Privacy Policy

How NQLA collects, uses, shares and protects your personal data — plus our cookie policy.

9 min read

Last updated: 17 July 2026

nqla ("nqla", "we", "us") operates the NQLA platform (nqla.online), an order-management, delivery, storage and subscription platform. This policy explains what personal data we collect, how we use it, who we share it with, and your rights. We are based in Amman, Jordan. For any privacy question, contact info@nqla.online.

1. Data we collect

  • Account data: your name, email, phone number, password (stored only as a secure hash), preferred language, and — for business accounts — your company name and type. Profile photo (avatar) if you upload one.
  • Identity & payout data (companies and drivers): for drivers, national ID and driving-license numbers (stored encrypted). For withdrawals, bank/IBAN or CliQ details and receipts (stored encrypted).
  • Customer/recipient data you enter: when a merchant creates an order, we process the recipient's name, phone, email, delivery address and location so the order can be delivered.
  • Payment data: card payments are processed by Stripe on Stripe's own hosted checkout — we never see or store your full card number or CVV. We store payment records (amount, currency, status, invoice, and Stripe customer/subscription identifiers) and wallet balances and transactions.
  • Location data: during an active delivery ("out for delivery"), the assigned driver's live GPS location is processed to show order tracking.
  • Technical & usage data: IP address, browser/user-agent, device information, and logs of requests and security events (e.g. logins) — used for security, fraud prevention and troubleshooting.
  • Mobile app analytics & crash diagnostics: if you use the mobile app — anonymous app-usage statistics (screens viewed, in-app actions such as sign-up, login or order creation, an app-instance identifier, device model, OS and app version, and coarse country/region) and crash diagnostics (crash reports and stack traces with device state at the time of the crash). These contain no customer or recipient names, phone numbers, emails or addresses. See sections 4–5.
  • Cookies: see section 4.
  • Uploaded content & push tokens: images you upload (products, avatars, receipts) and, if you use the mobile app, a device push-notification token.
  • Contact-form submissions: if you write to us through the contact form, we store your name, email, an optional phone number, the subject you choose and your message (see section 9).

2. How we use your data

To create and manage your account; process orders, deliveries and storage; process payments, subscriptions and wallet withdrawals; send service and order notifications; provide support; keep the platform secure and prevent abuse; and comply with legal obligations. We also use anonymous usage statistics and crash reports to understand how the product is used, improve it, and detect and fix crashes and defects.

Marketing & announcement communications. From time to time we may send you promotional announcements and product-update emails and in-app messages. These are separate from the service and account notices above (such as security, order and payment notifications), which we always send. You can opt out of promotional announcement emails at any time — use the one-click unsubscribe link in every such email, or turn off "Announcements & Updates" under your notification preferences (Profile → Notification Preferences on the web, or the equivalent screen in the mobile app). Opting out stops promotional emails only; essential service and account notices are unaffected.

We process data to perform our contract with you, for our legitimate interests (security, service improvement), to comply with the law, and — where required — with your consent (e.g. optional analytics cookies on the website); for mobile-app usage statistics and crash reports we rely on our legitimate interest, with the in-app opt-out described in section 5.

4. Cookies

We use strictly necessary cookies: an encrypted session cookie, a CSRF-protection cookie, and an optional "remember me" cookie. We also use optional Google Analytics cookies on the website — only with your consent, requested via the cookie banner; you can decline, and withdraw consent at any time via "Manage preferences". We do not run advertising cookies. The mobile app does not use cookies; the analytics identifiers it uses are described in sections 1 and 5.

5. Who we share data with (sub-processors)

We do not sell your personal data. We share data only with providers that help us run the service:

  • Stripe — payment processing (receives your name, email and payment details you enter on Stripe's checkout).
  • Email delivery provider — to send you emails and notifications.
  • Google LLC (Firebase Cloud Messaging) — mobile push-notification delivery (your device's push token).
  • Google LLC (Google Analytics / Firebase Analytics) — usage analytics on our website (only with your cookie-banner consent, IP anonymized) and in our mobile app (screens viewed, in-app actions, an app-instance identifier, device model, OS and app version, coarse country/region). Events contain no names, phone numbers, emails or addresses; all advertising features and signals are disabled. Analytics event data is retained by Google for two (2) months.
  • Google LLC (Firebase Crashlytics) — mobile app only: crash and error reports (stack traces, device model, OS and app version, app state at the time of the crash, and a Crashlytics installation identifier) so we can find and fix bugs. Retained by Google for approximately 90 days.
  • Map & font providers (OpenStreetMap, Google Fonts) and content delivery networks — your browser contacts these to load maps, fonts and scripts, which involves your IP address.
  • Our own search, real-time and error-monitoring servers are self-hosted by us (not third parties).

Your choice in the mobile app. Usage statistics and crash reports are turned on by default when you install the app. You can turn both off at any time from Profile → "Usage Analytics" in the app — one switch controls both, and turning it off stops collection immediately. Push notifications are separate and controlled by their own switch. On the website, analytics runs only if you accept analytics cookies (section 4).

We may also disclose data where required by law or to protect our rights and users' safety.

6. International transfers

Some providers (e.g. Stripe, Google) process data on servers outside Jordan. Where this happens, we rely on those providers' safeguards and contractual protections.

7. Data retention

We keep account and order data for as long as your account is active and as needed to provide the service and meet legal/financial obligations. Security and request logs are retained for up to 90 days; live delivery-location data is retained for up to 90 days after an order is completed. Backups containing personal data are kept for a limited period.

When you delete your account, we do not simply drop everything. We erase your personal data (name, email, phone, addresses, identity and payout details, and similar), but the financial and tax records the law requires us to keep — payments, invoices and wallet transactions — are retained in pseudonymized form (no longer linked to you as a person) for the legally required period, approximately five (5) years under Jordanian law.

8. Your rights

You may access, correct, or request deletion of your personal data, and object to or restrict certain processing. You can revoke your active device sessions yourself from your account.

You can exercise your access (export) and deletion rights yourself, at any time, from Profile → Privacy & Your Data on the web, or the equivalent Privacy screen in the mobile app: request a machine-readable export of your data, or schedule account deletion with a cancelable grace period. As described in section 7, deletion erases your personal data while the financial records the law requires are retained in pseudonymized form. If you prefer, you can still contact info@nqla.online and we will respond within a reasonable period.

9. Contact-form submissions

When you send us a message through the contact form on our website, we collect and store the details you provide: your name, email address, an optional phone number, the subject you choose, and your message, together with the language you were using. For abuse prevention we also record limited technical metadata — a keyed, one-way hash of your IP address and a shortened copy of your browser's user-agent string.

  • We never store your raw IP address. Only a keyed HMAC digest is kept, which cannot be reversed back into your address; it is used solely to detect and rate-limit spam and abuse.
  • Your email address is not verified, and a message is linked to your NQLA account only if you were signed in when you sent it. Otherwise it is stored as an anonymous enquiry.
  • No captcha or third-party bot-detection service runs on the form. Spam filtering happens entirely on our own servers (a hidden honeypot field, a timing check and rate limits), so submitting the form does not hand your data to any outside anti-spam provider.

Purpose. We use this data only to receive your enquiry, reply to you, and route it to the right team (e.g. sales or support).

Legal basis. Our legitimate interest in answering enquiries, and pre-contractual communication at your request.

Emails about your enquiry. We may email you about your message through our email delivery provider (see section 5) — including, where this feature is enabled, an automated acknowledgement that we have received it. These emails are sent from our own branded address; we do not pass your details to a separate marketing service.

Retention. Contact submissions are kept for a limited period — by default 180 days, which an administrator can adjust — after which they are automatically and permanently erased. An enquiry we have not yet answered is kept until we have dealt with it, so that a message never disappears before we reply.

Erasure and your rights. In addition to the automatic deletion above, if you were signed in when you wrote to us, your contact messages are included in the personal-data export you can request, and are anonymised (your name, email and technical identifiers removed) when you delete your account — see section 8. Messages sent without signing in are not linked to an account; you can ask us to delete them at any time by emailing info@nqla.online.

10. Security

We protect your data with encryption in transit (HTTPS/HSTS), encryption at rest for sensitive fields (e.g. IDs, bank details, secrets), hashed passwords, optional two-factor authentication, strict access controls and tenant isolation.

11. Children

NQLA is a business platform and is not directed at children under 18.

12. Changes

We may update this policy; we will post the new version here with an updated date.

13. Contact

nqla — Amman, Jordan. Email: info@nqla.online.

14. Governing law

This policy is governed by the laws of the Hashemite Kingdom of Jordan, and disputes are subject to the competent courts of Amman.