Privacy policy
Version 2026-08-18
1. What this covers
This describes what AgriBit collects about you, why, and who else, if anyone, sees it. It sits alongside the terms and conditions rather than replacing them: §4 there already covers AgriBit's own access to your farm data in more detail than this document repeats.
2. What we collect
Account details: your email, password (stored hashed, never as readable text), full name, phone number, and date of birth, plus, optionally, a company name and how you heard about us.
If you sign in with Google: the email address and name Google gives us, and Google's own confirmation that the email really is yours. We never receive your Google password, and we do not ask for or receive access to your Gmail, Drive, Calendar, or anything else in your Google account, only enough to sign you in.
Farm data: whatever your nodes send (soil moisture, temperature, and whatever else your hardware reports), plus the farms, nodes, automation rules, and access grants you create.
Security records: which IP address made which sign-in or registration request, and when, kept to detect and slow down abuse, not to track you day to day.
3. How we use it
To operate the platform, investigate faults, and answer support requests: the same reasons the terms' §4 names for AgriBit's own access to your data.
With your farm's and your identity removed, we may also use it to improve the platform: spotting failing sensors, building features that compare conditions across regions, and training the models those features need.
4. Who we share it with
Kavenegar, an SMS provider, to deliver the phone verification code you request. We send them your phone number and the code, nothing else.
Google, only if you choose to sign in that way. The authorization code your browser receives from Google gets exchanged, server to server, for confirmation of your email address.
Enamad, Iran's e-commerce trust-certification authority: every public page loads their trust-seal badge directly from their own server, which is how the badge is verified. So, like any site displaying it, Enamad's server sees the visiting browser's IP address on every page view. This is a display requirement, not a data hand-off: we do not send them any account or farm data ourselves.
Nobody else. We do not sell your data, and this site carries no advertising or analytics trackers. Nothing here counts your visits or builds a profile of you for ads.
5. Where it's stored
On our own servers, not a shared cloud data warehouse, located in Iran.
6. Cookies
A session cookie that keeps you signed in: httpOnly, so no script running on the page, including ones we did not write, can read it.
A cookie that remembers whether you last used the English or Persian version of the site.
If you sign in with Google, a short-lived cookie used only to confirm the sign-in request really came from your own browser, cleared immediately after.
Nothing else: no advertising cookies, no cross-site tracking.
7. Your rights
You can export your own readings as CSV or JSON at any time from the dashboard. Ask us, through the Support page, and we will delete your account and the data identifying you.
We don't have a fixed retention period beyond what running the platform and the law require. Ask at any time and we'll tell you what we hold, or delete it. Anonymised data derived from your farm (§3 above) may be kept after your account is closed, because it can no longer be traced back to you.
Daily database backups are kept for 30 days for disaster recovery. Deleting your account removes it from the live database immediately; a copy may still exist in one of these backups until it ages out, same as anyone else's data does.
8. Changes to this policy
This document will be expanded as the platform grows. If a future version changes materially what we do with your data, we will say so rather than changing it quietly.
9. Contact
Questions about this policy or about your data: use the Support page inside the dashboard.
