Your privacy first

Privacy Policy

We collect the minimum needed to run the platform, we do not sell your data, and you can delete your account at any time.

Last updated: 1 September 2026

Language notice: this English text is provided so that international members can read our terms in full. The Arabic version remains the legally binding reference. Where the two differ, the Arabic text prevails.

The short version: we take your privacy seriously. We collect only what we need to run the platform, we do not sell your data, and you can delete your account at any time.

1. Who we are

Mahara (the «Platform» or «we») is an Arab freelance platform connecting developers, designers and marketers with clients. We act as a data controller and comply with the applicable data-protection laws, including the European General Data Protection Regulation (GDPR) for users resident in the European Union where it applies.

Privacy contact: info@mahara.sy

2. The data we collect

We collect your data only in order to serve you. The main categories:

  • Account data: email address, name, country, and preferred language.
  • Profile data (for freelancers): skills, experience, portfolio, pricing, and display picture.
  • Phone number: required to create a profile. It is never shown publicly and is never disclosed to the other party in any dealing: it is readable only by the Mahara team, and only to reach you or to resolve a dispute.
  • Telegram data (optional): if you choose to verify your number through Telegram, Telegram sends us the number registered to your account with your explicit consent, and we store the chat id alongside it so we can message you. We use them for three things only: verifying the number, sending you notifications about your work if you enable them, and sending your two-factor code if you enable that.
    We cannot read your messages, your contacts, or anything else in your Telegram account. You can unlink at any time from your account settings, and this data is deleted immediately.
  • Project data: project briefs, messages, and AI matching results.
  • Saved searches: the search terms, filters and alert state you deliberately save. We use them only to match new services, experts and jobs; you can disable an alert or delete a saved search at any time.
  • Payout data: the payout method a freelancer adds; account fields are encrypted by the application with a key kept separately from the database.
  • Automatic technical data: IP address, browser type, operating system, pages visited. Used for security and analysis. Ordinary activity is recorded against a SHA-256 fingerprint of the address, which we never display, never share, and never use for anything but security. For attacks on the platform (automated scanning, injection attempts, requests to trap paths) we do keep the address in clear, because a fingerprint alone cannot support an abuse report to a hosting provider, a firewall rule, or a complaint to the competent authorities.
  • Device notification subscription: only after your explicit permission, we store the Web Push service endpoint, public encryption key, a random installation identifier, alert language, and your preview choice. By default, an alert contains no message text.
  • Cookies: only those essential for signing in and for your preferences. We do not use advertising-tracking cookies without your consent.

What we do not collect: your card details (payments are made by bank transfer or Sham Cash), and no special-category data (religion, ethnicity, orientation, and so on).

4. How we use your data

  • To run your account and the platform's features.
  • To match clients with freelancers using AI.
  • To translate a specific message into Arabic or English only when a conversation participant explicitly asks for it. We do not store the translation or alter the original message.
  • To notify you about your projects and messages.
  • To detect and prevent fraud and abuse.
  • To improve the user experience (anonymous analytics).
  • To comply with the law when requested by the competent authorities.

What we do not do: we do not sell your data. We do not use it to train third-party AI models. We do not share it for targeted advertising.

5. Who we share it with

We do not sell or trade your data. We share the minimum necessary with a limited set of technical service providers needed to run the platform (hosting, sending email, and processing optional AI matching and translation requests, and your browser's push notification service), under strict data-processing agreements that bind them to use it for providing that service alone.

If you enable Telegram verification, the messages we send you travel through Telegram's servers and are subject to Telegram's own privacy policy. We send only what is necessary: a verification code, or a short notice about your work. We share no data about you with Telegram beyond what is needed to deliver the message to your chat.

The Web Push payload is encrypted to your device. If you choose to show previews, your operating system may display message text on the lock screen according to your notification settings.

6. How long we keep it

  • Account data: for as long as your account exists, plus 30 days after an erasure request. We then erase profile data that is not legally required.
  • Transaction records: up to 7 years (accounting obligation), with unnecessary profile data removed and only an internal record identifier retained.
  • Security audit logs: one year at most.
  • Device notification subscriptions: while they remain enabled; we remove them when you disable notifications, sign out, erase the account, or when the push service confirms that the subscription has expired.
  • Pre-launch waiting list: until launch and your notification, then 30 days.

7. Your rights

You have an absolute right to:

  • Access: request a copy of all your data (we provide a JSON download).
  • Rectification: correct any inaccurate information.
  • Erasure («the right to be forgotten»): delete your account and data that we are not legally required to retain from your account settings. Required transaction records may remain for the retention period above.
  • Restriction: ask us to pause the processing of your data.
  • Portability: receive your data in a format you can move to another platform.
  • Objection: object to any processing based on legitimate interest.
  • Withdrawal of consent: at any time, without affecting processing already carried out.
  • Complaint: to the competent authority in your country.

To exercise any right: info@mahara.sy. We reply within 30 days at the latest.

8. International transfers

Our servers and database are hosted in Germany (European Union), while our AI service provider is located in the United States. When data is transferred outside the European Union we rely on the appropriate safeguards approved by the European Commission, such as Standard Contractual Clauses (SCCs).

9. Cookies

See the cookie policy for full details.

10. Minors

Mahara is intended for adults (18+). We do not knowingly collect data from minors. If you become aware that a minor has submitted their data, contact us immediately and we will delete it.

11. Security

We apply strict security controls:

  • Encrypted connections in transit (TLS)
  • Encrypted sensitive authentication and payout fields at rest
  • Strict access controls at both the application and the database layer
  • Audit logs for every sensitive operation
  • Automatic blocking of suspicious attempts

If a data breach occurs, we assess the impact and notify competent authorities and affected users within the legally required periods where those duties apply.

12. Changes to this policy

We will update this policy when necessary. Material changes will be announced with a clear notice inside the platform 30 days before they take effect.

13. Contact us

Questions, requests, complaints: info@mahara.sy