Privacy Policy
Last updated: September 2026
Team Syria (فريق سوريا) respects your privacy. This policy explains what information we collect when you use the platform and how we use, share, retain, and protect it.
Information we collect
- Account and setup information: your name, email address, country, city or town, its associated administrative region, and your Syrian or supporter participation lane. A lane is not nationality, and we do not collect your age or date of birth.
- Personal-trust recording: a short video we sometimes ask you for after account setup, reviewed by a human before personal trust is granted.
- Profile and business information: information you choose to add, such as your photo, bio, services, skills, work history, resume, and business details.
- Employer verification evidence: a private document you submit for review of one employer-only profile.
- Content you provide: posts, jobs, projects, events, offers, questions, comments, messages, and related attachments.
- Location: we use device coordinates transiently only when you choose a location action, so we can suggest your city or town or show nearby results and stations. We do not store those coordinates in your profile or continuously track your location.
- Technical information: device and browser details and sign-in records needed to operate and protect the platform and prevent abuse.
- Device notifications: an app-specific notification token, the device platform, and a random installation identifier when you choose to enable notifications.
Personal-trust recordings and employer documents
Personal-trust videos and employer verification documents are stored privately and are available only through a temporary link to the person or staff authorized to review that exact request. Personal-trust videos are reviewed by a human and are not used for automated facial recognition. We begin deleting a video when its trust review is approved, rejected, or expires. We begin deleting an employer document as soon as its employer review is approved or rejected; a temporary review hold retains it until a decision can be made. Cleanup runs in the background and may take a short time to finish.
How we use information
- To operate the platform, including profiles, directories, messaging, applications, events, offers, and other community features.
- To complete open email signup, evaluate personal-trust requests, and review one employer when you submit evidence for it.
- To provide search, location, and map features you request.
- To communicate with you about your account, requests, and important service notices.
- To protect the platform and its members, investigate reports, and prevent fraud and abuse.
- To understand platform performance, improve the service, and fix failures.
Sign-in
Sign-in is tied to your email address. We either send a temporary code to that address, or, on our website or in the iPhone app, you choose “Continue with Apple” or “Continue with Google” as proof that the address is yours. None of these uses a password.
Content safety review
New public posts, comments, questions, answers, and attached still images are kept out of public view while automated safety services assess them against our content policy. Human reviewers may then publish the item or confirm a violation. We send only the submitted content and the limited context needed for that assessment, not your private contact details, résumé, or direct messages. A service error leaves the item held for retry. An automated hold is not a warning or violation; only a human-confirmed decision affects your moderation record, and an accepted appeal reverses that decision.
Profile visibility
Full member profiles are available only to people who completed an account. By default, a shared profile link shows a generic Team Syria preview outside the community. You may opt in to a limited preview containing your name, photo, city, and headline. An approved professional listing is public because listing is an explicit opt-in. Public content you author remains public under that content area's rules even when your profile preview is off.
Privacy officer
The person with highest authority at Team Syria acts as our privacy officer. Contact them about anything concerning your personal information, or to exercise the rights above, at privacy@teamsyria.com. If you are not satisfied with the response, you may complain to Quebec’s Commission d’accès à l’information.
Account security and abuse prevention
When account setup is completed or a personal-trust request is submitted, we derive a keyed one-way fingerprint from the network address. The private key remains on our servers, and the network address itself is not stored in this record. We use the fingerprint to show authorized reviewers how many accounts were previously created from the same connection. It is never an automatic block because households, workplaces, and VPNs may share one address. The request link is deleted within 30 days, the direct account link is removed when the account is deleted, and account fingerprints are automatically deleted within one year of the last related account creation.
First-party analytics and diagnostics
We use first-party analytics only, with no third-party analytics or advertising tools. We record the event type, the page path without search terms, the referring domain, a coarse device category, and a random identifier scoped to one browser tab. If you are signed in, an event may be associated with your account. We use the network address transiently for rate limiting but do not store it in the analytics row. Analytics rows are deleted after 90 days. We also receive sanitized technical error reports. Search terms, field values, request bodies, raw URLs, and sensitive keys are removed; similar failures are merged under a technical fingerprint and deleted after seven days.
Device notifications
We ask for notification permission only when you choose to enable it. Our servers bind the notification token to your account and use it to send the alert categories you leave enabled, such as messages, opportunities, and events. We begin unbinding it when you disable notifications or sign out, and also remove it when you delete your account or the delivery provider confirms that it is no longer valid. A limited technical delivery record contains the raw account identifier, hashed technical identifiers, and only the success status or error code, not the notification text. We configure these records to expire after 30 days; the database service removes expired records asynchronously, so removal is not immediate. We do not use notification tokens for tracking or advertising.
The assistant
The assistant is available to members only. When you ask it something, we send your message, any image you attach, the page context and your city to a contracted provider to generate the answer; we do not send your name or email. Conversations are saved to your account and can be deleted from the history; attached images are not saved there. The assistant can remember preferences you choose to share, such as what you eat or what suits your family. It saves what you say about yourself, never what it infers, and tells you in the conversation every time it saves or changes something, with an undo button. You can review, edit or delete what it remembers, or switch memory off, under “What I remember about you” in the assistant history. The assistant does not save your religion, political views, legal status or health. Conversations and remembered preferences are deleted when you delete your account.
Service providers
We use service providers for specific parts of the platform:
- Google Firebase for authentication, the database, application hosting, and device-notification delivery.
- Cloudflare R2 for private and public file storage and public content delivery.
- Resend for sign-in codes, account messages, and newsletters.
- Algolia for server-side search indexing and search; your browser does not connect to Algolia directly.
- Reoon to validate an email address during signup.
- A contracted provider to run the assistant, which receives your message and its context to generate an answer.
- GoHighLevel (LeadConnector) to provide support chat on help pages; it may process the message and contact details you choose to enter.
- Google, only if you choose “Continue with Google” on our website or in the iPhone app. Google learns that you signed in to Team Syria, and sends us your email address, the name on your Google account, and a stable identifier for your account with them; it may also include a link to your profile picture, which we do not use. We use this only to confirm that the address is yours and to fill in your name during setup for you to confirm or change, and we do not keep the Google identifier with your account. We never see your password and cannot reach anything else in that account. Signing in with an emailed code does not involve Google.
- Apple, only if you choose “Continue with Apple” on our website or in the iPhone app. Apple sends us your email address (or, if you choose to hide it, a private relay address that forwards our messages to you), a stable identifier for your Apple account that is specific to our app, and, the first time only and only if you choose to share it, your name. We use the address to confirm that it is yours and the name to set up your account without asking for it again. We keep the identifier, in hashed form, with your account so we can recognise you when Apple sends only the identifier on a later sign-in, and we may keep a token Apple issues for this link, used only to revoke the link when you delete your account; all of it is deleted with the account. We never see your password, and Apple does not see your activity in Team Syria. You can stop using Sign in with Apple with Team Syria at any time in your Apple account settings. This option is entirely optional.
- A contracted automated safety service to assess held public text and still images before publication.
- A contracted automated service that works out which city a public post or question is about after it is published, so it can be shown first to people there; it receives the text and the author’s city only, never their name, account, or images.
- BigDataCloud to turn coordinates you provide into a country and city or town that we can offer for selection.
- OpenStreetMap to display map tiles. The tile provider may receive your network address and the requested map tile coordinates.
- Google Places for server-side city and town search and selection, and for business or event-place searches you request.
Cookies and local storage
We use cookies and browser storage to keep you signed in and remember preferences. You can control them through your browser settings, but disabling them may prevent some features from working.
How we share information
We do not sell personal information or share it for advertising. Information you intentionally publish, such as an opted-in profile preview, approved professional listing, directory business, or post, is shown to visitors or members according to that area's access rules. We may disclose information when required by law or when reasonably necessary to protect the platform and its members or investigate abuse.
Retention and account deletion
We keep account information while your account is active and as needed to provide the service. You can start account deletion in the app's settings or use the account deletion page if you no longer have the app installed. After you confirm your email and request, we disable the account immediately and securely delete its data in the background; you do not need to keep the page open. We may retain a limited record without a public profile or name when necessary to preserve another person's message or application history, investigate a safety report, or meet a legal obligation. Protected backups may retain an older copy for up to seven days. Newsletter consent is separate from the account and can be withdrawn through the unsubscribe link in any newsletter.
Your rights
You may request access to, correction of, or deletion of your information and withdraw consent where applicable. You can delete your account through settings or the account deletion page. Contact us below for any other privacy request.
Security
We use reasonable safeguards, including access controls and temporary links for private files. No electronic transmission or storage method is completely secure, so we cannot guarantee absolute security.
Children
The platform is intended for adults (18 and over), as stated in the terms of use. We do not ask for or verify age or date of birth, we do not enable or restrict features based on an age band, and we do not knowingly collect information from anyone under that age. If we learn that an account belongs to a minor, we delete the account and its data. Contact us at privacy@teamsyria.com if you believe we hold a child's information so we can remove it. Our child sexual abuse and exploitation standards are published on the child safety page.
Changes to this policy
We may update this policy from time to time. We will publish the updated version here and change the last-updated date above.
Contact us
For privacy questions or requests, email privacy@teamsyria.com.