Privacy Policy

Pathora ("pathora.net")

Effective Date: 26 April 2026

Last Updated: 26 April 2026


1. Introduction

This Privacy Policy explains how Pathora ("Platform", "we", "us", "our"), operated by [Company Legal Name] and registered in the Kingdom of Saudi Arabia, collects, uses, shares, and protects your personal data.

This Policy applies to all users of pathora.net, including Mentors and Mentees, and to any personal data collected through the Platform's websites, mobile applications, and APIs.

We are committed to compliance with:


2. Data Controller

[Company Legal Name]

Registered Address: [Registered Address, Riyadh, Saudi Arabia]

Email: [[email protected]]

For EU users, the Data Controller may appoint an EU representative. Contact us at the email above.


3. Data We Collect

3.1 Account and Profile Data

DataCollected fromPurpose
Full nameRegistration formAccount identity
Email addressRegistration formAuthentication, transactional email
Phone number (optional)Profile settingsAccount recovery, contact reveal
Profile photoProfile settingsPublic profile display
Bio and professional backgroundProfile settingsMentor discovery
Preferred language and localeApp settingsLocalized experience

3.2 Mentor Verification Data

Mentors are required to submit additional documentation:

DataPurposeRetention
Government-issued photo IDIdentity verificationUntil account deletion + 5 years
Business registration / commercial licenceProfessional verificationUntil account deletion + 5 years
Proof of income or professional credentialsPlatform integrityUntil account deletion + 5 years

Verification documents are stored with restricted access and are not shared with other users.

3.3 Session and Booking Data

DataSourcePurpose
Session request detailsUser inputSession facilitation
Booking timestampsCal.comScheduling confirmation
Session status (pending, completed, cancelled)PlatformService delivery
Session notes or goals (if provided)User inputSession context

3.4 Messaging Data

Messages sent through the Platform (pre-booking intro messages and in-session messages) are stored and used to facilitate the mentorship relationship and to investigate disputes.

3.5 Payment Data

Pathora does not store full card numbers or CVV codes. Payment processing is handled by Moyasar. We retain:

DataPurposeRetention
Transaction IDPayment reconciliation7 years (legal requirement)
Amount and currencyInvoicing and tax records7 years
Payout status and timestampsMentor disbursement records7 years
Refund historyDispute resolution7 years

3.6 Reviews and Ratings

Reviews submitted by Mentees are associated with your account and displayed publicly on Mentor profiles. We retain reviews unless a content policy violation is established or an account is deleted.

3.7 Technical and Usage Data

DataSourcePurpose
IP addressServer logsSecurity, fraud prevention
Browser type and device informationServer logsPlatform optimisation
Page views and click eventsPlausible AnalyticsAggregate usage analysis
Session identifiers and cookiesSupabase AuthAuthentication state
Error reports and stack tracesSentryBug detection and resolution

Plausible Analytics is used for privacy-preserving, cookieless analytics. No personal identifiers are passed to Plausible.

3.8 Communications Data

We retain records of support communications (emails, in-app messages with our team) for a period of 3 years.


4. Legal Basis for Processing

Under PDPL (Saudi Arabia)

We process personal data on the following bases under the PDPL:

Processing activityLegal basis
Account creation and authenticationContractual necessity / consent
Session booking and facilitationContractual necessity
Payment processing and disbursementContractual necessity / legal obligation
Mentor identity verificationLegitimate interest (platform integrity)
Marketing communicationsExplicit consent (opt-in)
Legal record retentionLegal obligation
Fraud and abuse preventionLegitimate interest
Aggregate analytics (Plausible)Legitimate interest

Under GDPR (EU users, where applicable)

Processing activityLegal basis (GDPR)
Account and session managementArt. 6(1)(b) — performance of contract
Payment and financial recordsArt. 6(1)(c) — legal obligation
Fraud prevention and securityArt. 6(1)(f) — legitimate interests
Marketing with consentArt. 6(1)(a) — consent
Aggregate analyticsArt. 6(1)(f) — legitimate interests

5. How We Use Your Data

We use personal data to:

We do not sell your personal data to third parties.


6. Third-Party Processors

We share personal data with the following sub-processors only to the extent necessary for service delivery:

ProcessorPurposeData sharedLocation
SupabaseDatabase hosting and authenticationAll account and session data, verification documentsEU (Frankfurt, Germany)
Cal.comSession scheduling and calendar syncName, email, booking timesEU / US
MoyasarPayment processingPayment card data, transaction amounts, account holder nameKSA
PostmarkTransactional email deliveryEmail address, name, email contentUS
Plausible AnalyticsPrivacy-preserving usage analyticsPage URL, referrer, device type (no PII)EU
SentryError tracking and monitoringAnonymised error logs, stack tracesUS

Each processor is contractually bound to process data only as instructed, maintain appropriate security, and comply with applicable law.

For Supabase: data is stored in EU (Frankfurt). Users in Saudi Arabia should be aware that personal data may be transferred to and stored in the EU. Such transfers are made under appropriate contractual safeguards.

For US-based processors (Postmark, Sentry): transfers occur under standard contractual clauses or equivalent safeguards.


7. Data Retention

We retain personal data for as long as necessary to provide the service and meet legal obligations:

Data categoryRetention period
Account and profile dataDuration of account + 30 days after deletion
Session and booking data3 years after session date
Messages2 years after session date
Payment and financial records7 years (KSA commercial records requirement)
Mentor verification documentsUntil account deletion + 5 years
Support communications3 years
Server and security logs90 days
Anonymised analytics dataIndefinite (no personal data)

When a retention period expires, data is securely deleted or anonymised. Data subject to ongoing legal disputes or regulatory investigations may be retained beyond standard periods until resolution.


8. Data Subject Rights

8.1 Rights Under PDPL (All Users)

Under Saudi Arabia's Personal Data Protection Law (PDPL), you have the right to:

8.2 Additional Rights for EU Users (GDPR)

If you are located in an EU member state, you additionally have the right to:

8.3 Exercising Your Rights via API

To exercise your data access and deletion rights programmatically:

Data Export (access request):

Returns a JSON file containing all personal data held on your account, including profile data, session history, messages, and payment records (excluding full payment card numbers which are not stored).

Account and Data Deletion:

Permanently deletes your account and all associated personal data, subject to data we are legally required to retain (e.g., financial records). Deletion is irreversible. You will receive a confirmation email upon successful deletion.

8.4 Manual Requests

You may also submit requests by email to [[email protected]]. We will verify your identity before processing the request and respond within 30 days (or within the timeframes required by applicable law). Where a request is complex or numerous, we may extend this period by a further 60 days and will inform you accordingly.

We will not charge a fee for data access requests unless they are manifestly unfounded or excessive.


9. Cookies and Similar Technologies

Pathora uses:

TechnologyPurposeCan be disabled?
Session cookies (Supabase)Authentication state — required to stay logged inNo (required for service)
Preference cookiesLanguage and locale settingsYes (via browser settings)
Plausible AnalyticsCookieless, privacy-preserving usage analytics — no personal dataN/A (no cookies used)

We do not use advertising cookies or third-party tracking cookies.


10. Children's Privacy

The Platform is not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have collected data from a person under 18, we will delete it promptly. Please contact us at [[email protected]] if you believe we have inadvertently collected data from a minor.


11. Security

We implement appropriate technical and organizational security measures to protect your personal data, including:

No system is completely secure. If you discover a security vulnerability, please report it to [[email protected]].

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and relevant authorities in accordance with applicable law.


12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes via email at least 14 days before the revised Policy takes effect. The "Last Updated" date at the top of this Policy reflects the most recent revision. Continued use of the Platform after the effective date constitutes acceptance of the revised Policy.


13. Contact

For privacy-related enquiries, data subject requests, or complaints:

Privacy Officer — Pathora

Email: [[email protected]]

Website: https://pathora.net

If you are not satisfied with our response, you have the right to lodge a complaint with:


This Privacy Policy was last reviewed and approved on 26 April 2026.