Privacy Policy
Last updated: June 26, 2026
Sheda (“Sheda,” “we,” “us,” “our”) operates a mobile marketplace application that connects guests with independent property owners (“hosts”) for short-term accommodation in Iraq and the Kurdistan Region. This Privacy Policy describes the information we collect, how we use and protect it, the third parties we share it with, your rights over your data, and how to contact us. By creating an account or using the Sheda app, you agree to the practices described here.
1. Information We Collect
1.1 Account Information
When you register, we collect:
- Full name — displayed on your profile and shared with hosts/guests for bookings.
- Email address — used for login and essential transactional communications.
- Phone number — used for account recovery and WhatsApp-based customer support.
- City — used to personalize property recommendations.
- Role — whether you use Sheda as a guest, host, or both.
- Profile photo (optional) — displayed on your public profile.
We authenticate users with email and password only. We do not use Sign in with Apple, Google, or any other third-party social login. Passwords are salted and hashed; we never store or transmit plaintext passwords.
1.2 Identity Verification Documents
To maintain a safe and trusted community, Sheda requires identity verification before a user can book a stay or list a property. We collect:
- A photograph of a government-issued ID (Iraqi national ID card / unified card, passport, or driver’s license).
- A selfie photograph for face-match comparison with the ID.
How verification works
- You upload your ID photo and selfie through the Sheda app.
- An automated analysis service (Google Gemini, provided by Google LLC) compares the documents to confirm the ID appears genuine and the selfie matches the photo on the ID.
- A Sheda administrator performs a final manual review and approves or rejects the verification.
- You receive an in-app notification of the outcome.
How identity documents are stored
- ID photos and selfies are uploaded to a private, access-controlled storage bucket hosted by Supabase (see Section 3). The bucket is not publicly accessible; files cannot be accessed via a public URL.
- Access is restricted to: (a) you (the document owner), (b) authorized Sheda administrators, and (c) the host of a confirmed booking (so they can verify who is staying at their property).
- Documents are permanently deleted when you delete your account.
Purpose and legal basis
Identity verification serves our legitimate interest in fraud prevention, user safety, and compliance with Iraqi regulations governing short-term rental marketplaces. You may decline verification, but you will not be able to book or list properties.
1.3 Property Listings, Location, and Media
- Hosts provide property details (title, description, type, amenities, pricing, check-in/check-out times, maximum guests), photos, videos, a text address, and a map-pin location (latitude and longitude).
- If the host grants permission via the iOS location prompt, we use device location solely to help place the property pin on the map. We do not track location in the background or use it for advertising.
- Photos and videos are stored in a media storage bucket organized per property.
1.4 Bookings and Payments
- We store booking metadata: property ID, check-in and check-out dates, guest count, total amount (in Iraqi Dinar / IQD), booking status, and a unique booking code.
- Payments are processed exclusively by our third-party payment provider, Wayl (Ideas Space for IT, Fintech, Banking, HR Development & General Trade Ltd., registered in Iraq, Reg. No. 18/03/2019 - R.C.A. 2-000009249, also registered in Abu Dhabi Global Market, License No. 21262). Wayl is a PCI DSS Level 1 certified payment processor supporting FIB and FastPay. The payment flow opens Wayl’s secure checkout in a WebView; Sheda never collects, transmits, or stores your card number, bank account, or any payment credentials.
- When you complete a payment through Wayl, your payment data (card details, bank account information) is collected and processed directly by Wayl under their own Privacy Policy and Terms of Service. Wayl encrypts all data in transit and at rest, maintains SOC 2–compliant infrastructure, and retains transaction records for a minimum of 7 years as required by Iraqi financial regulations.
- We retain a record of each transaction on our side: amount, currency (IQD), payment status, Wayl order/reference ID, and timestamp — solely to operate the booking, calculate host payouts and service fees, and comply with Iraqi financial record-keeping requirements. We do not have access to your full card number or bank credentials.
Why payments are not processed through Apple’s In-App Purchase.
Sheda facilitates payment for
physical, real-world accommodation — a place to stay at a specific address in Iraq. This is a real-world service between an independent host and a guest. It is not a purchase of digital goods, digital content, premium app features, subscriptions, or in-app currency. Under
Apple’s App Store Review Guidelines §3.1.3(e), apps may use external payment methods for physical goods and services delivered outside the app. Sheda’s payment model complies with this guideline.
Wayl’s own legal policies apply to your payment data.
When you enter payment details on Wayl’s checkout, you are interacting directly with Wayl’s platform. Wayl’s data handling is governed by their
Privacy Policy and
Terms of Service. Wayl does not sell personal data to third parties for marketing. Wayl shares payment data only with payment processors (QI Card, FIB, ZainCash), as required by law, or in connection with business transfers. For questions about how Wayl handles your payment data, contact Wayl at
privacy@wayl.io.
1.5 Messages and Chat Media
- Text messages exchanged between guests and hosts through the in-app chat.
- Photos and videos shared within chat conversations, stored in a dedicated chat-media storage bucket.
Chat data is associated with a conversation (linked to a property and two participants) and is used solely to facilitate communication between the parties to a booking.
1.6 Device and Technical Data
- Push notification token — if you enable notifications, we store an Expo push token to deliver booking confirmations, payment updates, new messages, and verification status changes. You can disable notifications at any time via iOS Settings.
- Device platform and OS version — stored alongside the push token for delivery routing.
- Device integrity signals — at app launch (in production builds only), we perform a local-only check for jailbreak/root status and hooking frameworks as a fraud deterrent. The result is logged to a
security_events table. This check does not transmit device identifiers or fingerprints to any third party.
1.7 Data We Do NOT Collect
- We do not use advertising identifiers (IDFA) or tracking frameworks.
- We do not use analytics SDKs (Google Analytics, Firebase Analytics, Facebook SDK, etc.).
- We do not track users across other apps or websites.
- We do not collect precise location in the background.
- We do not collect contacts, calendars, health data, or browsing history.
- We do not sell, rent, or trade personal information to any third party for advertising or marketing purposes.
2. How We Use Your Information
| Purpose | Data used |
| Create and manage your account | Name, email, phone, city, role, password hash |
| Verify identity and prevent fraud | ID photo, selfie, device integrity signals |
| Display and manage property listings | Listing details, photos/videos, map coordinates |
| Process bookings and calculate pricing | Booking dates, guest count, property pricing, service fees |
| Facilitate payments and host payouts | Wayl order ID, amount, payment status |
| Enable in-app messaging | Chat messages and media |
| Send push notifications | Expo push token, device platform |
| Provide customer support | Account info, booking history, chat history |
| Comply with legal and financial obligations | Transaction records, audit logs |
| Enforce our Terms of Service | Account activity, admin audit logs |
3. Third-Party Service Providers
We share data with the following providers, strictly to operate the service:
| Provider | Purpose | Data shared | Location |
| Supabase Inc. | Backend database, authentication, file storage, real-time messaging, edge functions | All user data (encrypted at rest and in transit) | United States (AWS infrastructure) |
| Google LLC (Gemini) | Automated identity verification (ID genuineness + face match) | ID photo and selfie (sent per verification request) | United States |
| Wayl (Ideas Space Ltd., Iraq & ADGM) — Privacy · Terms | Payment processing (FIB, FastPay) — PCI DSS Level 1 certified | Booking amount and reference — card/bank details entered on Wayl’s checkout only, processed under Wayl’s own privacy policy | Iraq / UAE (ADGM) |
| Expo (Software Mansion) | Push notification delivery | Expo push token, notification title/body | United States |
| Google Maps Platform | Map tiles and geocoding for property locations | Latitude/longitude of property pins | United States |
Each provider processes data only as needed to deliver its service and is subject to its own privacy policy. We do not share data with advertising networks, data brokers, or any party not listed above.
4. Data Storage and Security
4.1 Where data is stored
All data is hosted on Supabase (PostgreSQL database + S3-compatible object storage on AWS). Identity documents and payment proofs are in private buckets with no public URL access. Chat media is in a separate storage bucket.
4.2 Authentication credentials
On iOS and Android, authentication tokens (session JWT) are stored in the device’s encrypted keychain via expo-secure-store. Tokens are never stored in plain-text storage (e.g., AsyncStorage or UserDefaults). On web, tokens use localStorage (browser-standard storage).
4.3 Access controls
- Row-Level Security (RLS) is enabled on every database table with no exceptions. Each query is evaluated against the authenticated user’s JWT; users can only access rows they are authorized to see.
- Role-based permissions: admin actions (ID review, payout recording, property approval) are restricted to accounts with the
is_admin flag. All admin actions are logged to an admin_audit_log table.
- Server-side price recalculation: booking totals are recalculated in a Supabase Edge Function from property pricing and dates. The app never trusts client-sent amounts.
- Webhook signature verification: Wayl payment webhooks are verified via a shared secret before any booking is confirmed.
- Input sanitization: all user-submitted text (property descriptions, chat messages) is sanitized to strip HTML and script content.
4.4 Encryption
- In transit: all communication between the app and Supabase uses TLS 1.2+.
- At rest: Supabase encrypts database volumes and storage objects at rest using AES-256.
5. Data Retention
- Active accounts: data is retained for as long as your account is active.
- Deleted accounts: when you delete your account (via Profile → Delete account in the app, or by contacting us), all personal data is permanently removed within 24 hours. See our Data Deletion page for details.
- Financial records: anonymized transaction records (amounts and reference IDs without personal identifiers) may be retained as required by Iraqi financial reporting laws and for audit purposes.
- Admin audit logs: retained for security and compliance purposes.
6. Your Rights and Choices
- Access and edit your profile information (name, phone, city, photo) at any time in the app.
- Delete your account and all associated data directly in the app (Profile → Delete account). Your data will be permanently removed within 24 hours. You may also request deletion by contacting us.
- Disable notifications at any time via iOS Settings > Sheda > Notifications.
- Revoke location permission at any time via iOS Settings > Sheda > Location.
- Revoke camera/photo access at any time via iOS Settings > Sheda > Photos / Camera.
- Request a copy of your personal data by contacting us.
- Request correction of inaccurate personal data by contacting us.
7. User-Generated Content and Moderation
Sheda allows users to create property listings, send chat messages, and share photos/videos. To maintain a safe community:
- Users can report any listing, host, or user directly from the app.
- Users can block other users to prevent further communication.
- Reported content is reviewed by our team within 24 hours.
- We reserve the right to remove content and suspend accounts that violate our Terms of Service.
8. iOS Device Permissions
The Sheda app may request the following device permissions. Each is optional and can be revoked at any time in iOS Settings:
| Permission | Purpose | When requested |
| Location (When In Use) | Help hosts pin their property on the map | Only when adding/editing a property location |
| Camera | Take photos for property listings or identity verification | When tapping "Take photo" in media picker or ID verification |
| Photo Library | Select existing photos/videos for listings, chat, or ID verification | When tapping "Choose from library" |
| Notifications | Receive booking, payment, message, and verification alerts | After first login |
9. Age Requirements
Sheda is available to all ages on the App Store, but booking a stay and listing a property requires identity verification, which is only available to users aged 18 and older. Users under 18 may browse properties but cannot create bookings or host. We do not knowingly collect identity documents from minors. If we become aware that a person under 18 has submitted identity verification, we will remove the documents and reset their verification status.
10. International Data Transfers
Your data may be transferred to and processed in the United States (where Supabase, Google, and Expo infrastructure is located) and Iraq (where Wayl operates). By using Sheda, you consent to these transfers. We ensure that all service providers maintain appropriate security measures.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page. Continued use of Sheda after changes constitutes acceptance of the updated policy. We encourage you to review this page periodically.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us:
We aim to respond to all requests within 48 hours.