1. Who We Are
Baab Rizq (باب رزق / baabrizq.com) is a job marketplace that connects job seekers with employers in Iraq. In these legal documents, the service is identified only by the brand name “Baab Rizq.” For privacy questions, contact info@baabrizq.com.
2. Scope
This policy applies to baabrizq.com, the Baab Rizq iOS and Android apps, and the APIs that power them. Third-party websites or apps we link to (for example payment provider pages or social login screens) have their own policies.
3. Account and Identity Data
Depending on how you register or sign in, we may process: full name; email address; phone number in E.164 format; a hashed password (we do not store plaintext passwords); account type (seeker or employer); preferred language (locale); country and phone dialling metadata; industry, governorate, and city selections; company name for employer accounts; and records that you accepted the terms.
4. Authentication Methods
We support: (1) email or phone with password; (2) WhatsApp one-time passwords (OTP) sent through Meta’s WhatsApp Business Cloud API—OTP security records may include phone number, a hashed code, request IP, and short retention for anti-abuse; (3) Google Sign-In with email and profile scopes—we may receive Google user id, email, email verification status, name, profile picture URL, and locale; (4) Facebook Login with email and public_profile permissions—we may receive Facebook user id, email (when Facebook provides it), name, and picture. Linked social accounts may store provider name, provider user id, provider email, and related verification metadata. Facebook SDK auto-logging of app events is disabled in our Android configuration.
5. Profile, Resume, and Company Data
Seekers may add professional profile fields such as headline, about text, date of birth, gender, address, skills, languages, hobbies, years of experience, employment-type preferences, training courses, and an optional map pin (latitude/longitude). You may upload a profile photo and resume files (PDF, DOC, or DOCX, size-limited). Employers may create company profiles including name, logo, cover image, about, website, contact email and phone, address, map coordinates, industry, location taxonomy, company size, and social links. Files are stored on our configured storage (Microsoft Azure Blob Storage and/or our own servers).
6. Location
We use two kinds of location data: (a) Structured location you select from our lists (governorate, city, and related fields) during registration, profile completion, company setup, and job posting. (b) Device location on mobile: if you grant permission, the app may read approximate GPS coordinates (when-in-use only) to help show nearby jobs and companies on the map, and may temporarily cache recent coordinates on the device. We do not request always-on background location.
7. Job Applications and Interviews
When you apply for a job we process the job reference, an optional linked resume, any cover note you write, application status history, and employer-side notes, tags, or ratings where that feature is used. Interview details set by employers (time window, location or meeting URL, rejection reason) may be stored and shown to the parties involved.
8. Messages
Application-related messaging between seekers and employers stores text message bodies with sender and thread metadata. Realtime delivery uses Pusher private channels. Baab Rizq chat does not provide in-app voice or video call recording.
9. Payments
Optional paid features may include premium CV generation, job listing promotions, and candidate premium subscriptions. Payment methods we integrate today: Stripe (card Checkout Sessions, PaymentIntents, and subscriptions—we do not receive full card numbers; we may store Stripe customer and subscription identifiers and limited receipt metadata such as card brand/last4 from Stripe events); and Zain Cash (mobile wallet; callbacks may include transaction identifiers and payer MSISDN). Stripe subscriptions may renew until cancelled under Stripe’s billing rules.
10. Notifications
On mobile we use Firebase Cloud Messaging (with Apple and Google push infrastructure) to deliver push notifications you are eligible for. We store device push tokens and platform (iOS or Android) associated with your account. The apps may also use Firebase Analytics and PostHog to measure product usage (screens, funnels, and account role) without collecting advertising IDs for ads or enabling App Tracking Transparency for advertising.
11. Technical and Security Logs
We may process IP address, User-Agent, and similar request metadata for security, rate limiting, abuse prevention, and limited first-party funnel/event logging we store ourselves and/or optional product analytics tools (for example PostHog and Firebase Analytics on mobile; Google Analytics/GTM, Microsoft Clarity, and PostHog on the website after you choose “Accept all” cookies). We do not currently ship Mixpanel, Amplitude, or Sentry SDKs, and we do not track advertising IDs for advertising purposes.
12. How We Use Information
We use personal information to create and secure accounts; verify phone ownership; operate profiles, jobs, applications, and company pages; enable messaging; process payments you initiate; send transactional notices and push alerts you enable; maintain reliability and prevent fraud or abuse; meet legal obligations; and respond to access, export, and deletion requests.
13. Legal Bases (GDPR-Style)
Where GDPR or similar frameworks apply, we rely on: performance of a contract (providing the marketplace account and features you request); consent (for example optional device location, cookie choices beyond essential, and permissions you grant to Google or Facebook); legitimate interests (security, service integrity, limited first-party operational analytics); and legal obligation where applicable.
14. Sharing
We do not sell your personal data. Depending on the feature, processing may involve: Meta (Facebook Login and WhatsApp OTP delivery); Google (Sign-In and Firebase Cloud Messaging); Stripe; Zain Cash; Microsoft Azure (file storage when enabled); Pusher (realtime messaging); and hosting or email providers we use to run the service. Employers you apply to or message can see the application, profile, resume, or message content you share through the product.
15. Cookies and Similar Technologies (Website)
Essential HttpOnly session cookies named br_at (short-lived access token) and br_rt (refresh token) keep you signed in. We store a baabrizq_cookie_consent preference cookie. The site also uses browser localStorage/sessionStorage for language and theme preferences, temporary registration or login drafts, and similar UX state. Optional analytics tools (such as Google Analytics/GTM, PostHog, and Microsoft Clarity) load only if operators configure them and you choose “Accept all.” Full details are in the Cookie Policy at /legal/cookies/ on baabrizq.com.
16. Mobile On-Device Storage
The apps store access and refresh tokens in encrypted secure storage (Keychain/Keystore). Preferences storage may hold locale, theme, an optional remember-me identifier, and a short-lived on-device location cache.
17. Retention
We keep account data while your account is active and as needed after account closure for security, disputes, payments, and legal requirements. OTP security records, technical logs, and payment-related records are retained as needed for those purposes. Uploaded files remain while required for account features or until you delete or replace them.
18. Your Rights
You may update much of your information in profile and settings tools. Where available in the product, you can download a JSON export of personal data associated with your account. You may close your account through in-app account deletion: when you request deletion, the account is immediately deactivated and becomes inaccessible; credentials and primary contact fields are cleared as designed; sessions and push tokens are revoked; and linked social logins are removed. Certain information may be retained for a limited period where required for legal, security, fraud prevention, payment, or regulatory purposes, after which remaining personal data is permanently deleted or anonymized. Steps are described in the Data Deletion Policy at /legal/data-deletion/ and, for Facebook Login, at /facebook-data-deletion/ on baabrizq.com. For other requests, email info@baabrizq.com. We may verify your identity.
19. Children
Baab Rizq is not directed to children under 16 (or a higher age if required by local law). Do not create an account if you are under the applicable age.
20. Security
We use HTTPS/TLS in transit, password hashing, secured session cookies or tokens, and access controls. No online service is perfectly secure.
21. International Transfers
Some providers (including Google, Meta, Stripe, Azure, and Pusher) may process data in countries other than Iraq. We rely on the contractual and technical safeguards customary for those services.
22. Changes
We may update this Privacy Policy when our practices or the product change. Material updates will be reflected by the date shown on this page.
23. Contact
Privacy questions and data rights requests: info@baabrizq.com