Legal & privacy

Privacy Policy

Effective 6 September 2026

This Privacy Policy explains what information BeityCare collects, why we use it, when it may be shared, and the choices available to clients and suppliers.

1. Who we are

The controller of the personal information described in this policy is BeityCare S.A.R.L (“BeityCare”, “we”, “us” or “our”). BeityCare provides a platform that connects clients with participating home-service suppliers. This policy applies to the BeityCare website and mobile applications for clients, suppliers, and administrators.

Privacy questions and requests concerning personal information may be sent to privacy@beitycare.com. General support questions may be sent to support@beitycare.com.

2. Information we collect

Depending on how you use BeityCare, we may collect:

  • Account information, including name, telephone number, role, and optional email.
  • Service details, addresses, location coordinates, notes, access instructions, and photographs you choose to upload.
  • Requests, quotations, appointments, messages, cancellations, refunds, and service history.
  • Payment status and transaction references. BeityCare does not intend to store complete card credentials.
  • Supplier information, including business or legal name, identification details when provided, address, coverage, commission terms, and invoices.
  • Device and technical information, including notification tokens, app version, device platform, language, and security or diagnostic records.

3. How we use information

We use information to:

  • Create and secure accounts and verify contact information.
  • Match requests with eligible suppliers and arrange visits.
  • Enable quotations, chat, notifications, invoicing, payments, cancellations, and refunds.
  • Provide client support, investigate disputes, prevent misuse, and protect the platform.
  • Meet accounting, tax, legal, and regulatory obligations.
  • Improve reliability, performance, accessibility, and service availability.

4. How information is shared

We share only what is reasonably necessary to provide and protect the service. Assigned suppliers receive the client and request information needed to complete a job. Clients receive relevant supplier, quotation, appointment, and invoice information. We may also use service providers for database hosting, authentication, file storage, notifications, maps, communications, payment processing, security, and technical support. These may include Supabase, Google and Firebase, Apple, Google Maps, Infobip for SMS verification, Meta or WhatsApp where enabled, and approved payment providers such as OMT or Whish where available. We may disclose information when required by law or to protect users, BeityCare, or the public. We do not sell personal information.

5. Location, photographs, chat, and notifications

Location is used to place and fulfil a service request and is accessed only with device permission or information you provide. Uploaded photographs and chat messages are used for the related request, quotation, support, safety, and dispute handling. Notification tokens are used to deliver service and account updates. If you opt in, they are also used to send BeityCare service reminders and offers. We record your promotional notification preference and when it changes. You can turn promotional notifications off in your account at any time without turning off order or timeout updates. You can manage location, photo, and notification permissions in your device settings, although disabling them may limit some features.

6. Retention and account deletion

We apply the following standard retention periods. A record may be kept longer only when reasonably necessary for an unresolved service, payment, refund, complaint, fraud or safety investigation, legal claim, court order, or legal, accounting, or tax obligation. When the applicable period ends, we delete the information or irreversibly anonymize it.

  • Account and profile information: retained while the account is active. After a confirmed deletion request, account access is deactivated immediately and account information that is not required for an obligation described below is deleted or irreversibly anonymized within 30 days.
  • Telephone verification records: one-time verification codes expire shortly after issue. Verification challenge and attempt records are deleted within 30 days.
  • Security and access records: retained for up to 12 months, unless needed longer to investigate suspected fraud, abuse, or a security incident.
  • Service requests: information needed for an open request is retained while the request remains active. Closed requests, quotations, appointments, cancellations, ratings, and complaint outcomes are retained for up to 5 years after closure, except where they form part of a financial record covered by the 10-year period below.
  • Chat messages and photographs: retained while the request is active and for up to 24 months after it closes. Following account deletion, messages and photographs are deleted or de-identified within 30 days unless a specific item is required for an unresolved complaint, safety matter, fraud investigation, or legal claim.
  • Invoices, payment, and refund records: invoices, transaction references, quotations supporting an invoice, refunds, commissions, supplier settlements, tax records, and associated accounting evidence are retained for 10 years from the end of the year to which the record relates. Access to these records is restricted. We remove or mask direct identifiers where the retained record does not legally need to identify the person.
  • Supplier business and compliance records: supplier agreements, billing identity, commission terms, and documents needed to support accounting, tax, payment, or legal obligations are retained for up to 10 years after the relevant relationship or transaction ends.
  • Notification tokens: retained while the account and device registration remain active. They are disabled when deletion begins and removed within 30 days, or earlier when the token becomes invalid.
  • Support communications: retained for up to 3 years after the matter is closed.
  • Deletion records: a minimal record of the deletion request, identity verification, dates, and completion status is retained for 5 years after completion so that BeityCare can demonstrate that the request was handled.
  • Backups: information removed from active systems may remain in restricted backup copies until the normal backup cycle overwrites them, for no more than 90 additional days. Backup copies are not used for ordinary business purposes.

In the iPhone or Android application, a client or supplier can start permanent deletion from Account → Delete account. The user is shown the consequences and must confirm the request. Confirming the request deactivates access immediately as the first security step and begins permanent deletion; deactivation is not the final outcome. BeityCare normally completes deletion within 30 days and provides confirmation when it is complete.

An active service, amount due, pending refund, or dispute is not erased by deleting an account. BeityCare may retain only the information needed to resolve that matter or meet a legal obligation. If this requires more than 30 days, we will inform the user. No new service requests may be placed after deletion begins.

Users who cannot access the application can use our public account-deletion page to submit a deletion request without reinstalling the app. Emailing privacy@beitycare.com remains available for assistance or another privacy right.

7. Security and international processing

We use reasonable administrative and technical safeguards designed to protect personal information. No internet service can guarantee absolute security. Some technology providers may process information outside Lebanon or the country where you use BeityCare. We take reasonable steps to use providers and protections appropriate to that processing.

8. Your choices and rights

Subject to applicable law, you may ask to access, correct, or delete your personal information, object to or restrict certain processing, or withdraw consent where consent is the basis for processing. You may update some account information directly in BeityCare. To delete an account from the iPhone or Android application, use Account → Delete account. For other requests, contact privacy@beitycare.com. We may need to verify your identity before completing a request.

9. Children

BeityCare is intended for adults and is not directed to children under 18. We do not knowingly allow children to create accounts. Contact us if you believe a child has provided personal information.

10. Changes to this policy

We may update this policy as BeityCare, its providers, or legal requirements change. The effective date shown below identifies the latest version. Material changes may also be communicated through the application or website.

ملخص سياسة الخصوصية

الجهة المتحكّمة بالبيانات الشخصية الموضّحة في هذه السياسة هي BeityCare S.A.R.L، مشغّل BeityCare. تجمع BeityCare بيانات الحساب والاتصال والموقع وتفاصيل الطلبات والمحادثات والصور والفواتير والمعلومات التقنية اللازمة لتقديم الخدمات وتأمين الحسابات وإدارة الطلبات والمدفوعات والإشعارات والدعم. لا نبيع البيانات الشخصية، ولا نشارك إلا المعلومات اللازمة مع المورّد المعيّن ومقدّمي الخدمات التقنية أو الجهات المختصة عند وجود موجب قانوني.

تُرسل تذكيرات BeityCare بالخدمات والعروض عبر الإشعارات فقط عند اختيارك استلامها. نسجّل تفضيلك ووقت تغييره. يمكنك إيقاف الإشعارات الترويجية من حسابك في أي وقت دون إيقاف تحديثات الطلبات وانتهاء المهلة.

يمكن للعميل أو المورّد بدء الحذف الدائم من تطبيق iPhone أو Android عبر الحساب ← حذف الحساب. يؤدي تأكيد الطلب إلى تعطيل الوصول فوراً كخطوة أمنية وبدء عملية الحذف الدائم، ولا يُعد التعطيل بديلاً عن الحذف. تُحذف بيانات الحساب غير الواجب الاحتفاظ بها، أو تُزال هويتها بصورة غير قابلة للرجوع، خلال 30 يوماً عادةً، ويُرسل تأكيد عند اكتمال العملية.

إذا تعذّر تسجيل الدخول، يمكن تقديم الطلب من صفحة حذف الحساب العامة من دون إعادة تثبيت التطبيق.

تُحفظ سجلات التحقق لمدة تصل إلى 30 يوماً، وسجلات الأمن لمدة 12 شهراً، والمحادثات والصور لمدة 24 شهراً بعد إقفال الطلب، وسجلات الطلبات المقفلة لمدة 5 سنوات، والسجلات المالية والفواتير والدفعات والمبالغ المستردة لمدة 10 سنوات من نهاية السنة المعنية. يُحتفظ بمعلومات الدعم لمدة 3 سنوات، وبالحد الأدنى من سجل طلب الحذف لمدة 5 سنوات. قد تبقى النسخ المحذوفة في النسخ الاحتياطية المقيّدة لمدة لا تتجاوز 90 يوماً إضافياً.

قد نحتفظ بسجل محدد لمدة أطول عند وجود طلب مفتوح أو دفعة أو استرداد أو نزاع أو تحقيق أمني أو موجب قانوني أو محاسبي أو ضريبي. في هذه الحالات نقيّد استخدام السجل ونحذف أو نحجب البيانات التعريفية التي لا يلزم الاحتفاظ بها. للمساعدة أو لممارسة حق آخر، يمكن التواصل عبر privacy@beitycare.com.