consent: kept for as long as we may need to demonstrate that our processing was lawful. A record that a message to you could not be delivered or was reported as unwanted is kept with your account record, for as long as your account exists. When no longer needed, data is securely deleted.
8. Security
We use reasonable technical and organizational measures to protect your data, including encrypted connections and access controls. No method is perfectly secure, but we work to protect your information and will notify you and the competent authority of a breach as required by law.
9. Your rights
Under the Personal Data Protection Law you have the right to: be informed of how your data is used; access your data and obtain a copy; request correction, update, or completion; request deletion; and withdraw your consent at any time.
You can withdraw your consent to the email brief yourself and immediately, either from the unsubscribe link at the foot of every digest or from the delivery setting in your account — you do not need to write to us first. We keep a record of when a consent was given and when it was withdrawn, on which surface, and under which version of this policy, so that we can demonstrate the basis for our processing. To exercise any other right, contact hello@bawadir.io; we respond within 30 days.
10. Cookies
We set at most two cookies, and both are essential to a function you asked for. The first is the sign-in session cookie. The second is set only if you arrive through a referral link from an existing subscriber: it stores the short referral code from that link for sixty days, so that the subscriber who referred you can be credited if you subscribe. It contains that code and nothing else — no identifier for you, and nothing about your browsing. If you never open a referral link, it is never set. Your theme choice is a preference your own browser stores locally and never sends to us. We use Cloudflare Turnstile to prevent abuse on our forms, and Cloudflare's edge security may set its own short-lived bot-management cookie. Neither our own measurement nor Cloudflare Web Analytics (section 4) sets a cookie. We do not use advertising or cross-site tracking cookies, and the Service carries no advertising.
11. Children
The Service is intended for professionals and is not directed to anyone under 18.
12. Complaints
If you have a concern, contact us first at hello@bawadir.io. You also have the right to lodge a complaint with the Saudi Data & Artificial Intelligence Authority (SDAIA), the competent authority for personal data protection.
13. Changes
We may update this policy; material changes will be notified by email or on the Service. The date at the top of this page is the version in force, and it is the version recorded against any consent you give while it is in force.