Privacy Policy

Last updated: August 16, 2026

Datary is operated by Ali Akbari Muscat, Sultanate of Oman.

This policy covers both datary.tech (this website) and go.datary.tech (the Datary application).


Two different people are described here

Business owners create a Datary account and set up a survey. We hold an account for them.

Customers scan a business’s code and answer four questions. We do not hold an account for them, ask for their name, or set any cookie on them.

Where a business collects answers from its own customers, that business decides what is asked and why. Datary stores and displays those answers on the business’s behalf.


What we collect from business owners

When you create an account:

  • Business name
  • Industry you selected
  • Email address
  • Password, stored only as a bcrypt hash — we cannot read it or recover it
  • The survey questions you write or edit
  • Your reward text, if you turn rewards on

Automatically:

  • A session cookie named datary_session, which keeps you signed in for 30 days. It contains your account ID and a signature, nothing else. It is not used for advertising or tracking, and there is no way to switch it off while staying signed in.
  • Your IP address, held briefly in memory to limit repeated sign-in attempts. It is not written to any database and disappears when the server restarts.

When you ask to reset your password, we store a hashed reset token and an expiry time for one hour, then delete both.


What we collect from survey respondents

When someone answers a business’s survey we store:

  • The answers themselves: a score from 0 to 10, the options chosen, and any free text written
  • The date and time
  • A six-character reward code, if that business has rewards switched on, and whether it has been redeemed

We do not collect a name, an email address, a phone number, a device identifier, or an account. We do not set a cookie on the survey page. We do not use analytics or advertising trackers on it.

An IP address is held briefly in memory to stop automated flooding of a survey. It is not stored with the answer and cannot be linked back to it.

Because answers carry no identifier, we cannot tell you which person gave which answer — and neither can the business.

One thing to be aware of: the free text box is open. If someone types their own name or phone number into it, that text is stored as written and is visible to the business. Do not put personal details in that box.


Why we hold it

WhatWhy
Account detailsTo let you sign in and run your survey
Survey answersTo show the business its own results
Email addressTo send password resets and essential service notices
Reward codesTo let staff check a code has not already been used
IP address, brieflyTo stop automated abuse

We do not sell personal data. We do not share it for advertising. We do not build profiles of survey respondents.


Who else touches the data

Hostinger — hosting, database and outgoing email. Servers are located in Europe (Lithuania).

Groq — only when a business presses the button to generate a written briefing. At that moment the survey’s answer counts and any free-text comments from the selected period are sent to Groq’s API, which is operated outside Oman, and a summary is returned. No account details, email addresses or reward codes are sent. If a business never presses that button, nothing is ever sent to Groq.

Google Fonts — our pages load a typeface from Google’s servers, which means Google receives the visitor’s IP address and browser details. This applies to the survey page too.

jsDelivr — the owner dashboard loads a QR-code library from this CDN. Survey respondents never touch it.

UptimeRobot — checks every five minutes that the site is up. It only reads a status page containing no personal data.

Transferring personal data outside Oman requires consent under the Personal Data Protection Law, except where the transfer is carried out so that the person cannot be identified. Survey answers carry no identifier.


How long we keep it

  • Survey answers: until the business deletes them or closes its account.
  • Account details: for as long as the account is open.
  • Reset tokens: one hour.
  • Rate-limiting records: minutes, in memory only.

Ask us to delete an account and we remove the account and every response attached to it.


Your rights

Under the Personal Data Protection Law (Royal Decree 6/2022) and its Executive Regulations, you may:

  • Ask what personal data we hold about you
  • Ask for a copy of it
  • Ask us to correct anything wrong
  • Ask us to delete it
  • Withdraw consent
  • Complain to the Ministry of Transport, Communications and Information Technology

Write to shapur@datary.tech and we will reply within 30 days.

Survey respondents: because answers carry no identifier, we usually cannot locate an individual answer. If you told a business you had answered and want that answer removed, contact the business directly — they can identify the entry by its date and remove it.


Security

Passwords are hashed with bcrypt. The session cookie is HTTP-only and, in production, sent only over HTTPS. Reset links are stored as hashes and expire after an hour, so a copy of our database cannot be turned into a working reset link. Sign-in attempts, survey submissions and reward-code checks are all rate limited. The site is served over HTTPS with security headers set. The database is backed up daily.

No system is perfectly secure. If a breach affects your personal data we will notify you and the Ministry as the law requires.


Children

Datary is a tool for businesses and is not directed at children.


Changes

We will post any change on this page and update the date at the top. Material changes will be emailed to account holders.


Contact

shapur@datary.tech

Datary on Product Hunt