What this covers
This policy covers safedaira.com and the interest-registration and contact forms on it. It does not yet cover the Safe Daira band, the operator console or the family app, because none of those has been released. When they are, this policy will be extended and the change will be dated here rather than made silently.
Safe Daira is pre-launch. At the time of writing, the forms on this site do not transmit to a server: they validate in your browser and stop there. That will change when the backend is connected, and this section will be updated on the same day it does.
What we collect from this website
If you submit the interest-registration or contact form, we collect what you type into it:
- Your name, email address and, if you provide one, your phone number.
- For operators: your organisation name, the country your pilgrims travel from, and your approximate number of pilgrims per season.
- Anything you write in the free-text field.
We also use a single analytics measurement to count page views. It records the page visited, an approximate country-level location derived from your IP address, and general device information. It does not identify you personally and we do not combine it with form submissions.
Alongside page views it counts a few anonymous interactions, so we can tell which parts of the site are actually used: for example whether readers switch the map on the journey page between the diagram and satellite imagery, and how far down the eleven stages they read. These are counts of what was used, never of where you are. No location from your device, no coordinate and nothing you typed into a form is ever sent to analytics.
We do not use advertising pixels, cross-site trackers, session recording, heat-mapping or any third-party marketing tags on this site.
Why we collect it, and what we do with it
We use what you submit for exactly one purpose: to contact you about the Safe Daira pilot programme and to answer what you asked. That is the entire basis on which you gave it to us and it is the only thing we will use it for.
We do not sell, rent, or share your details with third parties for their own marketing. We do not add you to a general mailing list you did not ask for. Every email we send you will have a working unsubscribe link.
Location data from the band and console
This section describes how the product is being designed to handle location data. It is a statement of commitment about a product not yet released, published now so that it can be held against us later.
- A pilgrim’s location is visible to their registered group leader and to the next-of-kin that pilgrim personally nominated at fitting. Nobody else: not other pilgrims in the group, not other families, and not other operators.
- Default retention for continuous position history is the pilgrimage plus 90 days, after which it is deleted. Operators on the Fleet and Authority tiers can shorten that. Nobody can extend it indefinitely.
- The audit trail of alerts, acknowledgements and resolutions is stored separately from continuous position history, because those two things have different retention justifications and merging them is how location data quietly becomes permanent.
- We will not sell location data (not raw, not aggregated, not anonymised, and not as "insights") to advertisers, data brokers, insurers, or anyone else, at any price.
- The band is removable at any time by the wearer. Consent is captured at fitting and withdrawing it is as simple as taking the band off.
- Under the Authority tier, data residency and retention are set by the contracting authority.
How long we keep website data
Form submissions are kept until the pilot programme concludes or until you ask us to delete them, whichever comes first. Analytics data is retained for 14 months.
Your rights
Wherever you are, you can ask us to show you what we hold about you, correct it, delete it, or stop contacting you. Email hello@safedaira.com and we will act on it within 30 days. We will not ask you to justify the request.
If you are in the UK or the EU, the UK GDPR and the GDPR give you these rights as a matter of law, along with the right to complain to your national supervisory authority. If you are elsewhere, we extend the same rights to you as a matter of policy.
Security
The site is served over HTTPS with HSTS and a restrictive Content Security Policy. We will describe the security architecture of the band, console and app when they are released, in specific terms rather than as reassurance: vague security claims are worse than none.
Children
This website is not directed at children and we do not knowingly collect information from them. Where a minor performs pilgrimage as part of a family group, any band would be provisioned by and consented to through a parent or guardian.
Changes to this policy
If we change this policy, the date at the top changes and the change is recorded in the public repository history for this site. If we ever weaken a commitment in the location-data section, that will be visible, and you should ask us why.
Contact
Questions about this policy, or any request about your data: hello@safedaira.com.