Privacy Policy
Last updated: 20 August 2026
3a Tari2ak (also called PeerPacks) is a campus peer-delivery app. Students order from shops near their university, and other students from the same university fetch the order and hand it over in person. This policy explains what the app collects, why, who can see it, and how to get it deleted.
For any question about this policy or about your data, contact hadichamli01@gmail.com.
What we collect
| Data | Why we collect it |
|---|---|
| Name, university, university email address | To create your account, to scope everything you see to your own campus, and so the student meeting you in person knows who they are meeting. |
| Student ID number and a photo of your student ID | Every account is approved by hand. An administrator reads the ID photo to confirm you are a student at the university you selected. This is the only thing that actually gates membership. |
| Profile photo | Shown to the other student on an order so you can recognise each other at the handover. |
| Gender | Used only for the female-couriers-only option, which lets a student restrict who may accept their order. |
| Precise location | While an order is active, both students share live location with each other so they can meet. Location is collected only while the app is open — the app does not request background location and cannot track you when it is closed. |
| Orders, delivery fees, drop-off descriptions, special instructions | To run the order itself and to show both sides their history. |
| Reports, appeals, and post-delivery feedback | To handle disputes between students and to review the service. Ratings are never shown publicly to other students. |
| Notification token | To send push notifications about your orders, deliveries and reports. |
| Crash diagnostics | If the app crashes, we receive a technical report (device model, operating system version, and the error) so it can be fixed. |
The app does not process payments. Money changes hands directly between the two students in cash, and no card or bank details are collected.
Who can see what
- Other students on your order see your name, profile photo, drop-off description, order contents and — while the order is active — your live location. They never see your student ID photo, your ID number, or your email address.
- Administrators can see your account details and your student ID photo, which they read once when approving your account and again if you are involved in a report. Access to ID photos requires an administrator account and a short-lived, signed link; the images are not publicly readable.
- Nobody else. Your data is not sold, rented, or shared for advertising. There is no advertising in the app.
Services we rely on
Running the app means storing your data with a small number of providers, who process it on our behalf:
- Google Firebase — account sign-in, database, push notifications, abuse protection and crash reporting.
- Cloudflare — image storage and the server that handles administrative actions and notifications.
- Google Maps — the map shown while an order is being delivered.
How long we keep it
Account data is kept while your account exists. Orders, reports and feedback are kept after an order finishes, because both students may need to refer to them and because a dispute may be raised afterwards.
What happens when you delete your account. Deleting your account removes your sign-in, your saved favourites, your profile photo and your student ID photo. It does not erase your past orders and reports, and your name, university, university email and student ID number stay attached to them.
This is deliberate. Orders and reports involve a second student who has their own record of what happened, and an open report must not become unresolvable because one side deleted their account. Your account is marked as deleted, and you can no longer sign in or be matched with anyone.
Full detail, and how to ask for a deletion, is on the account deletion page.
Security
Data is transmitted over encrypted connections. Student ID photos are served only through short-lived signed links available to the owner of the ID and to administrators. Access to the administrative dashboard requires an administrator account.
No system is perfectly secure. If you believe your account or your data has been exposed, email hadichamli01@gmail.com and it will be investigated.
Your choices
- Location can be refused or revoked in your device settings. Live delivery tracking will not work without it.
- Notifications can be turned off in your device settings.
- Your account can be deleted from inside the app at any time, under Account → Delete Account.
- A copy of your data, or a correction to it, can be requested by email.
Children
The app is for enrolled university students and is not directed at children. Accounts are approved manually against a student ID.
Changes to this policy
If this policy changes, the date at the top of this page changes with it. Material changes will also be announced in the app.