Privacy Policy

Last updated: 27 September 2026

This Privacy Policy explains what personal data COMO COMPUTER CONSULTING LLC, trading as MulkiVal ("MulkiVal", "we", "us"), collects when you use the MulkiVal website, mobile applications and API (the "Service"), why we collect it, how long we keep it, and the choices and rights you have.

The data controller is COMO COMPUTER CONSULTING LLC, located in Amman, Jordan. Privacy enquiries: support@mulkival.com.

1. Data we collect

1.1 Account and identity data

When you register we store your email address, a cryptographic hash of your password (never the password itself), your account role and status, and the time your account and password were created or last changed. If you provide them, we also store your first name, last name and phone number. Your name and phone number are contact and profile details only; they are not required to obtain a valuation.

1.2 Sign-in with Google or Facebook

Where third-party sign-in is enabled, and only if you choose to use it, we store the provider name, the provider's stable identifier for you, the email address supplied by the provider at the time you linked the account, and the time you linked and last signed in. We never receive your password for that provider. We do not post to those accounts or read your contacts, and we do not request profile data beyond your identifier and email address.

1.3 Property details you enter

To produce a valuation we process the property attributes you supply, which may include property type, city, district and administrative location, area and built area, number of bedrooms, bathrooms and floors, age, condition, finishing level, and other descriptive characteristics.

1.4 Location data

If you confirm a location on the map, we process the exact coordinates of the map pin you confirmed. We do not read your device's GPS or background location in order to value a property; the pin is a location you place deliberately. Where a listing is published, exact coordinates are held in private fields and are deliberately removed from the publicly visible listing data.

1.5 Expected-value input

If you enter what you expect the property to be worth before seeing the result, we store that figure together with the property context. It is recorded as your unverified estimate. This input is never supplied to the valuation model and cannot influence the estimate you receive; it is retained only so we can compare user expectations against model output.

1.6 Property photographs

If you upload photographs, we store the image file, its dimensions, byte size, content type, a cryptographic hash and a perceptual hash used to detect duplicate submissions, together with validation results and the upload session they belong to. Photographs are uploaded only when you choose to add them.

Please avoid photographing identifiable people, neighbours' property, or documents you do not intend to share.

1.7 Automated analysis of photographs

MulkiVal contains an optional feature that sends uploaded photographs to Google's Gemini API for automated assessment of visible property condition. This feature is disabled. While it is disabled, no photograph is transmitted to that provider or any other third-party analysis service. If we enable it, we will update this policy and identify the processor before any image is sent.

1.8 Valuation requests and results

We store a record of each valuation request, including its status (for example: succeeded, abstained, failed, or awaiting payment), a non-reversible fingerprint of the request, the resulting valuation output, and the reason where a valuation could not be produced.

1.9 Listings you publish

If you publish a listing, we store its title and description, asking price, property summary, the valuation details attached to it, any contact details you choose to include, any cover or gallery photographs, and any ownership document you upload. Contact details and documents are supplied entirely at your choice. Removing a listing marks it as removed and hides it from the feed.

1.10 Entitlement and payment data

We store your valuation entitlements — including your complimentary valuation, its expiry, and whether it has been reserved or consumed — and an audit trail of those changes. Where a payment is processed, we store the payment reference, amount, currency and status returned by the payment provider.

MulkiVal does not receive or store your full card number, card security code or bank credentials. Where payments are available, those are handled by the payment method or processor presented at checkout.

1.11 Security, session and abuse-prevention data

We store server-side session records (a hashed session token, creation, expiry, last-seen and revocation times), hashed password-reset tokens, and security audit events such as sign-in, password change, export and deletion events.

IP addresses are not stored in readable form. Where an IP address is recorded against a security event it is stored only as a keyed one-way hash. Rate-limiting counters are likewise keyed by one-way hashes, not by addresses or email addresses, and expire on a short operational cycle.

1.12 Cookies and similar technologies

The MulkiVal website uses two strictly necessary cookies: a session cookie that keeps you signed in, and a token used to protect against cross-site request forgery. We do not use advertising cookies, tracking pixels or cross-site profiling. The mobile applications do not use cookies for tracking.

1.13 Analytics

MulkiVal does not use any analytics or product-tracking service. There is no Google Analytics, advertising SDK, attribution SDK or behavioural analytics product in the website, the API or the mobile applications.

1.14 Crash and error reporting

MulkiVal can report server errors to Sentry so faults can be diagnosed. Where this is enabled, reports are filtered before they leave our servers: request bodies are reduced to a fixed list of non-identifying property fields, and authentication cookies, authorization headers, API keys, CSRF tokens, email addresses and exact coordinates are removed. The filter operates on a keep-list, so any field not explicitly approved is discarded rather than sent.

2. Why we use your data and on what basis

PurposeData usedBasis
Create and operate your accountAccount and identity data, sign-in dataPerformance of our agreement with you
Produce a valuationProperty details, confirmed location, photographsPerformance of our agreement with you
Manage entitlements and paymentsEntitlement and payment dataPerformance of our agreement with you; legal obligation for financial records
Publish a listing you createListing data you supplyPerformance of our agreement with you
Keep the Service secure and prevent abuseSession records, hashed IP, audit events, rate-limit hashesOur legitimate interest in a secure service
Diagnose faultsFiltered error reportsOur legitimate interest in a working service
Compare user expectations with model outputExpected-value input and property contextOur legitimate interest in evaluating accuracy
Send service email (password reset, deletion confirmation)Email addressPerformance of our agreement with you

3. What we do not do

4. Service providers

We use the following categories of provider. Each processes data on our instructions and only as needed to deliver its function.

ProviderFunctionStatus
Fly.ioApplication hostingPrimary region Paris, France.
SentryError and crash reportingOptional; enabled only when configured. Filtered as described in section 1.14.
Google (Gemini API)Automated photograph assessmentDisabled. No image is sent while disabled.
Google / FacebookOptional third-party sign-inOnly if you choose that sign-in method.
OpenStreetMapMap tiles on the websiteServes map imagery to your browser.
Google FontsTypefaces on public web pagesServes fonts to your browser.

5. International transfers

MulkiVal serves properties in Jordan, but its application servers and servers are hosted in the European Union (Paris, France). Personal data you provide is therefore transferred outside Jordan. Email, error reporting and sign-in providers may process data in other countries.

6. How long we keep data

DataRetention
Account recordUntil you delete your account.
Expired or revoked sessionsRemoved 30 days after expiry or revocation.
Password-reset tokensExpire after 30 minutes; removed 30 days after expiry.
Deletion-confirmation tokensExpire after 24 hours; unused tokens removed 30 days after expiry.
Security audit events90 days, then deleted automatically.
Rate-limit countersShort operational window; stored only as one-way hashes.
Photographs and upload sessionsDeleted when you delete them, when the upload session expires, or when you delete your account.
ListingsUntil removed by you or deleted with your account.
Payment and entitlement recordsRetained in anonymized form after account deletion where required for financial and anti-fraud records.
Encrypted backupsDeleted data may persist in encrypted backups until those backups expire.

7. Deleting your account and data

You can delete your MulkiVal account at any time, and you do not need to keep the app installed to do so:

Deleted immediately: your name, phone number and email address are removed from the account record; the account is disabled; all active sessions are revoked and unused password-reset links are invalidated; any linked Google or Facebook identity is removed; your listings and their photographs, documents and exact coordinates are deleted; your uploaded property images and their stored files are deleted; and your security audit history is stripped of your account identifier.

Retained after deletion: a non-identifying disabled record is kept so that historical references remain coherent; payment and entitlement records are kept in anonymized form for financial and anti-fraud purposes; anonymized security events are kept for the remainder of their 90-day window; and encrypted backups may contain pre-deletion data until they expire.

Once deleted, an account cannot be used to sign in again and cannot be recovered. You can also obtain a copy of your data before deleting it — see section 8.

8. Your rights

Subject to applicable law, you may request access to your personal data, a copy of it in portable form, correction of inaccurate data, deletion, restriction of or objection to certain processing, and withdrawal of consent where processing relies on consent.

Signed-in users can export their own data at any time from the account settings, which returns account details, listings, image validation records, billing records, expected-value entries, and session and audit metadata. The export deliberately excludes password hashes, token hashes and API keys.

To exercise any other right, contact support@mulkival.com. If you are in Jordan, you may also complain to the Personal Data Protection Directorate at the Ministry of Digital Economy and Entrepreneurship.

9. Security

Passwords are stored using a slow one-way hashing function. Session and reset tokens are stored hashed. Traffic is served over HTTPS. Access to production systems is restricted, database backups are encrypted, and error reports are filtered before leaving our servers. Exact coordinates are held in private fields and removed from public listing responses. No system is perfectly secure, and we cannot guarantee absolute security.

10. Children

MulkiVal is intended for adults transacting in or researching property and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Changes to this policy

We may update this policy as the Service changes. The last-updated date above will be updated, and we will give notice of material changes where required.

12. Contact

Privacy and data protection: support@mulkival.com
General support: MulkiVal support