سياسة الخصوصية
آخر تحديث: 20 سبتمبر 2026 · تسري على موقع مبارياتي وتطبيقه على أندرويد.
الخلاصة: لا نطلب حساباً، ولا اسماً، ولا بريداً، ولا رقم هاتف. مفضّلاتك وإعداداتك محفوظة على جهازك وحده. ما يخرج من جهازك هو ما تحتاجه الخدمة للعمل: طلب بيانات المباريات، ورمز إشعارات مجهول، وطلبات الإعلانات من Google.
1. المتحكّم بالبيانات
أحمد، ألمانيا. للتواصل في شؤون الخصوصية: [email protected].
2. ما الذي نجمعه فعلاً
| البيانات | لماذا | الأساس القانوني | مدة الاحتفاظ |
|---|---|---|---|
| عنوان IP ونوع المتصفح/الجهاز، ضمن سجلات الخادم | تشغيل الخدمة، ومنع إساءة الاستخدام، وتطبيق حدود الطلبات | المصلحة المشروعة | حتى 30 يوماً في السجلات التشغيلية |
| عدّاد المستخدمين النشطين — تجزئة مجهولة من IP ووكيل المستخدم بملح يتغيّر يومياً | معرفة حِمل الخادم وهل يحتاج توسعة | المصلحة المشروعة | خمس دقائق في ذاكرة الخادم؛ لا يُخزَّن عنوان IP |
| رمز إشعارات Firebase (FCM token) | إرسال إشعارات الأهداف والمباريات التي اخترت متابعتها | موافقتك عند تفعيل الإشعارات | حتى تُوقف الإشعارات أو تحذف التطبيق |
| مفضّلاتك ولغتك وإعداداتك | تخصيص ما تراه | — | على جهازك فقط، ولا تصلنا أبداً |
| معرّفات الإعلانات وملفات الارتباط الإعلانية (Google) | عرض الإعلانات وقياسها ومنع تكرارها | موافقتك (الإعلانات المخصّصة) أو المصلحة المشروعة (غير المخصّصة) | حسب سياسات Google |
ما لا نجمعه
- لا اسم ولا بريد ولا رقم هاتف ولا تاريخ ميلاد.
- لا موقع جغرافي دقيق — لا نطلب إذن الموقع أصلاً.
- لا جهات اتصال ولا صور ولا ملفات ولا ميكروفون ولا كاميرا.
- لا نبيع بياناتك، ولا نشاركها لأغراض تسويقية لطرف ثالث.
3. الأطراف التي تعالج البيانات نيابة عنّا
- Google Firebase (قاعدة البيانات والإشعارات والتحليلات) — سياسة Firebase.
- Google AdSense / AdMob (الإعلانات) — كيف تستخدم Google البيانات من شركائها.
- مزوّد استضافة الخادم —
Hetzner. - مزوّدو بيانات المباريات (football-data.org وESPN) — يتلقّون طلبات من خادمنا، لا من جهازك، ولا تصلهم أي معلومة عنك.
4. نقل البيانات خارج بلدك
خوادم Google قد تعالج البيانات خارج بلد إقامتك، بما فيها الولايات المتحدة. تعتمد Google البنود التعاقدية القياسية المعتمدة من المفوضية الأوروبية كضمانة لهذا النقل.
5. الأطفال
الخدمة غير موجّهة لمن هم دون 13 عاماً، ولا نجمع عن علم بيانات منهم. طلبات الإعلانات مضبوطة على تصنيف محتوى عام (G). إن علمت أن طفلاً أرسل إلينا بيانات، راسلنا لنحذفها.
6. حقوقك
لك — بحسب قوانين بلدك، وبموجب اللائحة الأوروبية العامة لحماية البيانات وقانون كاليفورنيا لخصوصية المستهلك حيثما انطبقا — أن تطلب:
- الاطّلاع على ما نحتفظ به عنك، أو نسخة منه.
- تصحيحه أو حذفه.
- تقييد معالجته أو الاعتراض عليها.
- سحب موافقتك على الإشعارات أو على الإعلانات المخصّصة في أي وقت.
- تقديم شكوى إلى جهة الرقابة المختصّة في بلدك.
عملياً، وبما أننا لا نربط بياناتك بهوية، فأسرع طريق للحذف الكامل موضّح في صفحة حذف البيانات. للطلبات الأخرى راسلنا على [email protected] ونردّ خلال 30 يوماً.
7. كيف نحمي البيانات
- كل الاتصالات عبر HTTPS، وترويسات حماية صارمة (CSP وHSTS وغيرها).
- قواعد وصول على قاعدة البيانات تمنع أي كتابة من العملاء عدا ما يقوم به الأدمن.
- مفاتيح مزوّدي البيانات محفوظة على الخادم في مجموعة لا يقرأها أي عميل، ولا تظهر في أي واجهة.
- سجل تدقيق لكل عملية إدارية، وحدود طلبات لمنع إساءة الاستخدام.
8. تغييرات هذه السياسة
ننشر أي تعديل هنا مع تحديث التاريخ أعلاه، ونُعلم داخل الخدمة بالتغييرات الجوهرية.
9. التواصل
Privacy Policy
Last updated: 20 September 2026 · Covers the Mubarayati website and Android app.
In short: we ask for no account, no name, no email, no phone number. Your favourites and settings stay on your device. What leaves your device is what the service needs to work: a request for match data, an anonymous notification token, and Google's ad requests.
1. Data controller
Ahmad, Germany. Privacy contact: [email protected].
2. What we actually collect
| Data | Why | Legal basis | Retention |
|---|---|---|---|
| IP address and browser/device type, in server logs | Operating the service, preventing abuse, enforcing rate limits | Legitimate interest | Up to 30 days in operational logs |
| Active-user counter — an anonymous hash of IP + user agent with a daily-rotating salt | Knowing server load and whether capacity needs expanding | Legitimate interest | Five minutes in server memory; the IP itself is never stored |
| Firebase notification token (FCM) | Sending goal and match alerts you chose to follow | Your consent when enabling notifications | Until you disable notifications or uninstall |
| Your favourites, language and settings | Personalising what you see | — | On your device only; never sent to us |
| Advertising identifiers and ad cookies (Google) | Serving, measuring and frequency-capping ads | Your consent (personalised) or legitimate interest (non-personalised) | Per Google's policies |
What we do not collect
- No name, email, phone number or date of birth.
- No precise location — we never request the location permission.
- No contacts, photos, files, microphone or camera.
- We do not sell your data or share it for third-party marketing.
3. Processors acting on our behalf
- Google Firebase (database, messaging, analytics) — Firebase privacy.
- Google AdSense / AdMob (advertising) — How Google uses data from partner sites.
- Our server host —
Hetzner. - Match-data providers (football-data.org, ESPN) receive requests from our server, not from your device, and receive no information about you.
4. International transfers
Google's servers may process data outside your country of residence, including in the United States. Google relies on the European Commission's Standard Contractual Clauses as the safeguard for such transfers.
5. Children
The service is not directed at children under 13 and we do not knowingly collect their data. Ad requests are set to a general (G) content rating. If you believe a child has sent us data, contact us and we will delete it.
6. Your rights
Depending on your jurisdiction — and under the GDPR and the CCPA where they apply — you may request to:
- access what we hold about you, or receive a copy;
- have it corrected or erased;
- restrict or object to its processing;
- withdraw consent to notifications or personalised advertising at any time;
- lodge a complaint with your supervisory authority.
In practice, because we do not link your data to an identity, the fastest route to complete deletion is set out on the data deletion page. For other requests email [email protected]; we respond within 30 days.
7. How we protect data
- All traffic over HTTPS, with strict security headers (CSP, HSTS and others).
- Database rules that block client writes other than the administrator's.
- Provider API keys held server-side in a collection no client can read, and never shown in any interface.
- An audit log of every administrative action, plus rate limiting against abuse.
8. Changes to this policy
Any amendment is published here with the date above updated, and material changes are announced in-service.