Privacy Policy

Last updated: 14 September 2026

Who publishes this app

Visit Ramallah is published by Ramallah Municipality. The Municipality is responsible for the app and for the small amount of information described here. Contact details are at the end of this page.

The short version

  • The app has no accounts. You never sign up and never log in.
  • We do not ask for or collect your name, email address, phone number, photos or contacts as you use the guide. There are two exceptions, and you choose both: sending us a photograph of a place, and applying to volunteer as a greeter. Each is described in full below, and you never have to use either to use anything else in the app.
  • If you do send a photograph, it is reviewed by a person before anyone sees it. Your photograph, the name you give and your caption are then published in the app. The email address or phone number you leave is never published — it is only so the Municipality can reach you about your photograph.
  • If you apply to volunteer as a greeter, you send us your name, one way of contacting you, and what you write about yourself. None of it is published anywhere. It is read only by Ramallah Municipality staff, and it is deleted on the timetable set out below.
  • A photograph's location is the place you chose from the guide, not you. Before it will send a photograph the app checks, on your phone, that you are near that place — the reading never leaves the phone — and the picture is rebuilt from its pixels, so the GPS coordinates, capture time and camera details a phone normally writes into a photo file do not survive.
  • There is no advertising in the app, no advertising identifier, and no tracking of you across other apps or websites.
  • The app contains no third-party analytics service and no crash-reporting service.
  • If you turn location on for the heritage trail, your position stays on your phone. It is never sent to us or to anyone else — and nothing else in the app, including sending a photograph, transmits your position either.
  • Our own server records which pieces of content are opened, but nothing that identifies you or your device.
  • If you allow notifications, the app registers an address your phone's push service gives it, so that a message can reach you. That is the one thing the app stores that is tied to your installation, it is explained in full below, and turning notifications off stops it.
  • The map pictures come from two outside services. Those services see your device's internet address. This is explained below, because it is the app's most significant flow of data to a third party.

Location

The app uses your location for two things: the self-guided heritage trail on the Trails screen, and checking that you are at a place before you send a photograph of it.

What it does on the trail. While you are walking the trail, the map shows a blue dot for where you are. When you stay near the stop you are heading for, the app asks “Arrived at …?” so you can tick the stop off with one tap. The map also shows the blue dot whenever the map is open and you have given permission, so you can see where you are without starting a walk.

What it does for a photograph. When you open the form to send a photograph of a place, the app asks your phone where it is and compares that with the coordinates of the place, on your phone. If you are not near the place, the app will not send the photograph. This is why: a photograph of a place should come from someone who was at it. Your position is used for that comparison and nothing else — it is not sent with the photograph, it is not sent to our server at all, and there is nowhere on our server that could receive it. The location recorded against a published photograph is the location of the place, never yours.

Anyone can defeat this check with a fake-location app. It makes sending a photograph of somewhere you have never been harder; it does not prove that anyone was anywhere.

When it is used. Only while the app is open on screen, and only while a walk is in progress, a map is showing, or you are on the photograph form. The app stops using location the moment you switch to another app, pause the walk, finish it, abandon it, leave those screens, or turn the switch off. The app never uses location in the background. It holds no background-location permission on either Android or iOS.

When you are asked. Never at first launch. The app asks in three places only:

  1. When you tap Start the trail and choose Use my location on the explanation screen that appears first. Not now starts the walk without location.
  2. When you switch Location Services on yourself in the app's Settings screen.
  3. When you open the form to send a photograph of a place. If you refuse, the rest of the app is unaffected; only sending a photograph is unavailable.

Where it goes: nowhere. Positions are held in your phone's memory while you walk and then discarded. They are never written to your phone's storage, never sent to our server, and never sent to any other company. The app has no way to send them: nothing in it transmits coordinates.

The app does save your progress along the trail on your phone — which stops you have ticked off, when, and whether you ticked them off by tapping I'm here or by answering the arrival question. That record contains no coordinates.

You do not need it for the trail. The trail works completely without location. The I'm here button is available at every stop, in every state, including when location is switched on and working. If the app's own reading of where you are disagrees with you, it says so and lets you mark the stop anyway — it never blocks you out of your own walk. If you refuse permission — even permanently — you can still walk and complete the whole trail.

Sending a photograph is the one thing that does need it, and it is the only thing in the app that does. Applying to volunteer as a greeter does not: that form never asks your phone where you are.

The map, and the two outside services that draw it

The map in the app is drawn from small square pictures, called tiles, which are downloaded as you pan and zoom. They do not come from us. They come from:

  • Esri / ArcGIS Online (server.arcgisonline.com) — the satellite view. This is also the source used on the small map on each place's page, and for the offline map download.
  • OpenStreetMap (tile.openstreetmap.org) — the street view.

To send those pictures to your phone, those servers necessarily receive:

  • your device's internet (IP) address, which usually indicates roughly where in the world you are, and
  • the coordinates of the tiles you are asking for, which show the area of the map you are looking at.

This happens whenever the map is on screen, and whenever you use Download for offline, whether or not you have given the app permission to use your location. It is how any online map works. Your own position — the blue dot — is not sent to them; it is drawn on your phone, on top of the pictures they send.

Those two services are independent of Ramallah Municipality and handle that information under their own privacy policies:

Tiles you have already seen, or downloaded with Download for offline, are kept on your phone and reused, so revisiting the same area does not fetch them again.

Directions, and the Virtual Tour

When you tap Directions for a place, the app hands the destination's coordinates to another app on your phone and steps out of the way. On iPhone it offers Apple Maps, and Google Maps if you have it installed. On Android it offers Google Maps and any other maps app you have. From the moment that app opens, what happens is governed by that app's own privacy policy, not this one. We are not told what you do there.

The Virtual Tour link opens vr.ramallah.ps in your web browser, outside the app.

Content, pictures and video

Text, photographs and videos in the app are fetched from Ramallah Municipality's own server at visitramallah.ramallah.ps as you browse, and cached on your phone so they work offline. Making that request means the server receives your device's internet address, as it must in order to reply. What the server keeps is set out in the next section.

Visitor photos

You can send us a photograph of a place in the guide. This is optional, and nothing else in the app depends on it. Browsing, the map, the trail, favourites and saved trips all work without ever sending us a photograph or a single detail about you.

What you send. When you submit a photograph you give us:

  • the photograph itself;
  • a name to publish it under (2 to 80 characters — it can be your first name or anything you would like the credit to read);
  • an email address or a phone number, so the Municipality can contact you about the photograph;
  • a caption, if you want one — optional, up to 280 characters, in Arabic or English; and
  • the place you are submitting it for, which you pick from the guide.

You must also tick a box to confirm you agree. The confirmation reads:

I confirm that this is my own photograph, that I am happy for Ramallah Municipality to publish it in the Visit Ramallah app together with the name and caption I have given, and that anyone clearly identifiable in it has agreed to that.

Consent is never assumed. If the box is not ticked, the submission is refused.

What becomes public. If a moderator approves it: the photograph, the name you gave, and your caption, on that place's page in the app. Nothing else.

What never becomes public. The email address or phone number you left is never published, and is never sent to the app. It is visible only to the Municipality staff who moderate submissions, on their own password-protected screen. It exists so that somebody can write to you about your photograph — to ask a question about it, or to tell you it has been removed — and for nothing else. It is not added to a mailing list and it is not used for anything the app does.

Your location still never leaves your phone. The form does ask your phone where it is, and refuses to send the photograph if you are not near the place — but that whole check happens on your phone, against the coordinates the guide already publishes for that place. Your reading is compared and then discarded. It is not attached to the photograph, it is not sent to our server, and there is no field on our server that could receive it. That is why “Location: not collected” remains the true answer on both app stores, and why the promise in the Location section above is unchanged by this feature. The coordinates that go with a published photograph are the coordinates of the place you chose from the guide's own list — the same coordinates already shown on that place's page for every user. They describe the place, not you.

The check is not proof that you were there. Anyone can defeat it with a fake-location app. It makes sending a photograph of somewhere you have never been harder, and that is all it does: neither the app nor a published photograph should be read as evidence that any person was at any place at any time.

The photograph is rebuilt from its pixels. A photograph taken on a phone normally carries hidden information inside the file: the GPS latitude and longitude where it was taken, often to within a few metres; the exact date and time; the make and model of the phone; sometimes a camera serial number. None of it survives. The picture we keep is not your file. Our server decodes your photograph to plain pixels and writes a completely new image from them, so that hidden information is not “removed” — it is simply never written into the file that is stored and published. Nobody, including us, can read it back out of a published photograph.

Every photograph is checked by a person first. Nothing you send appears in the app automatically. Until a moderator approves it, a submitted photograph is held outside the public part of the server and has no web address at all — it cannot be found, guessed or linked to. Moderators can approve it, reject it, or publish it and take it down again later.

Likes are anonymous. You can like a published photograph without an account. To stop the same phone liking the same photograph repeatedly, the app makes up a random identifier for itself the first time it is used and the server stores only a scrambled (hashed) form of it, mixed with a secret the server keeps. It is not your device's identifier, it is not shared with any other app, it says nothing about you, and it cannot be turned back into anything. It is deliberately left out of your phone's backup, so installing the app again gives it a new one.

Reporting a photograph is anonymous too. If you see a photograph that should not be there you can report it from the app. A report carries no identity at all — no name, no contact details and no internet address. It tells a moderator which photograph and which reason, and nothing more.

Notifications

The app can send you a notification — that a photograph you submitted has been approved, that someone liked it, or an announcement from the Municipality. Notifications are optional. Your phone asks you before the first one is sent, and you can turn them off at any time in your device settings. Turning them off stops delivery.

What we store in order to deliver them. Two things, and only while notifications are switched on:

  • A Firebase Cloud Messaging token — an address your phone's own push service issues for this installation, which tells that service where to deliver a message.
  • The random per-installation identifier the app already makes up for itself the first time it is used — the same one described under Visitor photos.

Neither is your name, your telephone number, your email address, an advertising identifier, or your device's hardware identifier. Neither says anything about you. Both are replaced if you reinstall the app, and neither is included in your phone's backup.

What the identifier is linked to. It links a photograph you submitted to the installation that sent it, so that we can tell you when that photograph is approved or liked. It is not linked to your name or to any way of contacting you.

Who carries the message. Google's Firebase Cloud Messaging delivers it to your phone on our behalf. It is the delivery service, not an audience: the token exists so that service knows which phone to hand the message to. Nothing here is sold, and nothing here is used for advertising or to track you.

No position, no internet address. A notification, and the registration behind it, store neither. Allowing notifications tells us nothing about where you are.

How long. A notification is deleted 90 days after it is sent. A registration we have not seen for 180 days is deleted, and the token goes with it.

Volunteering as a greeter

The Ramallah Greeters are residents who volunteer to show visitors around the city. If you tap Become a Greeter and fill in the form, you send us:

  • the name you want to be called;
  • one way of contacting you — an email address or a phone number, not both;
  • which languages you speak, chosen from a list;
  • roughly when you are free — mornings, afternoons, evenings, weekends, or by arrangement. Not a calendar and not specific dates;
  • a short paragraph about yourself in your own words; and
  • a confirmation that you are 18 or over. We store only the fact that you confirmed it. We do not ask for your date of birth and we do not have one.

That is the complete list. In particular we do not ask for your address, any identity or passport number, your gender, a photograph, a CV, or a second way of contacting you — and there is nowhere in our records for any of them. Your location is not involved at all: the form does not ask your phone where you are and cannot receive it.

Nothing you send is published. It is not shown in the app, not shown on the website, and not visible to other visitors or to other volunteers. It is read only by Ramallah Municipality staff who have been given access to it, so that somebody can consider your application and reply to you. If you are accepted, the profile that later appears in the app is written separately by the Municipality — it does not come from this form.

Your internet address is used, for a few seconds, only to limit how many applications can be sent from one connection in an hour. It is held in a temporary cache for the length of that hour and is never written into our records.

You can ask us to delete your application at any time, using the contact details at the end of this page. We will delete it outright — there is no archived copy and nothing is kept.

What our server records

When the app asks our server for content, the server may add one row to an internal statistics table. That row contains:

  • the date and time of the request;
  • what kind of content was requested (a page, a category, a file, the home screen, the map, a menu, a tag) and which one it was;
  • the language you were reading in (Arabic or English);
  • the platform the request came from (android or ios);
  • the app version;
  • a two-letter country code; and
  • for visits arriving from a web page, the host name of the referring site. The app itself does not send one, so this is empty for app traffic.

That is the complete list. In particular the row contains:

  • no IP address. Your address is read once, in memory, and looked up against a copy of the MaxMind country database held on our own server to get the two-letter country code. It is then discarded. It is not written down, and it is never sent to any outside lookup service.

    Your internet address is used in one other place, and also without being stored: to stop automated bulk sending, the server counts how many photo submissions, likes, reports and greeter applications have come from an address in the last hour or minute. That count lives in the server's temporary memory, expires with the time window it covers, and is never written to a table, a log line or a column. No part of this app writes an IP address down.
  • no visitor identifier, session identifier, device identifier or cookie. There is nothing in the table that could connect two rows to the same person or the same phone. Counting unique visitors was considered and deliberately rejected.
  • no coordinates, of any precision.
  • no name, email address or anything else about you. Browsing the guide never asks you for any of it, and if you have sent us a photograph or applied to volunteer, nothing in this table is connected to it.

The result is a count of how often each part of the guide is read, by language, by platform and by country. It cannot be turned back into a person.

How long things are kept

  • On your phone — favourites, trails you have built yourself, saved trips, trail progress, your language and theme choice, and the cached content, pictures and map tiles stay until you clear the app's data or uninstall the app. We cannot see any of it.

    A reinstall can bring some of it back. The app is included in your phone's own backup — Android's Auto Backup, and the standard iPhone backup — so favourites, trails you built yourself, saved trips and your language choice may be restored when you install the app again. That backup belongs to your phone and to your device account, not to us: we cannot read it and it is never sent to us. Two things are deliberately kept out of it and are never restored: the random identifier behind photo likes, and the record that you refused location permanently. The identifier is dropped because restoring it would let one identifier follow a person from one phone to another, which is exactly what this design avoids; the refusal is dropped because a phone that has never asked you should not begin by telling you that you said no.
  • On our server (statistics) — the individual statistics rows described above are kept for 90 days and then deleted. Daily totals (for example “12 people in Jordan opened this page on this day, in Arabic, on Android”) are kept indefinitely. Those totals contain no more detail than the rows they came from.
  • On our server (photographs you send)
    • A published photograph, with the name and caption published beside it, is kept for as long as the app carries that place — or until you or someone in the picture asks us to take it down, or a moderator removes it.
    • A rejected photograph is deleted 30 days after it is rejected — the record and the image files, together.
    • The email address or phone number you left is erased 12 months after your photograph is published. The photograph and the name published with it stay; the way to contact you does not. After that we no longer hold anything that identifies you, and a takedown request has to be made by describing the photograph rather than by matching it to your address.
    • A submission still waiting for a decision after 90 days is reported to the moderators so that it is not left in limbo. It is not deleted automatically.
  • On our server (greeter applications) — if your application is declined, it is deleted 90 days after the decision. If it is never reviewed, it is deleted one year after you sent it. If it is accepted, we keep it for as long as you are an active volunteer; staff confirm that at least once a year, and it is deleted when you stop volunteering or when you ask us to delete it. Deletion means the record is removed; we keep no copy.
  • On our server (notifications) — a notification is deleted 90 days after it is sent, together with the record of whether it had been read. A device registration we have not seen for 180 days is deleted, which removes its delivery token. If you turn notifications off, your phone stops answering for that registration, and it falls away on the same 180-day clock.

Children

Visit Ramallah is a city guide, suitable for all ages. There is no sign-up, no profile, no messaging between users, and no advertising.

There are two ways to send us something, and neither is needed to use any part of the app. Visitor photographs, described above, are not aimed at children, and the form asks for a name and a way to contact you. We ask that people under 16 do not use it without a parent or guardian. We do not verify anyone's age — we do not ask for it, and asking would mean collecting more about everybody than we collect now. Applying to volunteer as a greeter is for adults: that form asks you to confirm you are 18 or over, and the Municipality does not accept volunteers under that age.

If you are a parent or guardian and believe your child has sent us a photograph or an application, write to the address at the end of this page and we will remove it and everything sent with it. You do not have to explain or prove anything, and we will not ask you for further details about the child.

Every photograph is checked by a person before it appears, and a moderator will reject a photograph whose subject is a child on their own, or anyone who plainly did not expect to be photographed.

What you can do

  • Turn location off. Open Settings in the app and switch Location Services off. The position stream stops immediately and the trail falls back to the manual I'm here button.
  • Take the permission away entirely.
    • iPhone: Settings → Privacy & Security → Location Services → Visit Ramallah.
    • Android: Settings → Apps → Visit Ramallah → Permissions → Location.
    The app checks again each time you return to it, and behaves correctly if you have revoked it.
  • Delete everything the app has stored. Uninstall the app. That removes your favourites, your own trails, saved trips, trail progress, settings, and all cached content, pictures and map tiles from the phone. On Android you can also use Settings → Apps → Visit Ramallah → Storage → Clear data without uninstalling. If you do not want your phone's own backup to restore any of it when you install the app again, turn the app's backup off in your phone's backup settings too — that copy belongs to your phone, not to us.
  • Take back a photograph you sent. Write to the address at the end of this page, describing the photograph and the place it shows, and we will remove it from the app and delete it from the server. You do not have to give a reason. If you sent it within the last 12 months, quoting the email address or phone number you submitted with it is the quickest way for us to find it.
  • Ask us to remove a photograph of you that someone else sent. You do not have to have used the app. Write to the same address, or use Report on the photograph in the app, and a moderator will look at it. Where a photograph is clearly of an identifiable person who did not agree to it, it is taken down.
  • Report a photograph from inside the app. Every published photograph has a Report action. It is anonymous and it reaches a person, not an automatic filter.
  • Ask us to delete your data, or ask what else we hold. Apart from a photograph you have sent and an application to volunteer, there is nothing: there is no account, no profile and no record of your browsing that belongs to you, and the statistics described above cannot be traced back to a person, so there is nothing in them we could find and remove on request. If you have applied to volunteer as a greeter, write to us at the address below from the email address you used, or tell us the phone number you gave, and we will delete your application outright. We keep no copy of a deleted application.

Changes to this policy

If the app starts doing something this page does not describe, this page will be updated before that version is released, and the date at the top will change.

Contact

Questions about this policy, or about the app:

Ramallah Municipality
Email: tic@ramallah.ps
Website: www.ramallah.ps

Contact Us


Ramallah Municipality

Tel: 00970 2 294 5555 ex.123

Free Number: 1800 10 11 01

tic@ramallah.ps

ramallahtouristcenter