LEGAL & DATA GOVERNANCE

Privacy Policy

Effective Date: September 6, 2026 | Ashraf Systems Enterprise

01Introduction & Scope

Ashraf Systems Enterprise ("Ashraf Systems", "we", "us", or "our"), registration number 202603134409 (AS0515440-A), operates websites (including ashrafsystems.com), enterprise platforms (including UrusKargo TMS), and consumer mobile applications distributed via the Google Play Store and Apple App Store, including Wiridly: Digital Tasbih Companion and KiblatSaya: Qibla Compass (com.kiblatsaya.app).

We are deeply committed to respecting and protecting your privacy. This Privacy Policy outlines our principles regarding the collection, storage, use, and safeguarding of information when you interact with our digital services and mobile applications.

Our Core Privacy Commitment

  • check_circleZero Data Monetization: We never sell, rent, trade, or monetize your personal information or usage activity with advertisers or data brokers.
  • check_circleData Minimization: We only collect the bare minimum data necessary to deliver the intended functionality (e.g. syncing your personal notebooks).
  • check_circleOffline-First Sovereignty: Our mobile apps prioritize local device storage (SQLite), operating completely offline without requiring network connectivity.

02Mobile Application Disclosures — Wiridly: Digital Tasbih

Wiridly: Digital Tasbih Companion is engineered as a private spiritual recitation and litany notebook companion. Below are the precise data practices applicable to Wiridly:

A. Guest Mode (Zero Data Collection)

Users may use Wiridly completely anonymously in Guest Mode ("Quick Tasbih"). When in Guest Mode, zero personal data is collected or transmitted to any server. All counter increments and tallies remain strictly in-memory on your device and are cleared upon app termination.

B. Authenticated Accounts & Synchronization

If you choose to sign in with Google OAuth to backup or sync your custom prayer notebooks across devices, we collect and store:

  • Profile Details: Your Google Account email address, display name, and avatar image URL (managed securely via Supabase Auth).
  • Liturgical Content: Titles, prayer page sequences, dhikr target counts, Arabic verses/notes, and favorited books authored or curated by you.
  • Private PIN Codes: Optional 6-character sharing codes created by you to share notebooks privately with family or associates.

C. Device Hardware & Location Permissions

Wiridly requests only the minimum hardware capabilities necessary to deliver tactile recitation feedback and accurate Qibla orientation:

  • Vibration / Haptics (android.permission.VIBRATE): Used exclusively to deliver subtle 15ms physical clicks on counter increments and double pulses upon reaching target milestones or aligning with the Qibla.
  • Keep Screen Awake (android.permission.WAKE_LOCK): An optional setting to prevent the device display from dimming or locking during prolonged contemplation sessions. This is active exclusively during an active recitation session.
  • Device Location & Compass Orientation (ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION): Used solely while the user is actively viewing the Qibla Finder tab to calculate the great-circle mathematical bearing and distance to the Holy Kaaba in Makkah and display the user's current city. Location data is processed ephemerally on-device, is never stored on external cloud servers, is never collected in the background, and is never shared, monetized, or transmitted to third parties or data brokers.
  • No Other Sensitive Hardware Access: Wiridly does not request or access camera, microphone, contacts, calendar, or financial storage.

03Mobile Application Disclosures — KiblatSaya: Qibla Compass

KiblatSaya: Qibla Compass (com.kiblatsaya.app) is a standalone, privacy-first Qibla direction finder. Below are the precise data practices applicable to KiblatSaya:

A. Zero User Accounts & Anonymous Usage

KiblatSaya operates with zero login walls or user registration. We do not collect names, email addresses, phone numbers, advertising identifiers, or account credentials. All app preferences (such as selected color themes and display modes) are stored strictly on-device using local storage.

B. Foreground Location & Compass Sensors

KiblatSaya requires only the minimum device permissions needed to determine the accurate direction to the Holy Kaaba in Makkah:

  • Location Access (ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION): Used exclusively while the app is open in the foreground to calculate the great-circle mathematical bearing and distance to the Kaaba (`21.422487° N, 39.826206° E`) and resolve your current city name. Location coordinates are computed ephemerally on-device, are never stored on cloud servers, are never collected in the background, and are never shared or sold to third parties.
  • Vibration / Haptics (android.permission.VIBRATE): Used solely to provide subtle tactile feedback when the device rotates into exact alignment with the Kaaba.
  • Magnetometer & Motion Sensors: Used in real time to rotate the compass dial relative to True North. Sensor data is processed entirely in device memory.

C. Offline Capabilities & Zero Trackers

KiblatSaya includes a preloaded regional database of cities across Southeast Asia and the world, allowing full functionality without internet connectivity. The app contains no third-party advertising SDKs, no behavioral trackers, and no analytics profiling.

04Enterprise & Logistics Mobile Applications (UrusKargo)

For specialized enterprise applications such as the UrusKargo Driver App, data collection is strictly tied to operational dispatch services authorized by your employer or transport contractor:

  • Location Data: Background and foreground geographic coordinates are collected solely while a trip is active to calculate accurate delivery ETAs and geofenced terminal arrivals.
  • Camera / Document Storage: Used to capture delivery order photos and sign-on-glass electronic Proof-of-Delivery (e-POD).

05Data Storage, Security & Encryption

We implement robust technical and architectural security controls designed to safeguard your information:

  • Encryption in Transit: All data transmitted between our mobile applications, web platforms, and cloud servers is protected using Transport Layer Security (TLS 1.3 / HTTPS).
  • Database Isolation: Cloud data is secured via PostgreSQL Row Level Security (RLS), cryptographically preventing any user from accessing another user's private liturgical notebooks or records.
  • Local Database Sandboxing: Offline SQLite databases (AndroidX Room KMP) are stored inside the operating system's protected private application sandbox.

06Third-Party Service Providers

To provide reliable, high-availability infrastructure, we partner with industry-leading technology providers who adhere to strict data security standards:

  • Google LLC (Google Play Services & Google Identity): For distribution of Android applications and optional single sign-on authentication.
  • Supabase Inc.: For enterprise-grade managed PostgreSQL cloud database hosting, user session token management, and cryptographic authentication.

None of these third parties are permitted to use your personal information for marketing, advertising, or secondary commercial purposes.

07User Rights & Account Deletion Policy

In compliance with Google Play Store User Data policies and global privacy regulations (including PDPA and GDPR), you retain full ownership and control of your data:

  • Content Deletion: You can delete any book, page, or set directly within the Wiridly app at any time. Deletions cascade immediately to remote cloud storage.
  • Permanent Account & Data Deletion: You may request complete, irreversible deletion of your account, authentication profile, and all synced litany notebooks. To initiate account deletion, email us at privacy@ashrafsystems.com with the subject line "Account Deletion Request" from your registered account email. All personal records will be permanently purged within 30 days.

08Children's Privacy

Our services and applications are not directed towards children under the age of 13. We do not knowingly solicit or collect personal information from children under 13. If we become aware that personal information has been collected from a child without verifiable parental consent, we take immediate steps to delete that data from our servers.

09Contact & Inquiries

For any questions, requests, or privacy inquiries regarding this Privacy Policy or our mobile applications, please reach out to our privacy compliance officer:

Ashraf Systems Enterprise

Registration No: 202603134409 (AS0515440-A)

Email: privacy@ashrafsystems.com

General Inquiries: contact@ashrafsystems.com

Website: https://ashrafsystems.com

Country: Malaysia

Questions about our privacy protocols?

Our engineering team is committed to complete transparency and data sovereignty.

Contact Privacy Teamarrow_forward