Your customer data is a trust. We protect it seriously.
DAWEM is built from the ground up with tenant isolation and sensitive data encryption — because your data is not ours, it belongs to your customers.
PII Encryption
Phone numbers, names, and emails are encrypted in the database with AES-256. Logs and URLs contain only anonymised identifiers.
Full tenant isolation
Every merchant sees only their own customers' data. No tenant can access another tenant's data — isolated at the database query level.
PII-free audit logs
"Customer #123 viewed card" — not the name or number in system logs. Integration secrets are never written to logs.
Rate limiting & CSP
All public endpoints are rate-limited. Strict CSP headers prevent XSS. No eval, no inline scripts on card pages.
Encrypted API keys
WhatsApp and external API keys are encrypted in the database. Cannot be viewed in plain text even by administrators.
PDPL Compliance
Complete Arabic privacy policy, explicit consent at enrolment, and a clear data deletion request path. Built for the Gulf.
How we handle your data
| Data type | How stored | Who sees it |
|---|---|---|
| Phone number | AES-256 encrypted | Owning merchant only |
| Customer name | Encrypted | Owning merchant only |
| Stamp history | Tenant-scoped | Owning merchant only |
| Integration secrets | DB-encrypted, invisible in logs | Nobody (write-only) |
| My DAWEM identity | Encrypted, no tenant_id | Customer only via Google OAuth |
| Activity logs | Anonymised IDs only | DAWEM team for diagnostics |
Our security commitments
- We never sell your customer data to third parties or share it with other merchants.
- We provide encrypted daily backups and a documented recovery plan.
- We store no payment card data — payments go through licensed gateways.
- We notify of any breach within 72 hours per PDPL requirements.
- Demo data is entirely fabricated — no real PII in the demo environment.