Legal

Privacy Policy

Effective Date: April 20, 2026

1. Privacy at a Glance

Majir is built to help users find and manage rewards and offers without turning private communications into a data product. We design for:

Data Minimization: We collect and retain only what we need to deliver rewards discovery and attribution.

Purpose Limitation: Inbox data is used to detect and maintain offers and rewards, not to read personal conversations.

User Control: Inbox access, notifications, and location are optional and can be turned off at any time.

No Sale of Personal Information: We do not sell your personal information.

2. What the Service Does

Email Read Access: If you connect Gmail or Microsoft Outlook, Majir processes reward and promotion-related emails from recognized senders to identify offers and rewards.

Rewards Summary: Majir surfaces a consolidated view of your offers and keeps them up to date.

Notifications (Optional): Alerts before rewards and offers expire.

Location (Optional): Used to match offers to real store locations and improve relevance. Majir does not send location-based alerts today.

3. Information We Collect and Process

a. Information You Provide

Account data (such as email address and preferences you set in the app) and support communications you send to us.

b. Read-Only Email Data (Only If You Connect Gmail or Microsoft Outlook)

Depending on the provider and permissions granted, we may process email metadata (sender, subject, date/time) and email content necessary to detect and extract offer and reward details (for example, merchant name, offer value, expiration date, redemption terms).

Important: Majir's intent is to avoid storing full message bodies. When feasible, we store only extracted offer attributes needed to operate your Rewards Summary.

c. Notifications

Device notification tokens and notification preferences.

d. Location

Approximate or precise location based on your device settings.

e. Device and Usage Data

IP address, device type, operating system, app version, logs, diagnostic data, and feature usage events.

f. Partner and Attribution Data

Click and referral identifiers and conversion signals used to measure offer performance and attribute outcomes.

4. How We Use Information

We use data collected to:

  1. Provide and operate the Service (connect inbox, detect offers, maintain the Rewards Summary).
  2. Improve relevance and reliability (deduplication, ranking, fraud prevention, debugging, performance).
  3. Deliver user controls (notifications, settings, location preferences).
  4. Support security and compliance (monitoring, abuse detection, audits, legal obligations).
  5. Partner measurement (aggregated reporting and conversion attribution).

5. How We Share Information

We do not sell personal information. We also do not share your private email content with merchants or affiliate partners. We may share limited data as follows:

a. Service Providers

We use vendors for hosting, analytics, security, and support. They process data on our behalf under confidentiality and security obligations. Current categories of service providers include:

  • Cloud Infrastructure: Microsoft Azure (hosting, storage, managed databases) and Azure AI Foundry (large language model inference, including DeepSeek models) for offer extraction and ranking.
  • Location Services: Google Places API for resolving the store locations shown with offers.
  • Authentication and Inbox APIs: Google (Gmail API) and Microsoft (Graph API) for the optional inbox connection you authorize.
  • Notifications: Firebase Cloud Messaging (Google) for push notification delivery.
  • Payments: Stripe for subscription billing where applicable.

b. Partners and Affiliate Networks (Attribution)

When you click or redeem an offer, we may share referral/click identifiers, offer or campaign identifiers, conversion signals (such as timestamp and event type), and aggregated performance metrics. We share what is reasonably necessary to operate attribution and reporting.

c. Legal, Safety, and Business Transfers

We may disclose information to comply with law, protect rights and safety, prevent fraud and abuse, or in connection with financing, acquisition, or asset transfers, subject to appropriate protections.

6. Advertising and Tracking

Majir may use analytics to understand product performance. We do not use connected inbox content to build cross-site behavioral advertising profiles from private messages.

Do Not Track Signals: Because there is no accepted standard for how to respond to Do Not Track browser signals, Majir does not currently respond to DNT signals. As Majir is a mobile application, this is generally not applicable to our Service.

7. Your Controls and Choices

  • Disconnect Gmail/Microsoft Outlook: Turn off inside the Service and/or revoke access in your Google or Microsoft account settings.
  • Disable Notifications: In device settings.
  • Disable Location: In device settings.
  • Access, Delete, or Correct Your Data: Contact us, reach out to us here.

8. Data Retention

We retain personal information for 90 days from the date of collection or last activity, unless a longer period is required to:

  • Protect against fraud and abuse,
  • Meet legal, tax, accounting, or audit obligations,
  • Resolve disputes or enforce agreements.

After the retention period, we delete or de-identify data.

9. Data Breach Notification

In the event of a data breach affecting your personal information, we will notify you via email at the address associated with your account. The notification will include:

  • A description of the breach and the types of information involved,
  • Steps we are taking to address the breach,
  • Recommended actions you can take to protect yourself,
  • Contact information for questions or concerns.

We will provide this notification without unreasonable delay and in accordance with applicable law, including the breach notification requirements under Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA") where those requirements apply. Where PIPEDA applies, we will also report breaches that pose a real risk of significant harm to the Office of the Privacy Commissioner of Canada and maintain records of breaches as required by law.

10. Security

We use safeguards designed to protect data, including access controls, encryption in transit, and secure handling of authentication tokens. We continuously improve protections.

11. Children

The Service is not intended for children under 13 (or the age required by local law). We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child under 13, we will delete it promptly.

12. International Users (United States, Canada, Mexico)

The Service is currently offered to residents of the United States, Canada, and Mexico. Users in other countries are not the intended audience of the Service.

a. Cross-Border Data Transfers

Majir is a United States company. Personal information collected through the Service is stored and processed in the United States on Microsoft Azure infrastructure, and may be processed by United States-based service providers listed in Section 5.a. If you access the Service from Canada or Mexico, you acknowledge that your personal information will be transferred to and processed in the United States, which may have data protection laws that differ from those in your country of residence. We rely on service provider contractual commitments and administrative, technical, and physical safeguards to protect your information during and after transfer.

b. Canadian Users (PIPEDA)

If you are a resident of Canada, Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA") and applicable provincial privacy laws (including Quebec's Law 25) may apply to our processing of your personal information. You may:

  • Request access to, correction of, or deletion of your personal information by contacting us through our contact form with the subject "Canada Privacy Inquiry",
  • Withdraw consent to specific processing at any time (for example, by disconnecting Gmail or Outlook and disabling notifications or location),
  • Receive a response to a privacy request within thirty (30) days where required by law.

External Redress: If you are not satisfied with our response to a Canadian privacy request, you may contact the Office of the Privacy Commissioner of Canada ("OPC") at www.priv.gc.ca, or your applicable provincial privacy regulator.

c. Mexican Users (LFPDPPP and ARCO Rights)

If you are a resident of Mexico, the Federal Law on Protection of Personal Data Held by Private Parties ("LFPDPPP") may apply to our processing of your personal information. Under LFPDPPP you have ARCO rights, meaning the right to:

  • Acceso (Access): Know what personal information we hold about you and how we use it,
  • Rectificación (Rectification): Correct personal information that is inaccurate or incomplete,
  • Cancelación (Cancellation): Request deletion of personal information when its processing is no longer justified,
  • Oposición (Objection): Object to specific uses of your personal information.

How to Submit an ARCO Request: Contact us through our contact form with the subject "ARCO Request". Please include your name, the email address associated with your Majir account, the ARCO right(s) you wish to exercise, and any documents reasonably necessary to verify your identity. We will respond within the timeframes required by LFPDPPP (generally within twenty (20) business days to acknowledge the request).

External Redress: If you are not satisfied with our response, you may contact Mexico's National Institute of Transparency, Access to Information and Personal Data Protection ("INAI") at home.inai.org.mx.

d. Users Outside the United States, Canada, and Mexico

We do not intend the Service for users outside these three countries and we do not knowingly collect personal information from individuals who are not residents of one of them.

13. California Privacy Notice (CCPA/CPRA)

This section provides disclosures for California residents and applies to the extent the California Consumer Privacy Act, as amended by the CPRA ("CCPA/CPRA"), applies.

a. Notice at Collection

In the last 12 months, we may have collected these categories of personal information:

  • Identifiers: Email address, account IDs, device identifiers.
  • Commercial Information: Offer interactions and redemption-related events.
  • Internet or Network Activity: Usage logs, IP address, device data.
  • Geolocation: Approximate or precise location (only if enabled).
  • Inferences: Offer relevance signals derived from your interactions.

Sources: You, your connected email provider (only with your authorization), your device, and our partners for attribution data.

Business Purposes: Operate the Service, maintain your Rewards Summary, improve product performance, secure the Service, and measure partner attribution.

b. Sale and Sharing

We do not sell personal information as "sell" is defined under the CPRA. We also do not "share" personal information for cross-context behavioral advertising. If our practices change, we will update this policy and provide opt-out mechanisms required by law.

c. Sensitive Personal Information

Sensitive personal information may include precise geolocation and contents of communications. Majir uses such information only as reasonably necessary to provide the Service you request (for example, detecting offers you asked us to find) and for permitted security and compliance purposes.

d. Your California Rights

Subject to verification and legal exceptions, you may have the right to:

  • Know/access the personal information we collected and how we used it,
  • Delete personal information,
  • Correct inaccurate personal information,
  • Opt out of sale or sharing (not currently applicable as described above),
  • Limit the use of sensitive personal information (where applicable),
  • Non-discrimination for exercising rights.

How to Submit a Request: Reach out to us here with "California Privacy Request" in the message. We will verify your request (for example, by confirming control of the account email). You may also use an authorized agent consistent with CPRA requirements.

e. Retention (California)

We retain personal information for 90 days, or longer as reasonably necessary to meet legal requirements, resolve disputes, and enforce agreements.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will revise the Effective Date at the top of this document. For material changes, we will provide notice through the app or via email before the changes become effective.

15. Contact

Majir Inc.
Questions? Reach out to us here.

Appendix: Inbox Permissions and Scope Usage (Google and Microsoft)

Google Gmail Scope

Scope: https://www.googleapis.com/auth/gmail.readonly

Meaning: Read-only access to Gmail messages and metadata you authorize. Majir cannot send email, delete messages, or modify your mailbox using this scope.

How Majir Uses It: Detect and extract reward and promotion offer details; maintain your Rewards Summary and notify you before offers expire (if enabled).

Microsoft Outlook Permission

Permission: Mail.Read

Meaning: Read access to mail messages you authorize. Majir cannot send, delete, or modify mail using this permission alone.

How Majir Uses It: Detect and extract reward and promotion offer details; maintain your Rewards Summary and notify you before offers expire (if enabled).

User Control: You can disconnect at any time in Majir settings and revoke permissions from Google or Microsoft account security settings.