Skip to content

Privacy policy

Version 2026-10

Draft for legal review. This text is a plain-language draft and has not yet been approved by a lawyer.

Masar helps employers see where their delivery workers are during working hours. This policy explains, in plain language, what data is handled, why, who can see it and how to have it deleted. It is written for workers and for employers.

Who we are and our roles

Masar is a service that employers (called workspaces) use to see the working-hours position and day summary of their delivery workers.

For workers' data the workspace is the controller: it decides to use the service and what to do with the data. Masar is the processor and handles that data only for the workspace and on its instructions.

For the account data of workspace admins (sign-in, contact and billing details) Masar is the controller.

What data is handled

Depending on your role, the service handles the following.

  • Workspace admin data: name, e-mail address, phone number, business address, the workspace name and the devices and browsers you are signed in on.
  • Worker identity and plan: name, phone number, job title, notes, weekly schedule and days off.
  • Precise location points recorded during the scheduled hours and the grace period: time, position, accuracy, speed and heading.
  • Stops and trips that are derived from those points.
  • Device information: operating system, app version, battery level, connectivity, whether location and GPS are switched on and whether the phone reports a mock location.
  • Worker events: start and end of the day, pause and resume with an optional reason, and permission changes.
  • An access log of when employers viewed or exported location data, and support and billing messages.

What we never collect

The worker app does not read or collect your contacts, photos, messages, other apps, microphone or camera.

Why the data is used

Location data is used only so that the employer can see the live position during working hours, keep a record of stops and trips, and see attendance. It is never used for advertising, never sold and not used for profiling.

The legal basis for workers' data is the contract between Masar and the workspace and the employer's legitimate interest in running its deliveries. The location permission you give on your phone is the technical consent that switches tracking on. For account data the basis is the contract with the workspace.

When tracking happens

Tracking follows the worker's scheduled hours, plus a short grace period. The app starts up to 15 minutes before the scheduled start and stops at the scheduled end. The server accepts points from 60 minutes before the start until 60 minutes after the end and rejects everything outside that window. There is no tracking on days off.

Your employer can see your live position only during your scheduled hours. The stored history can also include the grace-period minutes.

While tracking is active the phone shows it: a persistent notification on Android and the system location indicator on iPhone. If the workspace allows it, you can pause tracking. Pausing is logged with an optional reason and is visible to your employer.

You can see your own day, and what is being shared, in the app at any time.

Who can see the data

Only the admins of your workspace can see your location data. Every time they view live positions or a day, or export a timeline, a row is written to an access log that the workspace can read.

The platform operator can see counts and system health but never positions, stops or trips of any worker.

A coordinate reaches a third party in one case only: when an employer explicitly clicks the link to open a stop in Google Maps or Apple Maps. That opens the other service in a new tab and is never done automatically. No third-party geocoding service is used.

We use the following kinds of service providers, listed by category: a hosting provider for the application, a database provider for storage, an e-mail delivery provider for account e-mails and a map tile provider whose tiles your browser loads (tile requests reveal the area being viewed, never which worker is shown).

Where data is stored

Data is stored with the hosting and database providers described above, in the region chosen by the operator, which can be outside your country. We rely on our agreements with those providers and on the safeguards in this policy.

How long data is kept

Different data is kept for different periods. Each workspace can change both location periods within these limits, and the worker sees the numbers in the app.

  • Exact location points: up to 30 days by default. A workspace can choose between 7 and 90 days.
  • Stops and trips (day summaries): up to 180 days by default. A workspace can choose between 30 and 730 days.
  • Worker events: up to 90 days.
  • Access log: 12 months.
  • Backups: they age out within 30 days, so deleted data can remain in a backup for up to that long. If a backup is ever restored, earlier deletions are applied again.

Your rights and how to use them

You can ask to see your data, have it corrected, have it deleted, limit it or object to its use. Workers can see their own day in the app. Because the workspace is the controller of workers' data, requests about it can also go to the employer.

To delete location data: workers use "Leave and delete my data" in the app, employers can delete a worker's location data on the Workers page, and anyone else can contact us. The delete-my-data page explains each path. We answer requests within 30 days.

How we protect it

Traffic is encrypted. Each workspace's data is kept separate from every other workspace, passwords and device tokens are stored only as one-way hashes, join codes work once and expire, and phones keep their token in the system's secure storage.

If a breach puts your data at risk, we tell the affected workspaces without undue delay so that workers can be told.

Children

The service is for adult workers. Employers must not add workers under 18, and we do not knowingly process data of children.

Changes and local law

If this policy changes in a way that matters, we update the version number above, and the app asks workers to accept the new text before tracking continues.

No comprehensive data-protection law is currently in force in Iraq, including the Kurdistan Region. We therefore apply GDPR-style principles: transparency, a fixed purpose, as little data as possible, limited storage, security, and rights of access and deletion. Employers remain responsible for any other law that applies to them.

Cookies on the website

The website uses a session cookie to keep you signed in and a security cookie that protects forms. Both are strictly necessary. The site also remembers your light or dark choice on your device. There are no analytics, no advertising cookies and no third-party trackers.

Contact

For questions about this policy or to use your rights, contact us. To delete location data directly, see the delete-my-data page.

Back to top