Treble Privacy Policy

Version 1.1 · Effective Monday, September 1, 2026, 00:00 EET (Cairo)

DocumentTreble Privacy Policy (English)
ApplicationTreble for iOS, bundle identifier com.theagenticlab.treble, and the servers it connects to
Version1.1
Effective fromMonday, September 1, 2026, 00:00 EET (UTC+2, Africa/Cairo)
Last revisedMonday, August 24, 2026, EET
SupersedesVersion 1.0, dated August 23, 2026 — superseded before its own effective date, so this is a correction to the document that will first take effect, not a change to a document already in force
Next scheduled reviewOn or before March 1, 2027, and upon any change to the providers named in section 5
Governing frameworkEgyptian Personal Data Protection Law No. 151 of 2020 and its implementing regulations as in force

The Agentic Lab™ makes Treble. Businesses use it to run their returns desk: staff sign in, read the return and exchange requests their customers filed, and accept or decline them. Treble is a working tool for named staff at a business. It is not a shopping app and it is not for the public.

This policy sits alongside the policy set of the business you work for or bought from. It does not replace it. The business using Treble today is RYZE Fragrances, and RYZE publishes its own Privacy Policy at ryzeeg.com covering everything that happens on the storefront.

1. Who this policy covers

Operators. Staff who sign in to Treble. The Agentic Lab holds your account information and decides what happens to it. Section 2 lists it.

Customers of a business using Treble. People who bought something and asked to return or exchange it. Their information reaches Treble because the business put it there. The business decides what happens to it, and RYZE's own Privacy Policy says the same thing in its opening paragraph: RYZE is the data controller. The Agentic Lab handles that information only on the business's instructions.

That split decides where you send a request. Section 8 has the addresses.

2. What Treble collects

Your business email address. It is your identity in Treble. A one-time sign-in code goes to it, and any Face ID passkey you create binds to it. There is no password, so there is no password to store or lose.

Your passkey's public key. The private half stays inside your iPhone's secure hardware. We never receive it and cannot read it.

Your device details, and your sessions list. At sign-in the app sends the device model identifier, the iOS version, an identifier the app generates for that installation, and a label so you can recognise the device in your own list. You can be signed in on more than one device at once — your own phone and, if your business issues one, another operator's or a shared device — and each one carries its own Face ID gate and its own notifications. Inside the app you can see every session currently open on your account: which device it is, when it signed in, when it was last active, and the city-level location it signed in from (see “Your network address,” below). You can sign any single session out from that list, or sign out every session except the one you are using.

A notification token, if you ask for notifications. iOS issues the token and the app forwards it so alerts can reach that phone. Leave notifications off and Treble works the same, minus the alerts.

A sign-in journal. We record sign-in events so you and the business owner can see when someone signed in, and so a stranger trying your address leaves a trace. Every entry carries a keyed one-way fingerprint of the address, computed under a key kept for that purpose alone. The address itself is stored in readable form only when it belongs to an operator the business has enrolled, because the owner has to be able to recognise his own staff in his own log. An address that is not enrolled is reduced to its first character and its domain, so the journal can never become a list of the addresses someone tried.

Your network address, and the city it places you in. The IP address you connect from is recorded on each sign-in event, and a one-way fingerprint of it is used to limit how many sign-in attempts can be made and to recognise a network you have already signed in from successfully. Without it we cannot tell your own repeated attempts apart from an attack on your account.

We also derive a city and country from that address — Cairo, EG; Newark, US — using the location our network provider (Cloudflare) already assigns your connection at its edge. This is not GPS and not a device location service; Treble asks nothing of your phone’s location hardware and this figure is never more precise than a city. That city/country pair is attached to the session record it came from and shown in your own sessions list and to the business owner, the same way your device details already are. It exists to make the sessions list useful for spotting a session that should not be there, and for the same anti-abuse purpose your IP address already serves.

What The Agentic Lab sees about your sessions, as the platform’s operator. Treble is one platform running the same software for more than one business. The Agentic Lab — the company that makes Treble, already named in section 1 as the holder of operator account information — operates a control surface across every business on the platform for service administration: keeping the service running, spotting abuse, and supporting a business that writes in with a problem. On that surface, for each business and each operator email enrolled there, we can see the count of that operator’s currently active sessions and the city/country those sessions are signing in from. We do not see session content, cannot open a business’s return desk from that surface, and this view carries no customer data of any kind — it is limited to operator account metadata, the same category of data section 2 already describes. This is not a new recipient receiving your data under section 5; The Agentic Lab is the maker and operator of Treble throughout this policy, and this paragraph names a capability it already has reason to hold, stated plainly rather than left implicit.

Customer return and exchange records. When a customer asks a business for a return or exchange, Treble holds their order number, name, the email address or phone number they used, the items concerned, the reason they gave, any note they wrote, and the outcome the operator decided. The desk also reads live order status from the business's Shopify account each time the screen draws.

3. Why, and on what legal basis

Article 6 of Law No. 151 of 2020 makes electronic processing lawful where one of its four conditions is met. Two apply here.

PurposeBasis under the PDPL
Signing you in and keeping you signed inYour consent, Article 6(1)
Sending alerts to your phoneYour consent, Article 6(1), given when you turn notifications on
Showing an operator a customer's return request and recording the decisionExecution of an agreement for the benefit of the person concerned, Article 6(2)
Telling the customer what was decidedExecution of that same agreement, Article 6(2)
Keeping a record of who signed in and what they decidedThe controller performing its obligations, Article 6(4)

Article 3 sets the boundaries: a legitimate, specific and stated purpose; correct and secured data; use confined to the purpose it was collected for; no retention past what the purpose needs.

4. What Treble does not do

No tracking. Treble does not follow you across other companies' apps or websites and builds no advertising profile. There is no tracking technology in the app to switch off.

No analytics, no third-party code. Treble bundles no analytics toolkit, no crash reporter and no third-party code libraries at all. RYZE's storefront uses Microsoft Clarity and an AI concierge, both disclosed in RYZE's own Privacy Policy. Neither runs inside Treble.

No AI. Nothing in Treble is processed by an AI model.

No payment data. Checkout belongs to the shop's payment provider. Treble never touches a card number.

No location, contacts, photos, microphone or camera.

We never sell personal data.

Alerts say nothing. A Treble notification says a return request needs review. It names no customer, no order and no item. A notification paints itself on a locked screen in front of whoever holds the phone, and a customer never agreed to that.

5. Who we share data with

RecipientRoleWhat it receives
CloudflareHosting and database (processor)Everything in section 2. Cloudflare Workers runs the application and Cloudflare D1 stores the data
ResendTransactional email (processor)An operator's email address and the sign-in code addressed to it
ApplePush deliveryThe alert and its device token, relayed through Apple Push Notification service. The alert itself carries no customer information
The push service belonging to your browser, if you open the desk in a browser instead of the appPush deliveryThe same contentless alert and the subscription address that browser issued. On Safari that service is Apple's, on Chrome it is Google's, on Firefox it is Mozilla's
Shopify Inc.E-commerce platform (processor)Order lookups against the business's own Shopify account, and return decisions written back to it
AuthoritiesWhere Egyptian law requiresOnly what the law compels

Two links inside the desk hand data to a third party when an operator taps them. A WhatsApp button opens a conversation with the customer using the phone number on the order, which passes that number to WhatsApp on the operator's phone in the ordinary way. A tracking button opens the customer's own shipment page on the shop's website, which the business operates under its own privacy policy.

Bosta carries the parcels. The business shares delivery details with Bosta under its own arrangement with them, disclosed in RYZE's Privacy Policy. Treble reads shipment status that comes back from that relationship and sends nothing to Bosta.

6. Where the data lives, and the transfer out of Egypt

Treble's data sits in a Cloudflare D1 database, and the application that reads and writes it runs on Cloudflare Workers. The database's primary location is set to Cloudflare's Eastern North America region, so the data is stored in the United States. Cloudflare's documentation treats a location setting as a preference and places the database in the nearest available location, so we describe the region rather than a city.

The businesses using Treble operate in Egypt. Most customers whose return requests appear in it live in Egypt. Their information is therefore stored outside Egypt.

Egyptian law regulates that. Article 14 of Law No. 151 of 2020 allows personal data to be transferred, stored or shared outside Egypt only where the destination country's protection level meets or exceeds Egypt's requirements, and subject to a Licence or Permit from the Personal Data Protection Centre. Article 16 sets conditions on disclosing personal data to a controller or processor abroad. Article 15 lists the cases where explicit consent permits a transfer without that minimum protection level.

The position as of this version: the transfer is real, it is described here accurately, and the businesses using Treble are working through the Centre's requirements with legal counsel. Egypt's Executive Regulations issued on 1 November 2025 and give affected organisations until 31 October 2026 to bring their positions into compliance. Write to us and we will tell you where that stands for your own data.

The United States has no national privacy law equivalent to Egypt's. Protection there comes from state laws and sector rules written around residents of particular states and businesses above particular size thresholds, such as California's Consumer Privacy Act, whose scope is set by California Civil Code section 1798.140. Neither the businesses using Treble nor the people whose data it holds are United States residents, so those laws are not what protects this data. Egyptian law, the commitments in this policy and the security in section 9 are. One consequence follows from storage in the United States: while the data sits there, United States legal process can reach it in ways it could not if the data never left Egypt.

7. Retention

DataKept forWhy
One-time sign-in codesThe code itself stops working 10 minutes after it is sent; the record of it is deleted automatically 24 hours laterA spent code has no further use
Sign-in sessions30 days from the sign-in that created them; expired sessions are deleted automatically, and a session you sign out is revoked immediatelyKeeping you signed in between shifts
Sign-in journal entries, including the IP address each one records90 days, then deleted automaticallyLetting you and the owner audit access
The city/country location derived from your network addressAttached to a live session, it is visible for as long as that session exists (up to 30 days, same row above) and is removed from your sessions list the moment the session is revoked or expires. Attached to a sign-in journal entry, it follows that entry’s own 90-day timerSame purpose as the session and journal rows it is attached to — it is not held on its own schedule or for its own separate purpose
The rate-limiting and known-network fingerprints derived from your IP addressMinutes to weeks, each on its own timer, then deleted automatically. The address itself is not kept in themStopping an attack on your sign-in without storing where you connect from
Passkey public keysUntil you remove the passkey or the business removes your accountSigning you in with Face ID
Device records: the identifier the app generates for an installation, the device model, the iOS version, the day the app first ran on it, and your label for itUntil the business removes your account. Signing a device out revokes its sessions; it does not erase the record, so the device stays in your own list and you can see it is signed outShowing you every phone signed in to your account and letting you sign one out by name
Notification tokensUntil you turn notifications off, sign that device out, or the business removes your account. Apple also reports dead tokens, which we deleteReaching your phone
Operator accountsUntil the business owner removes the operatorAccess control
Return and exchange recordsFive years from the end of the tax year of the orderA return record belongs to the order record, and RYZE's Privacy Policy section 7 keeps order records for that period under Egyptian tax and commercial obligations

Two caveats, stated rather than implied. No automatic timer enforces the five-year limit on return and exchange records today, and none enforces the device-record row either; both are deleted on request rather than on a clock, and the rows that say "until you remove it" or "until the business removes your account" end on that event, not on a timer. Deletion runs on request. If you are a customer and you want your return record deleted, ask the business you bought from, or write to us and we will pass it on and act on their instruction.

8. Your rights under Law No. 151 of 2020

Article 2 gives you the right:

Article 2 permits a fee for some of these requests, capped by decisions of the Personal Data Protection Centre. We charge nothing.

Operators: write to support@ryzeeg.com with the subject "Data Request", or ask the business owner who enrolled you. You can also sign any of your devices out from inside the app at any time.

Customers: the business you bought from controls your information, so write to them first. RYZE's route is support@ryzeeg.com with the same subject line. A request sent to us goes to the business, and we tell you that it did.

We verify identity, then answer within 30 days of the request timestamp, extendable once by 30 days for complex requests with written notice. That is the same window RYZE's Privacy Policy commits to.

You may also complain to the Egyptian Personal Data Protection Centre or the competent authority.

9. Security

Sign-in is passwordless. A one-time code goes to your business email address; after that you can add a passkey whose private key stays in your iPhone's secure hardware. Sessions live in a signed, HttpOnly cookie, expire, and can be revoked device by device. Sign-in attempts are rate-limited and journalled. All traffic runs over HTTPS. Only operators the business enrolled can reach the desk, and each business's data is fenced from every other business's.

No system is secure against everything. If something reaches your data, you will hear it from us.

10. Breach

Article 7 of Law No. 151 of 2020 requires the Personal Data Protection Centre to be notified within 72 hours of a personal-data infringement, and requires affected people to be told within three days of that notification. We will do both, and we will record the timeline (discovery, containment, notification) in Cairo time, matching the practice RYZE's Privacy Policy sets out.

11. Children

Treble is a workplace tool for adults. We do not knowingly collect information from anyone under 18. Egyptian law treats all data relating to children as sensitive personal data (Article 1 definitions, Article 12 restrictions), and Treble processes no sensitive personal data at all. Tell us if you believe a child's information reached us and we will delete it.

12. Changes and contact

A change to this policy brings a new version number, a revision timestamp and an effective date, and the document-control table at the top is the authoritative history. A change that materially affects what we do with your information reaches operators inside the app rather than waiting for you to re-read this page. Earlier versions stay available on request.

Contact: support@ryzeeg.com.

The Agentic Lab™ publishes Treble on the App Store under the identifier com.theagenticlab.treble. If you are a customer of a business using Treble and your question is about your own order or return, that business answers fastest.