← الرئيسية | Home

سياسة الخصوصية

آخر تحديث: 2026-09-05 · «حملتك | Hamletak» — www.hamlet-ak.com

١) من نحن

«حملتك» منصة تسويق بالذكاء الاصطناعي تساعد أصحاب الأنشطة على إنشاء الحملات الإعلانية وإدارتها ومتابعة نتائجها. مشغّل المنصة هو المسؤول عن معالجة بياناتك وفق هذه السياسة. للتواصل: infosecengm@hamlet-ak.com.

٢) البيانات التي نجمعها

  • بيانات الحساب: البريد الإلكتروني والاسم وكلمة مرور مشفّرة (عبر مزوّد المصادقة Supabase).
  • ملف النشاط التجاري: ما تُدخله عن نشاطك (الوصف، الخدمات، الأسعار، المعرفة التجارية) لتوليد حملات مخصّصة.
  • بيانات منصات الإعلان: عند ربط حسابك الإعلاني (Meta، TikTok، LinkedIn، Google، Snapchat، Microsoft) نخزّن رموز وصول OAuth مشفّرة (AES-256-GCM) ونقرأ بيانات حملاتك (الحالة، الإنفاق، النتائج) لعرضها والتحكم فيها بأمر منك.
  • عملاؤك المحتملون: بيانات الليدز والمبيعات التي تسجّلها أنت أو يجمعها وكيل المحادثة الخاص بنشاطك — وهي ملك لك.
  • بيانات تقنية: سجلات أمنية (عنوان IP، وقت الطلب) لأغراض الحماية ومنع إساءة الاستخدام.
  • قياس الزيارات: على صفحاتنا العامة فقط، تسجّل أدوات ميتا وجوجل وسناب شات فتح الصفحة والضغط على زر واتساب وإنشاء الحساب — التفاصيل في القسم ٥.

٣) كيف نستخدم البيانات

  • توليد الحملات والمحتوى بالذكاء الاصطناعي (تُعالج النصوص عبر مزوّد نماذج ذكاء خارجي ملتزم بمعالجة سرية ولا يستخدم بياناتك للتدريب).
  • تشغيل الحملات وقراءة نتائجها على المنصات الإعلانية المرتبطة — بتفويضك فقط وضمن الصلاحيات التي وافقت عليها.
  • تشغيل وكيل الرد على عملائك وحفظ الليدز في حسابك.
  • الفوترة والاشتراكات (تتم معالجة الدفع لدى Paymob — لا نخزّن بيانات بطاقتك إطلاقًا).
  • تأمين المنصة (تحقق بشري عبر Cloudflare Turnstile، حدود معدل الاستخدام، سجلات تدقيق).

٤) مشاركة البيانات

لا نبيع بياناتك. بيانات حسابك — ملف نشاطك، حملاتك، عملاؤك المحتملون، رموز وصولك — لا تُشارك مع أي طرف لأغراض إعلانية، باستثناء واحد تطلبه أنت بنفسك ونشرحه في القسم ٦: رفع قائمة عملائك إلى حسابك الإعلاني أنت. أما زيارات الموقع التسويقي فتقيسها أدوات ميتا وجوجل وسناب شات، ويشرح القسم ٥ ما يُرسل بالضبط وكيف توقفه. تُشارك البيانات مع مزوّدي الخدمة اللازمين للتشغيل: Supabase (قاعدة البيانات والمصادقة)، مزوّد نماذج الذكاء الاصطناعي (معالجة النصوص)، Paymob (الدفع)، Hetzner (الاستضافة)، ومنصات الإعلان التي تربطها بنفسك — وكلٌّ وفق سياساته وبالحد الأدنى اللازم.

٥) قياس زوار الموقع التسويقي

صفحاتنا العامة — الرئيسية، صفحات الدول والقطاعات، ومؤشر الأسعار — تحمّل أدوات قياس من ميتا وجوجل وسناب شات، وأداة القياس الخاصة بنا. لا تعمل هذه الأدوات داخل المنصة بعد تسجيل الدخول.

  • بيكسل ميتا: يسجّل فتح الصفحة، والضغط على زر واتساب، وإنشاء الحساب.
  • Google Analytics 4 و Google Ads: يسجّلان اللحظات نفسها.
  • بيكسل سناب شات: يسجّل اللحظات نفسها. وإذا كانت المطابقة التلقائية مفعّلة في حساب سناب، يقرأ البيكسل البريد أو رقم الهاتف المكتوب في نموذج على الصفحة ويرسله مشفّرًا من متصفحك، لا نصًّا صريحًا.
  • أداة القياس الخاصة بنا: نفس الكود الذي يضعه عملاؤنا في مواقعهم. يسجّل فتح الصفحة والضغط على روابط واتساب أو الهاتف أو البريد على خادمنا، ويرسل هذه اللحظات نفسها إلى ميتا من الخادم (Conversions API) بدل المتصفح وحده — نفس الأحداث ولا بيانات إضافية.
  • عند إنشاء حسابك يُرسل بريدك مشفّرًا إلى ميتا وجوجل ليربطا تسجيلك بالإعلان الذي جاء منه. لا يصل البريد نفسه إليهما، والتشفير يتم في متصفحك قبل الإرسال.

ما لا نرسله من هذه الصفحات: ملف نشاطك، حملاتك، عملاؤك المحتملون، رموز وصولك، ولا أي شيء داخل حسابك.

لماذا نقيس: لنعرف أي إعلان جاء بعميل حقيقي بدل أن ندفع بلا قياس.

كيف توقفه: أدوات منع التتبّع في متصفحك توقف هذه الأدوات. ويمكنك ضبط ما يصل إلى كل منصة من إعدادات إعلانات ميتا ومركز إعلانات جوجل، ومن تفضيلات الإعلانات داخل إعدادات تطبيق سناب شات.

٦) رفع قائمة عملائك (اختياري تمامًا)

تستطيع أن تطلب منا بناء «جمهور مخصّص» على حسابك الإعلاني أنت من أرقام عملائك، ليصل إعلانك إليهم أو إلى من يشبههم. لا يحدث هذا إلا بطلبك، ولا يعمل تلقائيًا أبدًا.

  • ماذا يُرسل: الرقم مشفّرًا (SHA-256) فقط. لا يغادر الرقم نفسه خادمنا، والمنصة الإعلانية تستقبل التشفير لتطابقه مع حساباتها، ولا تستطيع استرجاع الرقم منه.
  • إلى أين: إلى حسابك الإعلاني وحده على المنصة التي ربطتها بنفسك. لا يُشارك مع أي طرف آخر، ولا مع عملاء آخرين لدينا، ولا يُباع.
  • إقرارك قبل الرفع: نطلب منك تأكيدًا صريحًا بأن هؤلاء عملاؤك وأن لديك إذنهم بالتواصل التسويقي. نسجّل من أكّد ومتى وعدد الأرقام — ولا يتم أي رفع بدون هذا التأكيد.
  • ما لا نحتفظ به: لا نخزّن الأرقام المرفوعة ولا نسخها المشفّرة. تتم المعالجة في الذاكرة أثناء الرفع فقط.
  • الحذف: الجمهور يعيش داخل حسابك الإعلاني، وتستطيع حذفه في أي وقت من مدير الإعلانات الخاص بك.

٧) بيانات منصات الطرف الثالث

عند ربط حساب إعلاني، نستخدم واجهات البرمجة الرسمية (مثل Meta Marketing API) ونلتزم بشروط كل منصة (بما فيها Meta Platform Terms). لا نستخدم بيانات هذه المنصات إلا لتقديم الخدمة لك، ولا نحتفظ بها بعد فصل الربط أو حذف الحساب.

٨) بيانات جوجل تحديدًا

نتعامل مع جوجل في موضعين منفصلين، ولكلٍّ منهما تفويض مستقل تمنحه أنت من شاشة جوجل نفسها:

  • تسجيل الدخول بجوجل (Sign in with Google): نستقبل من جوجل بريدك واسمك وصورة ملفك الشخصي فقط، لإنشاء حسابك وتسجيل دخولك عبر مزوّد المصادقة Supabase. لا نطلب أي صلاحية أخرى.
  • ربط حساب Google Ads: نطلب صلاحية واحدة هي https://www.googleapis.com/auth/adwords (إدارة حملات Google Ads). لا نطلب الوصول إلى Gmail أو Drive أو جهات الاتصال أو التقويم أو أي خدمة جوجل أخرى.

ما نقرأه من حساب Google Ads: الحسابات الإعلانية المتاحة لك، وحملاتك ومجموعاتك الإعلانية وإعلاناتك وكلماتك المفتاحية ونتائجها (الظهور، النقرات، الإنفاق، التحويلات)، ومصطلحات البحث، وتقديرات حجم البحث للكلمات المفتاحية (Keyword Planner).

ما نكتبه فيه: إنشاء الحملات التي وافقت عليها، وتشغيلها أو إيقافها، وإضافة كلمات سلبية، وضبط أهداف التحويل — بأمر منك في كل مرة، ولا شيء تلقائيًا. رقم حساب Merchant Center تُدخله أنت لحملات Shopping، ولا نقرأ محتوى Merchant Center نفسه.

فيمَ نستخدمه: لعرض حساباتك وحملاتك داخل المنصة، ولإطلاق حملات وافقت عليها، ولمتابعة نتائجها وتقديم توصيات تحسين لك. لا نستخدم بيانات Google Ads لأي غرض آخر — لا لتوجيه إعلانات إليك، ولا لتدريب نماذج، ولا لبناء ملفات تعريفية عنك أو عن عملائك.

ما نخزّنه: رموز الوصول والتحديث (access/refresh tokens) مشفّرة AES-256-GCM في صف الربط الخاص بحسابك وحده، ونسخة من نتائج حملاتك (الإنفاق، النقرات، التحويلات) لعرضها في تقاريرك.

من يراه: أنت وأعضاء مساحة عملك حسب أدوارهم، ومشغّل المنصة لأغراض الدعم والتشغيل فقط. لا يُشارك مع أي طرف ثالث ولا يُباع ولا يُنقل.

فصل الربط والحذف: عند الضغط على «فصل» في صفحة الربط نحذف رموز الوصول من قاعدة بياناتنا فورًا، وتُحذف كذلك مع حذف حسابك. ولإلغاء التفويض من جهة جوجل نفسها: صلاحيات حساب جوجل.

الالتزام بسياسة جوجل: استخدام «حملتك» للمعلومات المستلمة من واجهات Google APIs ونقلها إلى أي تطبيق آخر يلتزم بـGoogle API Services User Data Policy، بما فيها متطلبات الاستخدام المحدود (Limited Use).

٩) الاحتفاظ والأمان

نحتفظ بالبيانات طوال مدة نشاط حسابك. إجراءات الحماية تشمل: تشفير رموز الوصول، اتصالات HTTPS، عزل بيانات كل عميل عن غيره على مستوى الخادم، صلاحيات دنيا، وسجلات تدقيق.

١٠) حقوقك وحذف البيانات

لك في أي وقت: الاطلاع على بياناتك، تصحيحها، تصدير عملائك المحتملين، فصل أي منصة مرتبطة (يُحذف رمز وصولها من عندنا فورًا)، أو حذف حسابك وكل بياناته نهائيًا.

لطلب الحذف: أرسل بريدًا إلى infosecengm@hamlet-ak.com من بريد حسابك بعنوان «حذف الحساب»، وسيُنفَّذ الحذف خلال ٣٠ يومًا كحد أقصى، ويشمل ملف نشاطك وحملاتك المولّدة ورموز الوصول والليدز.

١١) التعديلات

قد نُحدّث هذه السياسة، وسنعرض تاريخ آخر تحديث أعلى الصفحة. استمرارك في استخدام المنصة بعد التحديث يعني موافقتك عليه.

Privacy Policy

Last updated: 2026-09-05 · Hamletak — www.hamlet-ak.com

1) Who we are

Hamletak is an AI marketing platform that helps businesses create, launch, and measure advertising campaigns. The platform operator is the data controller for the processing described here. Contact: infosecengm@hamlet-ak.com.

2) Data we collect

  • Account data: email, name, and a hashed password (via our authentication provider, Supabase).
  • Business profile: information you enter about your business (description, services, prices, business knowledge) used to generate tailored campaigns.
  • Ad-platform data: when you connect an ad account (Meta, TikTok, LinkedIn, Google, Snapchat, Microsoft) we store OAuth access tokens encrypted (AES-256-GCM) and read your campaign data (status, spend, results) to display and control it on your instruction.
  • Your leads: lead and sales records you log or that your business chat agent collects — these belong to you.
  • Technical data: security logs (IP address, request time) for protection and abuse prevention.
  • Visit measurement: on our public pages only, Meta, Google and Snap tools record page views, WhatsApp button clicks, and account creation — see section 5.

3) How we use data

  • AI campaign and content generation (text is processed by an external AI model provider under confidentiality, and is not used for training).
  • Launching campaigns and reading their results on connected ad platforms — only as authorized by you and within the permissions you granted.
  • Running your customer chat agent and saving leads to your account.
  • Billing and subscriptions (payments are processed by Paymob; we never store your card details).
  • Platform security (human verification via Cloudflare Turnstile, rate limiting, audit logs).

4) Data sharing

We do not sell your data. Your account data — business profile, campaigns, leads, access tokens — is never shared for advertising, with one exception you ask for yourself and which section 6 describes: uploading your customer list to your own ad account. Visits to our marketing site are measured by Meta, Google and Snap tools; section 5 sets out exactly what is sent and how to stop it. Data is shared with the processors required to operate the service: Supabase (database & auth), our AI model provider (text processing), Paymob (payments), Hetzner (hosting), and the ad platforms you yourself connect — each under its own terms and limited to what is necessary.

5) Marketing-site measurement

Our public pages — the homepage, the country and sector pages, and the ad price index — load measurement tools from Meta, Google and Snap, plus our own. These tools do not run inside the platform once you sign in.

  • Meta Pixel: records a page view, a click on the WhatsApp button, and account creation.
  • Google Analytics 4 and Google Ads: record the same moments.
  • Snap Pixel: records the same moments. If automatic matching is switched on in the Snap account, the pixel reads an email or phone number typed into a form on the page and sends it hashed from your browser, never in plain text.
  • Our own measurement tag: the same code our clients put on their sites. It records the page view and clicks on WhatsApp, phone or email links on our server, and sends those same moments to Meta from the server (Conversions API) rather than the browser alone — the same events, no extra data.
  • When you create an account, your email is sent to Meta and Google hashed, so they can match your signup to the ad it came from. Neither receives the address itself; hashing happens in your browser before anything is sent.

What we never send from these pages: your business profile, your campaigns, your leads, your access tokens, or anything inside your account.

Why we measure: so we know which ad brought a real client instead of spending with no measurement.

How to stop it: tracking protection in your browser blocks these tools. You can also control what reaches each platform from Meta ad preferences and Google My Ad Center, and from Ad Preferences in the Snapchat app's settings.

6) Uploading your customer list (entirely optional)

You can ask us to build a Custom Audience on your own ad account from your customers' phone numbers, so your ad reaches them or people who resemble them. This only ever happens when you ask for it; it is never automatic.

  • What is sent: the number hashed (SHA-256), nothing else. The number itself never leaves our server; the ad platform receives the hash to match against its own accounts and cannot recover the number from it.
  • Where: to your ad account alone, on the platform you connected yourself. It is not shared with anyone else, not with our other clients, and not sold.
  • Your attestation first: we require an explicit confirmation that these are your customers and that you have their permission for marketing contact. We record who confirmed, when, and how many numbers — and no upload happens without it.
  • What we do not keep: neither the uploaded numbers nor their hashes. Processing happens in memory during the upload only.
  • Deletion: the audience lives inside your ad account, and you can delete it at any time from your own Ads Manager.

7) Third-party platform data

When you connect an ad account we use the official APIs (e.g., Meta Marketing API) and comply with each platform's terms (including the Meta Platform Terms). Platform data is used solely to provide the service to you and is not retained after you disconnect the platform or delete your account.

8) Google user data, specifically

We touch Google in two separate places, each under its own consent you grant on Google's own screen:

  • Sign in with Google: we receive only your email, name, and profile picture from Google, to create your account and sign you in through our authentication provider, Supabase. No other permission is requested.
  • Connecting a Google Ads account: we request a single scope, https://www.googleapis.com/auth/adwords (manage your Google Ads campaigns). We do not request access to Gmail, Drive, Contacts, Calendar, or any other Google service.

What we read from your Google Ads account: the ad accounts available to you; your campaigns, ad groups, ads, and keywords with their results (impressions, clicks, spend, conversions); search terms; and keyword search-volume estimates (Keyword Planner).

What we write to it: creating the campaigns you approved, enabling or pausing them, adding negative keywords, and setting up conversion goals — each on your instruction, nothing automatically. A Merchant Center account id is something you type in for Shopping campaigns; we do not read Merchant Center content itself.

What we use it for: showing your accounts and campaigns inside the platform, launching campaigns you approved, tracking their results, and giving you optimization recommendations. Google Ads data is used for nothing else — not to target ads at you, not to train models, not to build profiles of you or your customers.

What we store: the access and refresh tokens, encrypted with AES-256-GCM, in your account's own connection record; and a copy of your campaign results (spend, clicks, conversions) to show in your reports.

Who can see it: you and the members of your workspace according to their roles, and the platform operator for support and operations only. It is never shared with a third party, sold, or transferred.

Disconnecting and deletion: pressing "Disconnect" on the Connections page deletes the tokens from our database immediately, and they are deleted with your account as well. To revoke the grant on Google's side: Google account permissions.

Google policy compliance: Hamletak's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

9) Retention & security

We retain data for as long as your account is active. Safeguards include encrypted access tokens, HTTPS-only transport, per-client data isolation enforced server-side, least-privilege access, and audit logging.

10) Your rights & data deletion

At any time you may: access and correct your data, export your leads, disconnect any linked platform (which immediately deletes its stored access token), or permanently delete your account and all associated data.

To request deletion: email infosecengm@hamlet-ak.com from your account email with the subject "Delete my account". Deletion is completed within 30 days and covers your business profile, generated campaigns, access tokens, and leads.

11) Changes

We may update this policy; the "Last updated" date above will reflect it. Continued use of the platform after an update constitutes acceptance.

حملتك | Hamletak · شروط الاستخدام | Terms of Service

كلّمنا واتساب