Privacy Policy
Last updated September 28, 2026
Version: v1.0
Effective date: 28 September 2026
The English version of this Privacy Policy is the controlling version. The Persian version is provided as a translation. If the two versions conflict, the English version governs to the extent permitted by applicable law.
1. Scope and who is responsible
This Privacy Policy explains how dooobi collects, uses, stores, shares, and protects personal data when you use dooobi’s applications, websites, tracking portal, verification, support, and related services (the “Service”). “dooobi” refers to the platform operating under that name. No registered company or operator has yet been designated, so this Policy does not invent or state one.
For privacy questions or requests, contact privacy@dooobi.com. For account deletion and general assistance, contact support@dooobi.com.
2. Data we collect
Depending on how you use the Service, we may collect:
• Account and contact data: email address, phone number, first and last name, account identifiers, language, verification status, account status, and authentication events.
• Identity and verification data: date of birth, nationality, identity-document type, number and expiry date, an image of the identity document, and a selfie or profile photo where required. We also keep review status, rejection reasons, and verification timestamps.
• Listing and travel data: origin and destination countries and cities, travel dates, flight number if supplied, capacity, item title and description, category, weight, declared value, item photos, requested or proposed reward, currency, and the Sender’s selected payment method.
• Transaction and evidence data: matches, accepted reward and rate, Platform Fee amount and receipt, payment-status declarations, handover and delivery confirmations, QR-related events, tracking code, Receiver PIN status, timestamps, cancellations, disputes, reviews, and confirmation records.
• Communications and support data: listing messages, support tickets, reports, replies, attachments, and information you provide when asking for help or raising a dispute.
• Receiver data: information a Sender provides for Receiver access, delivery status and confirmation, and records associated with a Receiver’s use of a tracking code and PIN. A Receiver may use the Service without a dooobi account.
• Technical and security data: request and event timestamps, IP address and device or browser information available to our infrastructure, application errors, security logs, and first-party analytics events needed to operate and protect the Service.
• Information from service providers: confirmation from authentication, hosting, storage, email, SMS, or identity-support providers where needed to deliver the Service.
Please do not provide personal data that is unnecessary for a listing, message, or support request.
3. How we use personal data
We use personal data to:
• create and secure accounts, authenticate users, verify email and phone numbers, and conduct identity and profile-photo review;
• publish listings, find compatible routes, create matches and Transactions, calculate the 5% Platform Fee from the recorded reward, and show Transaction status;
• reveal the limited contact information and approved profile photo needed by the Sender and Traveler after Admin approval of the Platform Fee for that Transaction;
• provide tracking and limited Receiver access, process delivery confirmations, and maintain Transaction history;
• record evidence, prevent abuse, investigate fraud, handle support requests and disputes, enforce the Terms, and protect users and the Service;
• send service, security, support, and Transaction notifications;
• maintain, troubleshoot, measure, and improve the Service; and
• comply with applicable law, lawful orders, and the establishment, exercise, or defence of legal claims.
We process data where it is necessary to provide the Service you request, based on your consent where required, for legitimate safety and operational purposes, and to comply with law. Where explicit consent is legally required for sensitive personal data, we will rely on that consent or another lawful basis available under applicable law.
4. Verification data and what verification means
Identity documents and related KYC data are stored in private storage and are not part of your public profile. Access is limited to authorized review and operational personnel and service providers that need it for the Service. Your approved profile photo is private by default but may be shown to the other participant in a specific Transaction after its Platform Fee is approved.
Verification reduces risk but does not guarantee a person’s identity, conduct, reliability, creditworthiness, legal compliance, or performance. Full KYC documents are not freely provided to other users.
5. When we share data
We may share personal data only as reasonably necessary:
• With Transaction participants: after Platform Fee approval, the other participant may receive the name, phone number, and approved profile photo needed for that Transaction. Listing, route, item, reward, and Transaction evidence is shared according to the Service flow and access controls.
• With a Receiver: a Receiver with the correct tracking code and, where required, PIN may view limited status and Traveler contact information and confirm delivery. The Receiver does not receive full KYC data.
• With service providers: infrastructure, database, authentication, private storage, website hosting, email, SMS, and similar providers process data for us under their service terms and security controls. Current infrastructure includes Supabase-based database, authentication and storage, Cloudflare-based website delivery, and an SMS provider for Iranian phone verification. Google authentication may be used when selected by the user.
• For disputes and safety: we may share limited information with the other participant where reasonably necessary and legally permitted to pursue a genuine claim. This does not mean routine release of identity documents.
• With authorities or advisers: we may preserve or disclose information in response to valid legal process, to a competent authority, or where reasonably necessary to protect rights, safety, users, or the Service, investigate fraud, or establish or defend legal claims.
• In a future organizational change: if the Service is transferred to a legally established operator or successor, relevant data may transfer subject to this Policy, applicable law, and appropriate notice.
We do not sell personal data. We do not use KYC documents for advertising.
6. International processing
The Service uses online infrastructure and providers that may process or store data outside Iran. This can involve countries with different data-protection rules. We limit access, use private storage for verification documents, apply contractual and technical safeguards where available, and use providers only for operating the Service. By using the Service and submitting data, you understand that such cross-border processing may occur, subject to applicable law.
7. Security
We use measures designed to protect data, including private storage for verification documents and support attachments, row-level access controls, authenticated and role-limited operations, short-lived signed links for private files, and logging of important confirmations. No system is completely secure. You must protect your password, verification codes, tracking codes, and Receiver PIN and must not send full identity documents through ordinary chat or to other users.
8. Retention
We retain account and KYC data while the account is active when needed to provide verification and the Service. Transaction, confirmation, support, dispute, fraud-prevention, financial, security, and audit records may be retained for as long as reasonably necessary for their purpose or a legal requirement.
When an account is deleted, dooobi normally removes or de-identifies direct profile identifiers and KYC references and disables account access. Verification files should be deleted unless specific data must be preserved for an active Transaction or dispute, fraud prevention, security, enforcement, or a legal obligation. Shared Transaction history, messages, reviews, Receiver-related history, and evidence may remain where deletion would affect another person’s rights, the integrity of the record, or a lawful retention need.
Receiver information is private but may remain as part of the relevant Transaction history even where the Receiver never created an account.
9. Account deletion and privacy requests
You may request account deletion, access, correction, or another privacy review by contacting privacy@dooobi.com or opening a Support ticket. Account deletion is currently handled through Support rather than a self-service button. We may need to verify your identity before acting on a request.
Deletion does not require us to remove data that must reasonably be retained for an active Transaction, dispute, fraud prevention, another user’s legitimate record, security, financial records, or law. Where full deletion is not appropriate, we may restrict access, separate, or de-identify the data. We will explain material limits where legally permitted.
You can update basic profile information in the Service. Changing identity information or a profile photo may reset its verification status and require a new review.
10. Children
The Service is for adults aged 18 or older. We do not knowingly permit a person under 18 to use dooobi. If you believe a minor has provided personal data, contact privacy@dooobi.com so we can investigate and take appropriate action.
11. Cookies and analytics
The public website and applications may use essential local storage, session technologies, and first-party event records needed for authentication, language preferences, security, reliability, and basic product measurement. The current Service does not rely on a third-party advertising network or sell data for targeted advertising. If materially different analytics or advertising technology is introduced, this Policy will be updated as required.
12. Changes to this Policy
We may update this Policy as the Service or legal requirements change. Material changes will use a new policy version and may require you to accept that version before continuing to use authenticated features. Acceptance records contain the policy key, version, time, and selected locale.
13. Governing framework and contact
This Policy is intended to operate primarily under the laws of the Islamic Republic of Iran, including applicable rules on electronic commerce, personal data, computer systems, evidence, and lawful authority requests, without limiting mandatory rights that apply in a particular case.
Privacy: privacy@dooobi.com
Legal: legal@dooobi.com
Support and account deletion: support@dooobi.com
No registered office address is designated in this version.