Back to home
Legal

Privacy Policy

MyDoha — Last updated: July 2026

1. Data Collected

When using MyDoha, we collect the following data: • Email address (authentication) • First name, neighborhood in Doha, interests, arrival date in Qatar • Profile photo (optional) • Push notification token (Expo Push Token) • Notification preferences (categories, frequency, schedule) • Saved events and associated reminders • Questions and answers posted in the community help section • Support messages, reports and suggested corrections • Activity logs (last login date) Community help: the questions and answers you post are publicly visible to other members of the app, along with your first name and profile photo.

2. Legal Basis for Processing (GDPR)

In accordance with the General Data Protection Regulation (GDPR, EU 2016/679), we process your data on the following legal bases: • Article 6(1)(b) — Contract performance: processing necessary to provide the service (authentication, notifications, events, favorites) • Article 6(1)(a) — Consent: for optional anonymous usage analytics and optional notifications • Article 6(1)(f) — Legitimate interests: for application security, abuse prevention and service improvement You may withdraw your consent at any time for consent-based processing.

3. Data Usage

Your data is used to: • Authenticate and secure your account via magic link • Send personalized push notifications (weather, events, reminders) • Personalize your event feed based on your interests • Manage your favorites, reminders and preferences • Enable member-to-member help (public questions and answers) • Process support requests, reports and suggested corrections • Measure our marketing campaigns, only with your consent (see section 6) • Improve the app's content and recommendations

4. Data Storage and Security

Your data is stored on Supabase servers (PostgreSQL infrastructure hosted on AWS, US East region). Data access is protected by: • Supabase Row Level Security (RLS): each user only accesses their own data • Encryption in transit (TLS/HTTPS) and at rest • Magic link authentication (no passwords stored) • API keys not exposed client-side (Supabase Edge Functions) In the event of a data breach, you will be notified in accordance with GDPR Article 34 within 72 hours of detection.

5. Data Retention

We retain your data for the following periods: • Profile data: for the duration of your registration, erased immediately upon account deletion • Saved events, reminders and preferences: for the duration of your registration • Support messages, reports and corrections: 24 months • Activity logs: 12 months • Push notification tokens: until revoked or app uninstall You can request early deletion via Profile → Delete Account or by email.

6. Third-Party Services

We use the following service providers who access some or all of your data: • Supabase Inc. (USA) — Authentication, database, storage. DPA: supabase.com/legal/dpa • Expo (USA) — Push notification delivery for iOS and Android • Apple Inc. (USA) — Apple Push Notification Service (APNs) for iOS • Google LLC (USA) — Firebase Cloud Messaging (FCM) for Android • PostHog (European Union) — Anonymized usage analytics, only with your consent • Meta Platforms — Measurement of our advertising campaigns and reach to similar audiences (Facebook/Instagram), only with your consent. On iOS, this sharing is also subject to your App Tracking Transparency (ATT) authorization. Off by default, revocable at any time in your profile. Each provider has its own privacy policy.

7. International Transfers

As a European resident, your data may be transferred to the United States (Supabase, Expo, Apple, Google, Meta). These transfers are covered by: • The European Commission's Standard Contractual Clauses (decision 2021/914/EU) • The EU-US Data Privacy Framework for certified companies You may request a copy of these safeguards by contacting us at the address listed in section 11.

8. Event-related data

MyDoha aggregates public information about events in Doha and lets you save events, create reminders and suggest corrections. Event information may come from third-party public sources. We make best efforts to keep it up to date, but dates, venues, prices and availability may change without notice. Always verify critical information with the official organizer.

9. Data Selling

We do not sell, rent, or transfer your personal data to third parties. If — and only if — you explicitly consent, certain in-app usage data (for example registration, viewing or searching for events) may be shared with Meta to measure the effectiveness of our advertising campaigns and to introduce MyDoha to similar audiences. This sharing is optional, off by default, subject on iOS to your tracking authorization (ATT), and revocable at any time from your profile. Outside of this specific, consented case, your data is never used for third-party advertising targeting.

10. Your Rights (GDPR Art. 15-22)

As a resident of the European Union, you have the following rights: • Right of access (Art. 15): obtain a copy of all your data • Right to rectification (Art. 16): correct inaccurate data • Right to erasure (Art. 17): delete your account via Profile → Delete Account • Right to restriction (Art. 18): limit certain processing • Right to data portability (Art. 20): receive your data in a structured format • Right to object (Art. 21): object to certain processing • Right to withdraw consent: at any time To exercise these rights: contact@mabaguetteadoha.com. Response within one month (Art. 12(3) GDPR). If the dispute is unresolved, you may contact your national data protection authority.

11. Data Controller — Contact

Data controller: VirtualBridge LLC Wyoming, United States Email: contact@mabaguetteadoha.com Website: mydoha.app For any request regarding your personal data, contact us by email. We will acknowledge receipt within 48 hours.

Back to home

© 2026 VirtualBridge LLC, Wyoming, USA. All rights reserved.