Security & Privacy

Your customer data is a trust. We protect it seriously.

DAWEM is built from the ground up with tenant isolation and sensitive data encryption — because your data is not ours, it belongs to your customers.

PII Encryption

Phone numbers, names, and emails are encrypted in the database with AES-256. Logs and URLs contain only anonymised identifiers.

Full tenant isolation

Every merchant sees only their own customers' data. No tenant can access another tenant's data — isolated at the database query level.

PII-free audit logs

"Customer #123 viewed card" — not the name or number in system logs. Integration secrets are never written to logs.

Rate limiting & CSP

All public endpoints are rate-limited. Strict CSP headers prevent XSS. No eval, no inline scripts on card pages.

Encrypted API keys

WhatsApp and external API keys are encrypted in the database. Cannot be viewed in plain text even by administrators.

PDPL Compliance

Complete Arabic privacy policy, explicit consent at enrolment, and a clear data deletion request path. Built for the Gulf.

How we handle your data

Data type How stored Who sees it
Phone number AES-256 encrypted Owning merchant only
Customer name Encrypted Owning merchant only
Stamp history Tenant-scoped Owning merchant only
Integration secrets DB-encrypted, invisible in logs Nobody (write-only)
My DAWEM identity Encrypted, no tenant_id Customer only via Google OAuth
Activity logs Anonymised IDs only DAWEM team for diagnostics

Our security commitments

  • We never sell your customer data to third parties or share it with other merchants.
  • We provide encrypted daily backups and a documented recovery plan.
  • We store no payment card data — payments go through licensed gateways.
  • We notify of any breach within 72 hours per PDPL requirements.
  • Demo data is entirely fabricated — no real PII in the demo environment.