Privacy
What this platform collects, why it collects it, how long it keeps it, who else ever sees it, and what you can ask us to do about it. Written from the code that actually runs here.
Last updated:
This policy was drafted for this platform by the team that built it, and it describes how the platform actually works today. It is not the work product of a lawyer. Before relying on it — and before treating it as compliant with any particular law — have it reviewed by a lawyer qualified in the United Arab Emirates.
This website (weeam.info) and the products sold on it are operated by WEAM ELNAGGAR REAL ESTATE, a real-estate brokerage licensed in Dubai, United Arab Emirates, holding RERA licence number 1196276. The owner is Weeam El Naggar, known in the market as «العرّاب» — the Real Estate Godfather.
Registered legal name: [TO BE COMPLETED: the exact registered name of the legal entity]. Registered address: [TO BE COMPLETED: registered office address]. Trade licence number: [TO BE COMPLETED: trade licence number].
You can reach a person at info@weeam.info, or on WhatsApp at +971 58 557 7271. Every message is read by a human being, not a queue.
We collect what we need to give you an account, sell you a book or a course, let you read it, answer you, and keep the whole thing secure. We do not sell your personal data, and we do not hand it to advertisers.
Your payment card details never reach our servers at all — see "Buying, paying and refunds" below.
You can ask us, at any time, for a copy of what we hold, for a correction, for deletion, or to stop marketing email. Write to info@weeam.info and a person will handle it.
The rest of this page is the long version, section by section, because the short version is not enough to agree to.
Data protection contact: [TO BE COMPLETED: name and email of the person responsible for data-protection requests — until this is filled in, requests go to info@weeam.info].
WHAT WE COLLECT. The signup form asks for, and we store: your full name (split into a first and last name), your email address, your phone number, and your nationality. Both the phone number and the nationality are required. The phone number is normalised on our server into international E.164 format; the nationality is stored as a two-letter ISO country code, not as the text you saw in the list.
We also store: a one-way cryptographic hash of your password (bcrypt, cost factor 12 — the password itself is never stored and cannot be recovered from the hash, only reset); the date and time you ticked "I agree to the Terms of Service" and "I agree to the Privacy Policy"; whether you opted in to marketing email; your preferred language; and the IP address your signup request arrived from.
WHAT WE DO WITH THE IP ADDRESS. It is stored, and it is used once — after your account is created — to look up the city and country the signup came from, which we store alongside it. That lookup is done against a database file on our own server. Your IP address is not sent to any third-party geolocation service. If the owner has not enabled the lookup, no city or country is derived and only the IP is kept. The IP address is shown only on the individual learner screen inside the admin, to staff with a specific permission; it is deliberately kept out of admin lists, CSV exports and emails.
WHY. To create and secure the account, to know who bought what, to be able to reach you about your purchase, and — because this is a Dubai real-estate business — to understand where our readers are and what they may be eligible to buy.
BASIS. Performing the contract you asked for (an account and access to what you bought), your consent for marketing email specifically, and our legitimate interest in operating and securing the platform.
HOW LONG. For as long as the account exists, and afterwards as described under "What deleting your account actually removes".
AGE. This platform is sold to and intended for adults. Do not create an account if you are under 18. If we learn that an account belongs to a child, we will remove it.
While you read a book or take a course, we record your progress so you can pick up where you left off and so the owner can tell what is actually being read.
WHAT WE COLLECT. Which chapters, sections and lessons you have completed; where in a chapter you stopped (a scroll position); a percentage complete; total time spent reading or learning; bookmarks you create, including any short label you type on one; your answers in interactive worksheets and checklists inside a lesson; and any review or rating you choose to publish.
IF YOU ARE NOT SIGNED IN, none of this is sent to us. A signed-out reader's progress is kept only in that browser's local storage, holds nothing identifying, and is merged into your account the first time you sign in.
WHY. To make the product work, and to see which material lands.
BASIS. Performing the contract; the reviews you write are published with your consent.
HOW LONG. For as long as the account exists. Progress records are deleted when an account is deleted.
WE NEVER SEE YOUR CARD. Checkout on this site is a redirect to the payment provider's own hosted payment page — Stripe or Network International (N-Genius), whichever the owner currently has switched on. You enter your card details on the provider's page, on the provider's systems. This application does not embed a card field, does not receive a card number, expiry date, security code or cardholder name, and stores none of them — not even the last four digits. We verified this claim against the payment code before writing it here.
WHAT WE DO STORE. An order record: your user id, the status, the currency, the amount in minor units, which provider and whether it was in test or live mode, the provider's reference for the transaction, the products bought with a snapshot of their title and price, and the timestamps for creation, payment and refund. We also store the provider's webhook events by event id, so a repeated delivery cannot create a duplicate order — the stored event holds the event type, its status and whether it was a test or live event, not the provider's full payload. For a refund we additionally store the provider's payment, charge and refund references.
Your email address is passed to the payment provider so it can send you its receipt.
REFUNDS. If you ask for a refund we store the email you paid with, the language you asked in, the product, the reason you picked, anything you typed in the free-text box, and a snapshot of how the guarantee applied at that moment. The refund promise itself, and how to use it, live on the refund page: /refund.
WHY. To sell you something lawfully, to give you what you paid for, to honour the guarantee, and to keep the accounting records a business must keep.
BASIS. Performing the contract, and our legal obligation to keep financial records.
HOW LONG. Order, payment-event and refund records are kept as business and tax records after an account is deleted — they are financial history, not profile data, and they stop being linked to a live identity once the account is anonymised.
If you use the AI investment advisor, you answer a questionnaire — your goal, budget band, payment preference, timeframe, experience, whether you have bought before, risk style, readiness, and the country you live in (which you type yourself).
WHAT IS SENT, AND TO WHOM. Those answers are sent, from our server, to Anthropic — the company behind the Claude models — which generates the plan. We use Anthropic's official SDK and Anthropic's Claude models. Alongside your answers the prompt carries the brokerage's own public profile and a filtered set of projects and market figures from our own database. Your name, email address, phone number, IP address and account id are NOT placed in the prompt. Anthropic is a processor acting on our instructions; see Anthropic's own privacy terms for how they handle API data.
WHAT WE STORE. Your questionnaire answers, the full generated plan, which projects it referenced, whether it used a paid credit, and the token counts and cost of the generation. Plans are visible to the owner and to staff working the advisor queue, because the whole point of the advisor is that a human follows up.
WHY. To produce the plan you asked for, and to let the owner follow up on it as a real-estate enquiry.
BASIS. Performing the service you requested.
HOW LONG. For as long as the account exists. When an account is deleted, your questionnaire answers and the generated plan text are erased; only the cost and paid-credit accounting for the generation is kept — see "What deleting your account actually removes".
THE CONSULTATION FORM stores your name, email, phone number, the kind of business you described, your reason for writing, a budget band, your message, the language you wrote in, the page you wrote from, and any campaign parameters (utm_source, utm_medium, utm_campaign) that were on that link. We also record whether the notification email reached us.
THE WAITING LIST stores your name, email, WhatsApp number, which product you are waiting for, the consent you gave, whether you opted in to marketing, the page you signed up from and the same campaign parameters.
WHY. To answer you, and to tell you when the thing you asked about exists.
BASIS. Your consent — you chose to write to us.
HOW LONG. Lead and waiting-list records are kept while they are commercially live. When an account is deleted, both lead and waiting-list records under the same email address are anonymised — including the phone and WhatsApp numbers and anything you typed in the message.
Transactional email — account verification, password reset, invitations, purchase confirmation, refund decisions — is queued on our server and sent through whichever provider the owner has configured: Resend, or a standard SMTP mail server. The provider is a processor and sees the message it is asked to send.
WHAT WE LOG. For each message: the recipient address, the type of message, the language, delivery status, how many attempts were made, which provider sent it, the provider's message id, and a sanitised error code if it failed. The single-use tokens inside verification, invitation and reset links are never stored and never logged — only their hashes exist in the database, and the link itself is built and sent without being written down.
MARKETING EMAIL is separate and only goes to people who ticked the optional box. You can withdraw that at any time — write to info@weeam.info, or use the unsubscribe route in the message.
BASIS. Performing the contract for transactional mail; consent for marketing mail.
COOKIES THIS SITE SETS. Every one of them, and nothing else: - weeam_learner_session — your signed-in session as a reader. Signed, http-only, 24 hours. - weeam_admin_session — a staff session, scoped to /admin. Signed, http-only, 12 hours. - weeam_gateway — which workspaces a signed-in staff member may open. Signed, http-only, 12 hours. It carries no identity, no roles and no secrets. - weeam_nav — a display-only hint so the header can show the right link without re-rendering every page per visitor. Readable by the page, carries no identity. - weeam_view / weeam_view_nav — a 30-minute "view the site as a learner" mode for staff. - weeam_consent — your analytics and marketing choices, if a consent banner is ever shown. Default lifetime 180 days.
Session cookies are marked Secure in production. The consent cookie is written by the page itself and is currently not marked Secure; that is a gap we are recording honestly rather than papering over.
WHAT YOUR BROWSER STORES LOCALLY (not sent to us): - theme — light or dark. - weeam_attr — first-party attribution: the campaign parameters, referrer and landing page of your first visit, plus a random session id. No personal data, no third-party cookie. - reading preferences — font size, line height, column width, reader theme. - reading position, "chapter read" flags and the last item you opened, per book and per course. - signed-out reading progress, and signed-out worksheet answers. - which admin sidebar groups are open (staff only).
Strictly necessary cookies (sessions, consent) are set because the site cannot work without them. Nothing else is set without your choice.
The platform contains an admin-configurable tracking layer that can be connected to Meta Pixel (with Meta's Conversions API), Google Analytics 4 and Google Tag Manager.
AS THE CODE SHIPS, NONE OF IT IS ON. A provider only loads if the owner has created it, enabled it, marked it live and validated it — and the shipped defaults are "disabled" and "not configured". Consent is deny-by-default: with no stored choice, consent is treated as refused. The Meta Pixel additionally requires marketing consent before its script is even injected. The server-side conversions endpoint does nothing at all unless a live, enabled, validated provider exists and consent was granted. There is no Vercel Analytics and no Speed Insights in this application.
This means: if you are seeing a cookie banner on this site, tracking has been switched on since this sentence was written, and the banner is where you choose. If you are not seeing one, nothing is loading.
IF IT IS EVER SWITCHED ON, this is what the code does: it logs the event name, the provider, the environment, the surface, whether consent was given, the HTTP status and a sanitised error — never a secret and never raw personal data — and keeps those logs for 90 days by default. Email addresses and phone numbers used for advertising "advanced matching" are SHA-256 hashed before they leave, and advanced matching is off by default.
We are not asserting that any specific advertising or analytics regulation is satisfied by this design. Have that assessed before enabling anything.
WHAT WE RECORD FOR SECURITY. Staff actions inside the admin are written to an audit log: who acted, what they did, which record, a short metadata note, the IP address of the request and a truncated user-agent string. A small number of public events are logged the same way — a learner signup, an email verification, a confirmed payment, a change to the refund policy, an account archive, restore or deletion, and a CSV export.
RATE LIMITING. When a form or endpoint is rate-limited, the record identifies the visitor by a SHA-256 digest, not by a readable IP address.
SECRETS. Passwords are stored only as bcrypt hashes. Verification, invitation and password-reset tokens are stored only as SHA-256 hashes. Payment-gateway, email-provider and AI-provider credentials are encrypted at rest with AES-256-GCM and are never rendered back into the admin screens.
MEDIA. Images in the media library are uploaded by staff only; there is no learner upload anywhere on the platform. Each asset records who uploaded it. Files are stored on the configured object storage (S3-compatible, or Vercel Blob); private course and book resources are stored separately and delivered only through short-lived signed links.
WHY. To keep accounts and money safe and to be able to reconstruct what happened.
BASIS. Our legitimate interest in the security and integrity of the platform.
We do not sell your personal data and we do not share it with advertisers.
We do use service providers, each of which sees only what it needs to do its job: - The payment provider you check out with — Stripe or Network International (N-Genius), whichever the owner currently has switched on. They see your email and the transaction; they, not us, handle your card. - Anthropic — only if you use the AI advisor, and only the questionnaire answers and the brokerage's own catalogue data described above. - The configured email provider (Resend, or the owner's SMTP host) — the message and the address it goes to. - The hosting and storage providers that run the site and hold uploaded files.
We will also disclose data where a law, a court or a regulator in the United Arab Emirates requires it.
Notably, we do NOT send your IP address to a geolocation service: that lookup runs against a file on our own server.
The business is in Dubai, United Arab Emirates. Some of the service providers above operate outside the UAE — Anthropic and Stripe are United States companies, and the hosting, storage and email providers may run in other regions depending on how the owner has configured them. Using this platform means your data may be processed outside the UAE by those providers under their own terms.
[TO BE COMPLETED: the hosting region, storage region and email provider actually in use in production, so this section can name them]
Where a period is not fixed above, we keep the record for as long as it serves the purpose it was collected for, or as long as a law requires — whichever is longer.
You can ask us to: - give you a copy of the personal data we hold about you; - correct anything that is wrong; - delete your account and the personal data attached to it; - withdraw a consent you gave — including the marketing opt-in — without affecting anything done before you withdrew it; - stop sending you marketing email; - explain anything on this page in plain language.
HOW. Write to info@weeam.info from the email address on the account, or message +971 58 557 7271 on WhatsApp. Say what you want; you do not have to justify it.
BE AWARE OF ONE HONEST LIMITATION: there is no self-service "delete my account" button on the site today. Deletion is carried out by the owner or an authorised administrator, from the admin, after confirming the exact email address and recording a written reason. It is a real, working procedure — it is simply operated by a person rather than by you. We will confirm to you when it is done.
If you are not satisfied with how we handled a request, tell us first — and then you are free to raise it with the competent authority in the United Arab Emirates.
We would rather state this precisely than let you assume it.
DELETED OUTRIGHT: your reading and course progress, section-level progress, reading and learning state, bookmarks, reviews and helpful votes, everything you typed into interactive worksheets and checklists, any internal notes staff wrote about you, pending invitations, password-reset and email-verification tokens, linked-account records and coupon links. Your AI-advisor questionnaire answers and the generated plan text are destroyed. Active access to books and courses is revoked.
ANONYMISED IN PLACE: the account row itself becomes a tombstone. Your email address, name and display name are replaced; your phone number, password hash, nationality, timezone and profile photo are cleared; the IP address recorded at signup and the city and country derived from it are cleared; and marketing consent is set to false. Lead and waiting-list records under your email address are anonymised, including phone and WhatsApp numbers and anything you typed. Mail already sent to you keeps only a tombstone address, and anything still queued is cancelled. On a refund request, the email and order reference you typed and your free-text reason are erased. The row survives only so that the financial records below still point somewhere consistent.
RETAINED DELIBERATELY, AS BUSINESS RECORDS: orders and order items, payment events, subscriptions, coupon redemptions, the structured half of any refund request (amount, currency, product, decision, dates, who decided), the cost and paid-credit accounting for advisor generations — kept as empty shells, with your answers and the plan text destroyed — and the sanitised audit history, which records that an action happened without keeping the personal data behind it. These are records of money moving and of who did what; we are required to keep them, and they no longer point at a live identity.
If you believe something personal survived that is not on this list, say so and we will remove it by hand.
We may update this policy — for example when the platform starts doing something new, or stops doing something described here. The "last updated" date at the top of this page changes when the published text changes.
If a change materially affects what we collect or what we do with it, we will make a reasonable effort to tell account holders by email before it takes effect. Continuing to use the platform after a change means the updated policy applies.
Questions about anything on this page go to info@weeam.info.