← Raabta

Privacy Policy

Version 2026-09-07 · in effect from 7 September 2026

What we hold, why, who else can see it, and what you can ask us to do about it. Anything unclear, ask us at support@raabta.agency.

1. What this covers

This policy explains what personal data Raabta handles, why, who else can see it, how long it is kept, and what you can ask us to do about it. It applies to raabta.agency and to the Raabta application.

It sits alongside our Terms of Service. Where the Terms describe the agreement, this describes the data.

2. Two kinds of data, and two different roles

This is the distinction the rest of the policy rests on, and it is the one most privacy policies blur.

The first kind is data about the people who USE Raabta — an agency owner, an admin, an agent. We decide what we collect and why, so for that data we are the controller.

The second kind is data about the people your agency DEALS WITH — leads, buyers, tenants, landlords, contacts. You decide what to collect, why, and how long to keep it. For that data you are the controller and we are only your processor: we hold it and show it back to you on your instructions, and we do nothing else with it.

  • Why it matters to you. If one of your clients asks to see or delete their data, that request is yours to answer, not ours. We will help you find and export it, but the duty and the deadline are yours.
  • Why it matters to them. It means nobody at Raabta is deciding anything about your clients. We cannot market to them, profile them, or pass them to anybody.

3. What we collect about you

When you create an account and use it, we hold:

  • Your identity. Name, email address, the agency you belong to, your role, and whether your account is active, paused or removed.
  • Sign-in data. Handled by Google Firebase Authentication. Where you sign in with a password we never see it; where you use Google, we receive your name and email address and nothing else.
  • What you did. The activity trail a CRM is for: which lead you called, what you logged, when. It is your agency's own audit record and it is visible to you.
  • Billing. Your plan, seat count, invoices and payment outcomes. Card numbers are held by Stripe and never reach us.
  • Technical data. Server logs, IP address and error reports, kept to keep the service running and secure.
  • What you send us. Support messages and anything you attach to them.

4. What we hold on your behalf

This is your clients' data, held under your instructions: names, phone numbers, email addresses, budgets, areas, requirements, the notes your agents write, call outcomes, the text of messages sent through the product, viewings, deals and any documents you upload.

We do not decide what goes in here. If you collect something you should not have, that is a decision made on your side of the line — see section 11 of the Terms.

5. Where it comes from

Directly from you and your team as you work. From your public enquiry form, when somebody fills it in. From a portal or another tool you connect to the lead webhook. From an integration you switch on, such as BedFlow, where you have connected it yourself.

We do not buy data, we do not scrape it, and we do not enrich your records from third-party sources.

6. Why we process it, and on what basis

For data where we are the controller:

  • To provide the service — performance of a contract. Running your account, storing your work, showing it back to you, taking payment.
  • To keep it secure — legitimate interests. Detecting abuse, rate limiting, investigating incidents, keeping audit records.
  • To support you — legitimate interests. Answering your questions and fixing faults.
  • To meet the law — legal obligation. Keeping invoices and tax records for as long as we are required to.
  • Phone alerts — consent. Push notifications are off until you switch them on, per device, and you can switch them off at any time.
  • To improve the product — legitimate interests. Aggregate, anonymised usage statistics only. Nothing that identifies you, your agency or any client.

7. What we do not do

Some of this is worth saying plainly, because a privacy policy that only lists permissions tells you very little.

  • No advertising or analytics trackers. Raabta loads no Google Analytics, no advertising pixel, and no third-party analytics or session-recording script of any kind.
  • No selling or sharing. We do not sell personal data, we do not rent it, and we do not share it between agencies on the platform.
  • No AI training on your data. Where an AI feature is used, the content is sent to the provider to produce that answer and is not used to train models.
  • No profiling and no automated decisions. Nothing in Raabta makes a decision about a person that has a legal or similarly significant effect on them.

8. Cookies and browser storage

Raabta uses no advertising or analytics cookies, so there is no consent banner — there is nothing to consent to.

What the app does store in your browser is the minimum needed to work:

  • Your sign-in session. Firebase Authentication keeps a token so you stay signed in between visits. Signing out clears it.
  • Small preferences. Things like how many rows you last chose to see. They never leave your device.
  • reCAPTCHA. Where Firebase App Check is enabled, Google reCAPTCHA runs to confirm requests come from the real app and not from a script. It is a bot check, not a tracker, and it operates under Google's own privacy terms.

9. Who else can see it

Inside your agency, access is decided by role and enforced by the database itself, not by the interface: an agent sees the leads assigned to them, a manager sees the desk, and the mailbox and integration secrets are readable only by the owner.

Outside your agency, only the sub-processors below, each under contract and each doing one job:

WhoWhat they doWhere
Google (Firebase)Database, authentication and file storageGoogle Cloud, multi-region
VercelApplication hosting and deliveryGlobal edge network
StripeSubscription payments and card storageIreland and the United States
AnthropicThe AI writing and summarising features, when usedUnited States
Your own mail providerSending and receiving email you connectWherever you host it

10. Where your data is stored

On Google Cloud infrastructure through Firebase, and delivered through Vercel. This means personal data may be stored or processed outside the United Arab Emirates, including in the European Union and the United States.

Those transfers rely on the safeguards those providers operate, including standard contractual clauses where they apply. By using Raabta you agree to this transfer.

11. How long it is kept

While your account is active, your data is kept so you can use it — a CRM whose history quietly expires is not a CRM.

  • After you cancel. 30 days, so you can export it or change your mind.
  • Then deleted. Backups age out on their own cycle within a further 90 days.
  • Invoices and payment records. Kept for as long as UAE law requires, and used for nothing else.
  • Sooner on request. Write to support@raabta.agency and we will delete, subject to those legal retention duties.
  • Your clients' retention is your decision. You decide how long to keep a lead. Delete it in the product and it is gone from ours.

12. How it is protected

Access rules run on the server on every read and every write, so what somebody can see is decided by the database and cannot be changed from a browser. One agency can never read another's records.

Traffic is encrypted in transit with HTTPS and HSTS; data at rest is encrypted by our infrastructure providers. Mailbox passwords and integration keys are readable only by the agency owner. Card numbers never reach us.

Section 11 of the Terms sets out the part of this only you can do — passwords, two-factor authentication, and removing people the day they leave. Most incidents in systems like this start there rather than in the software.

13. Your rights

Under the UAE Personal Data Protection Law, and under the GDPR where it applies to you, you can ask us to:

  • Show you what we hold. A copy of your personal data and an explanation of what we do with it.
  • Correct it. Fix anything inaccurate or incomplete.
  • Delete it. Erase it, where we are not required to keep it.
  • Restrict or object. Stop or limit a particular use, including anything we do on the basis of legitimate interests.
  • Take it elsewhere. Receive it in a portable format. The product's own export tools do this for your working data without having to ask.
  • Withdraw consent. Where we relied on consent — phone alerts — switch it off without affecting anything done before.

14. If you are somebody an agency has on Raabta

If a real estate agency holds your details in Raabta and you want to see, correct or delete them, contact that agency. They decided to collect your data and they are the controller of it; we hold it for them and are not permitted to change or release it on our own initiative.

If you do not know which agency it is, or they do not respond, write to support@raabta.agency and we will do what we can to identify them and pass your request on.

15. Children

Raabta is a business tool and is not directed at children. Accounts require you to be at least 18. If we learn we hold a child's personal data without a lawful basis, we will delete it.

16. If something goes wrong

If a security incident affects personal data, we will tell you without undue delay, say what we know and what we are doing, and give you what you need to meet your own notification duties.

Where you are the controller — your clients' data — deciding whether to notify the UAE Data Office or the individuals is your call and your deadline.

17. Changes to this policy

We may update this policy. The version and date are at the top, and the version current on the day you signed up is recorded against your profile. For material changes we will give reasonable notice in the product, by email, or both.

18. Contact and complaints

For any question about this policy, to exercise a right, or to report a security problem: support@raabta.agency. Security reports are answered first.

If you are not satisfied with our answer you can complain to the UAE Data Office, or to your local data protection authority where the GDPR applies to you.

Version 2026-09-07. The version current on the day you created your account is the one recorded against your profile.