سياسة الخصوصية

تطبيق قيم — QAYEM POS · نظام نقاط البيع والمحاسبة

العربية English

آخر تحديث: 30 يوليو 2026

نحن في تطبيق قيم (QAYEM POS) نحترم خصوصيتك ونلتزم بحمايتها. توضّح هذه السياسة أنواع المعلومات التي يتعامل معها التطبيق وكيفية استخدامها. باستخدامك للتطبيق فإنك توافق على ما ورد في هذه السياسة.

1. طبيعة التطبيق — نسختان بسلوك مختلف

يصدر «قيم» في نسختين، وتعامُل البيانات مختلف بينهما اختلافًا جوهريًا:

  • النسخة الأوفلاين (بترخيص جهاز): تعمل بدون اتصال دائم. بيانات عملك — المنتجات والفواتير والعملاء والموردون والمخزون والتقارير — تُخزَّن في قاعدة بيانات على جهازك، ولا تُرفَع تفاصيلها إلى خوادمنا، فيما عدا ملخّص يومي مجمّع موضّح في البند 2، وأي نسخة احتياطية ترفعها أنت بنفسك — أو تُرفَع تلقائيًا إلى حساب Google Drive الخاص بك كل فترة تحدّدها، وذلك فقط بعد أن تُفعّل تلك الميزة بنفسك (متوقفة افتراضيًا).
  • النسخة السحابية (باشتراك وحساب): غرضها الأساسي هو المزامنة بين أكثر من جهاز أو فرع. ولذلك تُرفَع سجلات بيانات عملك وتُخزَّن على خوادمنا حتى تصل لباقي أجهزتك. هذه ليست ميزة جانبية بل هي جوهر النسخة السحابية.

2. البيانات التي نتعامل معها

النسخةالبياناتالغرضأين تُخزَّن
الأوفلاين بيانات العمل الكاملة (منتجات، فواتير، عملاء، موردون، مخزون…) تشغيل التطبيق على جهازك فقط
الأوفلاين ملخّص يومي مجمّع (آخر 30 يومًا): إجمالي وعدد فواتير البيع والمرتجعات والمصروفات لكل يوم، عدد العملاء وعدد الأصناف، وأسماء أكثر 20 صنفًا مبيعًا وكمياتها وقيمتها. بدون أسماء عملائك أو أرقامهم أو تفاصيل الفواتير أو التكاليف (وتُنقّى أسماء الأصناف قبل الإرسال من أي سلاسل أرقام طويلة قد تكون رقم هاتف). متابعة تشغيل الاشتراك، الدعم الفني، وتحسين الخدمة خوادمنا (Cloudflare) — يُرسَل تلقائيًا كل ٦ ساعات. يمكنك إيقافه من داخل التطبيق: الإعدادات ← سياسة الاستخدام والخصوصية ← «مشاركة الملخّص المجمّع»
السحابية كل سجلات بيانات عملك: المنتجات والفواتير وبنودها والمدفوعات والمشتريات والمخزون والخزائن والمخازن، وبيانات عملائك ومورّديك (الاسم والهاتف والبريد والعنوان والرقم الضريبي والرصيد، وإحداثيات موقع محل العميل (GPS) إن أضفتها بنفسك — اختيارية تمامًا ولا تُسجَّل إلا بإجراء مباشر منك)، وبيانات موظفيك (الاسم والوظيفة والهاتف والرقم القومي إن أدخلته والراتب والحضور والمرتبات)، وسجل التدقيق والورديات.
⚠️ صورة محل العميل لا تُرفَع إلى خوادمنا إطلاقًا: الصورة تبقى ملفًا على الجهاز الذي التقطها، والذي يُزامَن هو مسار الملف فقط — لذلك يظهر العميل على جهاز آخر بنفس المسار بدون الصورة.
مزامنة بياناتك بين أجهزة حسابك خوادمنا (Cloudflare D1) — الإحداثيات فقط؛ صورة المحل تبقى على الجهاز ولا تُرفَع
السحابية حسابات دخول موظفيك: اسم المستخدم والاسم والدور والصلاحيات، وكلمة المرور مخزَّنة بصيغة مُجزَّأة (hash) لا يمكن استرجاعها كنص تسجيل الدخول وإدارة الصلاحيات خوادمنا
النسختان معرّف الجهاز، إصدار التطبيق، نظام التشغيل، آخر عنوان IP، وقت آخر ظهور، وإشارات تقنية عن سلامة التثبيت (هل الجهاز محاكٍ، ومصدر تثبيت التطبيق). وفي النسخة الأوفلاين يُرسَل مع نبضة التحقق أيضًا توكن الترخيص الموقَّع المحفوظ على جهازك، ليُثبِت الجهاز ملكيّته للترخيص قبل أن يردّ الخادم بأي بيانات التفعيل، حد عدد الأجهزة، ومنع إساءة استخدام الترخيص والقرصنة خوادمنا
اختياري نسخة احتياطية مشفَّرة من قاعدة بياناتك استعادة بياناتك عند تغيير الجهاز أو فقدانه خوادمنا (Cloudflare R2) عند رفعك لها يدويًا، و/أو حساب Google Drive الخاص بك (رفع تلقائي متكرر بعد تفعيلك للميزة — متوقفة افتراضيًا، ويمكنك إيقافها في أي وقت)
اختياري تذاكر الدعم الفني: اسمك وهاتفك/بريدك ونص المشكلة وصورة مرفقة إن أرسلتها الرد على طلب الدعم خوادمنا
تطبيقات
أندرويد
معرّف الإعلان (Advertising ID / GAID) وبيانات جهاز تقنية (الطراز ونظام التشغيل ولغة الجهاز) وأحداث التطبيق (التثبيت، فتح التطبيق، الجلسات، تفعيل الاشتراك وقيمته). هذا معرّف إعلاني قابل للربط عبر التطبيقات وليس بيانات مجهّلة. لا تُرسَل أي من بيانات عملك أو بيانات عملائك إلى Meta. قياس أداء الحملات الإعلانية وإسناد عمليات التثبيت Meta (Facebook)

3. خدمات الطرف الثالث ومعالِجو البيانات

  • Cloudflare: استضافة خوادمنا وتخزين بيانات المزامنة والنسخ الاحتياطية (Workers / D1 / R2). شبكة Cloudflare موزّعة عالميًا، لذلك قد تُخزَّن بياناتك أو تُعالَج على خوادم خارج بلدك. (سياسة Cloudflare)
  • Meta (Facebook) App Events: يعمل في تطبيقات أندرويد فقط (نسخة ويندوز لا ترسل شيئًا إلى Meta). يُرسَل إليها معرّف الإعلان وبيانات جهاز تقنية وأحداث التطبيق (تثبيت / فتح / تفعيل اشتراك) لقياس أداء حملاتنا الإعلانية وإسناد عمليات التثبيت. لا نرسل لها أي من بيانات عملك. يمكنك تقليل هذا التتبّع من إعدادات جهازك: الإعدادات ← الخصوصية ← الإعلانات ← «حذف معرّف الإعلان» أو «إيقاف تخصيص الإعلانات». (سياسة Meta)
  • Google (تسجيل الدخول + Drive): اختياري تمامًا ولا يعمل إلا لو فعّلت ميزة «النسخ الاحتياطي على Google Drive». نطلب صلاحية drive.file فقط — أي أن التطبيق يرى ويدير الملفات التي أنشأها بنفسه في حسابك ولا يطّلع على باقي ملفاتك. يُحفَظ بريدك الإلكتروني على جهازك لعرض الحساب المرتبط. (سياسة Google)

4. الأذونات المستخدمة

  • الكاميرا: لمسح الباركود (QR / Barcode)، ولتصوير محل العميل إن اخترت أنت إضافة صورة له.
  • التخزين / الملفات: لحفظ النسخ الاحتياطية وتصدير التقارير (PDF / Excel)، ولاختيار صورة محل العميل من ملفات جهازك إن أضفتها.
  • الطباعة والبلوتوث: للطباعة على طابعات الإيصالات.
  • جهات الاتصال: تُطلَب فقط لما تضغط «اختيار من جهات الاتصال» أثناء إضافة عميل. يقرأ التطبيق حينها أسماء وأرقام جهات اتصالك على الجهاز ليعرضها لك في قائمة تختار منها. لا تُرسَل جهات اتصالك إلى أي جهة، ولا يُحفَظ إلا الاسم والرقم اللذان تختارهما — ويُعامَلان بعدها كبيانات عميل عادية (أي يُزامَنان مع خوادمنا في النسخة السحابية). يمكنك رفض الإذن واستخدام التطبيق بالكامل وإدخال البيانات يدويًا.
  • الموقع (GPS): يُطلَب فقط في اللحظة التي تضغط فيها «حدّد الموقع الحالي» لعميل بعينه، ليُحفَظ إحداثيات محل ذلك العميل مرة واحدة مع بياناته. لا يوجد تتبّع في الخلفية ولا تتبّع مستمر لك ولا لموظفيك: التطبيق لا يطلب إذن الموقع في الخلفية، ولا يقرأ الموقع إلا في تلك اللحظة، ولا يسجّل أي مسار أو حركة. ورفض الإذن لا يمنعك من استخدام أي شيء في التطبيق — يمكنك إدخال العنوان أو الإحداثيات يدويًا.
  • الإنترنت: للتفعيل والمزامنة والنسخ الاحتياطي السحابي والدعم الفني والتحليلات.

5. مشاركة البيانات والاطّلاع عليها

نحن لا نبيع بياناتك ولا نشاركها مع أي جهة لأغراض تسويقية. في النسخة السحابية، الوصول إلى بياناتك مقصور على أقل عدد ممكن من فريقنا وللأغراض التشغيلية والدعم الفني فقط، أو عند وجود التزام قانوني. أما لوحة الإدارة لدينا فتعرض ملخّصات المبيعات المجمّعة لكل متجر (الإجماليات وأكثر المنتجات مبيعًا) لمتابعة الاشتراكات والدعم.

6. أمان البيانات

  • كل الاتصالات مع خوادمنا عبر HTTPS/TLS، وكلمات المرور تُخزَّن مُجزَّأة (hash).
  • ملفات النسخ الاحتياطية مشفَّرة بـAES-256-GCM، ومصدر مفتاح التشفير يختلف بين النسختين (وأي ملف نسخة قديم يظل يُفتح كما هو).
  • النسخة السحابية: مفتاح النسخ الجديدة مشتق (PBKDF2-SHA256) من سِر عشوائي مرتبط بحسابك يولّده خادمنا ولا يظهر لك، ويصل إلى الجهاز عند تسجيل الدخول ويُحفَظ في التخزين الآمن للجهاز. لذلك أي جهاز جديد يحتاج تسجيل دخول ناجح واحد بحسابك قبل أن يستطيع فتح نسخك الاحتياطية — ملف النسخة وحده لا يكفي من دون بيانات حسابك.
  • النسخة الأوفلاين: مفتاح التشفير ما زال مشتقًا من معرّف اشتراكك، وهو مُعرِّف وليس كلمة سر عالية العشوائية. تنبيه مهم: التشفير هنا يحمي الملف من الاطّلاع العابر لكنه لا يُعتبر حماية ضد مهاجم محترف. وفي الحالتين احتفظ بملفات النسخ في مكان آمن ولا ترسلها عبر قنوات عامة.
  • ننصحك بعمل نسخ احتياطية دورية والاحتفاظ بها في مكان آمن.

7. الأطفال

التطبيق موجّه لأصحاب الأعمال والتجار وغير مخصص للأطفال دون 13 عامًا.

8. مدة الاحتفاظ وحذف البيانات

  • النسخة الأوفلاين: يمكنك حذف بياناتك في أي وقت بإلغاء تثبيت التطبيق أو مسح بياناته من إعدادات الجهاز. ويمكنك إيقاف إرسال الملخّص المجمّع من داخل التطبيق (الإعدادات ← سياسة الاستخدام والخصوصية ← «مشاركة الملخّص المجمّع»)، كما تُحذف الملخّصات المرفوعة سابقًا بطلب منك.
  • النسخة السحابية: نحتفظ ببياناتك طالما الاشتراك قائم لتوفير خدمة المزامنة. يمكنك طلب حذف حسابك وكل بياناته من خوادمنا في أي وقت عبر وسيلة التواصل في البند 11، وننفّذ الطلب خلال 30 يومًا من التحقق من هويتك — ويشمل ذلك سجلات المزامنة والنسخ الاحتياطية المرفوعة وتذاكر الدعم.
  • نسخ Google Drive: موجودة في حسابك أنت، وتُحذف من داخل حسابك على Drive.

9. حقوقك

لك الحق في الوصول إلى بياناتك لدينا، وتصحيحها، وطلب نسخة منها، وطلب حذفها، وسحب موافقتك على المزامنة (بالتحوّل إلى النسخة الأوفلاين أو إغلاق الحساب). للممارسة تواصل معنا عبر البند 11.

ملاحظة مهمة: بيانات زبائنك وموظفيك أنت المتحكّم فيها ومسؤول عن مشروعية جمعها وإبلاغهم، ونحن نعالجها نيابة عنك فقط لتشغيل الخدمة وبتعليماتك. وهذا يشمل موقع محل العميل (إحداثيات GPS) وصورة محله — تسجيلهما اختياري بالكامل، وأنت المسؤول عن إبلاغ العميل والحصول على موافقته قبل تسجيل موقع محله أو تصويره، وعن الالتزام بالقوانين المعمول بها في بلدك، وعن حذفهما من بيانات العميل إن طلب ذلك.

10. التعديلات على السياسة

قد نقوم بتحديث هذه السياسة من وقت لآخر، وسيظهر تاريخ آخر تحديث في أعلى الصفحة.

11. التواصل معنا

لأي استفسار بخصوص الخصوصية أو لطلب حذف بياناتك:
واتساب: ‎+20 101 529 2513

Last updated: July 30, 2026

At QAYEM POS we respect your privacy and are committed to protecting it. This policy explains what information the app handles and how it is used. By using the app, you agree to this policy.

1. Nature of the App — Two Editions

QAYEM POS ships in two editions that handle data very differently:

  • Offline edition (device license): works without a permanent connection. Your business data — products, invoices, customers, suppliers, inventory and reports — is stored in a database on your device and its details are not uploaded to our servers, except for an aggregated daily summary described in section 2, plus any backup you upload yourself — or one uploaded automatically to your own Google Drive account on a schedule you choose, and only after you enable that feature (it is off by default).
  • Cloud edition (subscription account): its core purpose is syncing across multiple devices or branches. Therefore your business data records are uploaded to and stored on our servers so they reach your other devices. This is not a side feature — it is what the cloud edition is.

2. Data We Handle

EditionDataPurposeWhere it is stored
Offline Full business data (products, invoices, customers, suppliers, inventory…) Running the app On your device only
Offline Aggregated daily summary (last 30 days): per-day sales/returns/expenses totals and invoice counts, customer and product counts, and the names, quantities and value of the top 20 best-selling items. No customer names, phone numbers, invoice details or costs (item names are also scrubbed of long digit runs that could be a phone number before sending). Subscription monitoring, support and service improvement Our servers (Cloudflare) — sent automatically every 6 hours. You can turn it off in the app: Settings → Usage & Privacy Policy → "Share aggregated summary"
Cloud All of your business data records: products, invoices and line items, payments, purchases, inventory, cash accounts and warehouses; your customers' and suppliers' details (name, phone, email, address, tax number, balance, plus the customer's shop location (GPS coordinates) if you add them yourself — entirely optional and only recorded by a direct action of yours); your employees' details (name, job title, phone, national ID if entered, salary, attendance and payroll); plus audit logs and cashier shifts.
⚠️ A customer's shop photo is never uploaded to our servers: the image stays as a file on the device that captured it, and only the file path is synced — which is why the customer opens on another device with the same path but without the picture.
Syncing your data across your account's devices Our servers (Cloudflare D1) — coordinates only; the shop photo stays on the device and is never uploaded
Cloud Staff login accounts: username, name, role and permissions; passwords stored hashed and not recoverable as plain text Login and permission management Our servers
Both Device ID, app version, operating system, last IP address, last-seen time, and technical install-integrity signals (whether the device is an emulator, and the app's install source). In the offline edition the verification heartbeat also sends the signed license token stored on your device, so the device proves it owns the license before the server returns any data Activation, device limits, license-abuse and piracy prevention Our servers
Optional Encrypted backup of your database Restoring your data when changing or losing a device Our servers (Cloudflare R2) when you upload it manually, and/or your own Google Drive account (recurring automatic upload once you enable the feature — it is off by default and can be turned off at any time)
Optional Support tickets: your name, phone/email, message text and an attached screenshot if you send one Answering your support request Our servers
Android
apps
Advertising ID (GAID), technical device data (model, OS, locale) and app events (install, app open, sessions, subscription activation and its value). This is an advertising identifier that can be linked across apps and is not anonymised data. None of your business or customer data is sent to Meta. Ad-campaign performance measurement and install attribution Meta (Facebook)

3. Third-Party Services & Processors

  • Cloudflare: hosting of our servers and storage of sync data and backups (Workers / D1 / R2). Cloudflare's network is global, so your data may be stored or processed on servers outside your country. (Cloudflare Policy)
  • Meta (Facebook) App Events: active in the Android apps only (the Windows build sends nothing to Meta). It receives your advertising ID, technical device data and app events (install / open / subscription activation) to measure our ad campaigns and attribute installs. We do not send any of your business data to Meta. You can limit this from your device: Settings → Privacy → Ads → "Delete advertising ID" or "Opt out of ads personalisation". (Meta Policy)
  • Google (Sign-In + Drive): fully optional; used only if you enable the "Google Drive backup" feature. We request the drive.file scope only — the app can see and manage only the files it created in your account and cannot access the rest of your Drive. Your email address is kept on your device to show the linked account. (Google Policy)

4. Permissions

  • Camera: barcode / QR scanning, and taking a photo of a customer's shop if you choose to add one.
  • Storage / Files: backups and exporting reports (PDF / Excel), and picking a customer's shop photo from your device files if you add one.
  • Printing & Bluetooth: receipt printer support.
  • Contacts: requested only when you tap "pick from contacts" while adding a customer. The app then reads your contacts' names and numbers on the device to show you a list to choose from. Your contacts are never sent anywhere; only the name and number you pick are saved, and they are then treated as ordinary customer data (so they sync to our servers in the cloud edition). You may deny this permission and still use the whole app by typing details manually.
  • Location (GPS): requested only at the moment you tap "use current location" for a specific customer, in order to save that customer's shop coordinates once with their record. There is no background and no continuous tracking of you or your staff: the app never requests background location, reads the location only at that moment, and records no route or movement history. Denying the permission does not block anything in the app — you can type the address or the coordinates manually.
  • Internet: activation, syncing, cloud backup, support and analytics.

5. Data Sharing & Access

We do not sell your data and do not share it for marketing. In the cloud edition, access to your data is limited to the smallest possible number of our staff and only for operational and support purposes, or where legally required. Our admin dashboard displays aggregated per-store sales summaries (totals and best-selling products) for subscription monitoring and support.

6. Data Security

  • All communication with our servers uses HTTPS/TLS, and passwords are stored hashed.
  • Backup files are encrypted with AES-256-GCM; where the encryption key comes from differs between the two editions (any older backup file still opens as before).
  • Cloud edition: the key for new backups is derived (PBKDF2-SHA256) from a random secret tied to your account that our server generates, never shows you, and delivers to the device when you sign in — it is then kept in the device's secure storage. A new device therefore needs one successful sign-in to your account before it can open your backups; the backup file alone is not enough without your account credentials.
  • Offline edition: the encryption key is still derived from your subscription identifier, which is an identifier rather than a high-entropy secret. Important: the encryption protects the file from casual inspection but should not be relied on against a determined attacker. In both editions, keep backup files somewhere safe and do not share them over public channels.
  • We recommend taking periodic backups and keeping them in a safe place.

7. Children

The app is intended for business owners and merchants, not for children under 13.

8. Retention & Data Deletion

  • Offline edition: you can delete your data anytime by uninstalling the app or clearing its data from device settings. You can also stop the aggregated summary from being sent inside the app (Settings → Usage & Privacy Policy → "Share aggregated summary"), and previously uploaded summaries are deleted on request.
  • Cloud edition: we retain your data for as long as the subscription is active in order to provide the sync service. You can request deletion of your account and all of its data from our servers at any time via the contact in section 11; we complete such requests within 30 days of verifying your identity, including sync records, uploaded backups and support tickets.
  • Google Drive backups: they live in your own account and are deleted from within your Drive.

9. Your Rights

You have the right to access the data we hold about you, correct it, request a copy, request its deletion, and withdraw your consent to syncing (by moving to the offline edition or closing the account). To exercise these rights, contact us via section 11.

Important: you are the controller of your own customers' and employees' data and are responsible for the lawfulness of collecting it and for informing them; we process it on your behalf solely to operate the service and on your instructions. This includes a customer's shop location (GPS coordinates) and shop photo — recording them is entirely optional, and you are responsible for informing the customer and obtaining their consent before recording their shop's location or photographing it, for complying with the laws applicable in your country, and for deleting them from the customer's record on request.

10. Changes

We may update this policy from time to time; the latest update date appears at the top.

11. Contact Us

For any privacy inquiry or a data-deletion request:
WhatsApp: +20 101 529 2513