Privacy Policy
This Privacy Policy describes how Motiva (“we”, “us”, or “our”) collects, uses, processes, stores, and shares information in connection with the Motiva mobile application (the “App”) and its backend services (the “Services”). Motiva is an automotive services and marketplace platform that connects customers, vendors, and operators for vehicle services and for the buying and selling of vehicles and related products in Kuwait and the surrounding region.
By installing, registering with, or otherwise using the App, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please discontinue use of the App and Services.
1. Scope and Applicability
This Policy applies to all processing of personal information carried out through the Motiva mobile application (iOS and Android) and Motiva's backend platform. It covers data you provide directly, data generated through your use of the App, and data uploaded by you or generated by other users in connection with your use of the marketplace and services.
This Policy does not apply to third-party websites, services, or applications that you may access through links available within the App. We are not responsible for the privacy practices of such third parties.
2. Data Controller and Contact
The data controller for the personal information described in this Policy is the entity operating Motiva (“Motiva”, “we”). For all privacy inquiries, data subject requests, and complaints, please contact us using the details provided in Section 14 (“Contact Us”).
3. Information We Collect
We collect the categories of information described below. Some categories are required to provide the App; others are optional or generated automatically.
3.1 Account and Identity Information
- Phone number — used as the primary identifier; required for customer, vendor, and operator accounts.
- Full name — your display name visible to other users (e.g., on reviews).
- Email address — optional, used for notifications and account recovery.
- Username and password — for administrator accounts; passwords are stored only as bcrypt hashes.
- Profile photo URL — an avatar you choose to associate with your account.
- Role and verification status —
customer,vendor,operator, oradmin; whether your phone has been verified.
3.2 Authentication and Session Information
- One-time passcodes (OTPs) — short numeric codes sent to your phone during sign-in and verification; stored temporarily in our database with an expiry timestamp.
- Access tokens — short-lived JWTs issued to your device after authentication.
- Refresh tokens — long-lived session keys used to renew your access tokens. We store a reference to active refresh tokens so you can end sessions at any time.
- Session metadata — for each active session we store the device user agent string and the originating IP address, which is used for security (e.g., session invalidation) and rate limiting.
3.3 Vendor, Operator, and Business Information
- Business name and commercial license number — required for vendor onboarding.
- Government-issued identity documents — images of commercial license, civil ID, and trade license, uploaded for vendor verification (KYC).
- Bank account details — for vendor payouts: bank name, account number, account holder name, and Kuwait Code.
- Operator accounts — full name, phone, email (optional), and password for sub-accounts created by vendors to dispatch field work.
- Operational metadata — business logo, cover image, working hours, order capacity, availability status, and schedule exceptions.
3.4 Delivery, Pickup, and Service Location Information
- Default delivery address — a structured address (street, area, block, building, floor, apartment, and notes) saved to your profile and reused for product orders.
- Service-order locations — pickup, drop-off, and on-site service latitude/longitude coordinates and human-readable addresses recorded for each booking.
- Operator location — the real-time latitude/longitude of an operator while a service order is in progress, shared with you via a live stream and stored on the order record.
3.5 Vehicle Information
- Garage entry fields — make, model, year, trim, color, and Vehicle Identification Number (VIN).
- Marketplace listings — the same vehicle fields plus mileage, engine size, transmission, condition, damage report (with structured damage points), images, damage images, registration document image, and inspection report image.
3.6 Commercial and Transactional Information
- Product browsing and cart — products you view, add to cart, and purchase, including quantities and prices.
- Service bookings — service chosen, vendor, scheduled time, dynamic form answers captured at booking, status transitions, cancellation reasons, and fees.
- Product orders — items, totals, delivery address, payment method (cash on delivery), and status updates.
- Wallet and loyalty data — wallet balance, ledger entries, loyalty point balances, and earn/redeem history.
- Vouchers — voucher codes, redemption status, and the user who redeemed each code.
- Payout requests — payout amount and re-entered bank details at the time of withdrawal, plus admin review notes.
3.7 User-Generated Content
- Reviews — rating (1–5), review body text, and the order/item being reviewed.
- Vendor offers and descriptions — promotional copy authored by vendors.
- Listing descriptions and condition notes — free-text seller descriptions and damage-report notes.
- Dynamic attribute answers — answers to configurable questions captured during service orders.
3.8 Service-Document and Media Uploads
- Booking/service-order documents — files uploaded by either party in connection with a service order.
- Vehicle, vehicle-listing, vendor, and category images — photos and artwork uploaded for cataloguing or promotional purposes.
- Profile avatars — images you upload for your account.
3.9 Device, Network, and Log Information
- IP address — captured for every HTTP request to enable rate limiting, security, and abuse prevention.
- User agent string — captured for active sessions.
- Server-side request logs — we record HTTP method, URL path, response time, request identifier, and (on errors) the authenticated user identifier.
What we do not collect. Motiva does not integrate any advertising networks, marketing pixels, analytics SDKs (such as Google Analytics, Meta Pixel, Segment, Mixpanel, Amplitude, or Hotjar), or external payment card processors. We do not collect advertising identifiers (IDFA or GAID) or device fingerprinting data beyond what is listed above. The App does not currently dispatch push notifications.
4. How We Use Your Information
- Account creation, authentication, and security. Verifying phone numbers, issuing and refreshing authentication tokens, enforcing rate limits, detecting fraud and abuse, and enabling secure logout and session invalidation.
- Providing the marketplace and services. Matching customers with vendors and operators, transmitting booking requests and acceptance messages, displaying order status, and dispatching field operators to the correct location.
- Real-time location features. Streaming operator location to customers and vendors during an active service order via authenticated real-time channels; storing pickup, drop-off, and service locations on the order record.
- Order processing and fulfillment. Recording product orders and service bookings, calculating totals and commissions, and producing receipts and order history.
- Payments and payouts. Crediting and debiting wallets, processing voucher redemptions and loyalty earnings, and reviewing and processing vendor payout requests.
- Reviews and ratings. Publishing reviews you submit and aggregating vendor ratings; moderating content that violates our policies.
- Vendor onboarding and compliance. Reviewing submitted commercial and government identity documents; reviewing vendor bank details before approving payouts.
- File and media storage. Hosting images, documents, and other uploads associated with your profile, listings, vendor shop, or service orders in our object storage.
- Operational logging and diagnostics. Recording request logs for security incident investigation, debugging, and capacity planning.
- Compliance and legal obligations. Meeting record-keeping, tax, and regulatory obligations; responding to lawful requests from public authorities.
5. Legal Bases for Processing
Where applicable data protection law requires a lawful basis (such as the EU GDPR or Kuwait's data protection principles), we rely on the following bases:
- Performance of a contract — to create and maintain your account, deliver the services you book, and process payments and payouts.
- Legitimate interests — to secure the App, prevent fraud and abuse, maintain service quality, and improve operational reliability, balanced against your rights and freedoms.
- Consent — for processing precise location (GPS) data and for sending push notifications, where consent is required; you may withdraw consent at any time as described in Section 11.
- Legal obligation — to retain records required by applicable tax, commercial, or anti-money-laundering laws.
6. How We Share Information
We do not sell personal information, and we do not share it with advertising networks or data brokers. We share personal information only as described below.
- With other users as needed to provide the service. Your name and rating are visible to other users on reviews and listings. Vendor shop information (logo, working hours, address) is visible to customers. Location data is shared with the relevant vendor and operator for the duration of an active service order.
- With service providers (Section 7). With vendors that process data on our behalf to deliver infrastructure (object storage, messaging, database hosting).
- For legal and safety reasons. When we believe in good faith that disclosure is necessary to comply with a law, regulation, court order, or valid request from a public authority; to protect the safety, rights, or property of Motiva, our users, or others; or to detect and address fraud or security incidents.
- In a business transition. If Motiva is acquired, merged, or sells substantially all of its assets, your information may be transferred to the acquiring entity subject to this Policy.
- With your consent. For any other purpose disclosed at the time of collection, subject to your consent.
7. Third-Party Service Providers
We engage the following categories of third parties to deliver the App. Each is contractually restricted from using personal information for any purpose other than providing services to Motiva.
| Provider | Role | Data Sent |
|---|---|---|
| Cloudflare R2 S3-compatible object storage |
Stores user-uploaded images, vendor documents, KYC documents, and booking documents. Uploaded objects are publicly readable at URLs derived from R2_PUBLIC_URL. |
Image and document file bytes; associated metadata (filename, MIME type, folder key). |
| Firebase Cloud Messaging Operated by Google LLC |
Delivers push notifications to your device when the App is not in the foreground. | FCM device tokens (which you may revoke), notification title, body, and a small data payload (typically the related order ID and status). Firebase notifications are disabled in the current build of the App and are not yet active. |
| PostgreSQL hosting Per DATABASE_URL |
Primary transactional data store, including all user profile, order, wallet, and review data. | All information listed in Section 3. |
| SMS provider Pluggable interface |
A pluggable interface (SmsProvider) exists for sending OTP codes. The active binding is a development-only stub that logs codes; no third-party SMS provider is currently used. |
When an SMS provider is enabled in the future: phone number and OTP code. |
Payments are accepted by cash on delivery at the customer's door. Motiva does not integrate any third-party card processor and does not store any payment card numbers or security codes.
8. International Data Transfers
Motiva's primary operations are based in Kuwait. However, some of the third-party providers listed in Section 7 may process data in other countries:
- Cloudflare R2 stores objects in Cloudflare's global edge network. The S3 client is configured with
region: 'auto'and accesses your account-specific R2 endpoint. - Firebase Cloud Messaging is operated by Google LLC; push delivery may occur in Google data centers outside Kuwait. Not active in the current build.
- PostgreSQL hosting is set via
DATABASE_URL; the production deployment is expected to be located within the Gulf region.
By using the App, you understand that your information may be transferred to and processed in countries other than your country of residence. Where required, we rely on appropriate safeguards (such as contractual clauses) with our processors.
9. Data Retention
We retain personal information for as long as necessary to provide the App and for legitimate operational and legal purposes, after which it is deleted or anonymized. Specific retention periods include:
| Data Category | Retention |
|---|---|
| OTP codes | 10 minutes after issuance. |
| Verification tokens | 15-minute lifetime. |
| Access tokens | Short-lived; refreshed on demand. |
| Refresh tokens / user sessions | 30 days from issuance; deleted on logout, on password change, or when you delete your account. |
| Operator live GPS | Stored on the order record while the order is in progress. |
| All other account, order, wallet, review, vendor, and listing data | Retained while your account is active. On account deletion, data is soft-deleted and then permanently deleted on a rolling basis, save for records we must retain for legal, tax, accounting, or anti-money-laundering obligations. |
| Uploaded files | Deleted when the underlying record is deleted or when you explicitly request deletion. |
10. Data Security
We implement administrative, technical, and physical safeguards designed to protect personal information, including:
- Password storage: passwords are hashed with bcrypt (10 rounds) and are never stored or transmitted in clear text.
- Authentication: JWTs use signed tokens; refresh tokens for administrators are stored only as one-way hashes so they can be revoked immediately.
- Transport: the App and backend communicate over HTTPS/TLS.
- Rate limiting: global and per-endpoint limits are enforced to mitigate credential stuffing, scraping, and denial-of-service attacks.
- Input validation: all incoming data is validated and trimmed via class-validator before reaching business logic.
- Upload hardening: maximum file size limits, MIME-type allowlists (images and PDFs), and an upload confirmation step that verifies the file actually exists in storage.
- Structured server logs: requests are logged for operational and security review.
No method of transmission or storage, however, is 100% secure. We cannot guarantee absolute security. If you believe your account has been compromised, please contact us immediately.
10.1 Public Object Storage. Files uploaded to our object storage (vendor logos, listing photos, uploaded KYC and booking documents that you choose to attach) are served from a public URL prefix. Do not upload content you do not intend to share with anyone who can guess the URL, and never upload documents you do not need to share with us.
11. Your Rights and Choices
Subject to applicable law, you have the following rights:
- Access. View your profile, vehicles, orders, wallet, and loyalty data directly in the App at any time.
- Correction. Update your name, email, avatar, default delivery address, and vehicle information. Change your email via an OTP-verified flow; change your password (which signs you out of all devices).
- Deletion. Delete your account; deletion is processed as a soft delete that excludes your data from active operations, followed by permanent deletion on a rolling basis. You may also request deletion of specific uploaded files.
- Withdrawal of consent. Revoke optional consents (for example, precise location sharing) by adjusting your device permissions and/or App settings. Withdrawing consent does not affect processing carried out before withdrawal.
- Session management. Sign out of the App at any time to invalidate the current session.
To exercise any right not directly available in the App, contact us using the details in Section 14. We may need to verify your identity before acting on your request.
12. Children's Privacy
The Motiva App is not directed to children under the age of 13 (or such higher age as may be required by applicable law). We do not knowingly collect personal information from children. The App is a paid automotive services marketplace and is not designed for or marketed to minors. If we learn that we have inadvertently collected personal information from a child, we will delete it as soon as possible. Parents or guardians who believe their child has provided us with personal information may contact us to request deletion.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the App, or applicable law. The “Last Updated” date at the top of this Policy indicates when it was last revised. Material changes will be communicated through the App or by other reasonable means before they take effect. Your continued use of the App after the effective date of an updated Policy constitutes your acceptance of the revised Policy.
14. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us at:
Motiva — Privacy Team
Email: privacy@motiva.app
Support: support@motiva.app
We will respond to verified requests within the timeframes required by applicable law.