Privacy policy
Reflect is a digital mobile banking app that provides a modern and fresh banking experience, streamlining day-to-day banking needs that is powered by Arab Bank. It is located in Arab Bank’s headquarters in Amman Jordan. Address: 8 Shaker Bin Zaid St. Shmeisani, Amman 11195 Jordan.
Your privacy and the security of your Personal Data is very important to us. At Reflect, hereinafter referred to as (“us”, “we”, or “our”), we ensure that Personal Data you provided to us is always treated as private and confidential, afforded the highest level of security, and is processed in accordance with Arab Bank Privacy and Data Protection Policy and applicable regulatory requirements on Personal Data Protection. This includes Personal Data Protection Law 24/2023 and the Central Bank of Jordan Decision on Personal Data Processing by Entities Subject to its Supervision of 2025. This Privacy Notice, hereinafter referred to as “Notice”, aims to provide you with information on how we will use your Personal Data, what steps we will take to ensure it stays private and secure and what Personal Data we collect and process about you as well as your data privacy rights and how you can exercise them.
How we collect your data
We collect your data through one of the following methods:
– Directly: we obtain Personal Data directly from you in order to receive a service from or transacting with us, including without limitation, enter a business relationship, log a complaint, or for other purposes depending on the requested services or agreed upon.
– Indirectly: we may obtain Personal Data about you indirectly from a variety of sources, including: device ID’s, social media, public sources, business partners, and recruitment services to better understand and serve you, satisfy a legal obligation, or in pursuance of another legitimate interest.
How we use your Personal Data
We collect your Personal Data for various reasons in relation to our services, products or interacting with us, and for other business purposes, including, but not limited to:
– to provide and manage your account(s) and our relationship with you.
– to give you statements and other information about your account or our relationship.
– to handle enquiries and complaints.
– to provide our services to you.
– to conduct assessment, testing, and analysis for statistical purposes or other analysis for market research purposes.
– to evaluate, develop, and improve our services to you and other customers.
– to protect our business interests and to develop our business strategies.
– to contact you, by post, phone, text, email and other digital methods.
– to collect any debts owing to us.
– to meet our regulatory compliance and reporting obligations in relation to protecting against financial crime.
– to assess any application, you make.
– to monitor, record, and analyze any communications between you and us.
– to share your Personal Data with governmental authorities, credit reference agencies, fraud prevention agencies, and overseas regulators and authorities.
– to share your Personal Data with service providers and external auditors as clarified in section below (Who has access to your Personal Data and to whom it may be disclosed).
– recruitment and vetting agencies for prospective job applicants.
– for purpose of litigation, consultation, legal advice or documentation of transactions.
If you fail to provide Personal Data
If you fail to provide Personal Data which we are legally required to collect from you, or under the terms of a contract we have with you, and you fail to provide such data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to subscribe or use a specific product or services). In this case, we may have to cancel a product or service you have with us, but we will notify you if this is the case at the time.
On what legal grounds do we process your Personal Data
We rely on the following lawful reasons when we process your Personal Data:
– Contractual Basis: we process your Personal data as necessary for the entry and/or implementation of a contract with you, or for the conclusion of a contract at your request such as where you submit a request for an Instant loan.
– Legal Obligation: we process your Personal data as necessary to comply with a legal requirement from a regulatory or judicial authority. This includes Processing of your Personal Data to comply with laws and regulations we are subject to such as anti-money laundering, regulatory compliance, and fraud prevention laws and regulations. For example, our collection of Know Your Customer (KYC) data including your income details, your work address, and residential address is needed under Anti-Money Laundering (AML) regulations that we are subject to.
–Security Purposes: we process your Personal Data as necessary for security purposes such as CCTV / video surveillance.
–Legitimate Interest: we process your Personal Data as necessary to fulfil a legitimate interest such as Processing Personal Data as necessary to protect against cyber risks, enhance our products and services, and profiling activities intended to ensure more customized and personalized products and services tailored to your needs. We ensure the legitimate interest perceived does not affect individuals’ rights and interests and does not override them.
– Consent: Where none of the above basis apply, we shall process you Personal Data based on your consent. You can submit a request to withdraw such consent – please refer to section below (What are your rights and how you can exercise them).
Please refer to the Annex at the end of the Notice (Personal Data Processing Matrix) for further details on how we use your Personal Data and the legal grounds for Processing.
Which Personal Data do we collect and process
The Personal Data we collect includes data provided by you at the start of our relationship or at any time thereafter such as:
– Personal details such as name, date of birth, email, nationality, marital status, and gender and contact information.
– Current residential address and permanent residential address, and proof of address documents.
– Data about your identity including documents, details of ID cards, details of passports.
-Employer, employment status, job title, full name, email, address and telephone number(s) used for work purposes.
-Financial data: income and source of income, source of wealth, average account financial activity, and engagement data.
– Data about your tax status such as overseas tax-identification number, FATCA forms, etc.
– Details of transactions done by you or by any of your connected persons including dates, amounts, currencies, and payer and payee details.
– Sound and visual images including CCTV footage.
– Digital identifiers (IP address, email).
– Cookies (please refer to section below on Cookies).
– Risk rating information, e.g., credit risk rating and data about your ability to manage credit.
– Recruitment information and qualifications for prospective job applicants.
– Due diligence data, e.g., data required to comply with financial crime regulations (anti-money laundering, anti-terrorism financing, etc.) and data we need to fulfil regulatory obligations such as Suspicious Activity Reporting.
– Other individuals’ information, such as family and household members, emergency contacts, and/or guardians, which include their signatures, addresses and relationship with you.
– Legal dispute, complaints, and grievance information.
– Agreements, contracts, billing and commissions information.
– Security Information
– Data about your geographic location and ATMs used
– Data collected for credit assessment purposes, including information related to your credit history, credit scores, repayment behavior, and any data received from credit agencies.
Automated Decision Making
As part of the evaluation and approval process for loans and credit card applications, automated decision-making tools are used to assess your eligibility for such applications based on pre-defined criteria and risk models without human intervention. Please note the pre-defined eligibility criteria and risk models are tested and monitored to ensure ongoing accuracy and fairness to customers.
Please contact Reflect WhatsApp Support: +962 792777027 if you require your application to be processed via a manual process in lieu of the automated process. You can also contact the Data Protection Officer (DPO) at Privacy.Office@Arabbank.com.jo to submit such a request.
Data Storage, Hosting Locations, and Data Purging Methods
Reflect stores and processes your Personal Data using secure infrastructure located in two countries; Jordan and the United Arab Emirates. This is necessary for alignment with disaster recovery and business continuity requirements. Data backup operations are performed periodically using dedicated systems to preserve data across computer workstations and servers. All storage methods and hosting arrangements are subject to application of technical and organizational safeguards. Data is retained only for the periods necessary to fulfill the purposes for which it was collected or as required by law, after which it is securely deleted, for more information on data retention practices please refer to section (How long do we keep your Personal Data).
Copies of Personal Data also reside on employees assigned computing devices strictly in accordance with their operational duties, subject to the implementation of robust Data Loss Prevention (DLP) and information security controls.
Data purging methods applicable by Reflect include shredding, disintegration, incineration, or pulverizing.
Data Hosting Methods
· On-Premise / Proprietary Data Centers: Traditional banking records (core ledgers, account balances, and encryption keys) are hosted in the Bank’s own highly secure, physically isolated, and monitored data centers.
· Third-Party Hosting: We rely on service providers who may store the Personal Data in data centers outside Jordan and / or using cloud hosting services while ensuring appropriate security and regulatory safeguards in place. Each organization is required to safeguard Personal Data in accordance with our contractual obligations. This includes data sharing and the related data hosting by entities involved in cards and digital payments processing including entities outside Jordan such as VISA and AFS, external auditors, and entities providing courier and postal services. Please refer to the section “Who has access to your Personal Data and to whom it may be disclosed” for further details.
Additionally, when support channels are accessed via WhatsApp, communication is managed through InfoBip. Personal details provided during these interactions are processed by InfoBip to facilitate and document customer support. InfoBip is a global communications technology company, that helps businesses send messages to customers through Push notification, WhatsApp, Email and Chatbots,while noting InfoBip stores the data on cloud infrastructure. Communications through WhatsApp are governed by WhatsApp’s own privacy policy and data protection practices, which are outside the control of Arab Bank. Similarly, data shared through InfoBip is subject to InfoBip’s privacy controls and policies. Users are encouraged to review both WhatsApp’s privacy policy (https://www.whatsapp.com/legal/privacy-policy) and InfoBip’s privacy policy (https://www.infobip.com/privacy) prior to using these support channels.
Please avoid sharing critical data including financial data on Whatapp since the Whatapp channel aims to address general Questions and Answers (QA) only, and is not a formal communication channel with Reflect.
Marketing
You can opt out anytime from our marketing communications across different channels via our Reflect App by amending the marketing notifications settings. Once you amend your settings, the marketing communications will be adjusted accordingly. You can also object to receiving marketing messages / marketing communications from Reflect at any time by sending an email to noreply@marketing.reflectapp.com or communicating with Reflect Care center via WhatsApp on +962792777027.
How we protect and safeguard your Personal Data
We will take reasonable technical and organizational precautions to prevent the loss, misuse, or alteration of your Personal Data. We aim to ensure that access to your Personal Data is limited only to those who need to access it, and those individuals who have access to the Personal Data are required to maintain the confidentiality of such Personal Data. For further information, please refer to Arab Bank Security Statement (https://www.arabbank.com.jo/footernavigation/security-statement).
When using the reflect mobile application, you remain responsible for keeping your user ID and password confidential.
Who has access to your Personal Data and to whom it may be disclosed
We keep your Personal Data confidential. However, in order to service your needs to the best of our ability, we may share your Personal Data with other parties bound via contractual agreements to safeguard your Personal Data and only process it under our strict instructions. We may also transfer your Personal Data to other Arab Bank Group members and third-party organizations outside of the Hashemite Kingdom of Jordan when we have a business reason to engage Arab Bank Group members or third-party organizations. Each organization is required to safeguard Personal Data in accordance with our contractual obligations.
In essence, we may share the Personal Data about you and your dealings with us, with:
– Arab Bank group members for legitimate business purposes such as data backup processes or for insurance purposes.
– Correspondent banks such as, as part of funds transfers, trade services, and other services and products you may request from the us.
– Entities involved in cards and digital payments processing including entities outside Jordan such as VISA and AFS.
– Other Third – Party Service Providers including cloud service providers for legitimate business purposes and in line with applicable laws and regulations.
– External Auditors which need to conduct audits of us as per applicable laws and regulations and may request sample data for validation and testing purposes.
– Regulatory authorities, governmental bodies, financial crime prevention agencies, courts, Social Security Department, and tax authorities.
– Courier and postal services as necessary to make deliveries such as for requested credit/debit cards.
– Credit reference organizations.
– Law firms, lawyers, or professional advisors where we need to revert to such legal advisors.
– Debit collection firms when we revert to such service providers for the collection of outstanding debts.
– Other parties with which you have agreed to share your Personal Data with.
– Jordan Payments and Clearing Company, a domestic payment system operator, which provides ID API verifications (Identification Document Application Programming Interface).
Please refer to the Privacy and Data Protection Officer at Privacy.Office@Arabbank.com.jo for further details and contact details of such third parties as well as their respective Privacy Notices (where applicable).
How long do we keep your Personal Data
We retain your Personal Data to provide our services, stay in contact with you and to comply with applicable laws, regulations, and professional obligations, which we are subject to. This includes regulatory requirements for record retention applicable to banks, for example, customer identification Personal Data such as your ID, personal and work details, need to be retained for 5 years as of the termination of the relationship. Sometimes we may need to keep your information for longer. The reasons for this include:
• where we need the information to meet regulatory or legal requirements.
• to help detect or prevent fraud and financial crime.
• to answer requests from regulators.
Reflect will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of our Service, or where we are legally obligated to retain this data for longer time periods.
Processing Sensitive Personal Data
Sensitive Personal Data is defined as any data that, directly or indirectly, indicates the individual’s origin, race, political opinions, religious beliefs, financial status, health, physical or mental condition, genetic data, biometric data, or criminal record. Biometric data refers to unique characteristics, either physical (like fingerprints, DNA, iris patterns) or behavioral (like voice patterns), that are processed by specific technologies to uniquely identify or verify an individual. We ensure there is a lawful basis for Processing of Sensitive Personal Data. For example:
- Biometric Data: selfie photos are considered biometric data when used to identify or validate the identify of an individual. As such, we process your selfie photo (biometric data) as part of authentication when you use our digital apps.
- Health Data: we process your health data as part of procedures for granting loans and financial facilities. However, this is conducted following your consent including on the sharing of this data with the insurance company.
- Financial Status data: we process financial status data which is in alignment with Know Your Customer Regulations that we are subject to.
What Are Your Rights And How You Can Exercise Them
Pursuant to Personal Data Protection Regulatory requirements, you may exercise the following rights concerning your Personal Data:
- Right to access your Personal Data within the custody of Reflect
- Right to be notified of Processing.
- Right to withdraw prior consent you have provided for the Processing of your Personal Data (where the Processing is based on consent)
- Right to rectify, modify, or update your Personal Data
- Right to limit Processing for a specified purpose.
- Right to erase your personal Data or to restrict the Processing of your Personal Data
- Right to object to Processing and profiling if they are not necessary to achieve or outweigh the purposes for which the personal Data was collected, or if they are discriminatory, unfair, or violate the law.
- Right to Personal Data portability in some circumstances, where you have provided Personal Data to us, you can ask us to transmit that Personal Data (in a structured, commonly used, and machine-readable format) directly to another company if technically feasible.
- Right to be notified of inaccurate disclosure and breaches or your Personal Data. Note that in the event of a breach of your Personal Data security and safety that could cause serious harm to you, we shall notify you within (24) hours from the discovery of the breach and provide you with necessary measures to avoid any consequences resulting from the breach.
To submit a request to exercise any of these rights, please send an email to our Data Protection Officer (DPO) at Privacy.Office@Arabbank.com.jo. We have appointed a designated DPO – also referred to under the Personal Data Protection Law 24/2023 as the Data Protection Supervisor – who is responsible for overseeing inquiries related to this Privacy Notice. The DPO undertakes responsibilities to verify compliance with the Personal Data Protection controls, requirements, procedures and rules across Reflect. The DPO is also registered with the Central Bank of Jordan as the Data Protection Supervisor per regulatory requirements.
Handling Requests
Please note that we shall act promptly on received requests, replies are to be provided within (15) Business days from the date of receipt.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your Personal Data (or to exercise any of your other rights). This is a security measure to ensure that Personal Data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
Upon receiving a valid request, we will:
- Verify the requester’s identity
- Record and track the request
If you exercise your right to erasure, rectification or limit of Processing, we will communicate this with the applicable Personal Data recipients to ensure your requests are executed as applicable.
Please note that our fulfillment to your requests may be subject to limitations, in certain circumstances, in accordance with the Law. For example, a request to erase your Personal Data in our custody may not apply where we are required to retain this data under regulatory requirements on data retention.
In essence, we may not be able to fully or partially fulfill certain requests when doing so would:
- Conflict with applicable laws or regulatory requirements
- Affect the integrity of identity-related or beneficial ownership information
- Impact the accuracy of credit reporting
- Conflict with AML/CFT obligations
- Compromise the security or integrity of banking operations
If we are unable to take action in response to your requests to exercise your rights, we will inform you along with the reasons for our inability to take action.
Personal Data Breaches:
Whilst we take measures to secure your Personal Data and we have a robust incident response plan in place, risks to data security do exist, and there is always a possibility of unauthorized use, disclosure, modification and/or destruction of your Personal Data. In the event of a data breach, our robust data incident management process will be triggered and our incident management response team will be assembled. The incident will be assessed to identify whether a data breach has in fact occurred. Upon confirmation of an actual data breach, there are stringent protocols that we follow to ensure the efficient management of data breaches and compliance with our legal requirements. Our internal protocols enable the immediate containment, investigation and remediation of data breach through the implementation of corrective and preventative measures and an assessment of any regulatory reporting and disclosure requirements. As noted under the section “What Are Your Rights And How You Can Exercise Them”, in the event of a breach of your Personal Data that could cause serious harm to you, we shall notify you within (24) hours from the discovery of the breach and provide you with necessary measures to avoid any consequences resulting from the breach.
If you wish to report a data breach or would like further information on how we respond to and handle data breaches, please contact our DPO at: Privacy.Office@Arabbank.com.jo
Arab Bank’s headquarters, 8 Shaker Bin Zaid St. Shmeisani, Amman 11195 Jordan
For More Information
Should you have any questions regarding this Notice or want to learn more about our security practices, please read Arab Bank Security Statement (https://www.arabbank.com.jo/footernavigation/security-statement ) or contact the Privacy and Data Protection Officer at: Privacy.Office@Arabbank.com.jo
Use of Essential Cookies
What are Cookies?
Cookies are small text files that are stored on your computer or mobile device when you visit a website. They are widely used to make websites function efficiently, as well as to provide information to site owners. Cookies can be “session cookies,” which are erased from your device when you close your browser, or “persistent cookies,” which remain on your device for a set period or until you delete them. We do not use third-party cookies, and we do not use cookies for analytics, social media sharing, retargeting, or interest-based advertising. Reflect only utilizes essential cookies, and does not collect or process any information through non-essential or third-party cookies.
Why Do We Use Essential Cookies?
Essential cookies are required to ensure that the website functions as intended. They support basic features such as secure log-in, page navigation, and access to secure areas of the site. Without these cookies, key parts of our website would not work correctly, and you would not be able to access the services or information you need.
Importantly, essential cookies do not collect or store information that could be used for marketing or tracking your browsing activity across other websites. They are limited strictly to supporting the basic technical operations of the Reflect website.
These cookies cannot be disabled via on-site controls because they are necessary for the website’s basic functionality. If you choose however to disable or delete essential cookies through your browser settings, please be aware that some parts of the website may not function properly, and you may be unable to access certain features or services.
Inquires and Complaints:
If you have any inquiries regarding the Privacy Notice, including any requests to exercise your rights, or if you have any complaints on the Bank Personal Data Processing, please contact the DPO using: Privacy.Office@Arabbank.com.jo.
Please note the we shall act promptly on received matters; replies are to be provided within (10) days from the date of receipt.
You also have the right to share your concerns to the Personal Data Protection Council established per the Personal Data Protection Regulatory Requirements. Click to view the Personal Data Protection Council contact details.
Key Definitions:
Personal Data: any information relating to an identified / identifiable individual, whether it relates to his or her private, professional, or public life such as the Identification Document number or address.
Processing: any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Profiling: any form of automated Processing of Personal Data evaluating the personal aspects relating to a natural person, in particular to analyze or predict aspects concerning by way of example the individual’s economic situation, personal preferences or interests, behavior, location or movements.
Sensitive Personal Data: any data or information that directly or indirectly indicates the individual’s origin, race, political opinions, religious beliefs, financial status, health, physical or mental condition, genetic data, biometric data, or criminal record.
Know Your Customer or KYC: means mandatory requirements to ensure updated information about our customers, to perform identity verification and prevention of illegal transactions through the business relationship with Arab Bank in compliance with Central Bank of Jordan KYC requirements.
Jurisdiction and Applicable Law
The Hashemite Kingdom of Jordan courts will have exclusive jurisdiction over any claim arising from, or related to, this Website or Services offered through our Website or through the reflect mobile application. Any dispute or claim arising out of or in connection with this Website or the reflect mobile application shall be governed by and construed in accordance with the Laws of the Hashemite Kingdom of Jordan.
Changes to this Notice
We reserve the right to update this Notice to reflect changes to our practices in alignment with the Personal Data Protection laws and regulations. Any updates will become effective immediately after posting the updated Notice on our website. In the event of any material changes to this Privacy Notice, we will notify you via our approved communication channels. We encourage you to review this Notice periodically.
Annex (Personal Data Processing Matrix)
| Purpose | Categories of Personal Data | Legal Basis |
| Customer onboarding and account opening, including identity verification, due diligence and regulatory checks | Personal identification details, contact details, employment and professional information, financial information, internal identifiers, due diligence | Legal Obligation, Contractual Basis |
| Provision and management of banking products and services, including account operation, transactions, service delivery and access to digital platforms (including issuing access credentials) | Personal identification details, contact details, financial and transaction data, account information, digital activity | Contractual Basis, Legal Obligation |
| Sharing Personal Data with third parties to provide services, including payment providers, service providers and intermediaries | Personal identification details, financial data, transaction data, account information | Contractual Basis, Legitimate Interest For further details, please refer to the section “Who has access to your Personal Data and to whom it may be disclosed” |
| Client relationship management, including customer service, communications, support, engagement and maintaining ongoing relationships | Personal identification details, contact details, communication records, digital activity, usage data, financial information | Contractual Basis, Legitimate Interest |
| Creditworthiness and credit bureau checks | Personal identification details, contact details, financial information, credit data, internal identifiers | Contractual Basis, Consent |
| Compliance with legal and regulatory obligations, including Central Bank of Jordan requirements on Anti-Money Laundering, Know Your Customer, sanctions screening, reporting and regulatory investigations | Personal identification details, financial data, transaction data, communication records, due diligence data, financial status data (including source of income / wealth). | Legal Obligation |
| Risk management, fraud detection and prevention of financial crime, including monitoring transactions, preventing misuse of services and protecting customers and the Bank | Personal identification details, financial data, transaction data, technical data, usage data, communication records | Legal Obligation, Security Measures |
| Security and systems protection, including preventing unauthorized access, ensuring IT security and protecting infrastructure | Technical data, usage data, identification data, communication records | Legal Obligation, Security Measures |
| Communication monitoring, including recording and reviewing calls, messages and interactions for quality assurance, security and regulatory compliance purposes | Communication records, call recordings, identification data, account information | Legal Obligation, Security Measures, and Legitimate Interest |
| Operational management and internal administration, including audits, reporting, governance, policy compliance and internal controls | Personal identification details, financial data, internal records, communication records | Legal Obligation, Legitimate Interest |
| Improving products, services and customer experience, including service development, statistical analysis, and quality assurance | Usage data, technical data, communication records, customer feedback | Legitimate Interest |
| Managing complaints, disputes and legal claims, including investigations, enforcement of rights and legal proceedings | Personal identification details, communication records, transaction data | Legal Obligation, Legitimate Interest |
| Business Continuity and Disaster Recovery | Personal identification details, financial data, internal records | Legal Obligation, Legitimate Interest |
| Insurance-related activities (where applicable), including underwriting, claims handling and sharing with relevant third parties | Personal identification details, financial data, health data (where applicable), communication records | Contractual Basis, Legal Obligation Consent (where required) such as for sharing your Personal Data with the Insurance Company |
| Accessing your camera through our mobile application to allow you to validate your identity virtually and to use our application | Selfie Image | Legal Obligation, Legitimate Interest |
| Participation in Surveys | Personal identification details and survey results | Consent Further, if we engage a third party to support us in conducting the survey, we shall collect your prior consent for your Personal Data -mainly name and phone number – sharing with the service provider. |
| Conducting Business Intelligence and Advanced Analytics | Personal identification details and financial data (in limited cases) Reflect ensures the data processed is fully anonymous as much as doable. | Legitimate Interest Advance analytics refers to tools and techniques used to analyze large amount of data to provide actionable insights. This includes for example tracking credit cards spending to identify customer interests as well as tracking campaigns’ performance. The Processing aims to provide targeted products/ services that better suit customer needs while ensuring full alignment with treating customers fairly principles. |
Revision History
| Privacy Notice Posted | July 2021 |
| Privacy Notice Updated | September 2024 |
| Privacy Notice Updated | December 2025 |
| Privacy Notice Updated | July 2026 |

