Effective 16 August 2026

Privacy policy

This policy describes processing as implemented on the Ondx platform at ondx.app: stored fields, routes, and limits. We follow the Saudi Personal Data Protection Law. This page does not publish a mobile number, street address, or commercial registration.

1. Who controls data and who hosts it

The subscribing office enters operational data in its workspace: people (owners, tenants, buyers) with a national ID, name, and email or mobile; properties, units, contracts, installments, and payments; maintenance, listings, files, and tickets. Ondx hosts that data and runs isolation, permissions, support, and security.

Ondx directly controls: visitor profiles in user_profiles, contact-page rows in public_contact_inquiries, the office subscription record, security and sign-in logs, and in-app product-usage events after sign-in.

Privacy contact: contact@ondx.app. Subscribers open a ticket inside the office.

2. Public forms as built

Public pages collect only the fields in the forms below. Those forms have no national-ID field, no bank field, and no newsletter.

  • Contact: name (2–120 characters), email (up to 180), optional organization (up to 160), topic (sales, demo, support, privacy, partnership, or other), message (20–4000 characters), and page locale ar or en. The inquiry row stores those fields and created_at only. The internet address is passed for a limit of five messages per hour. The limit key is an md5 hash of the address, not a column on the inquiry.
  • Visitor sign-up: name, email, Saudi mobile, password, and city plus district (district id or district name).
  • Office sign-up: office name, admin name, email, Saudi mobile, password, and city plus district.
  • Provider sign-up: account email and password, account type (default individual), display name, optional company name, mobile, contact email if different, optional bio, required service categories, and city plus district. No national ID on this path.
  • Marketplace listing inquiry: sign-in required. Name (min 2), mobile (min 6), optional email, message (min 5). Stored for that listing’s office with the sender user id. Limits: 3 inquiries per listing per day, 20 inquiries per user per day.

3. Activating owner, tenant, and buyer accounts

The office creates the person in the workspace through create_office_person: national ID, name, and email or mobile. There is no self-sign-up for these roles on marketing pages.

The activation page asks for a national ID of 8 to 15 digits and matches it to a record the office already stored in user_identities or people. A one-time code is sent on channels enabled in platform settings: email, SMS, or WhatsApp, if the account has email or phone.

The code session lasts 10 minutes, with 5 verify attempts, a 60-second resend cooldown, and 5 resends. The session stores the internet address and user agent for the request and the verification.

4. What the office stores after sign-in

The isolated office workspace stores records staff enter, including:

  • Properties, units, and branches, and coordinates if entered through maps.
  • People: national ID, username, name, email, mobile, and owner, tenant, or buyer links.
  • Rental, sale, or investment contracts, installments, payments, expenses, and commissions.
  • Finance modules if enabled for the office: journals, VAT, e-invoicing, deposits, owner distributions, fiscal periods, bank reconciliation, common areas, utilities.
  • Maintenance, messages, attachments, and an assigned provider.
  • Listings, images, marketplace inquiries, and sales leads.
  • Tickets, documents, and files in private storage.
  • Staff and roles: office owner, manager, accountant, collection, maintenance, staff — with branch limits for roles other than owner and manager.
  • Audit logs, optional staff MFA, optional IP CIDR rules, and SSO or SCIM settings if enabled.

5. Portals as built in the app

Owner: dashboard, properties, contracts, financials, maintenance, tickets, notifications, and a read-only profile (name, username, national ID, email, phone, status).

Tenant: dashboard, contracts, payments, maintenance, tickets, notifications, and the same profile fields. Electronic installment checkout appears only if the payment-gateway secret is set. The “delete my personal data” panel is on the tenant profile only.

Buyer: dashboard, contracts, tickets, notifications, and a read-only profile. No installment checkout, no maintenance nav, and no deletion panel.

Provider: unassigned available jobs, assigned jobs, and a profile (display name, company, phone, email, city). No office workspace access.

Product analytics run only from the signed-in app layout: a page.view event with the pathname and office id if present in the URL. They are not mounted on public marketing pages.

6. What public pages do not collect or show

Public pages do not show a national ID, bank details, a platform mobile number, a street address, or a commercial registration. The public company constant is name, domain, contact@ondx.app, currency, and jurisdiction.

The contact form states that the data is used only to reply, and that national IDs, bank details, and operational secrets must not be included in the message.

7. Purposes

Processing is tied to the routes above:

  • Create accounts and run the office workspace, portals, marketplace, and maintenance network.
  • Manage the office subscription, limits, add-ons, and the service invoice.
  • Deliver a listing inquiry to that listing’s office, and a contact message by topic.
  • Tickets, support, and incident handling.
  • Security: office isolation, sign-up/contact/inquiry limits, audit logs, and unauthorized-access prevention.
  • A binding legal request, or a verified data-subject request.
  • Product stability from in-app page.view events after sign-in.

9. Who receives data outside the office

Personal data is not sold. A party inside an office sees their relationship only. A published listing is visible to the extent the office published it.

Providers receive data only if that tool is enabled in the runtime environment:

  • Supabase: database, authentication, and file storage. This is the core runtime.
  • Stripe: installment or office-subscription checkout when STRIPE_SECRET_KEY is set. Without it, electronic checkout is off. Ondx is not a bank and does not custody rent.
  • SMTP: operational email when mail-server settings are set. The code does not hard-code an email vendor name.
  • Twilio: SMS or WhatsApp one-time codes when those keys are set.
  • Sentry: error monitoring when NEXT_PUBLIC_SENTRY_DSN is set, with sendDefaultPii: false.
  • Nominatim (OpenStreetMap): property geocoding when the office uses the maps route.
  • Upstash Redis: cache and some rate limits when those keys are set.
  • DocuSign or Zoho Sign: e-signature when those keys are set.
  • Marketplace search or embeddings: OpenSearch or OpenAI if that path is enabled.
  • Authorized platform staff: only as needed for a ticket, a security incident, or a binding legal request.

10. Isolation and security logs

Each office is an isolated workspace with access policies. Inside the office, role and branch apply.

Sign-up is rate-limited: SHA-256 of the internet address in auth_signup_attempts, 8 attempts per 15 minutes.

Sign-in and OTP lockouts store a hashed identifier and last address and user agent. security_events may store an address and user agent, with email and national ID masked in metadata where maskIdentifier is used.

The office can require staff TOTP, enforce a CIDR allowlist, and configure SSO or SCIM if those settings are enabled.

11. Export, deletion, and correction as implemented

Correction: owner, tenant, and buyer profile pages are read-only. Name, national ID, or mobile is changed by the office that created the record, or through a verified ticket or email request.

Export: there is no export button in the UI. A linked personal account requests the package with GET /api/v1/me/data-export and a Bearer session. The JSON package includes identity, person account, office memberships, property ownership, contracts, payments, installments, expenses, maintenance, tickets and messages, notifications, listing inquiries, and product-analytics events. Default limit 500 rows per section, one request per 24 hours. The request is logged in pdpl_data_export_log.

In-app deletion: tenant profile only. Optional reason up to 500 characters. If the person is a tenant or a property owner on a contract that is active, pending_approval, or suspended, the request is rejected as active_contracts.

If accepted: pending_confirmation, then confirm moves it to scheduled for 7 days, and it can be cancelled before execution. Execution replaces national ID, username, and name on people, clears email and phone, disables office_people and person_accounts and unlinks the user, overwrites listing inquiries and ticket messages, and deletes notifications and usage events. Contracts, payments, and installments are not deleted.

Owners and buyers request deletion through the contact page or /api/v1/me/data-deletion after verification, because their profile does not mount the panel.

12. Retention

Office data remains for the life of the subscription. After expiry and grace the workspace becomes read-only; that is not deletion.

Deletion requests and the export log are kept to evidence the request. Security and audit logs are kept for protection and investigation.

There is no public marketing list. A marketplace inquiry goes only to the listing office.

13. Session and preferences

After sign-in, the auth session is kept in the browser through Supabase session cookies.

Language follows the /ar or /en path. Appearance is stored in the browser as ondx-theme. Sidebar collapse is stored locally in the app.

Usage events inside /app are sent by ProductAnalyticsBeacon. Public pages do not run third-party behavioral ads or a newsletter form.

14. Hosting location

The service is cloud-hosted on the infrastructure above. This page does not name a city for the shared database project, because that operational setting is not a field in the product UI.

A dedicated office project may set a region in that agreement. Monitoring, mail, or payment tools may process outside the Kingdom when those tools are enabled.

15. Children

The platform is for offices and adult counterparties. Public sign-up forms have no age field and no path to create an account for a child.

16. Changes

When a collect or store path in the product changes, we update this page and show the effective date at the top.

17. Contact

General privacy: contact@ondx.app or the contact page with the privacy topic.

Subscriber: an in-office ticket. Tenant: the deletion panel on the profile. Export: the API path above after the personal account is linked.

Public pages do not publish a mobile number, street address, or commercial registration.

Also read the terms of service.

Terms of service