Trust & transparency
Privacy Policy
How Wajha handles information in its consumer app and public website.
- Effective
- 6 August 2026
- Last updated
- 6 August 2026
- Version
- 2.0
About this Policy
This Privacy Policy explains what information Wajha processes, why it is processed, how it is shared, how long it may be retained and how you can make privacy requests. It applies to the Wajha consumer mobile application and the public Wajha website.
This is version 2.0, effective 6 August 2026. Version 2.0 is written in English for the Apple App Store, Google Play, Google OAuth and Qatar public launch.
Who operates Wajha
Wajha is a product developed by the Wajha founding team.
Built in Qatar. Operating from Qatar.
Eligibility — 18+
Wajha is only for people who are at least 18 years old. People under 18 may not browse, create an account or use Wajha. Wajha does not offer child accounts or a parental-consent workflow.
Age is collected as a numerical age, not as a date of birth.
Public and account-backed use
The public website and public catalogue are viewable without signing in. Account-backed features require authentication and include visits, check-ins, Access offer activity, Last Bite claims, loyalty and ratings.
Wajha processes only the information needed for the feature you use, the security of the service and the operation of the relevant Restaurant or catalogue flow.
Information stored locally
- A nickname, which is stored locally on the device.
- Age, gender and occupation, which are stored locally before sign-in and may be synchronized to Wajha’s backend after sign-in.
- Local profile information may remain until it is edited, cleared, uninstalled or removed through device storage controls.
- Locally stored profile data may be included in device backups managed by Apple or Google according to device and operating-system settings.
Information provided by identity providers
When you authenticate with Google or Apple, Wajha may receive identity information made available by that provider and needed to create or operate a Wajha account. The exact fields depend on the provider, your settings and the authentication flow.
- A provider account identifier that is stable for the provider account.
- Name and email address when the provider makes them available.
- A profile image supplied by the identity provider, where available.
- Authentication metadata necessary to operate the account.
Google user data
Users can create or access a Wajha account using Google Sign-In. Wajha may receive your Google name, email address, stable provider account identifier, a profile image supplied by Google, where available, and authentication metadata necessary to operate the Wajha account.
Wajha does not access Gmail, Google Drive, Google Contacts, Google Calendar, YouTube data or other Google account content. Wajha uses the Google identity and authentication information made available for the sign-in flow.
Apple identity data
Users can create or access a Wajha account using Sign in with Apple. Wajha receives a stable Apple user identifier and, where provided by Apple, a name, an email address or Apple private-relay email and authentication metadata needed to operate the account. Apple Hide My Email is supported.
Google and Apple provider identities create separate Wajha accounts by default. Wajha does not automatically merge accounts solely because they use the same or similar name or email address.
Profile and demographic information
Age is required for eligibility. Gender may include “Prefer not to say”, and occupation may include “Prefer not to say”. Gender and occupation are optional profile information used for personalization, product understanding or service improvement; they are not strictly necessary to browse or authenticate.
Wajha does not ask for a date of birth as part of this profile. If you provide profile information, it should be accurate and kept current where needed for the service.
Visits, check-ins, Access, Last Bite and loyalty
Account-linked activity may include visits and check-ins, Access offer redemptions, Last Bite claims, loyalty activity, Restaurant, location and offer identifiers, timestamps, validation state, code-use and redemption evidence and failed or suspicious validation attempts where needed for security and fraud prevention.
This activity is used to operate the relevant feature, maintain accurate account state, resolve disputes, prevent misuse and provide service insights. Wajha does not invent or require activity fields beyond what a particular flow needs.
Ratings and feedback
Ratings may be associated with authenticated and verified Wajha activity. They are used to operate, improve and evaluate the service and may contribute to aggregate Restaurant insights or rankings where applicable.
Wajha may moderate or remove abusive, fraudulent or misleading submissions. Users must not submit false or manipulated ratings.
Validation and security data
Validation codes and QR passes may be short-lived and one-time. Wajha may process validation state, code-use evidence and failed or suspicious attempts to confirm an applicable action and prevent fraud. Screenshots or copied codes may be rejected, but Wajha does not claim that screenshots are technically impossible.
Codes should be treated as sensitive. Do not share, transfer, resell or publish them. Restaurant staff should use codes only for the specified validation purpose.
Device permissions and what Wajha does not collect
The consumer app does not request location permission, collect or store precise GPS location, collect approximate location or use Restaurant proximity verification. It does not request camera, microphone or photo-library access for the consumer QR flow. The consumer app displays customer QR codes but does not scan them.
The Restaurant-facing portal may use a device camera to scan a customer QR code. That camera flow is used to decode the QR for validation. Wajha does not claim that camera images or video are uploaded or retained from that scanning flow, and a microphone is not required for QR scanning.
Wajha does not sell or use advertising identifiers for targeted advertising. The service does not process consumer card details through the app.
How information is used
- Provide catalogue browsing, authentication and account-backed features.
- Synchronize permitted account-backed profile and activity data across sessions.
- Process visits, check-ins, Access, Last Bite, loyalty and ratings.
- Validate codes and protect the service against fraud, abuse and security incidents.
- Improve, evaluate and troubleshoot the service and its catalogue.
- Respond to support, privacy and deletion requests.
- Comply with legal obligations and protect the rights, safety and integrity of Wajha and its users.
Restaurants and operational disclosures
Wajha does not sell personal information, use personal information for targeted advertising or share data with data brokers. Restaurants receive only information necessary to validate a code, confirm an applicable visit, redemption, claim or loyalty action and operate the relevant Restaurant feature.
The ordinary validation flow does not disclose the consumer’s account name or email to Restaurant staff. Validation and transaction context are still operational data. One Restaurant should not receive unrelated activity from another Restaurant.
Restaurants are responsible for their own food, products, fulfilment, service, safety and accurate honouring of their offers. Restaurant commercial arrangements are outside this consumer Privacy Policy.
Service providers
Wajha uses service providers and platform services in these categories:
- Google: optional Google authentication and related identity-provider services.
- Apple: Sign in with Apple, App Store distribution and platform services.
- Supabase: authentication, database and account-backed application services.
- Cloudflare: website and app delivery, storage, network security and infrastructure services.
- Apple and Google: application distribution, device services and platform-managed backups where applicable.
International processing
Wajha and its service providers may process information in countries outside Qatar according to their infrastructure, contractual arrangements and applicable technical and legal safeguards. Wajha does not state an exact server region unless it has been verified for the relevant provider and service.
No sale or targeted advertising
Wajha does not sell personal information, use personal information for targeted advertising or share personal information with data brokers. There is no consumer advertising system.
Legal and safety disclosures
Wajha may disclose information where reasonably necessary to comply with applicable law, respond to a lawful request, protect users or the public, investigate fraud or security incidents, enforce the Terms or protect Wajha, Restaurants and other rights holders. Disclosure is limited to what is reasonably needed for the purpose where possible.
Data retention
Local profile information remains until edited, cleared, uninstalled or removed through platform storage controls, subject to device backups. Account data remains while the account is active. Account activity remains as needed to operate visits, redemptions, loyalty, ratings and dispute resolution.
Support and privacy correspondence remains as needed to address the request and maintain evidence of resolution. Security and fraud-prevention records may remain longer where legitimately required. Backups may retain deleted information until normal backup expiration. Anonymized aggregate information may be kept when it can no longer identify or be linked to a person.
Account deletion
Authenticated users can initiate account deletion inside the Wajha app. Users can also review deletion information at https://wajha.qa/delete-account. Opening the website page alone does not delete the account; the in-app flow submits or initiates the deletion request.
Wajha normally completes deletion requests within 30 days, although most requests are handled sooner. Wajha confirms when processing is complete. During deletion, Wajha removes or anonymizes, where technically and legally feasible, the authentication account, provider identity, name, email, demographics, active account state, personal loyalty state, account-linked private history and account-linked ratings, and revokes or invalidates provider credentials or tokens where applicable.
Ratings are deleted or irreversibly anonymized when technically and legally feasible. Truly anonymous aggregate information may remain only when it can no longer be linked to you. Wajha does not claim that identifiable user-generated content remains indefinitely after deletion.
Wajha may retain minimal information required for security, fraud prevention, legal compliance, dispute resolution, deletion-request audit evidence, code-use or redemption integrity and backups until normal expiration. Retained data will not be used for unrelated purposes.
Uninstalling the app does not delete an authenticated account.
Your privacy rights
You may contact [email protected] to request access to personal data, a copy or export of personal data, correction, deletion, objection to certain processing, withdrawal of consent where processing relies on consent and information about how data is used. Wajha will review the request and may need information to verify the relevant account or request.
Some processing is necessary to provide account-backed services. If you withdraw consent for processing required to operate an account feature, Wajha may no longer be able to provide that feature. Mandatory legal, security and fraud-prevention processing may continue where permitted or required.
These rights are described with regard to the laws of the State of Qatar and do not replace any mandatory rights or protections that apply to you. This policy is not legal advice.
Consent and withdrawal
Before creating or accessing an account through Google or Apple, users are shown links to the Terms of Service and Privacy Policy and are informed that continuing means agreeing to the Terms and acknowledging the Privacy Policy.
Wajha records the applicable Terms version, Privacy Policy version, account identifier and acceptance timestamp. You may withdraw consent where processing relies on consent, subject to the service and legal limits described above.
Security
Wajha uses reasonable technical and organizational safeguards, including access controls and encryption in transit where supported by standard HTTPS/TLS, to protect information. No system is completely secure. Do not send passwords, one-time codes, QR passes or other authentication secrets through support or privacy channels.
Device backups
Local nickname, age, gender and occupation data may be included in device backups managed by Apple or Google according to device and operating-system settings. Removing data from the Wajha app does not necessarily remove copies held in a platform-managed backup until that platform’s controls and normal backup lifecycle apply.
Changes to this Policy
Wajha may update this Policy as the service or law changes. The effective date, last-updated date and version will be revised. Material changes will be communicated where practical, and the current policy will remain available at https://wajha.qa/privacy.
Contact
Privacy and deletion requests: [email protected]
General support: [email protected]
Primary general-support channel: Instagram @wajha_qa