Privacy Policy
Last updated: 29 March 2026
1. Introduction
AL-MUDIR Wealth and Fintech Ventures ("Company", "we", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal information when you use our platform ("Service").
2. Information We Collect
2.1 Information You Provide
- Account Data: Name, email address, phone number, and password during registration.
- KYC Documents: Government-issued identification, proof of residence, date of birth, and nationality when submitting identity verification.
- Financial Data: Broker account identifiers, wallet addresses, and transaction records.
- Profile Data: Profile pictures and display preferences.
2.2 Information Collected Automatically
- Session Data: IP address, browser type, device identifiers, and session timestamps.
- Usage Data: Pages visited, features used, and interaction patterns via Vercel Analytics.
3. How We Use Your Information
- To create, maintain, and secure your account.
- To verify your identity and comply with anti-money laundering (AML) and know-your-customer (KYC) regulations.
- To process transactions and display portfolio data.
- To send security alerts, OTP codes, and system notifications via email, SMS, or Telegram.
- To improve our Service through analytics and usage patterns.
- To detect, prevent, and respond to fraud, security threats, or technical issues.
4. Data Storage & Security
Your data is stored using AES-256-GCM encryption at rest. Passwords are hashed using PBKDF2-SHA256 with 100,000 iterations and unique random salts. Session tokens are cryptographically generated 256-bit values.
We use secure, encrypted communication channels (TLS 1.2+) for all data in transit. Access to stored data is restricted to authorized systems only.
5. Data Sharing
We do not sell your personal data. We may share information with:
- Third-Party Brokers: Broker name and account ID when you link a trading account.
- Service Providers: Email delivery (Resend), SMS (Twilio), and notification services (Telegram) necessary to operate the Service.
- Legal Authorities: When required by law, subpoena, or court order.
6. Data Retention
We retain your account data for the duration of your account and for up to 5 years after account closure as required by applicable financial regulations. Session data is automatically purged after 24 hours of inactivity. OTP codes expire after 10 minutes.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access and obtain a copy of your personal data.
- Rectify inaccurate or incomplete data.
- Request deletion of your data (subject to legal retention requirements).
- Withdraw consent for optional data processing.
- Object to automated decision-making.
To exercise any of these rights, contact us at privacy@al-mudir.com.
8. International Transfers
Your data may be processed in jurisdictions outside your country of residence, including the United Arab Emirates. We ensure appropriate safeguards are in place for international transfers in compliance with applicable data protection laws.
9. Children's Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from minors. If we learn that a minor has provided us with personal data, we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via the platform or email. The "Last updated" date at the top indicates the most recent revision.
11. Regulatory & Registration Details
Licensing and UAE registration references are maintained by our Compliance function and presented below for baseline due diligence.
- TLN Permit Number: 620822
- Registered Office: ABT 5 Tower, Office 1003, Mamzar, Sharjah, UAE
- Compliance Contact: legal@al-mudir.com
12. Contact
For privacy-related inquiries, contact our Data Protection Officer at privacy@al-mudir.com.