1. Overview
ielaan operates an on-demand marketplace for smart LED screen advertising, currently available in Pakistan and Saudi Arabia. This Privacy Policy describes how ielaan Technologies Pvt Ltd ("ielaan", "we", "us") collects, uses, and protects personal data from advertisers, space owners, agencies, and visitors to ielaan.com.
By creating an account or using the Platform, you acknowledge you have read and understood this policy. If you do not agree, please do not use the Platform.
Data controller: ielaan Technologies Pvt Ltd. Questions? Email privacy@ielaan.com — we aim to respond within 5 business days.
If you use the ielaan Android Screen Client (space owners), additional device-level data is collected as described in the Android Client Privacy Addendum available in the app settings.
2. Information We Collect
2.1 Data you provide directly
- Account data: name, email address, phone number, company name, role (advertiser / space owner / agency).
- KYC documents (space owners above payout thresholds): national ID number, business registration number, tax ID. These are encrypted at rest using AES-256 field-level encryption.
- Payment data: billing address, last-4 of card (Stripe tokenises full card numbers — we never see or store them), bank account details for payout (space owners).
- Ad creatives and campaign data: uploaded images/videos, campaign names, scheduling preferences, targeting criteria.
- Venue & listing data: venue name, address, photos, screen specifications, operating hours, pricing.
- Communications: messages sent via the in-platform chat (proposals, dispute evidence), support tickets, and emails you send to us.
- AI Studio inputs: prompts you submit to generate ad creatives; generated outputs are stored in your campaign library.
2.2 Data we collect automatically
- Usage data: pages visited, features used, clicks, time on page, campaign creation/booking events.
- Device & browser data: IP address, browser type and version, operating system, referring URL, session ID.
- Cookie data: see our Cookie Policy for a full list of cookies and their purpose.
- Screen heartbeat & Wi-Fi RF data (Android client): device ID, connectivity status, screen-on/off events, and play-event logs (ad ID, timestamp, duration). Each heartbeat also includes aggregate Wi-Fi environment statistics: visible access-point count, RSSI summary statistics (min, max, mean), band distribution (2.4 GHz / 5 GHz / 6 GHz counts), connected network link speed and frequency, and scan-cache age. No BSSIDs, SSIDs, or MAC addresses are ever collected or stored. This data is used for campaign delivery verification, dispute resolution, and occupancy research.
2.3 Data from third parties
- Stripe: payment status, transaction reference ID, payout schedule. We do not receive raw card data.
- Google Maps Platform: geo-coordinates are validated against the Google Maps API when you submit a venue listing.
- OpenAI: if you use the AI Creative Studio, your prompts are sent to OpenAI's API. OpenAI's data use is governed by their privacy policy. We do not send identifiable personal data in prompts.
- Firebase Cloud Messaging: push notification tokens for the Android client.
| Purpose | Legal Basis |
|---|---|
| Provide and operate the Platform | Contractual necessity |
| Process payments and release escrow | Contractual necessity |
| Verify identity and prevent fraud (KYC) | Legal obligation / Legitimate interest |
| Send transactional notifications (booking confirmations, payout notices, dispute alerts) | Contractual necessity |
| Moderate ad content and enforce content policies | Legitimate interest |
| Run dispute resolution and generate evidence reports | Contractual necessity / Legal obligation |
| Improve Platform features and fix bugs | Legitimate interest |
| Send product updates and marketing emails (opt-out available) | Consent / Legitimate interest |
| Comply with legal obligations (tax records, anti-money laundering) | Legal obligation |
| Generate AI ad creatives via OpenAI API | Contractual necessity / Consent |
| Analyse campaign performance and provide reporting | Contractual necessity |
| Detect and prevent security incidents | Legitimate interest |
| Conduct privacy-preserving Wi-Fi occupancy research and generate estimated venue occupancy levels from aggregate Wi-Fi RF statistics to inform ad-slot pricing recommendations and campaign scheduling. These are venue-level statistical estimates — no individual person's device is identified or tracked. | Legitimate interest |
We never sell your personal data to third parties. Occupancy estimates produced by our Wi-Fi model are venue-level statistical inferences based on aggregate RF data from the screen device; they do not identify or track any individual. We do not use your data for automated decision-making that produces legal or similarly significant effects without human oversight.
5. Payments & Financial Data
Financial data is handled with additional safeguards:
ielaan uses Stripe Connect as its primary payment processor. Stripe is PCI-DSS Level 1 certified. We never store raw card numbers on ielaan servers. Payout bank details (space owners) are encrypted at rest using AES-256 field-level encryption, accessible only to authorised finance staff.
Transaction records are retained for 7 years from the date of transaction to comply with financial reporting and anti-money laundering regulations in Pakistan and Saudi Arabia.
7. Data Retention
We retain personal data only for as long as necessary to fulfill the operational purposes outlined in this policy, satisfy statutory legal and accounting requirements, and resolve potential disputes:
| Data Category | Retention Period & Policy | Policy Details |
|---|---|---|
| Account Profile & Credentials | Lifetime + 90 Days | Retained for the active duration of your account, plus 90 days following closure to allow account recovery before permanent deletion. |
| Campaign & Booking Records | 7 Years | Retained from campaign completion date to comply with statutory accounting, tax, and commercial compliance laws in Pakistan & Saudi Arabia. |
| KYC & Identity Documents | 7 Years | Retained from last payout date in accordance with Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF) statutory regulations. |
| Chat Messages & Dispute Files | 2 Years | Retained from formal dispute resolution date to facilitate audit trails, regulatory inquiries, and claim reviews. |
| Ad Creative Media Assets | 30 Days | Retained in campaign storage post-expiration unless explicitly saved to your library; permanently deleted from media servers within 30 days. |
| System & Security Logs | 12 Months | Aggregated and anonymized after 90 days; raw server telemetry and access logs deleted after 12 months. |
| Device Telemetry & Play Logs | 2 Years | Cryptographic proof-of-play records and device heartbeats retained for campaign delivery verification and advertiser auditing. |
| AI Creative Studio Prompts | 90 Days | Ephemeral prompt cache and generated preview variations permanently purged 90 days following generation. |
| Wi-Fi Occupancy Observations | 3 Years | Aggregated RF environment statistics and crowd-density models retained for research calibration, then permanently anonymized. |
8. Security
ielaan implements industry-standard security measures to protect your personal data:
- Encryption in transit: all data between your browser, ielaan servers, and third-party APIs is transmitted over TLS 1.2+ (HTTPS).
- Encryption at rest: sensitive fields (KYC ID numbers, payment account details) use AES-256 field-level encryption. General data is stored on encrypted volumes.
- Access controls: internal access to personal data is role-based and limited to staff who require it. Production data is never accessed in development environments.
- Penetration testing: we conduct annual penetration tests on the Platform and remediate findings within defined SLA windows.
- Incident response: in the event of a data breach affecting your personal data, we will notify you and relevant supervisory authorities within 72 hours of becoming aware, as required by applicable law.
- mTLS between internal services: service-to-service communication in our production environment uses mutual TLS to prevent unauthorised inter-service calls.
Despite these measures, no system is completely secure. If you discover a security vulnerability, please report it responsibly to security@ielaan.com.
9. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure: request deletion of your data, subject to our legal retention obligations.
- Right to restriction: request that we limit processing of your data in certain circumstances.
- Right to data portability: receive your data in a structured, machine-readable format.
- Right to object: object to processing based on legitimate interests, including direct marketing.
- Right to withdraw consent: where processing is based on consent, withdraw it at any time without affecting prior processing.
To exercise any of these rights, email privacy@ielaan.com with your full name and the email address on your account. We will respond within 30 days. Identity verification may be required before fulfilling your request.
10. International Transfers
ielaan's primary data processing infrastructure is hosted on AWS in the ap-south-1 (Mumbai) and me-south-1 (Bahrain) regions, chosen for proximity to our operating markets. Some data (AI processing via OpenAI, payments via Stripe) is processed in the United States. For users in the Kingdom of Saudi Arabia, we ensure transfers outside the Kingdom comply with the Personal Data Protection Law (PDPL) requirements, including the use of Standard Contractual Clauses or equivalent safeguards where required.
11. Children's Privacy
The Platform is not directed to persons under 18. We do not knowingly collect personal data from minors. If we become aware that a minor has provided personal data, we will delete it promptly. If you believe a minor has registered, contact us at privacy@ielaan.com.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email and an in-app notification at least 14 days before they take effect.
The "Last updated" date at the top of this page reflects the most recent revision. We encourage you to review this policy periodically.
13. Contact Us
For privacy-related requests or questions: