Last updated: 5 October 2026
This policy explains how Melons, also known as Melons Web Development, handles information through its website, enquiries, client services, and Melons Books. Melons is based in Amman, Jordan, and was founded by Alaa Al Refai. For privacy questions or requests, email contact@melons.me or use our contact page.
Who this policy covers
We decide how information is used for our website enquiries and our own business administration. Melons Books supports private accounting and client-service work; it is not a public directory of client information. Access to a client portal or a business workspace depends on an authorised account and its permissions.
If we handle information on behalf of a client organisation under a separate agreement, that agreement also defines the instructions and responsibilities for that work. The organisation may have its own privacy notice. Contact us if you are unsure which organisation is responsible for a particular record. This policy does not cover unrelated websites reached through external links.
Information we handle
Website enquiries and project briefs
When you submit a contact form or project brief, we collect the information you provide: your name, email, company, phone or WhatsApp number, country, preferred contact method, service requirements, message, and any optional budget, currency, dates, time zone, business description, project goals, reference links, or supporting files. Required fields are marked in the form. You can leave optional fields blank.
We also record the source page, submission reference, consent wording and its version, and the time of consent. The form uses short-lived verification and rate-limit information, including a protected value derived from your IP address, to reduce spam and duplicate submissions. A submitted enquiry and its attachments may be transferred to our connected business workspace so the Melons team can review and follow it up, while the website retains its own copy. Uploaded files can contain metadata supplied by your device or editing software. Sending a form does not automatically create a client account or subscribe you to marketing.
Accounts, business records, and support
For authorised users and client contacts, we may hold names, email addresses, profile details or an uploaded avatar, account identifiers, the linked client organisation, roles, permissions, account status, and authentication information. Depending on the services provided, business records can include contact and billing details, projects, quotations, invoices, credit notes, bills, expenses, payments, balances, statements, attached documents, and correspondence. Payment records may identify a payment method or transaction reference; please do not send card security codes, passwords, or unnecessary identity documents through an enquiry or support message.
Support records include the request, public conversation, participants, status, and staff notes. Authorised client-service areas may also make relevant stored documents available. Internal task records include their description, assignee, schedule, and changes. In-app notifications record an intended recipient and read state. Staff-only notes and tasks are separate from the information made available to client contacts.
Security, activity, and delivery records
Systems may retain sign-in and security events, permission changes, record changes, financial actions, timestamps, actor identifiers, and email or backup delivery status. Supported changes in Melons Books can include before-and-after record history. Such history may contain earlier contact or business information even after the current record is corrected. Older events contain only what was recorded at the time.
New audit entries are designed to exclude passwords, one-time codes, authentication tokens, SMTP secrets, and full email bodies. Credentials and temporary authentication data are handled separately for their operational purpose. Email outboxes and business correspondence can retain recipients, subjects, message content, attachments, and sending outcomes. Hosting and security systems may also record IP addresses, requested pages, browser information, and technical errors.
Why we use this information
- To respond to enquiries, understand requirements, prepare proposals, and communicate about a requested project.
- To deliver agreed services, manage client relationships, issue and maintain business documents, and administer payments and accounting records.
- To provide authorised portal access, answer support requests, and organise internal work.
- To authenticate users, apply access permissions, prevent abuse, investigate errors, and maintain accountable records of activity.
- To send relevant service or security messages and to maintain and recover systems through authorised backups.
- To meet applicable legal obligations and handle complaints, disputes, or legitimate requests from competent authorities.
Where consent is required, we ask for it for the relevant purpose. The website form records your consent to handling the submitted enquiry. Other processing may be necessary for agreed services or permitted or required by applicable law. A privacy-policy link is not consent to unrelated marketing or to a new use of your information.
Who may receive information
Information is available to authorised Melons personnel and service providers to the extent needed for their work. Hosting providers store and operate the website and business systems. Configured email providers process the recipients and content of messages sent through them. A message can also be retained by the recipient and their email provider. If you ask us to contact you by phone or WhatsApp, the chosen communication service handles that communication under its own terms.
A client portal contact can access only the linked client’s information allowed by that contact’s permissions. Different contacts for the same client can have different access. Website enquiry, business-document, support, and security emails use their configured recipients and senders; an account does not automatically receive every message for a client.
When enabled, cloud storage providers receive the authorised backup files described below. Relevant information may also be disclosed to professional advisers or competent authorities where needed for a specific legal obligation or dispute. Public portfolio material or a testimonial may identify a client or reviewer where publication has been approved; submitting a private enquiry does not itself authorise public publication.
Providers may process information outside Jordan depending on the hosting arrangement, provider, and account settings. We do not promise that all data stays in Jordan or in one particular country. You can contact us for information about the services used for your engagement and raise concerns about a proposed transfer.
Cloud connections and encrypted backups
Connection information and archive contents
Melons Books contains administrator-controlled cloud connectors for Google Drive and Microsoft OneDrive. Connecting an account uses the provider’s authorisation screen. The application receives access and refresh tokens, permission information, and an account identifier with an email address or display name to identify the destination. It also stores relevant folder, drive, file, transfer, and verification metadata. Tokens and connection secrets are stored encrypted on the application server; the application must be able to decrypt them to perform authorised transfers.
The existing Google connector requests access to files created or opened by the application through the Drive file permission. The OneDrive connector requests account-profile access, access to its application folder, and continuing access for scheduled transfers. OneDrive verification can read back the uploaded encrypted archive. Provider account passwords are entered with the provider, not collected by this connector. These connectors are for configured backup operations; they are not a general inbox reader or a public file-sharing service.
A backup can contain much more than invoices. Depending on the selected scope, an archive may include accounting, contact, support, task and audit records, documents, WordPress users and password hashes, website content, configuration, and credentials or tokens contained in the backed-up installation. Archives are encrypted before cloud transfer. The provider still receives the account, filename, size, and other transfer metadata. Encryption is not a claim that Melons or an authorised server administrator can never access the underlying information.
Existing Google connection and Limited Use
Google’s current Workspace API policy prohibits backing up a developer application’s or project’s content to Drive. The existing Melons Books connector remains subject to that restriction. Describing retained connection data here does not make this an eligible or Google-approved backup service.
Melons commits to the Limited Use restrictions in the Google API Services User Data Policy for Google API data. Its use is limited to disclosed, permitted functions, without sale, advertising, credit decisions, or general-purpose AI training. Transfers and human access are limited to permitted circumstances, including specific authorisation, necessary security work, or legal obligations. This commitment does not claim provider approval.
Disconnecting and deleting cloud data
An administrator can disconnect a provider in Melons Books. This removes the current local access and refresh tokens, account identity, and folder mapping. OAuth application configuration, including its client identifier and secret, and historical backup job metadata remain until separately changed or removed. The Google connector also attempts to revoke the grant; provider-side revocation should be checked separately. You can revoke access in your Google or Microsoft account’s connected-app settings.
Disconnecting does not delete previously uploaded archives, other exported copies, or credentials inside an older encrypted backup. Deleting a local backup does not delete its cloud copy. Existing remote files must be managed in the relevant cloud account. For deletion of information held by Melons, contact us as described below; revoking a provider grant and deleting business records are separate actions.
Cookies, browser storage, fonts, and analytics
WordPress and account-security features use cookies where needed for sign-in, session verification, and temporary authentication challenges. Their lifetime depends on the sign-in or security function and any remember-me choice. Signing out ends the current authenticated session. The website can store your motion preference in your browser; Melons Books can store display preferences such as hidden columns. These preferences remain until changed or cleared in the browser.
The public theme uses local styling and font choices rather than requiring a Google Fonts download. Other enabled components may load external resources; those requests disclose normal connection information, such as an IP address, to their provider.
Analytics is optional. The Melons form integration can send a generic successful-enquiry event only when the analytics integration is enabled and the site’s consent system reports that statistics consent was given. That event includes the form type and submission method, not the submitted name, email, phone, budget, message, files, or enquiry identifier. This capability does not mean analytics is enabled on every page or installation. Any separately enabled analytics or advertising tools have their own collection and consent settings.
You can control cookies and stored site data in your browser. Blocking essential authentication cookies can prevent account access. Where optional cookie controls are provided, use them to change those choices; clearing browser data may also clear a saved preference.
Retention, correction, and deletion
There is no single automatic deletion period for all records. Enquiries and correspondence are retained according to their purpose and follow-up needs. Client, financial, support, security, and audit records may need to be retained for ongoing services, accounting obligations, security investigations, or disputes. A suspended account or an archived record is not the same as deleted data. The current software does not automatically erase all records when an account is closed.
Backup retention is separate from live-record retention. Local backup settings can limit eligible completed archives, while failed or incomplete jobs and remote copies may require separate review and deletion. A correction or deletion in the live system does not immediately rewrite historical audit entries or every backup. Retained recovery copies remain subject to their applicable retention and access restrictions.
Contact us to request access to your personal information, correction, a copy or transfer, restriction of use, objection to processing, withdrawal of consent, or deletion where applicable. Identify the relevant account, enquiry, or client relationship without sending a password or one-time code. We may request proportionate information to verify your identity or authority. We will explain if a particular record must be retained or if your request concerns information controlled by a client organisation.
Protecting information and raising concerns
Access controls, encrypted credentials and backup archives, authentication checks, and activity records help protect information. These measures depend on appropriate configuration, hosting, and account security; no system can guarantee protection against every loss or unauthorised access. Please report suspected account misuse or a privacy incident to contact@melons.me. Where an incident requires notification, we will notify affected people and the relevant authority as applicable.
Our services are intended for business and professional use. Please do not submit children’s personal information or sensitive information unrelated to the requested work. Contact us if such information has been provided in error.
You may raise a privacy complaint with Melons and, where applicable, with Jordan’s personal data protection authority at the Ministry of Digital Economy and Entrepreneurship. This policy does not limit rights available under applicable law.
Changes and related information
We may update this policy as services, data handling, or requirements change. The date at the top identifies the current version. We will provide an additional notice and seek fresh consent where required for a material change of purpose. Read our Terms and Conditions and the Melons Books information page for related service information.
