Skip to Content
GuidesYour data

Your data

Your company owns its data. You can take all of it with you at any time, in formats you can read; you can find, export or erase everything about one person; and when you leave, your data is deleted in a fixed order and a receipt says what happened. Nothing here depends on payment: export is always possible.

Downloads

Downloads in the account menu is where files made for you appear. Each is prepared in the background, for the person who asked, and listed with its state:

  • the leads you exported as CSV;
  • the reports you exported as CSV;
  • the full export of the company’s data.

A download link works for 15 minutes; open the screen again for a fresh one. Files are deleted 24 hours after they were made. The screen also holds Export all data and One person’s data, described below.

The full export

Export all data makes one ZIP file with everything your company holds. It needs a role that includes exporting all of the company’s data (Administrators by default), a fresh code from your authenticator app, and is recorded in the audit log.

PartContents
manifest.jsonWhen it was made, the app version, and the number of rows per table.
data/*.jsonOne file per kind of record, complete, with personal data readable.
csv/*.csvOne file per table for spreadsheets, encoded so that Excel shows Arabic correctly.
media/The original photos, in folders per listing or profile, read from your connected Google Drive. Files the export could not reach are counted in the manifest.
README.txtWhat each file is, in English and Arabic.

Guest accounts, booking access, embeddings and every setting are part of it. Left out, because they are secrets and not business records: passwords, authenticator secrets and recovery codes, API keys, webhook secrets and the company’s encryption keys. Personal data is readable in the export, because an export you cannot read is not portability.

A company whose account is suspended cannot sign in; Majali support produces the same file on request.

One person’s data

One person’s data finds everything held about one person by their email or phone: as a lead, a person in the CRM, an owner, a guest, a lessee, a contact on a booking or a team member, with their timeline entries and tasks. It needs a role that includes erasing personal data or exporting all data, a fresh code, and is recorded in the audit log. Two actions:

  • Export gives you a JSON file of everything found, for a person who asks for a copy of their data.
  • Erase wipes the personal fields. Anonymous counts and audit entries stay, so figures and history keep adding up. A guest loses every access and sign-in link at once.

The rules:

  • A team member can be erased only once their sign-in is off: mark them as having left first. The member is deleted, their homes, tasks and leads lose them, bookings lose the copy of their name and number, and their invitations go. The sign-in account itself stays, deactivated, for the audit trail.
  • Accounting records are kept: leases and rent payments, jobs, charges and inspections, payments and refunds. They lose the person’s details, not the figures.

Retention

Records lose their personal data on a clock, so nothing is kept longer than it is needed:

RecordRule
LeadsAnonymised after the company’s retention period without activity, 24 months by default. Their timeline texts and tasks are wiped with them. Ask Majali support to change the period.
PeopleAnonymised once they are left with no live record. A person with a lease is never released this way.
Guests of bookingsAnonymised after the same period.
DealsA deal untouched longer than the period loses its notes, feedback and timeline text; its stages, value and dates stay for the reports.
Leases, rent payments, jobs, charges and inspectionsAccounting records, never anonymised automatically.
Audit entriesDeleted after 12 months.
Outbound emailThe message log keeps 30 days.
Guest sign-in linksExpired links are purged daily.
DownloadsDeleted 24 hours after they were made.

Closing the account

Only an Administrator can close the company’s account, from Close the account in the account menu. It is a page of its own, outside the menu, with Back to the admin at any point. Five steps, each ending with its own consent:

  1. What closing means: the closing date, what is deleted, what stays yours.
  2. Your data: prepare the full export and download it, or record that you do not need a copy.
  3. Switch things off: what to end before the date, such as stays, contracts, payments, the website’s keys, your own hosts and your sender domain.
  4. Who is affected: your team, your owners, your clients and guests.
  5. Confirm: an optional reason, the company’s name typed exactly as shown, a fresh code, and your consent that after the date nothing can be recovered.

The closure is then scheduled 7 days later. Until then:

  • everything works as before, and every page of the back office shows the notice;
  • every Administrator is emailed when the closure is scheduled, again one day before the date, and if it is cancelled;
  • any Administrator can cancel it with Cancel the closure, without a code. Nothing is deleted when a closure is cancelled.

On the closing date, with no one needing to act:

  • every address of the company stops answering: the back office, the operations app, the owner space, the guest space, the website API and your own hosts;
  • every sign-in ends, and the owner space closes for your owners;
  • the company’s encryption keys are destroyed, which makes every copy of the data unreadable, backups included: this is what makes the deletion final;
  • shortly after, the records are deleted, the files Majali kept are removed, your own hosts and your sender domain are released, and a receipt without personal data is kept;
  • files in the Google Drive your company connected are never touched: your photos and documents stay yours;
  • your clients, lessees and guests are not contacted by Majali; tell them yourself.

When the deletion is done, the Administrators in place on the closing day receive a written confirmation in English and Arabic with the receipt number. It says what was deleted and that encrypted data is unreadable from that moment; backups of the database expire within 72 hours. Your company’s subdomain is held for 90 days and cannot be taken by anyone else in that time.