1. Who this covers
This policy explains what Al-Haytham collects when you use the platform, why, and the choices you have. Al-Haytham is operated from Pakistan. By using the service you agree to this policy alongside our Terms of Service.
2. What we collect
We keep collection to what we need to run the service:
- Your email address — to create your account, sign you in, and send essential service messages (like a verification link).
- Your password — stored only as a salted, hashed value. We never store, and cannot see, your actual password.
- The business data you enter — orders, hostel records, payroll, ledger entries, partners, and the rest of the books you build inside your workspace.
- Basic technical data — minimal information needed to keep the service secure and working, such as the IP address a request comes from (used, for example, to limit abuse of the signup form).
3. Your data is isolated per tenant
Al-Haytham is multi-tenant, and tenant isolation is built into the foundation — not bolted on. Each organisation’s data lives behind row-level security in the database, so one business can never see another business’s records. Your books are yours alone. This isolation is a core design principle of the platform, and one of the reasons we built it the way we did.
4. How we use your data
We use what we collect only to:
- provide, secure, and improve the service;
- sign you in and keep your session active;
- send essential account and service messages;
- prevent fraud and abuse, and meet our legal obligations.
We do not sell your data. We do not sell or rent your personal information or your business records to anyone.
5. Cookies
We use cookies only for the essentials — chiefly to keep you signed in and to keep your session secure. These are required for the app to work, so we do not need a separate consent banner for them. We do not use advertising or cross-site tracking cookies.
6. Service providers
We rely on a small number of trusted providers to run the platform — for example, cloud database hosting, and an email provider to deliver verification messages. They process data only on our instructions and only to help us deliver the service.
7. Keeping your data safe
We take reasonable measures to protect your data, including hashed passwords, tenant isolation, and access controls. No system is perfectly secure, but security is a first-class concern in how Al-Haytham is built and operated.
8. Accessing or deleting your data
Your data is yours. You can export or request a copy of the records in your workspace, and you can ask us to delete your account and its data. To make a request, email support@alhaytham.app from the address on your account, and we will help. We may keep limited records where the law requires it.
9. Changes to this policy
We may update this policy as the product and the law evolve. When we make a material change, we will update the date at the top of this page. Continuing to use Al-Haytham after a change means you accept the updated policy.
10. Contact
Questions about your privacy, or want to make a request? Email us at support@alhaytham.app.