Privacy Policy

Last updated: June 2026

1. Introduction

Mawgood ("موجود", "we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our attendance tracking and payroll management platform.

By using Mawgood, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

We collect the following types of information:

  • Personal Identification Information: Name, phone number, email address, employee ID, company name, and job title.
  • Attendance Data: Check-in and check-out times, attendance photos (selfies), GPS location coordinates at the time of check-in, and biometric fingerprint data (when using supported hardware).
  • Telegram Bot Data: Telegram user ID, Telegram username, messages sent to the bot for attendance check-in/out, and any photos shared via Telegram for verification.
  • Mobile App Data: Device type, operating system version, mobile app version, GPS location data collected during attendance check-in via the PWA mobile app, and camera access for selfie verification.
  • Fingerprint Hardware Data: Biometric fingerprint templates and punch timestamps collected from supported fingerprint scanner devices.
  • Usage Data: Pages visited, time spent on pages, browser type, and referring URLs.

3. How We Use Your Information

We use the collected information for the following purposes:

  • To provide, operate, and maintain our attendance tracking and payroll services.
  • To verify employee identity through selfie photos, GPS location, and biometric data.
  • To calculate payroll, including salaries, overtime, deductions, and bonuses.
  • To communicate with you via Telegram for attendance notifications and alerts.
  • To improve our platform and develop new features.
  • To comply with legal obligations and enforce our Terms of Service.

4. Data Storage and Security

All data is processed and stored on high-security, enterprise-grade cloud servers with automatic redundancy and daily backups (with optional dedicated private cloud hosting available for enterprise clients). Your organizational data is strictly isolated and never leaves your administrative control. We implement the following security measures:

  • End-to-end encrypted connections (SSL/TLS HTTPS).
  • Password and credential hashing using industry-standard modern algorithms.
  • Strict multi-tenant data isolation preventing any cross-organization data access.
  • Secure session management with HTTP-only, SameSite secure cookies.
  • Continuous security updates, vulnerability scanning, and patches.
  • Automated firewall protection, rate limiting, and DDoS mitigation.

5. Data Retention

We retain your personal data for as long as your account is active or as needed to provide you with our services. Attendance records are retained in accordance with applicable labor laws in Egypt and the MENA region. You may request deletion of your data by contacting us.

6. Data Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share information only:

  • With your consent.
  • To comply with legal obligations or court orders.
  • To protect our rights, property, or safety.
  • With service providers who assist us in operating our platform (e.g., Hetzner for server hosting), who are bound by confidentiality agreements.

7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • The right to access your personal data.
  • The right to rectify inaccurate or incomplete data.
  • The right to delete your personal data ("right to be forgotten").
  • The right to restrict or object to processing.
  • The right to data portability.

8. Biometric Data

When using connected biometric hardware (such as ZKTeco devices), biometric templates (irreversible encrypted hashes) remain securely stored within device hardware or your dedicated encrypted tenant database. Attendance punch logs are transmitted over secure, encrypted protocols (HTTPS/ADMS) and are never shared with or accessible by any unauthorized third party. Biometric verification is used strictly for workplace identity verification. Organizations may also utilize alternative check-in methods (such as GPS/selfie verification, Telegram, or dynamic QR kiosk).

9. GPS Location Data

GPS location data is collected only at the time of attendance check-in when using the mobile PWA app. This data is used to verify that the employee is at their designated work location. Location data is stored securely and is only accessible to authorized administrators of your company.

10. Telegram Bot Data

When you use our Telegram bot for attendance check-in, we receive your Telegram user ID, username, and any messages or photos you send to the bot. This data is used exclusively for attendance tracking and identity verification. We do not access your Telegram contact list or messages outside of the bot.

11. Cookies

We use essential cookies to maintain your session and provide core functionality. We do not use tracking cookies or third-party advertising cookies. You can control cookie settings through your browser preferences.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

13. Contact Us

If you have any questions about this Privacy Policy, please contact us:

Chat with us on WhatsApp