AQARIO · PRIVACY POLICY
Privacy Policy
Effective date: 14 September 2026
Privacy contact: info@aqario.ae
This policy explains how Aqario handles information through its public website and real estate CRM, including account access, customer workspaces and support. It describes the current web pilot. Any future Aqario mobile app that links to this policy will be assessed against its actual features, permissions and service providers before release, and this policy will be updated where necessary.
1. Aqario and your brokerage
Aqario is operated by Prime Advertising Services LLC, referred to in this policy as “Aqario”, “we” or “us”. Aqario is the public product name. Contact us at info@aqario.ae about this policy. For enquiries, account administration and service security, we manage the information needed to operate and support the service.
A brokerage decides which customer and prospect records it enters into its workspace, who may access them and how they are used for its real estate business. Aqario processes these records to provide the service under the brokerage’s instructions and agreed terms. If your details were entered by a brokerage, contact that brokerage about its marketing, contact preferences and handling of your information. You can also contact Aqario for help directing a request.
2. Information we process
- Website enquiries: your name, company name, work email, agent and administrator counts, selected lead-source channels, other sources and your message. The form prepares an email on your device; it does not submit these fields to an Aqario form server. We receive them if you send the email.
- Account and identity information: name, email address, identity-provider user ID, company membership, role, account status, verification state and sign-in/security information. Firebase Authentication processes sign-in credentials and authenticator enrollment where used. Passwords are not included in CRM business records.
- Brokerage records: information authorised users enter, such as contact names and contact details, enquiries, requirements, lead sources, notes, activity outcomes, assignments, follow-up dates, contact restrictions, property details, sales stages, deal values and approved commission information.
- History and security records: identifiers, timestamps, changes, versions, assignment and approval history, request identifiers, request outcomes and service diagnostics. These may identify the person who performed an action.
- Technical information: IP addresses, browser/device and request information may be processed by hosting and authentication providers. Aqario application request logs include request identifiers, HTTP method, status and duration; cloud infrastructure may maintain additional access and security logs.
- Support correspondence: information you choose to send when asking for assistance or exercising a privacy request.
The current web pilot does not request access to your device’s contact list, microphone, photo library or precise device location. It does not record calls. A property address entered into the CRM is business information, not device location tracking. Selecting Meta, Google, WhatsApp or another channel on the website enquiry form does not connect an account or authorise access to that platform.
3. Why we use information
- Respond to enquiries, discuss the pilot and arrange onboarding.
- Authenticate users and enforce current company membership and access permissions.
- Provide the requested CRM functions, including assignment, follow-up, property and deal workflows.
- Maintain attributable business history, protect accounts, investigate errors and prevent misuse.
- Support the service, maintain backups and handle account, privacy and contractual requests.
- Meet applicable legal obligations and establish, exercise or defend legal claims where necessary.
Where applicable, the basis for processing depends on the purpose and our role: providing the requested service or performing an agreement, legitimate operational and security interests, legal obligations, or consent where required. Brokerage processing follows its instructions and applicable agreement. Contact us to ask about the basis relevant to your information. Aqario does not currently sell personal information, use CRM records for advertising targeting or pool customer lead records for cross-brokerage advertising.
4. Who may receive information
Authorised brokerage users can access information according to their membership and role. An administrator’s visibility can differ from an assigned agent’s visibility. Aqario has the technical ability to access hosted information for service operation and authorised support; separate customer databases do not mean the service operator is technically unable to access data.
Service providers process information needed to deliver the service. The current platform uses Google Cloud for hosting, databases, storage and operational services, and Firebase Authentication for identity. Firebase Hosting delivers the public website. Email providers involved in your message and Aqario’s mailbox process correspondence. See Google’s Privacy Policy for Google’s information about its processing.
Other disclosures may occur when you request or authorise them, when required by applicable law, or when necessary to protect rights, security or people. Provider and brokerage terms govern their respective processing. An optional future integration will require its own configuration and applicable disclosures before customer data is sent through it.
5. Where information is processed
The current CRM API, named customer databases and private customer storage are deployed on Google Cloud in Doha, Qatar. Firebase Authentication processes identity data in the United States. The public website uses Firebase’s global delivery infrastructure. Email, provider operations and support may involve other locations; Doha CRM hosting is not a promise that every category of processing stays in Qatar or outside the US.
Customer processing locations, service providers and applicable transfer arrangements are addressed in the brokerage’s service terms. Contact us before supplying information if you have a specific location restriction.
6. Browser storage and device permissions
The public marketing pages do not add advertising pixels, marketing cookies or analytics trackers. The enquiry form does not save its fields to browser storage. The website’s delivery providers still process technical requests.
The CRM and administration applications use Firebase-managed browser storage to preserve sign-in. Aqario also stores a user/activity marker for its 24-hour browser inactivity policy and a per-tab workspace preference. These support sign-in and workspace restoration. Explicit sign-out clears the application’s sign-in state; clearing browser data can also require you to sign in again. It does not delete your account or server-side CRM records.
Future mobile permissions or optional analytics will be disclosed when introduced. Where consent or a device permission is required, the feature must request it before access. This policy is not permission to collect additional device data silently.
7. How long information is kept
Enquiries and support: correspondence is kept while needed to respond, manage an ongoing discussion or relationship, resolve a dispute or meet applicable obligations. You may request deletion when it is no longer needed.
Accounts and CRM records: records are kept while needed to provide the brokerage’s service and according to its instructions, agreed retention terms and applicable obligations. Disabling a user removes access; it does not automatically erase business records or history attributable to that user. At offboarding, deletion and any authorised export are coordinated with the brokerage. There is no automatic promise that every record disappears when a subscription ends.
Security and audit information: retention depends on the purpose, incident or dispute needs, applicable obligations and configured provider or customer retention. Access and business history may need to be retained after a user leaves. We explain relevant exceptions when responding to a deletion request.
Backups: current scheduled database backups have a 30-day retention setting. Storage soft-delete protection is configured for seven days; retained object versions and other copies can have separate lifecycles. Deletion from active systems does not mean immediate removal from all backups or retained versions. The scope, remaining copies and applicable expiry are reviewed during deletion. These settings do not establish one universal retention period for every category of information.
8. Your choices, account deletion and data requests
You may contact us to request access, correction or deletion of your information, or to raise a privacy concern. Other rights, including restrictions, portability, objections or withdrawal of consent, depend on the applicable law and processing purpose. Withdrawing consent does not reverse processing already lawfully performed.
To request deletion of your Aqario account and associated personal information:
- Email info@aqario.ae with the subject “Aqario account deletion request”.
- Include the email used for your Aqario account and your company name or workspace subdomain. State whether you are requesting account deletion, deletion of specific personal information, or both. Do not send your password or authenticator code.
- We verify the requester’s identity and scope, coordinate with the brokerage where its records are involved, and explain the next steps and any information that must be retained.
This is a manual request channel, not an instant deletion tool. Account deletion is distinct from ending a brokerage’s subscription or deleting its entire database. Subject to verified authority and any retention obligation, the request can cover identity/account information and related personal data. Shared business records, security evidence, audit history or information required for legal obligations may need to be retained or de-identified rather than erased. We explain relevant categories and retention reasons to the requester. Backup copies follow their applicable retention and deletion process.
If a brokerage holds your details as a prospect or customer, it may need to decide your request as the organisation responsible for that business record. Aqario will help route the request. We do not require your password to discuss privacy or account deletion.
9. Security
The service uses HTTPS, managed identity, server-side access checks, separate customer databases and private storage boundaries. Owner/Admin and platform administrator access uses authenticator verification. Safeguards reduce risk but cannot guarantee absolute security. Use your account only as authorised and report suspected unauthorised access to info@aqario.ae.
10. Children
Aqario is intended for business users, not children. We do not knowingly seek information from children through account signup or marketing. Contact us if you believe a child has supplied information so that we can investigate and take appropriate action.
11. Changes to this policy
We update this page when relevant features, processing practices or requirements change and revise the effective date. Material changes will be communicated through an appropriate service or contact channel where required. New mobile releases, SDKs and integrations must be reflected in their disclosures before launch.
12. Contact Aqario
Aqario — operated by Prime Advertising Services LLC.
For privacy questions or account/data requests, email info@aqario.ae. Include only the information needed to identify and discuss your request.