سي بي ام للشحن
سياسة الخصوصية

سياسة خصوصية تطبيق CBM Shipping

تُوضّح هذه السياسة ما البيانات التي يتعامل معها تطبيق موظفي سي بي ام للشحن، وكيف نستخدمها ونحميها، وما البيانات التي لا نجمعها إطلاقاً، وكيف تطلب حذف حسابك.

📅  تاريخ السريان:  12 أغسطس 2026
🔄  آخر تحديث:  12 أغسطس 2026
🏢  المُشغِّل:  CBM Shipping — سي بي ام للشحن
1

نبذة عن هذه السياسة

تنطبق سياسة الخصوصية هذه على تطبيق CBM Shipping للهواتف (Android وiOS)، وهو تطبيق داخلي مخصَّص لموظفي شركة سي بي ام للشحن لإدارة عمليات الشحن اليومية: استلام البضائع، الشحنات، التسليم، الرحلات والحاويات.

لا يتوفر في التطبيق تسجيل ذاتي: حسابات الدخول تُصدرها إدارة الشركة لموظفيها فقط، ولا يمكن لعامة المستخدمين إنشاء حساب أو استخدام التطبيق.

باستخدامك للتطبيق بصفتك موظفاً فإنك تُقرّ بأنك اطّلعت على هذه السياسة. وإن كانت لديك أي ملاحظة عليها فيمكنك التواصل معنا عبر القنوات المذكورة في نهاية الصفحة.

2

من نحن

تطبيق CBM Shipping تُشغِّله وتُديره شركة سي بي ام للشحن (CBM Shipping)، وهي شركة شحن ولوجستيات، وتُعدّ الجهة المسؤولة عن معالجة البيانات المذكورة في هذه السياسة (المتحكم بالبيانات).

التطبيق واجهة ميدانية لنظام الشركة الداخلي: البيانات التي يعرضها أو تُدخَل من خلاله تُحفَظ في خوادم النظام المركزي للشركة، وتخضع لضوابط الصلاحيات نفسها المطبَّقة على نظام الشركة.

📮 لأي استفسار حول البيانات التي نحتفظ بها، تواصل معنا على:
البريد الإلكتروني: info@cbmforlogistic.com
الهاتف / واتساب: +967 781 555 703
3

البيانات التي يتعامل معها التطبيق

يتعامل التطبيق مع الحد الأدنى من البيانات اللازم لأداء العمل. يُلخِّص الجدول التالي الفئات والغرض من كل منها:

فئة البياناتأمثلةالغرض
بيانات الحساب والدخولاسم المستخدم، كلمة المرور (للتحقق فقط)، نوع نظام الجهاز (Android / iOS)تسجيل الدخول وإدارة الجلسة
بيانات العمل التشغيليةالشحنات، وأسماء وهواتف وعناوين المرسِلين والمستلِمين، والأصناف والمبالغتشغيل عمليات الشحن اليومية
إثبات التسليماسم مستلم الشحنة، توقيعه بخط اليد على الشاشة، ملاحظة اختياريةتوثيق تسليم الشحنات
جهات الاتصال (اختياري وعند الطلب)الاسم والرقم اللذان تختارهما فقطتعبئة سريعة لطرف الشحنة
البحث في الخريطةنص البحث عن عنوان، وإحداثيات النقطة المختارة على الخريطةتحديد عناوين أطراف الشحنة
رمز الإشعاراترمز الجهاز لخدمة الإشعارات (FCM Token)إيصال الإشعارات الفورية
إعدادات محليةاللغة، المظهر، آخر اسم مستخدم، تفعيل البصمةتفضيلاتك — تُحفَظ على جهازك فقط
3.1 بيانات الحساب

عند تسجيل الدخول يُرسَل اسم المستخدم وكلمة المرور إلى خادم الشركة عبر اتصال مشفَّر للتحقق منهما فقط. كلمة المرور لا تُخزَّن على الجهاز إطلاقاً؛ يُصدر الخادم رمز جلسة (Token) يُحفَظ في المخزن المشفَّر للجهاز. كما يُرسَل نوع نظام الجهاز (Android أو iOS) كوصفٍ للجلسة في قائمة جلسات الخادم.

3.2 بيانات عملاء الشركة التي تُدخلها بحكم عملك

أثناء تسجيل الشحنات والتسليم يُدخل الموظف بيانات تخص عملاء الشركة (أسماء المرسِلين والمستلِمين وهواتفهم وعناوينهم وتوقيع مستلم الشحنة). هذه بيانات تشغيلية تُحفَظ في نظام الشركة المركزي، والشركة هي المتحكم بها وتعالجها لأغراض تنفيذ خدمات الشحن وتوثيقها.

3.3 جهات الاتصال — قراءة محلية فقط

عند الضغط على زر «الاختيار من جهات الاتصال» في نموذج إنشاء الشحنة، يطلب التطبيق إذن الوصول لجهات الاتصال ليعرض لك المنتقي على جهازك. قائمة جهات اتصالك لا تُرفَع ولا تُرسَل إلى أي خادم ولا تُزامَن؛ الاسم والرقم اللذان تختارهما فقط يوضعان في حقول نموذج الشحنة الذي تُنشئه بنفسك. يمكنك رفض الإذن والاستمرار بالإدخال اليدوي.

3.4 الخريطة والبحث عن العناوين

لتحديد عنوان مرسِل الشحنة أو مستلمها، يمكنك البحث بالنص أو النقر على الخريطة. يُرسَل نص البحث وإحداثيات النقطة المختارة إلى مزوّد خدمة الخرائط (انظر القسم 7) لتحويلها إلى عنوان مقروء. موقع الموظف الجغرافي لا يُطلَب أبداً — التطبيق لا يحمل أي إذن للوصول إلى الموقع أصلاً.

3.5 سجلات الخادم

كأي خدمة عبر الإنترنت، يُسجّل خادم الشركة تلقائياً بيانات تقنية عن الطلبات (مثل عنوان IP ووقت الطلب) لأغراض الأمان وكشف إساءة الاستخدام والتدقيق.

4

بيانات لا نجمعها إطلاقاً

حرصنا على أن يكون التطبيق خالياً من أي جمع بيانات لا يخدم العمل مباشرة:

  • الموقع الجغرافي: لا يطلب التطبيق إذن الموقع، ولا يتتبّع مكان الموظف لا في المقدمة ولا في الخلفية.
  • البصمة والوجه: التحقق بالبصمة يتم بالكامل داخل نظام تشغيل جهازك؛ التطبيق لا يصل إلى بياناتك الحيوية ولا يخزّنها ولا يرسلها (انظر القسم 6).
  • الكاميرا والميكروفون: لا يستخدمهما التطبيق ولا يطلب إذنيهما.
  • التحليلات والإعلانات: لا توجد أي حزم تحليلات أو تتبّع أو شبكات إعلانية داخل التطبيق.
  • بيع البيانات: لا نبيع أي بيانات ولا نشاركها لأغراض تسويقية.
5

كيف نستخدم البيانات

تُستخدَم البيانات المذكورة أعلاه للأغراض التالية فقط:

  • تشغيل عمليات الشحن اليومية: الاستلام، الشحنات، التسليم، الرحلات والحاويات.
  • التحقق من هوية الموظف وإدارة جلسته وصلاحياته وفرعه.
  • توثيق تسليم الشحنات (اسم المستلم وتوقيعه) كسجل تشغيلي وقانوني.
  • إرسال إشعارات فورية متعلقة بالعمل بلغة التطبيق التي اخترتها.
  • حماية النظام: كشف الوصول غير المصرَّح به وإساءة الاستخدام، وسجلات التدقيق.
  • الامتثال للالتزامات القانونية والمحاسبية المعمول بها.

لا تُستخدَم البيانات لأي تسويق أو تنميط أو أغراض خارج نطاق العمل.

6

فتح التطبيق بالبصمة

يمكنك استئناف جلستك بالبصمة (أو التعرّف على الوجه) بدل إعادة كتابة كلمة المرور عند كل تشغيل. هذه الميزة:

  • تعتمد على واجهة التحقق الحيوي المدمجة في نظام التشغيل (Android BiometricPrompt / Apple Face ID وTouch ID).
  • لا يصل التطبيق أبداً إلى بصمتك أو صورة وجهك — يستلم من النظام نتيجة «نجح/فشل» فقط.
  • لا تُخزَّن أي بيانات حيوية داخل التطبيق ولا تُرسَل إلى أي خادم.
  • حتى بعد نجاح البصمة، يتحقق التطبيق من صلاحية الجلسة لدى الخادم قبل الدخول؛ فالحساب الموقوف لا يفتح بالبصمة.
  • استخدامها اختياري — يمكنك دائماً الدخول بكلمة المرور.
7

الأطراف الثالثة والخدمات المستخدمة

لا نبيع بياناتك لأي جهة. يستخدم التطبيق عدداً محدوداً من الخدمات التقنية للأغراض المذكورة أدناه فقط:

الخدمةالغرضالبيانات المُرسَلة إليها
Google Firebase — ‏Cloud Messaging وRemote Configإيصال الإشعارات الفورية، وجلب إعدادات تشغيل التطبيقرمز إشعارات الجهاز ومعرِّفات تشغيل قياسية تخص الخدمة
Geoapify — خرائط وتحويل عناوينعرض بلاطات الخريطة، والبحث عن العناوين وتحويل الإحداثيات إلى عنواننص البحث المُدخَل وإحداثيات النقطة المختارة على الخريطة
الجهات الرسميةالامتثال لأمر قضائي أو طلب قانوني مُلزِمما يُطلَب بموجب القانون فقط
7.1 Google Firebase

نستخدم Firebase Cloud Messaging لإيصال الإشعارات وFirebase Remote Config لجلب إعدادات التشغيل (مثل عنوان الخادم). لا نستخدم أي منتج تحليلات أو إعلانات من Firebase. تخضع البيانات المارّة عبر هذه الخدمات لـسياسة خصوصية Google.

7.2 Geoapify

خدمة خرائط وتحويل عناوين تُستخدَم فقط عند فتح شاشة الخريطة أو البحث عن عنوان. يصلها ما تكتبه في حقل البحث وإحداثيات النقطة التي تختارها — وليس موقعك أنت. تخضع هذه الطلبات لـسياسة خصوصية Geoapify.

8

الأمان والتخزين والاحتفاظ

نُطبّق تدابير تقنية وتنظيمية لحماية البيانات، منها:

  • كل الاتصالات بالخادم عبر HTTPS/TLS مع تحقّق كامل من شهادة الخادم.
  • رمز الجلسة والإعدادات تُحفَظ في المخزن المشفَّر للجهاز (Android Keystore / iOS Keychain)، وكلمة المرور لا تُحفَظ إطلاقاً.
  • كل تشغيل للتطبيق يبدأ من شاشة الدخول؛ ولا تُستأنف الجلسة إلا بالبصمة أو بكلمة المرور.
  • الصلاحيات تُفرَض من الخادم: لا يصل الموظف إلا إلى الشاشات والبيانات المسموح له بها، وكل حساب معزول ضمن فرعه.
  • تقييد محاولات تسجيل الدخول للحد من هجمات التخمين.
  • تسجيل الخروج يُبطل رمز الجلسة لدى الخادم فوراً ويمسحه من الجهاز.
8.1 مدة الاحتفاظ
  • بيانات الحساب: طوال مدة عمل الموظف ونشاط حسابه لدى الشركة.
  • رموز الجلسات: صلاحية محدودة (لا تتجاوز 180 يوماً) وتُلغى عند تسجيل الخروج أو من إدارة النظام.
  • سجلات العمل التشغيلية (الشحنات، التسليمات، القيود المحاسبية): سجلات تجارية تخص الشركة، يُحتفَظ بها وفق سياساتها والأنظمة القانونية والمحاسبية المعمول بها.
  • البيانات المحلية على جهازك: تُمسَح عند تسجيل الخروج، وتزول ببساطة عند إلغاء تثبيت التطبيق.
9

حذف الحساب والبيانات

حسابات التطبيق تُصدرها الشركة لموظفيها، ولذلك يُدار إنشاؤها وإيقافها وحذفها عبر إدارة الشركة. يمكنك في أي وقت طلب حذف حسابك أو بياناتك الشخصية عبر مراسلتنا.

خطوات الطلب وما يُحذَف وما يُحتفَظ به لأسباب قانونية موضَّحة بالتفصيل في صفحة طلب حذف الحساب.

💡 لإرسال طلب حذف مباشرةً: راسلنا على info@cbmforlogistic.com بعنوان «طلب حذف حساب»، وسنعالج الطلب خلال 30 يوماً كحد أقصى.
10

حقوقك

وفق الأنظمة المعمول بها لحماية البيانات، يحق لك:

  • الوصول — معرفة البيانات التي نحتفظ بها عنك والحصول على نسخة منها.
  • التصحيح — طلب تعديل أي بيانات غير دقيقة.
  • الحذف — طلب حذف حسابك وبياناتك الشخصية وفق القسم 9.
  • الاعتراض وتقييد المعالجة — في الحالات التي تنطبق قانوناً.
  • إيقاف الإشعارات — من إعدادات جهازك في أي وقت، دون أثر على عمل الحساب.
  • تقديم شكوى — لدى الجهة المختصة بحماية البيانات في بلدك.

لممارسة أي من هذه الحقوق تواصل معنا عبر القنوات في نهاية الصفحة. قد نطلب التحقق من هويتك قبل تنفيذ الطلب حمايةً لحسابك.

11

خصوصية الأطفال

تطبيق CBM Shipping أداة عمل مخصَّصة حصراً لموظفي الشركة البالغين (18 سنة فأكثر)، ولا يستهدف الأطفال بأي شكل.

نحن لا نجمع عن قصد أي بيانات من أشخاص دون 18 عاماً، ولا يمكن أصلاً استخدام التطبيق دون حساب موظف صادر من الشركة. إن تبيّن لنا خلاف ذلك سنحذف تلك البيانات فوراً.

12

التغييرات على السياسة والتواصل

12.1 التغييرات على هذه السياسة

قد نُحدّث هذه السياسة من وقت لآخر بنشر نسخة جديدة على هذه الصفحة مع تحديث تاريخ «آخر تحديث» أعلاه. وفي حال إجراء تغييرات جوهرية سنُخطر الموظفين عبر إشعار داخل التطبيق أو عبر قنوات الشركة.

12.2 التواصل معنا

لأي سؤال أو طلب متعلق بهذه السياسة، تواصل معنا عبر القنوات أدناه وسنردّ في أقرب وقت ممكن.

تواصل معنا

لأي استفسار حول هذه السياسة، أو لطلب حذف حسابك، أو لممارسة حقوقك:

📧
البريد الإلكتروني info@cbmforlogistic.com
📞
الهاتف 01681015
💬
واتساب +967 781 555 703
🗑
طلب حذف الحساب صفحة حذف الحساب
Privacy Policy

CBM Shipping App Privacy Policy

This policy explains what data the CBM Shipping staff app handles, how we use and protect it, what we never collect, and how you can request deletion of your account.

📅  Effective Date:  August 12, 2026
🔄  Last Updated:  August 12, 2026
🏢  Operator:  CBM Shipping
1

About this policy

This Privacy Policy applies to the CBM Shipping mobile application (Android and iOS), an internal app reserved for employees of CBM Shipping to run day-to-day shipping operations: goods receiving, shipments, deliveries, trips and containers.

There is no self-registration: accounts are issued by the company's administration to its employees only. The general public cannot create an account or use the app.

By using the app as an employee you acknowledge that you have read this policy. If you have any questions about it, you can reach us through the channels listed at the end of this page.

2

Who we are

The CBM Shipping app is operated and managed by CBM Shipping, a shipping and logistics company, which acts as the data controller for the data described in this policy.

The app is a field interface to the company's internal system: data it displays or that is entered through it is stored on the company's central servers and is subject to the same permission controls applied to the company system.

📮 For any questions about the information we hold, contact us at:
Email: info@cbmforlogistic.com
Phone / WhatsApp: +967 781 555 703
3

Data the app handles

The app handles the minimum data needed to do the job. The table below summarises the categories and their purposes:

Data categoryExamplesPurpose
Account & sign-in dataUsername, password (for verification only), device platform type (Android / iOS)Sign-in and session management
Operational work dataShipments; sender and receiver names, phone numbers and addresses; items and amountsRunning daily shipping operations
Proof of deliveryRecipient name, on-screen handwritten signature, optional noteDocumenting shipment handover
Contacts (optional, on demand)Only the single name and number you pickQuickly filling a shipment party
Map & address searchTyped search text, coordinates of the point you pick on the mapResolving shipment party addresses
Notification tokenDevice push token (FCM)Delivering push notifications
Local settingsLanguage, theme, last username, biometric flagYour preferences — stored on your device only
3.1 Account data

At sign-in, your username and password are sent to the company server over an encrypted connection for verification only. The password is never stored on the device; the server issues a session token which is kept in the device's encrypted storage. The device platform type (Android or iOS) is sent as a label for the server's session list.

3.2 Company customers' data you enter as part of your job

While registering shipments and deliveries, employees enter data belonging to the company's customers (sender and receiver names, phone numbers, addresses, and the recipient's signature). This is operational data stored in the company's central system; the company is its controller and processes it to perform and document its shipping services.

3.3 Contacts — read locally only

When you tap "pick from contacts" in the shipment form, the app asks for contacts permission to show you the picker on your device. Your contact list is never uploaded, transmitted to any server, or synced; only the single name and number you select are placed into the shipment form you are creating yourself. You may deny the permission and type the details manually.

3.4 Map & address search

To set a shipment's sender or receiver address you can search by text or tap a point on the map. The typed search text and the coordinates of the picked point are sent to the mapping provider (see Section 7) to resolve them into a readable address. The employee's own location is never requested — the app holds no location permission at all.

3.5 Server logs

Like any online service, the company server automatically records technical request data (such as IP address and request time) for security, abuse detection and auditing.

4

Data we never collect

The app is deliberately free of any data collection that does not directly serve the work:

  • Location: the app never asks for location permission and does not track employees, neither in the foreground nor in the background.
  • Fingerprint and face data: biometric verification happens entirely inside your device's operating system; the app never accesses, stores, or transmits your biometric data (see Section 6).
  • Camera and microphone: not used and never requested.
  • Analytics and advertising: the app contains no analytics, tracking, or ad SDKs.
  • Selling data: we do not sell any data and do not share it for marketing purposes.
5

How we use the data

The data described above is used solely for the following purposes:

  • Running daily shipping operations: receiving, shipments, deliveries, trips and containers.
  • Verifying the employee's identity and managing their session, permissions and branch scope.
  • Documenting shipment handover (recipient name and signature) as an operational and legal record.
  • Sending work-related push notifications in the app language you chose.
  • Protecting the system: detecting unauthorised access and misuse, and keeping audit logs.
  • Complying with applicable legal and accounting obligations.

The data is not used for marketing, profiling, or any purpose outside the scope of work.

6

Biometric unlock

You can resume your session with your fingerprint (or face recognition) instead of retyping your password on every launch. This feature:

  • Relies on the operating system's built-in biometric prompt (Android BiometricPrompt / Apple Face ID and Touch ID).
  • The app never accesses your fingerprint or face image — it only receives a pass/fail result from the OS.
  • No biometric data is stored in the app or sent to any server.
  • Even after a successful biometric check, the app re-validates the session with the server before entering; a suspended account cannot be opened with a fingerprint.
  • Using it is optional — you can always sign in with your password.
7

Third parties & services we use

We do not sell your data. The app uses a small number of technical services, for the purposes below only:

ServicePurposeData sent to it
Google Firebase — Cloud Messaging & Remote ConfigDelivering push notifications; fetching app runtime configurationDevice push token and standard service identifiers
Geoapify — maps & geocodingRendering map tiles; address search and reverse geocodingThe typed search text and the coordinates of the picked map point
Legal authoritiesCompliance with a court order or binding legal requestOnly what is required by law
7.1 Google Firebase

We use Firebase Cloud Messaging to deliver notifications and Firebase Remote Config to fetch runtime configuration (such as the server address). We do not use any Firebase analytics or advertising products. Data passing through these services is subject to Google's Privacy Policy.

7.2 Geoapify

A mapping and geocoding service used only when you open the map screen or search for an address. It receives what you type in the search field and the coordinates of the point you pick — never your own location. These requests are subject to the Geoapify Privacy Policy.

8

Security, storage & retention

We apply technical and organisational measures to protect the data, including:

  • All server communication over HTTPS/TLS with full certificate validation.
  • The session token and settings are kept in the device's encrypted storage (Android Keystore / iOS Keychain), and the password is never stored.
  • Every app launch starts at the sign-in screen; a session can only be resumed with biometrics or the password.
  • Permissions are enforced by the server: employees can only reach the screens and data they are allowed, and every account is isolated to its branch.
  • Sign-in attempts are rate-limited to resist guessing attacks.
  • Signing out immediately revokes the session token on the server and wipes it from the device.
8.1 Retention periods
  • Account data: for the duration of the employee's engagement and active account with the company.
  • Session tokens: limited validity (at most 180 days), revoked on sign-out or by system administration.
  • Operational work records (shipments, deliveries, accounting entries): business records belonging to the company, retained according to its policies and applicable legal and accounting regulations.
  • Local data on your device: wiped on sign-out, and removed entirely when the app is uninstalled.
9

Account & data deletion

App accounts are issued by the company to its employees, so their creation, suspension and deletion are managed through the company's administration. You may request deletion of your account or personal data at any time by contacting us.

The request steps, what gets deleted, and what is retained for legal reasons are detailed on the Account Deletion page.

💡 To send a deletion request directly: email info@cbmforlogistic.com with the subject "Account Deletion Request", and we will process it within 30 days at most.
10

Your rights

Under applicable data protection laws, you have the right to:

  • Access — know what data we hold about you and obtain a copy of it.
  • Rectification — request correction of inaccurate data.
  • Erasure — request deletion of your account and personal data as described in Section 9.
  • Objection and restriction of processing — where legally applicable.
  • Disable notifications — from your device settings at any time, without affecting your account.
  • Complaint — with the competent data protection authority in your country.

To exercise any of these rights, contact us through the channels at the end of this page. We may verify your identity before acting on a request, to protect your account.

11

Children's privacy

The CBM Shipping app is a work tool reserved exclusively for the company's adult employees (18 years or older) and is not directed to children in any way.

We do not knowingly collect any data from individuals under 18, and the app cannot be used at all without a company-issued employee account. If we learn otherwise, we will delete that data promptly.

12

Changes to this policy & contact

12.1 Changes to this policy

We may update this policy from time to time by publishing a new version on this page and updating the "Last Updated" date above. For material changes, we will notify employees via an in-app notice or through company channels.

12.2 Contact us

For any question or request related to this policy, contact us through the channels below and we will respond as soon as possible.

Contact Us

For any inquiry about this policy, to request account deletion, or to exercise your rights:

📞
Phone 01681015
💬
WhatsApp +967 781 555 703
🗑
Account deletion Account Deletion page