Privacy Policy — Basmeh (WorkShift)

Last updated: 3 August 2026 Effective date: 3 August 2026


1. Introduction

This Privacy Policy explains how personal data is collected, used, stored and protected in connection with the Basmeh mobile and web application (the "Application" or "Basmeh"), operated by Ahmad Alkhoja ("we", "us", "the Provider").

Basmeh is a business-to-business (B2B) workforce attendance solution. It is licensed to companies, institutions and other employers (each a "Company"), which use it to record the attendance of their own personnel ("Employees").

This Policy is issued in compliance with:

Where the Application is used by, or its data relate to, individuals located in the European Economic Area or the United Kingdom, we additionally apply the standards of the EU General Data Protection Regulation (GDPR).

By using the Application you confirm that you have read and understood this Policy. If you are an Employee, please also read Section 3, which explains the respective responsibilities of your employer and of us.


2. Definitions

TermMeaning
Personal DataAny information relating to an identified or identifiable natural person.
ProcessingAny operation performed on Personal Data, including collection, recording, storage, use, disclosure and erasure.
ControllerThe party that determines the purposes and means of Processing.
ProcessorThe party that Processes Personal Data on behalf of, and on the documented instructions of, a Controller.
CompanyThe employer that subscribes to the Application and creates Employee accounts.
EmployeeAn individual end user whose attendance is recorded through the Application.
AdministratorThe individual who registers and manages the Company's account.

3. Roles and responsibilities (important)

The allocation of legal roles under this Policy is as follows, and it determines who is accountable to whom:

Consequently: the lawful basis for monitoring attendance, the provision of notice to Employees, any consultation with employee representatives, and compliance with applicable Jordanian labour law and workplace-monitoring requirements are the responsibility of the Company. Employees who wish to object to attendance monitoring, or to understand why it is carried out, should address their employer in the first instance.


4. Location data — our most sensitive processing

We treat location as the most privacy-intrusive element of the Application and have deliberately engineered it to be as narrow as technically possible.

4.1 Location is captured only at the moment of Check-in or Check-out

The Application requests the device's geographic position only at the exact moment an Employee taps "Clock In" or "Clock Out", in order to calculate the distance between the Employee and the workplace coordinates configured by the Company, and to determine whether the Employee is inside the permitted radius.

4.2 There is no continuous or background tracking

The Application does not track Employees continuously. It does not collect location while running in the background, while the screen is off, or when the Application is closed.

This is not merely a policy commitment; it is enforced by the permissions the Application requests:

Accordingly, the operating system itself prevents the Application from obtaining the Employee's position outside an active Check-in or Check-out action.

4.3 What is retained

For each attendance event we retain the latitude, longitude and the calculated distance in metres from the workplace, together with the date, time and event type (in/out). We retain no location history between events, no movement trail, and no route or journey information.

4.4 Refusal

An Employee may decline or revoke the location permission at any time through the device's operating-system settings. The consequence is functional only: the Application will be unable to verify presence and therefore unable to register a Check-in or Check-out. Any employment consequence of failing to record attendance is a matter between the Employee and the Company, not a matter determined by us.


5. Personal Data we process

5.1 Employee data

CategoryDataPurpose
IdentityFull name, job title, departmentTo identify the Employee in the Company's records
AttendanceEvent type (in/out), date, timeThe core service
LocationLatitude, longitude, distance from workplace — captured only at the moment of each eventTo verify presence within the authorised boundary
AuthenticationPassword stored only as a bcrypt hash; invite codeTo secure the account
DeviceA randomly generated device identifierTo bind an account to a single device and prevent one person clocking in on another's behalf

We do not collect Employee email addresses, telephone numbers, national identification numbers, photographs, biometric data, contacts, calendars, messages, photos or files.

5.2 Administrator and Company data

Email address, password (managed by our authentication provider and never stored in plain text), company name, full name, subscription tier and status, and — where push notifications are enabled — a push notification token.

5.3 Payment data

We never receive, process or store payment card details. Payments are handled exclusively by our payment providers (see Section 7). We receive only the subscription status, plan and expiry date.

5.4 Diagnostic data

If the Application encounters an error, a crash report may be transmitted to our error-monitoring provider. These reports are configured to be stored in the European Union.

5.5 Data stored only on the device

Employee reminders (the times an Employee chooses to be reminded to clock in or out) are stored exclusively on the Employee's own device and are never transmitted to our servers or made visible to the Company. The Company has no means of learning when, or whether, an Employee has set a reminder.


6. Legal bases for Processing

Where Jordanian law, the GDPR or an equivalent framework requires a legal basis, Processing is founded on:

  1. Performance of a contract — providing the Application to the Company and maintaining the Administrator's account.
  2. Legitimate interests — of the Company in accurately recording working time and verifying attendance at an authorised workplace, and of the Provider in securing the service against fraud and misuse. The Company is responsible for conducting any balancing assessment such reliance requires.
  3. Compliance with legal obligations — including the retention of records required by applicable labour, tax and accounting law.
  4. Consent — for device-level permissions such as location and notifications, which the operating system requests separately and which may be withdrawn at any time.

7. Disclosure and sub-processors

We do not sell, rent or trade Personal Data. We disclose Personal Data only to:

RecipientFunctionData location
SupabaseDatabase, authentication and server infrastructureCloud hosting
SentryError and crash diagnosticsEuropean Union
RevenueCatSubscription management for mobile in-app purchasesCloud hosting
PaddleMerchant of Record for web paymentsCloud hosting
ExpoDelivery of push notificationsCloud hosting
Apple / GoogleApplication distribution and in-app purchase processingPer their own policies

Each sub-processor is bound by contractual confidentiality and data-protection obligations. We may further disclose Personal Data where compelled by a competent judicial or regulatory authority, or where necessary to establish, exercise or defend legal claims.

Cross-border transfer. Personal Data is Processed on servers located outside the Hashemite Kingdom of Jordan. Specifically:

Such transfers are made in accordance with Article 15 of Law No. (24) of 2023 and are subject to appropriate contractual safeguards ensuring an adequate level of protection. By using the Application, the Company acknowledges and consents to this cross-border transfer on its own behalf and undertakes to inform its Employees accordingly.


8. Security

We apply technical and organisational measures appropriate to the risk, including:

No system is absolutely secure. In the event of a Personal Data breach likely to result in a risk to the rights of data subjects, we shall notify the Company without undue delay and shall cooperate with it in making any notification required to the competent Jordanian authority and to affected individuals.


9. Retention

Attendance records are retained for as long as the Company maintains an active subscription, because they constitute the Company's own working-time records and may be required for payroll, audit and statutory purposes.

Upon deletion of an account, associated Personal Data is deleted or irreversibly anonymised within ninety (90) days, save where longer retention is required by law. The Administrator may delete the Company account, and all data associated with it, from within the Application (Settings → Danger Zone → Delete Account).

Where the Company instructs deletion of an individual Employee's data, we act on that instruction as Processor.


10. Rights of data subjects

Subject to the conditions of Law No. (24) of 2023 and any other applicable law, individuals have the right to:

How to exercise these rights. Because the Company is the Controller of Employee data, an Employee should direct such requests to their employer, which has direct access to the records within the Application. Where a request is made to us directly, we shall forward it to the relevant Company without undue delay and assist in responding to it.

Requests concerning an Administrator's own account may be made to us directly at the address in Section 14.


11. Children

The Application is a workplace tool and is not directed at children. We do not knowingly collect Personal Data from any person under the age of eighteen (18). A Company must not enrol an individual below the minimum working age permitted by applicable law.


12. Automated decision-making

The Application does not make automated decisions producing legal or similarly significant effects concerning an Employee. It records data; every decision derived from that data — including any disciplinary, payroll or employment decision — is taken by the Company through human review. See the Terms of Service, which allocate sole responsibility for such decisions to the Company.


13. Amendments

We may amend this Policy to reflect changes in the Application, in our sub-processors or in applicable law. Material changes will be notified through the Application or by email prior to taking effect. The "Last updated" date at the head of this document indicates the current version.


14. Contact

Questions, requests and complaints concerning this Policy may be addressed to:

Basmeh (WorkShift) Email: ahmadalkhoja5@gmail.com WhatsApp: +962 79 582 7113 Jurisdiction: Hashemite Kingdom of Jordan

Data subjects also retain the right to lodge a complaint with the competent personal data protection authority in the Hashemite Kingdom of Jordan.