DRAFT — pending review by a lawyer. Not in force.
Legal

Privacy policy

What Rina keeps about people, why, who can see it, which services handle it and for how long. It describes what the software does today.

Who we are

Rina is software for real estate brokers: a workspace where a brokerage, an agency or an agent keeps leads, listings, deals, commission, documents and appointments, and public pages that show their listings and their team.

[To be confirmed: the legal name, registration number, registered address and licence of the company that runs Rina.]

[To be confirmed: who is responsible for the personal data in a workspace: where the workspace (the brokerage, agency or agent) decides how it is used and Rina handles it for them, and where Rina decides for itself, such as members' accounts and Rina's own billing.]

[To be confirmed: a data protection officer or privacy contact, if one is required.]

What we keep, and about whom

People who use Rina (members)

  • Your account: your name, your email address and your password, which is stored only as a hash (scrambled so it cannot be read back).
  • Your sign-ins: each signed-in session keeps the browser it was made from, and can keep the network (IP) address it was made from too (see below). A session ends about 30 days after it was last used: each day you use Rina, it is extended. Signing out ends it and deletes it.
  • Your professional profile: phone, WhatsApp, broker registration number (BRN), languages, areas, specialties, a short bio, a photo and links to your social accounts. Only you edit it, and it goes with you to any workspace you join.
  • Your role in each workspace (owner, admin or agent), your public page there and its settings.
  • Documents in your vault: passports, Emirates IDs, residence visas, broker cards, certificates and others, each with its number, expiry date and notes.
  • Bank details for payouts, if you add them: the account name, the bank and the IBAN. Each payout you ask for keeps a copy of those details as they were then.
  • Your commission and earnings, and the hours you take appointments.
  • How long you take to first answer each lead, and figures on your work, which the workspace's owners and admins see member by member: leads received and won, how long you take to answer, open leads, leads gone quiet, when you last worked on one, overdue tasks, live listings, open deals and the commission still to come on them, commission, documents missing or expired, and whether your page is published.
  • Notices inside Rina, which can repeat a lead's name and message.
  • Invitations: the invited person's email address, their role and who invited them.

[To be confirmed: whether sign-in sessions hold the network (IP) address. The sign-in library keeps it only when the request reaches Convex carrying exactly one forwarded address, which depends on how Vercel and Convex pass the request on; otherwise it keeps an empty value.]

Leads and visitors to public pages

  • What a visitor types into an enquiry or booking form: their name and mobile number, and if they give them, their email, what they are looking for, their budget, when they plan to move, a message and a time they ask for.
  • The language their browser asks for, used to pass the lead to an agent who speaks it.
  • Leads that members add by hand or import from a spreadsheet.
  • Each lead's timeline: enquiries, calls, WhatsApp taps, notes, viewings, tasks and appointments.
  • A score from 0 to 100 that Rina works out from where the lead came from, what it has told the agent and how far it has moved, used to sort the inbox. Rina also gives each new lead from a public page to an agent automatically: the agent whose page it came from, or the active agent of the listing it came from, or else one picked by the workspace's routing rules, or, when no rule picks anyone, an owner (or, if no owner is active, an admin).
  • If the mobile number is already a lead in that workspace, an enquiry is not a new lead: it is added to that lead, whether the lead came from a page or a member added or imported it. It stays with the member who holds the lead while they are active, fills in what the person wants, their budget and when they plan to move if the lead did not have them yet, and reopens the lead if it was marked lost. A name or email address given on a repeat enquiry is not added to the lead.
  • Counts of page views and taps for each day, with nothing that identifies the visitor. Each view and tap also counts towards a limit kept for the visitor's network, under a keyed code made from its network (IP) address (see how long it is kept, below).
  • Conversations with the AI assistant on an agent's page, described in the AI assistant notice.

People who apply to use Rina

When someone asks to use Rina from the apply page, Rina keeps their name, email address, mobile number, company, licence number, number of agents, the plan they are interested in and their message, with the time they agreed to these details being used. Rina uses them to reply to their request and to set up their workspace. Rina's operators, the people who run Rina, see each request with its status, their notes and its history, and the workspace set up from it. No workspace's members can see a request, the workspace set up from it included.

Property owners and landlords

Name, phone, WhatsApp, email, nationality, ID number, notes and tags. A record is private to the agent who holds it, and the workspace's owners and admins. It never reaches a public page. Each landlord statement a workspace issues keeps its own copy of the landlord's name, phone, WhatsApp and email, and of their tenants' names and rent cheque numbers, which stays if the owner record is deleted.

Tenants of properties a workspace manages

Name, phone, email and Emirates ID number; the tenancy's rent, deposit, Ejari number, DEWA account and rent cheques (number, bank, amount and due date); inspections, with photos, meter readings and the signatures drawn on screen with the signer's name; and maintenance requests.

Buyers, sellers and other parties to a deal

The client's and the other party's names, the other brokerage and any referrer with their licence numbers, and the deal's papers, which can include the buyer's, seller's, tenant's or landlord's passport or Emirates ID, forms, contracts and receipts. For off-plan sales, the buyer's expressions of interest and bookings.

People a workspace bills

The name, email, phone, address and tax registration number (TRN) on the workspace's billing documents, and the email address each was sent to. The workspace's own letterhead on those documents can carry its bank account and IBAN.

Business contacts

Developers' contacts (name, role, phone and email), and contractors (name, company, phone, email, TRN and notes) with the score members give them for each job. Every member of the workspace can see them, and each contractor's average score.

Workspaces that pay for Rina

  • The plan, its billing period, seats and dates, the trial's dates, any discount code and changes waiting for the next renewal.
  • Every attempt to take a payment: the amount, what it was for, its outcome, the address of its payment page, the references Mamo Pay gave the payment and the page, why a payment failed as Mamo Pay reported it, and the member who started it, when a member did.
  • Rina's invoices to the workspace, and their PDFs.
  • A history of every change to the plan and its payments, with the member who made each one when a member did, and any discount code used to choose a plan. When Rina grants a partner plan, the note it is granted with is kept too.
  • The card. Rina never receives the card number: the payer enters it on Mamo Pay's payment page. Rina keeps the reference Mamo Pay gives the saved card, its last four digits and its type, to charge renewals.
  • Notices to the workspace's owners about the trial, payments, invoices, seats and the plan, which can include amounts and invoice numbers.

Where it is kept

In Rina's database and file storage at Convex. Files you upload go from your browser straight to Convex's file storage. Vercel also keeps resized copies of photos shown on public pages in its cache for a time.

[To be confirmed: where Convex stores Rina's data, whether any personal data leaves the UAE, and the safeguards for any transfer.]

[To be confirmed: how long Convex and Vercel keep backups, request logs and cached copies of photos, and how a deletion reaches them.]

Services that handle it

  • Convex runs Rina's database, file storage, server code and scheduled jobs; sign-in runs inside it too. Members' browsers keep a live connection straight to Convex while they use the app, and upload files straight to it, so Convex receives their network address and browser details. Visitors' browsers load a workspace's logo and page videos straight from Convex's file storage, so Convex receives their network address and browser details for those requests too.
  • Vercel hosts Rina's app and public pages, so every page request passes through it, with the visitor's network address. Its image service resizes the photos on public pages, fetching them from Convex, and keeps resized copies in its cache for a time, so a deleted photo can still be served for a while.
  • Vercel BotID checks for bots when someone sends an enquiry, applies to use Rina, sends a message to the AI assistant or creates an account. The page loads Vercel's check through Rina's own address, and Rina's server then asks Vercel about the request, sending its address, method and headers, which carry the visitor's network address and browser details, but not what the person typed. Of the request's cookies, it passes on only those whose names start with KP_. Rina uses only the yes-or-no answer, for that one request. Its server log notes, for each request the check lets through, whether Vercel reported the check as bypassed and Vercel's short reason for its answer, and, when the check itself fails, the error; never the request's address, headers or anything the person sent.
  • Resend sends Rina's email, when email is set up: copies of notices to members (an email about a new lead can include the lead's name and message), appointment emails to visitors who give an email address, and the billing documents members send, with the PDF attached. For each request to use Rina, it sends a notice to Rina's operators with the request's details, and to the address given, an automatic reply that says the request was received and repeats nothing typed in the form.
  • Mamo Pay takes card payments for Rina's own plans, on its own payment page. For a payment page, Rina's server sends Mamo Pay the amount, a title (the plan, or the invoice number), a reference and the pages to return to after paying or after a failed payment. For a renewal, a retry or added seats, it sends the saved card's reference, the amount and a reference. It never sends the payer's name, email or phone, or the workspace's name. It asks Mamo Pay to email the payer its own receipt, and to save the card, so that Rina can charge renewals later without the payer present. From Mamo Pay's answers it keeps each payment's reference and outcome, and the saved card's reference, last four digits and type.
  • Anthropic writes the AI assistant's replies, when a workspace turns the assistant on. It receives the visitor's messages, including any name, number or email they type, the assistant's earlier replies, the agent's and the workspace's names, the profile the agent approved for their assistant, and the published page details the assistant looks up, which include the agent's public profile (AI assistant notice). It also receives the text of a member's voice note, to draft their profile from, when they record one.
  • ElevenLabs turns a member's voice note into text, when the member records their AI assistant profile. It receives the recording, and nothing else about the member or the workspace. Rina deletes the recording from its storage as soon as it is transcribed, or could not be, and once ElevenLabs answers, even too late to use, asks it to delete its copy of the text, trying again if that fails.
  • WhatsApp (Meta) only when someone taps a WhatsApp button or link: their own device opens WhatsApp with a number and a message ready to send. Rina sends nothing to WhatsApp itself.
  • Calendar apps, if a member subscribes one to their private Rina calendar feed: the app fetches their appointments, with the kind, times and status, the visitor's first name and the listing's title and community, but never the visitor's phone or email.
  • Instagram, TikTok and other sites a member links to from their page are plain links. They receive nothing from Rina, only what the visitor's browser sends if the visitor opens one.

There are no advertising, analytics or tracking services in Rina.

[To be confirmed: Rina's agreements with each of these services (data processing terms), and where each of them processes data.]

[To be confirmed: what Vercel BotID's check collects in the browser, whether it sets cookies (Rina's server passes on cookies named KP_, which suggests it does) or browser storage, and how long Vercel keeps what it receives.]

[To be confirmed: what Mamo Pay collects on its payment page, how long it keeps it and the saved card, and what its receipt email shows.]

[To be confirmed: that Rina's ElevenLabs account has opted out of its use of recordings and their text to train its models, and how long ElevenLabs keeps them after Rina asks it to delete them.]

[To be confirmed: whether Rina takes payments in production yet: which payment service runs is a setting, not in the code.]

Emirates IDs and passports

  • Where they are: in a member's own vault (passports, Emirates IDs, residence visas and broker cards); in a deal's papers (the buyer's, seller's, tenant's or landlord's passport or Emirates ID); and as numbers on tenancy records (the tenant's Emirates ID), on property-owner records (an ID number) and on vault documents (the document's own number).
  • Who can open them: a member's vault, that member and the workspace's owners and admins, who can also add, change and delete documents in it. A deal's papers, the deal's agent and the owners and admins; colleagues paid on the deal see their share, not the papers. A tenancy, the agent managing the property and the owners and admins. A property-owner record, the agent who holds it and the owners and admins.
  • No public address: these files never get a web address. To open one, Rina gives the member a signed pass for them alone (a token, not a web address), which Rina's server checks before it hands over the file. It ends within two hours, and works only for that member while they are still active in the workspace with the same role; it also stops when a record with files is handed from them to another member.
  • Stored as uploaded: Rina checks a file's type and size, then keeps it exactly as it was uploaded, including any details inside the file, such as where and when a photo was taken.
  • In downloads: document numbers are included when the documents list is downloaded as a CSV file, unless that column is hidden. An owner's or admin's download of the team's vaults holds every member's numbers, suspended members' included.
  • Deleting them: a vault document a member deletes can be restored for 30 days, then the document and its file are removed. A member's vault documents stay after the member is suspended: the owners and admins can still open them until one of them deletes the document, and the member can no longer see or delete them. A deal's papers can be removed until the deal is closed or cancelled, and are kept after that; once any commission on the deal is invoiced, only owners and admins can remove one. A deleted property-owner record can be restored for 30 days, then it is removed. Tenancy records, with the tenant's Emirates ID, have no end date yet.

[To be confirmed: how long identity documents and ID numbers are kept after a deal, a tenancy or a membership ends.]

What public pages show

  • A member's published page shows their name, photo, headline, areas, languages, specialties, BRN and WhatsApp number (or their phone number if they gave no WhatsApp number). It shows their bio and social links unless they turn them off, their phone number and account email only if they turn them on, and a video and a booking link if they add them.
  • A listing on a public page shows its agent's name, photo, WhatsApp number (or phone number) and BRN, while the agent is an active member, even if the agent has not published a page of their own.
  • A workspace's page shows its name, logo, ORN (its licence number), headline and about text, and the members who have published their pages.
  • Listings show their public details and photos, the Trakheesi permit number and the reference number, never the unit number, title deed reference, Form A, the owner or commission.
  • Booking shows an agent's free times, not what fills the rest of their day.
  • Permanent web addresses: every member's profile photo, every photo and floor plan of a listing and every photo of an off-plan project has a permanent web address that anyone can open, with no sign-in, for as long as the file exists, whether or not it is on a public page: listings that are drafts or were never published included. So do logos and page videos. Public pages carry these addresses in their code.
  • Photos are kept exactly as uploaded, including any details inside the file, such as where and when a photo was taken, so anyone with a photo's address can read them.

Cookies and browser storage

  • Members who sign in get a session cookie, which keeps them signed in until about 30 days after they last used Rina, and a short-lived access token cookie (15 minutes, the sign-in library's default) for Rina's database.
  • If a member chooses a theme in the app (light, dark or system), the choice is kept in their browser's local storage, under the name rina-theme. Every page reads it, so it opens in that theme.
  • Visitors to public pages get no cookie and no browser storage from Rina's own code. The AI assistant keeps its conversation key in the page's memory only.
  • Some secret keys travel in web addresses: the AI assistant's conversation key, in each request the page makes for a reply; the link to a visitor's appointment; a member's calendar feed address; and invitation links. Each opens a conversation, an appointment or a member's calendar to whoever holds it, and passes through Vercel, which can keep request addresses in its logs.
  • An invitation link shows whoever holds it the workspace's name and kind, the role offered, who sent the invitation and a masked form of the invited email address. Joining needs an account signed in with the invited address, but while Rina's email is not set up, addresses are not confirmed, so whoever holds a link can create an account with that address and join; the inviter and the owners are told who did. While email is not set up, a link that gives admin or owner access lasts only a day; other links last a week.
  • There are no advertising or analytics cookies.

[To be confirmed: whether Vercel BotID's check, which runs when someone sends a form, a message to the AI assistant or creates an account, sets cookies or storage of its own.]

[To be confirmed: whether Vercel's request logs keep the addresses these keys travel in, and for how long.]

How long it is kept

  • Deleted leads, listings, property-owner records and vault documents can be restored for 30 days. Then they are removed for good: a lead with its timeline, tasks and appointments, a listing with its photos and Form A, a document with its file. A workspace's bin of deleted leads or owner records is also cleared early, oldest first, once it passes its limit.
  • AI assistant conversations are deleted 30 days after their last message, except the part copied to a lead when the assistant passes a visitor's details on: that stays on the lead's timeline until the lead is deleted, and in the agent's notice and email.
  • What each visitor's network spent on the AI assistant in a workspace, and the record of each reply being made for it, under a keyed code made from its network (IP) address, is kept until the day or month it counts for is over, then deleted by a daily job.
  • The text of a member's voice note is kept until they approve a profile, or 30 days after it was made, then deleted by a daily job; the member can delete it sooner. The recording itself is not kept. The profile stays until the member changes it.
  • Uploads never attached to anything are deleted by an hourly job once they are more than two hours old.
  • Daily page statistics rolled up for each member, listing and the workspace are kept for 400 days.

Kept with no end date yet:

  • accounts, profiles and memberships (a member's name stays with their history after they leave);
  • sign-in sessions that expired without signing out, with the browser of each (and its network address, if kept): nothing clears them on a schedule, and signing out deletes the session;
  • workspaces;
  • leads, with their timelines, tasks and appointments (an appointment holds the visitor's name, phone and email), listings and property-owner records, until a member deletes them;
  • vault documents, including passports and Emirates IDs, also after their member is suspended, until an owner or admin deletes them;
  • deals, with their papers and history, commission records, bank details for payouts, and payouts with the bank details copied at the time;
  • off-plan expressions of interest and bookings;
  • developers' contacts and contractors, even after they are removed or archived;
  • issued billing documents and landlord statements;
  • tenancies, completed inspections (with their photos and signatures) and maintenance requests;
  • notices, including the AI assistant conversations copied into them, and invitations;
  • requests to use Rina, with their history: nothing in Rina deletes them yet;
  • Rina's billing records: the plan, payment attempts, invoices and their PDFs, the history of changes and the notices to owners. The saved card's reference stays too, after a plan is cancelled or the workspace is read-only; Rina removes it only when a partner plan ends for a workspace that had no paid plan running before it;
  • records Rina uses to limit repeated attempts, which can hold an email address used to sign in, an email address an appointment email was sent to, the digits of a phone number used in an enquiry, a code made from the email address of a request to use Rina, and a keyed code made from the network (IP) address of each sign-in, sign-up, enquiry, request to use Rina, message to the AI assistant and page view, and of each booking request, with the member it was for;
  • the raw daily counts of page views and taps for each member's page and each listing, which identify no visitor.

[To be confirmed: how long each of these is kept, including what UAE law requires for financial and tax records.]

[To be confirmed: how long requests to use Rina are kept, including those that are turned down or never answered.]

Who can see what

  • Each workspace is kept apart from every other: nobody in one workspace can read another's records.
  • Inside a workspace each member is an owner, an admin or an agent. A record that belongs to a member, such as their leads, deals, documents, payouts and appointments, is private to them and the workspace's owners and admins. Owners and admins can see the records of every member in the workspace and change most of them; they cannot change a member's bank details or profile, a deal's history or the commission ledger. No screen shows them AI assistant conversations or other members' notices.
  • Leads: an agent sees their own. Every member can see which colleague already holds a lead with a given phone number, but not the lead itself.
  • Listings: every member sees the workspace's listings. The unit number, owner, title deed reference and Form A are seen only by the listing's agent and the owners and admins.
  • Colleagues: members see each other's name, email, BRN, phone or WhatsApp, languages and photo. A suspended member shows by name only. Developers' contacts and contractors are shared with every member.
  • Bank details: only the member and the workspace's owners and admins.
  • Requests to use Rina: only Rina's operators, whose own accounts are listed on Rina's server, never in a workspace.
  • How each member works: owners and admins see every member's figures on leads, response times, listings, commission and documents; an agent sees only their own.
  • Rina's billing: owners and admins see the plan, the invoices and the card's last four digits and type; only owners change the plan or pay. Agents see only the plan's name, when a trial ends and whether the workspace is read-only. No screen shows the history of changes, the payment attempts or the card's reference.

[To be confirmed: who at Rina can reach the live database and files, and how that access is recorded.]

Your choices and requests

  • Members can edit their own profile at any time.
  • Members can download the lists they can see as CSV files: leads, listings, owners, deals, billing documents, the team and documents. Owners and admins can also download agents, receipts and payouts.
  • Members can turn off email copies of notices for each workspace. A change to their own bank details is emailed to them even if they turned email copies off, when Rina's email is set up.
  • Members delete records in a workspace as described above. Rina has no button to delete an account or a workspace, and a member cannot leave a workspace on their own: an owner or admin suspends them. For the data in a workspace, ask that workspace's owner.
  • A visitor who booked a time can cancel it from the link they were given.

[To be confirmed: how to ask Rina for a copy of your data, a correction, deletion, or to object, who answers and within what time; and the legal basis for each use of personal data described here.]

Children

Rina's sign-up asks only for a name, an email address and a password. It asks for no date of birth.

[To be confirmed: a minimum age for accounts.]

Changes to this policy

[To be confirmed: how changes to this policy will be announced, and when they take effect.]

Contact

[To be confirmed: how to contact Rina about privacy.]