ربحRibh

Privacy Policy

Last updated: August 8, 2026

This document is maintained in English only, to ensure legal and technical accuracy. In case of any conflict between a translation and this text, the English version prevails.

Ribh (رِبح) is an ad-attribution and reporting tool for e-commerce merchants on the Zid platform. This policy explains exactly what data we collect — including data accessed through the TikTok, Snapchat, and Meta advertising APIs — why we collect it, and how a merchant can have it deleted.

1. Who this policy covers

This policy applies to merchants who install Ribh from the Zid App Market and connect one or more advertising accounts to it. Ribh is operated by Amr Gamal, trading as Ribh (رِبح). For any privacy question or data request, contact privacy@ribh.app.

2. Data we collect from your Zid store

  • Store identity: store ID, store name, currency, and timezone — needed to compute spend and revenue in the merchant's own currency and to time the daily report correctly.
  • Order totals and status (placed, cancelled, refunded) — needed to compute revenue per channel. We do not read customer names, phone numbers, shipping addresses, or cart contents.
  • A visitor's ad-click identifier (for example TikTok's ttclid or Snapchat's ScCid), captured by a small, asynchronous script on the storefront and matched to an order placed within 7 days. This identifier is not personal data — it does not contain a customer's name, email, or phone number.
  • A WhatsApp number, provided directly by the merchant during onboarding, used solely to deliver the daily report.

3. Data we access through connected ad platforms

When a merchant chooses to connect an ad account, they are sent to that platform's own OAuth consent screen and grant access explicitly. Ribh requests read-onlyaccess and never requests permission to create, edit, pause, or otherwise manage a merchant's campaigns or budgets.

TikTok Marketing API

Using the ads.readscope, we read: the connected ad account's ID and name, and campaign / ad group / ad level performance metrics (spend, impressions, clicks, and conversions) for a rolling 7-day window, synced on a nightly schedule. We do not access TikTok content APIs, consumer profile data, videos, comments, or any organic (non-advertising) account data.

Snapchat Marketing API & Meta Marketing API

Equivalent read-only scopes are used to read ad account identity and the same category of campaign-level spend and performance metrics from Snapchat and Meta (Facebook / Instagram) ad accounts a merchant connects.

4. How this data is used

Order data and ad-platform spend/performance data are combined to compute, per channel: spend, attributed revenue, return on ad spend (ROAS), and a single ranked budget recommendation. This is compiled into one daily WhatsApp message sent to the merchant. We do not use this data for advertising, retargeting, profiling of the merchant's customers, or any purpose beyond generating the merchant's own report.

5. Data sharing

We do not sell data. We do not share a merchant's store or ad-performance data with other merchants, advertisers, or data brokers. Data is only shared with the infrastructure providers strictly necessary to run the service (database and hosting providers), each bound to protect it, and is never used by those providers for their own purposes.

6. Data retention and deletion

Ad-platform and store data is retained only for as long as a merchant keeps the app installed and the corresponding account connected. If a merchant disconnects an ad account, we stop syncing new data from it immediately. If a merchant uninstalls Ribh, all associated store and ad-performance data — including any data obtained via the TikTok, Snapchat, or Meta APIs — is permanently deleted within 30 days. A merchant can also request immediate deletion at any time by emailing privacy@ribh.app.

7. Security

Access tokens and store data are stored in an access-controlled database, scoped per merchant, and transmitted only over encrypted (HTTPS) connections. Tokens are used exclusively by scheduled server-side jobs to sync a merchant's own data — they are never exposed to the browser or to other merchants.

8. Children's data

Ribh is a business tool for e-commerce merchants and is not directed at, or knowingly used by, children.

9. Changes to this policy

If this policy changes in a material way, the "last updated" date above will change and, where required, merchants will be notified via the app or by email.