[PRIVACY POLICY]

Privacy Policy

This policy explains what personal data ielaan collects, how we use it, who we share it with, and your rights as a data subject.

Last updated: July 9, 2026·Effective: July 9, 2026
SECTION 01

1. Overview

ielaan operates an on-demand marketplace for smart LED screen advertising, currently available in Pakistan and Saudi Arabia. This Privacy Policy describes how ielaan Technologies Pvt Ltd ("ielaan", "we", "us") collects, uses, and protects personal data from advertisers, space owners, agencies, and visitors to ielaan.com.

By creating an account or using the Platform, you acknowledge you have read and understood this policy. If you do not agree, please do not use the Platform.

Data controller: ielaan Technologies Pvt Ltd. Questions? Email privacy@ielaan.com — we aim to respond within 5 business days.

If you use the ielaan Android Screen Client (space owners), additional device-level data is collected as described in the Android Client Privacy Addendum available in the app settings.

SECTION 02

2. Information We Collect

2.1 Data you provide directly

  • Account data: name, email address, phone number, company name, role (advertiser / space owner / agency).
  • KYC documents (space owners above payout thresholds): national ID number, business registration number, tax ID. These are encrypted at rest using AES-256 field-level encryption.
  • Payment data: billing address, last-4 of card (Stripe tokenises full card numbers — we never see or store them), bank account details for payout (space owners).
  • Ad creatives and campaign data: uploaded images/videos, campaign names, scheduling preferences, targeting criteria.
  • Venue & listing data: venue name, address, photos, screen specifications, operating hours, pricing.
  • Communications: messages sent via the in-platform chat (proposals, dispute evidence), support tickets, and emails you send to us.
  • AI Studio inputs: prompts you submit to generate ad creatives; generated outputs are stored in your campaign library.

2.2 Data we collect automatically

  • Usage data: pages visited, features used, clicks, time on page, campaign creation/booking events.
  • Device & browser data: IP address, browser type and version, operating system, referring URL, session ID.
  • Cookie data: see our Cookie Policy for a full list of cookies and their purpose.
  • Screen heartbeat & Wi-Fi RF data (Android client): device ID, connectivity status, screen-on/off events, and play-event logs (ad ID, timestamp, duration). Each heartbeat also includes aggregate Wi-Fi environment statistics: visible access-point count, RSSI summary statistics (min, max, mean), band distribution (2.4 GHz / 5 GHz / 6 GHz counts), connected network link speed and frequency, and scan-cache age. No BSSIDs, SSIDs, or MAC addresses are ever collected or stored. This data is used for campaign delivery verification, dispute resolution, and occupancy research.

2.3 Data from third parties

  • Stripe: payment status, transaction reference ID, payout schedule. We do not receive raw card data.
  • Google Maps Platform: geo-coordinates are validated against the Google Maps API when you submit a venue listing.
  • OpenAI: if you use the AI Creative Studio, your prompts are sent to OpenAI's API. OpenAI's data use is governed by their privacy policy. We do not send identifiable personal data in prompts.
  • Firebase Cloud Messaging: push notification tokens for the Android client.
Purpose
Legal Basis
Provide and operate the Platform
Contractual necessity
Process payments and release escrow
Contractual necessity
Verify identity and prevent fraud (KYC)
Legal obligation / Legitimate interest
Send transactional notifications (booking confirmations, payout notices, dispute alerts)
Contractual necessity
Moderate ad content and enforce content policies
Legitimate interest
Run dispute resolution and generate evidence reports
Contractual necessity / Legal obligation
Improve Platform features and fix bugs
Legitimate interest
Send product updates and marketing emails (opt-out available)
Consent / Legitimate interest
Comply with legal obligations (tax records, anti-money laundering)
Legal obligation
Generate AI ad creatives via OpenAI API
Contractual necessity / Consent
Analyse campaign performance and provide reporting
Contractual necessity
Detect and prevent security incidents
Legitimate interest
Conduct privacy-preserving Wi-Fi occupancy research and generate estimated venue occupancy levels from aggregate Wi-Fi RF statistics to inform ad-slot pricing recommendations and campaign scheduling. These are venue-level statistical estimates — no individual person's device is identified or tracked.
Legitimate interest

We never sell your personal data to third parties. Occupancy estimates produced by our Wi-Fi model are venue-level statistical inferences based on aggregate RF data from the screen device; they do not identify or track any individual. We do not use your data for automated decision-making that produces legal or similarly significant effects without human oversight.

SECTION 03

3. How We Use Your Information

We share personal data only in the following circumstances:

SECTION 04

4. Sharing & Disclosure

  • With counterparties to a booking: advertisers can see the venue name, address, and screen specs of a space owner's listing. Space owners can see the advertiser's business name and campaign creative for approved proposals. Neither party sees the other's payment details.
  • With payment processors: Stripe (global), EasyPaisa/JazzCash (Pakistan), mada/STC Pay (Saudi Arabia). Data shared is limited to what is required to process the transaction.
  • With AI service providers: OpenAI receives prompt text submitted to the AI Studio. No account identifiers are included in the prompt payload.
  • With legal / regulatory authorities: where required by law, court order, or to protect the rights of ielaan or third parties.
SECTION 05

5. Payments & Financial Data

Financial data is handled with additional safeguards:

ielaan uses Stripe Connect as its primary payment processor. Stripe is PCI-DSS Level 1 certified. We never store raw card numbers on ielaan servers. Payout bank details (space owners) are encrypted at rest using AES-256 field-level encryption, accessible only to authorised finance staff.

Transaction records are retained for 7 years from the date of transaction to comply with financial reporting and anti-money laundering regulations in Pakistan and Saudi Arabia.

SECTION 06

6. Cookies & Tracking

We use cookies and similar local-storage mechanisms to operate the Platform, maintain your session, remember your locale preference, and measure usage. A full description of cookies, their purpose, and how to control them is available in our Cookie Policy.

We do not use third-party advertising trackers or sell cookie data to ad networks.

SECTION 07

7. Data Retention

Cookie
Duration
Account data: retained for the lifetime of your account, plus 90 days after closure (to allow reactivation), then deleted.
Maintains your authenticated session
Campaign & booking records: retained for 7 years from campaign end date for financial and legal compliance.
Prevents cross-site request forgery attacks
KYC documents: retained for 7 years from last payout, as required by AML/CTF regulations.
Remembers your language/region preference
Chat messages and dispute evidence: retained for 2 years from dispute closure date.
Stores your cookie consent choice
  • Ad creatives: retained in your campaign library for 30 days after campaign expiry, unless you save them. Deleted creatives are purged from our media storage within 30 days.
  • Usage logs: aggregated and anonymised after 90 days; raw logs deleted after 12 months.
  • Device heartbeat & play-event logs: retained for 2 years for campaign delivery verification.
  • Cookies: see Cookie Policy for per-cookie durations.
  • Marketing email consent: retained until you withdraw consent (via unsubscribe link).
  • AI Studio prompts and outputs: retained for 90 days, then deleted.
  • Wi-Fi occupancy observations: aggregate RF environment statistics and manually entered people-count records collected during the occupancy research experiment. Retained for 3 years from collection date, then anonymised and aggregated.
SECTION 08

8. Security

ielaan implements industry-standard security measures to protect your personal data:

  • Encryption in transit: all data between your browser, ielaan servers, and third-party APIs is transmitted over TLS 1.2+ (HTTPS).
  • Encryption at rest: sensitive fields (KYC ID numbers, payment account details) use AES-256 field-level encryption. General data is stored on encrypted volumes.
  • Access controls: internal access to personal data is role-based and limited to staff who require it. Production data is never accessed in development environments.
  • Penetration testing: we conduct annual penetration tests on the Platform and remediate findings within defined SLA windows.
  • Incident response: in the event of a data breach affecting your personal data, we will notify you and relevant supervisory authorities within 72 hours of becoming aware, as required by applicable law.
  • mTLS between internal services: service-to-service communication in our production environment uses mutual TLS to prevent unauthorised inter-service calls.

Despite these measures, no system is completely secure. If you discover a security vulnerability, please report it responsibly to security@ielaan.com.

SECTION 09

9. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Right of access: request a copy of the personal data we hold about you.
  • Right to rectification: request correction of inaccurate or incomplete data.
  • Right to erasure: request deletion of your data, subject to our legal retention obligations.
  • Right to restriction: request that we limit processing of your data in certain circumstances.
  • Right to data portability: receive your data in a structured, machine-readable format.
  • Right to object: object to processing based on legitimate interests, including direct marketing.
  • Right to withdraw consent: where processing is based on consent, withdraw it at any time without affecting prior processing.

To exercise any of these rights, email privacy@ielaan.com with your full name and the email address on your account. We will respond within 30 days. Identity verification may be required before fulfilling your request.

SECTION 10

10. International Transfers

ielaan's primary data processing infrastructure is hosted on AWS in the ap-south-1 (Mumbai) and me-south-1 (Bahrain) regions, chosen for proximity to our operating markets. Some data (AI processing via OpenAI, payments via Stripe) is processed in the United States. For users in the Kingdom of Saudi Arabia, we ensure transfers outside the Kingdom comply with the Personal Data Protection Law (PDPL) requirements, including the use of Standard Contractual Clauses or equivalent safeguards where required.

SECTION 11

11. Children's Privacy

The Platform is not directed to persons under 18. We do not knowingly collect personal data from minors. If we become aware that a minor has provided personal data, we will delete it promptly. If you believe a minor has registered, contact us at privacy@ielaan.com.

SECTION 12

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email and an in-app notification at least 14 days before they take effect.

The "Last updated" date at the top of this page reflects the most recent revision. We encourage you to review this policy periodically.

SECTION 13

13. Contact Us

For privacy-related requests or questions:

ielaan Technologies Pvt Ltd
Data ControllerPrivacy Enquiries
General Supportsupport@ielaan.com
Registered Address: Karachi, Pakistan & Riyadh, Saudi Arabia
Privacy Policy — ielaan | ielaan