Wasl trust

Privacy Policy

Effective June 2026. Wasl operates a digital receipt, customer wallet, and merchant engagement platform for Bahrain and GCC merchants. This policy explains how we collect, use, store, share, and protect personal data.

Who this applies to

This policy applies to merchants and authorised users who use the Wasl merchant platform, customers who view or save digital receipts, customers who use a Wasl wallet, and visitors who submit lead or support enquiries.

Data we collect

We collect merchant business details, branch details, CR/VAT details, billing records, receipt content, receipt events, support tickets, customer wallet contact aliases, optional customer profile details, verification events, Wasl Device logs, and Receipt Assistant messages where the assistant is used.

Optional customer profile fields include full name, gender, and date of birth. These fields are not required to use the wallet.

How we use data

We use data to create and deliver digital receipts, verify wallet access by email or phone, provide receipt PDFs, support merchants, operate Wasl Devices, prevent abuse, manage invoices, improve platform reliability, and provide aggregate merchant analytics.

Customer email and phone

Verified customer email addresses and phone numbers are used for wallet access magic links, OTP authentication, service communications, security alerts, and privacy request confirmations. Wasl does not sell customer contact details and does not expose customer email or phone values to merchants. Merchants see aggregate wallet engagement metrics only.

Public receipt links

Public receipt pages are accessible to anyone who has the link or scans the QR/NFC tag at the point of sale. If a customer saves a receipt to a wallet, wallet access is additionally protected by verified email or phone authentication.

Receipt Assistant and AI

The Receipt Assistant uses visible receipt content only, such as merchant name, items, VAT, total, date, payment method, return policy, and warranty notes. Customer wallet profile data and contact details are not sent to the assistant. The assistant requires consent before use and responses are for convenience only, not tax, legal, accounting, or consumer-rights advice.

Service providers

Wasl uses Supabase for database, authentication, and storage; Vercel for hosting; Resend for email delivery; Twilio Verify for WhatsApp or SMS phone codes; Sentry for error monitoring; and OpenAI where the Receipt Assistant is enabled. These providers may process data outside Bahrain.

Security

Wasl uses encrypted transport, verified email magic links, WhatsApp or SMS phone codes, role-based access controls, Supabase Row Level Security, hashed device tokens, rate limits, webhook signature checks, audit events, and production error monitoring. No online service can be guaranteed perfectly secure.

Merchant visibility limits

Merchants can see their own receipt configuration data and aggregate receipt metrics such as views, saves, and downloads. Merchants cannot see individual customer email addresses, phone numbers, wallet profiles, or which individual customer saved a receipt.

Anonymized merchant benchmarks

Wasl may use receipt totals, item categories, payment mix, branch activity, wallet save rates, and platform events to produce aggregated merchant analytics and anonymized industry benchmarks. These reports are designed to help merchants understand their own performance and compare broad trends without exposing another merchant's raw data.

Wasl does not sell customer personal data. Customer email addresses, phone numbers, wallet profiles, and individual saved-receipt ownership are not included in merchant benchmark reports.

Retention

Merchant account data is retained while the account is active and for required business-record periods. Invoice and billing records may be retained for up to 10 years. Receipt data may be retained for the active merchant term plus up to 5 years where needed for business, VAT, audit, or dispute purposes. Customer wallet profile/contact data is retained until verified deletion request or 3 years of inactivity, then deleted or anonymised where possible. OTP and magic-link logs are normally retained for 90 days. AI assistant session data is normally retained for 30 days. Wasl Device logs and parser/debug captures are retained only as long as needed for support and security, normally 30 to 90 days depending on record type.

Your rights

Subject to applicable law, customers and merchants may request access, correction, deletion, export, objection, or withdrawal of consent where processing is based on consent. We verify identity before completing privacy requests and aim to respond within 30 calendar days of verified submission.

Deletion and export

Wallet deletion removes or anonymises eligible wallet profile fields, contact aliases, saved receipt associations, and access history. Public receipt links may remain live because receipt records are merchant business records. A customer may remove their wallet association with a receipt, but cannot normally require deletion of the merchant's underlying receipt record.

Some invoice, VAT, security, audit, legal defence, and privacy request records may be retained where required.

Contact

Submit privacy requests using the form below, inside your wallet, or through merchant support. For privacy enquiries, contact Wasl at support@trywasl.com.

Submit a privacy request

Use the same email or phone you used for your Wasl wallet. Verified wallet requests are processed fastest.

Back to Wasl