Legal

Privacy Policy

How Rasid handles account information, customer analytics data, Website events, WhatsApp clicks, integrations, billing records, and service usage.

Last updated:

On this page

1. Scope and our roles

Rasid is an independent software service operated by Ahmed Omar, trading as Rasid.

This Privacy Policy explains how Rasid handles information when you visit our public pages, create or use a Rasid account, manage a Workspace, connect an integration, subscribe to a plan, or contact us. It also explains how Rasid processes analytics information collected for customers through Rasid Website tracking and tracked WhatsApp links.

Account and service-administration information is handled by Rasid for operating the service. For customer tracking data, the Rasid customer generally decides why tracking is enabled and how the resulting analytics are used, while Rasid processes that information to provide the service. The exact legal roles can vary by context and applicable law.

If you are a visitor to a customer's Website or tracked WhatsApp link, that customer is the best first contact for questions about why its tracking is enabled. This policy does not replace the customer's own privacy notice.

2. Information we collect

The information Rasid handles depends on how you use the service. We collect information you provide, information generated through your use of Rasid, information received from integrations you choose to connect, and limited technical information needed to operate and protect the service.

Account and profile information

This can include your email address, display name, profile image, preferred locale, timezone, authentication method, and account and session metadata. When you use Google sign-in, Google and Supabase Auth provide the account information needed to authenticate you, such as your email, name, and profile image, subject to your Google settings and Google's terms. Rasid does not receive your Google password.

Workspace and configuration information

This can include Workspace names and settings, member roles, team invitations, Website names and domains, public site keys, campaign parameters, goals, estimated-value settings, tracked WhatsApp phone numbers, prefilled messages, link labels, and other settings you choose to configure.

Billing and subscription information

This can include your selected plan, event tier, billing interval, subscription status, provider customer and subscription identifiers, price identifier, trial and billing-period dates, scheduled subscription changes, currency, and amounts returned by the payment provider. Paddle collects and processes checkout, billing, payment-method, tax, and buyer information under its own terms and privacy notice. Rasid does not store full payment-card details in its application database.

Support and operational information

When you contact us, we receive the content of your message and the contact details you use. We also process limited diagnostics, security events, request information, and error details needed to operate, troubleshoot, and protect Rasid.

3. Customer Website tracking

When a customer installs the Rasid tracking script, the script can send page views and customer-defined lead or conversion events to Rasid. The standard event payload can include the Website's public site key, page URL without query parameters, page path, page title, referring URL without query parameters, UTM campaign attribution parameters, browser language, timezone, screen dimensions, event time, script version, and random visitor and session identifiers.

Rasid derives limited device, browser, operating-system, approximate country, region, and city labels from request context where available. Rasid also applies a user-agent heuristic to label likely automated traffic and claimed known bots. User-agent claims can be spoofed, so bot labels are signals rather than verified identity.

Rasid processes an incoming IP address transiently for abuse protection and can derive a one-way rate-limit identifier. Customer tracking-event rows do not store raw IP addresses or raw user-agent strings. Hosting and network providers may still process request information under their own terms.

The standard tracker is not designed to collect form contents, passwords, payment details, or the identity of an individual visitor. Customers must not place sensitive personal data in URLs, page titles, campaign parameters, conversion names, or event metadata, and must not configure Rasid to collect information they are not authorized to process.

4. WhatsApp link analytics

Customers can create a Rasid URL that records a click before redirecting a visitor to wa.me. Click analytics can include the tracked link and Website, campaign parameters, referring host, event time, random visitor or session identifiers when supplied, and the same approximate device, browser, operating-system, location, and likely-bot labels described above.

The destination phone number and optional prefilled message are customer-configured Workspace data used to build the WhatsApp destination. Rasid does not read the visitor's later WhatsApp conversation. WhatsApp and Meta process activity after the redirect under their own terms and privacy practices.

5. Campaign attribution, goals, and estimated value

Rasid associates page views, leads, conversions, goals, and WhatsApp clicks with available source, medium, campaign, content, and term parameters. Customers can also connect read-only Meta Ads data and map campaigns to Website activity.

Estimated value is calculated from settings supplied by the customer, such as an estimated value per lead. It is a modeled analytics figure, not confirmed revenue, a verified sale, accounting evidence, or a payment record. Attribution can be incomplete or inaccurate because of missing parameters, browser controls, customer configuration, cross-device behavior, spoofed traffic, and other technical limits.

6. Service usage, cookies, and local storage

Rasid uses Supabase authentication cookies to keep users signed in and HTTP-only preference cookies to remember the active Workspace or Website. These cookies are used for authentication, security, navigation, and service functionality.

The customer tracking script uses local storage for a random visitor identifier and session storage for a random session identifier. Rasid's authenticated dashboard uses similar random identifiers for first-party service analytics and session storage can temporarily retain a Paddle transaction identifier so a completed checkout can be finalized safely after return. These identifiers are not intentionally derived from a name, email address, IP address, or raw user-agent string.

Browser settings can block or clear cookies and storage. Doing so can sign you out, reset identifiers, or prevent parts of authentication, attribution, checkout finalization, and Workspace navigation from working as expected.

7. How we use information

We use information to provide, secure, maintain, and improve Rasid; authenticate users; manage Workspaces and permissions; collect and display authorized analytics; connect customer-selected integrations; process subscription state; enforce event and resource limits; prevent abuse; troubleshoot errors; answer support requests; and comply with legal obligations.

We may create aggregated or de-identified statistics for service operations and product improvement where those statistics are not reasonably linked to an identifiable person. We do not use customer tracking metadata as a place to collect sensitive personal data.

8. Reasons for processing

Depending on the information, relationship, and applicable law, processing may be necessary to perform our agreement with a customer, take steps requested before entering an agreement, pursue legitimate interests such as service security and improvement, comply with legal obligations, protect legal rights, or act with consent where consent is required.

Customers are responsible for identifying and communicating the lawful basis for tracking on their own Websites and links, obtaining consent where required, and honoring applicable visitor choices.

9. How information is disclosed

We disclose information only as needed to operate Rasid, follow customer instructions, complete a transaction, protect the service and its users, respond to legal process, or support a business transaction subject to appropriate protections. We do not represent that information is never shared, because service providers process information on our behalf or as independent providers.

Current service dependencies include Supabase for authentication and the application database; Vercel for application hosting and delivery; Google for optional Google sign-in; Paddle for checkout, subscriptions, payment processing, tax handling, and buyer support as merchant of record; Supabase Auth and its configured email-delivery provider for authentication email; and Meta when a customer chooses to connect read-only Meta Ads or follows a WhatsApp redirect.

Each third party handles information under its own agreement and privacy terms. Connected services can change their features or practices, and customers should review the terms of services they choose to enable.

10. International processing

Rasid and its providers may process information in countries other than the country where a user, customer, or Website visitor is located. Those countries can have different data-protection laws. Where required, the relevant party should use an approved transfer mechanism or other lawful safeguard.

11. Retention

We retain information for as long as reasonably needed to provide the service, maintain an account or subscription, preserve security and audit records, resolve disputes, enforce agreements, and meet legal obligations. Retention varies by data type, account status, customer instructions, provider behavior, and technical backup cycles.

Rasid does not promise a fixed deletion schedule in this policy. When information is no longer needed, we may delete, anonymize, or aggregate it, subject to legal, security, fraud-prevention, financial-record, backup, and dispute-resolution requirements.

12. Security

Rasid uses technical and organizational measures intended to protect information, including authenticated access, role-based Workspace permissions, database row-level access controls, server-only provider credentials, encrypted storage for connected Meta access tokens, input validation, and rate limiting on public collection routes.

No Internet service, transmission, or storage system is completely secure. Customers and users must protect their credentials, use appropriate access controls, limit access to trusted team members, and notify us promptly about suspected unauthorized use.

13. Privacy rights and choices

Depending on where you live and the applicable law, you may have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent, and to complain to a data-protection authority. These rights can be subject to identity verification, legal exceptions, and limits.

Account holders can update some profile and Workspace information in Rasid. For other requests, contact us. If your request concerns tracking performed for a Rasid customer, contact that customer first; we will assist the customer where required and technically feasible.

14. Account and deletion requests

Rasid does not currently expose a self-service account-deletion control. Contact support to request account closure or deletion. We will verify authority over the relevant account or Workspace and explain any information that must be retained for legal, security, billing, or dispute purposes.

Deleting or archiving a Website, link, integration, or Workspace setting can affect future collection or access but does not necessarily erase every historical, aggregated, billing, audit, or backup record immediately.

15. Children

Rasid is a business analytics service and is not directed to children who cannot legally consent to use of an online service in their location. We do not knowingly seek account information directly from children. Customers operating child-directed services must not deploy Rasid unless they have assessed and satisfied the consent, notice, and other legal requirements that apply to them.

16. Changes and contact

We may update this Privacy Policy as Rasid, its providers, or legal requirements change. We will post the updated version here and revise the last-updated date. Where required, we will provide additional notice.

For privacy questions or requests, contact the Rasid support address shown below. Do not send passwords, payment-card details, provider tokens, or other sensitive secrets by email.