Privacy Policy
The short version. We collect what we need to run your audit and send you the report. We keep it so a re-check is possible. We do not sell it, and we do not build advertising profiles. We never see your card details.
1. Who is responsible
Tabyian, a service operated by an individual based in Amman, Jordan, trading as Tabyian, is the controller of the data described here. Contact: privacy@tabyian.com.
2. What we collect
When you order
- Your name and email address
- The business name, business type, city and country
- The business website address
- The services the business sells
- Up to three competitor names and websites
- A referrer code, if you arrived through one
When you use the free check
The free check on the landing page takes a business type and a city. To stop it being abused we limit it to three checks per visitor per day. We do this by hashing your IP address with a secret salt and storing only the hash — the address itself is never written down, and the hash cannot be reversed back into one.
When you open your report
We record that a section of a report was viewed: the audit it belongs to, the section name, and the time. Deliberately nothing else — no IP address, no user agent, no identifier that could follow you anywhere. We use it for one thing: to know whether to send you a "you haven't opened it yet" reminder.
What we do not collect
Card numbers, bank details or billing addresses. Those go to Paddle and never reach our servers.
3. Why we hold it, and on what basis
- To perform the contract — running the audit, generating the report, delivering it, and running the re-check you paid for
- Legitimate interest — a small number of follow-up emails about your own report, fraud and abuse prevention, and rate-limiting the free check
- Legal obligation — records connected with payments, which Paddle holds as Merchant of Record
4. Who your data is shared with
Running the audit necessarily involves third parties. In plain terms, the business name and city you give us are put into questions that are sent to AI services, because that is the measurement you are buying.
- OpenAI, Google (Gemini) and Perplexity — receive the generated buyer questions, which contain the business name, service type and city. They do not receive your email address or contact details
- Anthropic — writes the Arabic prose from the measured facts file, and reviews it. The facts file contains the business details and the measurements
- Paddle — Merchant of Record. Takes payment, holds card and billing data, issues the invoice
- Resend — sends the emails, and therefore processes your email address
- Cloudflare — stores report artifacts and serves the site
- Railway — hosts the application and the database
We also fetch your website and your named competitors' websites, publicly, the way a search engine does, respecting robots.txt.
We do not sell your data, and we do not share it for advertising.
5. How long we keep it
- Audit data and reports — kept so a re-check can compare against your baseline, and so your report link keeps working. The day-85 re-check specifically re-asks the same questions recorded in your original audit, which is why the original is retained
- Free-check hashes — cleared on a rolling daily basis
- Cached free-check answers — 24 hours
- Payment records — retained by Paddle under their own policy and the law that applies to them
You can ask us to delete your audit data at any time. Doing so means a future re-check has nothing to compare against.
6. Your report link
Report links use a long random code. They are not sequential, not guessable, and not indexed by search engines. A request for a code that does not exist gets exactly the same response as one that does, so the site cannot be used to discover whether a report exists. Anyone who has your link can read the report, so treat it as confidential.
7. Cookies
We do not use advertising or analytics cookies. If you arrive through a referral link, the referrer code is stored in your browser so it can be applied at checkout. That is the only thing we store on your device.
8. Your rights
You may ask us to give you a copy of your data, correct it, delete it, or stop sending you follow-up emails. Email privacy@tabyian.com and we will respond within 30 days. Every email we send has an unsubscribe option.
Depending on where you live you may also have a right to complain to a data protection authority.
9. International transfers
We operate from Jordan and the services listed in section 4 are based mainly in the United States and the European Union. Using this service means your data is processed in those places.
10. Security
The site is served over HTTPS. Secrets are held in environment variables and never in our source code. Admin pages are password-protected. Visitor IP addresses used for rate-limiting are hashed and salted rather than stored.
11. Changes
If this policy changes materially we will update the date at the top of the page. Substantial changes affecting existing customers will be emailed.
Tabyian
Amman, Jordan
privacy@tabyian.com