Skip to content

Publishing on the Apple App Store

What is needed to put the Alhuda Travels app (apps/mobile) on the App Store, and the answers Apple asks for. The Android side is in Android app; the iOS build commands there are the same ones used here.

Nothing on this page has been done yet. No iOS build exists, and the company is not yet enrolled with Apple.

1. What the app already does for review

Apple rule Where it stands
5.1.1(v) — an app that lets people create an account must let them delete it from inside the app Built, as a request. Me → Request account deletion (partners: More → Request account deletion) — AUD-025 … AUD-027. The person starts the deletion inside the app; the business completes it after review, within 30 days (decided 2026-10-01: nobody erases their own account on the spot). Apple accepts this: 5.1.1(v) asks that deletion can be initiated in the app, and a business may review the request first (for example to settle money held or owed). Staff accounts are made by the company and are not offered it.
4.8 — an app that offers a third-party or social login (Google, Facebook …) must also offer Sign in with Apple or an equivalent Not needed. The app and the website sign in with email or phone and a password only (auth-login); there is no Google, Facebook or other social login anywhere (checked 30 Sep 2026). If one is ever added, Sign in with Apple must be added with it.
5.1.1(i) — a privacy policy link in the app and in App Store Connect Built. Me → Privacy: what we keep opens https://alhudatravels.in/privacy, which explains deletion (section 7a). Use the same URL in App Store Connect.
3.1.1 / 3.1.3(e) — in-app purchase Not needed. The app sells travel (trips, hotels, flights) used outside the app, so Razorpay is allowed; nothing digital is sold.
2.5.4 — background location only for a clear purpose The app asks for "Always" location for Share my location on a trip (the tour leader sees the traveller). Say so in the review notes (section 7).
5.1.2 — no tracking without permission The app has no advertising, analytics or crash-reporting SDK. The Meta Pixel runs only on the public website, never in the app.

2. Apple Developer Program — as an organisation

Enrol Alhuda Pvt Ltd as an organisation, not as an individual, so the seller name on the store is the company.

  • D-U-N-S number: 581610345.
  • The legal entity name must match the D-U-N-S record exactly.
  • A company email on the company domain (@alhudatravels.in), and the website https://alhudatravels.in.
  • Fee: USD 99 a year (about ₹8,000–9,000).
  • The person enrolling needs the authority to bind the company. Apple may phone to verify.

Owner's task. Nothing in the repository can do it.

3. App Store Connect API key

EAS uploads builds with an App Store Connect API key (Users and Access → Integrations → App Store Connect API → Generate API Key, role App Manager).

  • The key is a .p8 file, downloadable once. Keep it on the release Mac only, for example ~/.appstoreconnect/AuthKey_XXXXXXXXXX.p8, readable by the release user only (chmod 600).
  • Never paste it into a chat, an issue, a commit or eas.json. Never commit it.
  • Note the Key ID and the Issuer ID (shown on the same page). They are not secret on their own but keep them with the key.
  • If the file is lost or seen by anyone else, revoke the key in App Store Connect and make a new one.

4. Build and submit (EAS)

The project already has: bundle id in.alhudatravels.app, version 0.2.0 (app.json), runtimeVersion policy appVersion, ITSAppUsesNonExemptEncryption: false, the usage texts for camera, photo library, location and notifications, and eas.json build profiles development, preview and production (appVersionSource: remote, autoIncrement on production — EAS keeps the build number).

cd apps/mobile
npx eas-cli login                                   # an admin of the Expo organization alhudatravels
npx eas-cli credentials --platform ios              # once: distribution certificate, provisioning profile, push key (APNs)
npx eas-cli build --platform ios --profile production
npx eas-cli submit --platform ios --profile production --latest   # upload to App Store Connect / TestFlight

eas.json has an empty submit.production, so the first submit asks for the Apple account and the app. To use the API key kept on the Mac instead, the release Mac's copy of eas.json gets (EAS Submit fields, Expo docs):

"submit": { "production": { "ios": {
  "ascAppId": "<the app's numeric Apple ID>",
  "ascApiKeyPath": "/Users/<release user>/.appstoreconnect/AuthKey_XXXXXXXXXX.p8",
  "ascApiKeyId": "XXXXXXXXXX",
  "ascApiKeyIssuerId": "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx"
} } }

These are ids and a path, not the key; the .p8 file itself never enters the repository. Keep the path out of a commit if the release user's name should stay private.

Push notifications on iPhone: push-send sends through Firebase Cloud Messaging, so the APNs key that eas credentials creates must also be uploaded to the Firebase project (Project settings → Cloud Messaging → Apple app configuration), and the iOS app added to that Firebase project. Until then, an iPhone receives no push.

Over-the-air updates (expo-updates, channel production) work on iPhone as on Android for JavaScript changes; anything that changes native code or app.json permissions needs a new build and a new review.

5. TestFlight

  1. After submit, the build appears in App Store Connect → TestFlight within 10–30 minutes.
  2. Internal testing: add office staff by their Apple ID email (up to 100); no review.
  3. External testing (people outside the team): needs a short beta review; use the same review notes as below.
  4. Test on a real iPhone: sign in as a traveller, a partner and staff; scan a passport; switch location sharing on and off (Always and While using); receive a notification; pay online on a test booking; delete a test account (section 7).

6. The listing

Field What to enter
Name Alhuda Travels
Subtitle (30 characters) Hajj, Umrah and tours
Category Travel (secondary: none)
Description What a traveller and a partner can do — trips, programme, documents, payments, requests, the tour leader. Plain; no prices or claims that change.
Keywords hajj, umrah, ziyarat, srinagar, kashmir, tour, pilgrimage
Support URL https://alhudatravels.in (a contact page with the office phone and email)
Privacy policy URL https://alhudatravels.in/privacy
Copyright 2026 Alhuda Pvt Ltd
Screenshots 6.9" and 6.5" iPhone (portrait): My trip, Programme, Documents, Book this trip, Me. Taken from the demo account — never a real customer.
Age rating Answer "None" to every content question → 4+ expected. The app does not offer unrestricted web browsing (the in-app browser opens only the company's own pages and Razorpay), gambling, contests or user-to-user chat.
Price Free

7. App Review information

Demo accounts. Apple needs a login that works. The office creates them in production with invented details only — no real person's name, phone, passport or photo:

Account Set-up
Demo traveller Name "Demo Reviewer", an email on the company domain the office can read (e.g. appreview@alhudatravels.in), an invented phone; a demo departure (e.g. "App Review Umrah", dates a few months ahead, not on sale on the website) with one booking, fully paid, with an invented passport number. Shows My trip, Programme, Documents.
Demo traveller (for deletion) A second traveller with no booking, so the reviewer can send a deletion request. The office approves it after the review. Recreate it after each review.
Demo partner (optional) An approved partner "Demo Agency" with invented PAN/GSTIN-shaped values, if the reviewer should see the partner stack.

Two-step verification must be off on the demo accounts. Change their passwords after each review.

Notes for the reviewer (paste into App Review Information → Notes):

  • To test account deletion, sign in with the second demo traveller: Me → Request account deletion, type DELETE and the password. The request goes to our office, which reviews every deletion request (to settle any trip or money first) and completes it within 30 days; the app says so. The first account has a trip still to come, so its request also lists that trip.
  • Location: "Share my location" sends the traveller's position to their tour leader during a trip only while the switch is on; background ("Always") is used so the tour leader can find a traveller whose phone is in a pocket. Nothing is collected when the switch is off.
  • Camera: photographs a passport so its details can be read and filed with the booking.
  • Payments are for travel services used outside the app, through Razorpay.

8. App Privacy ("nutrition label")

Derived from the code on 30 Sep 2026. Tracking: No for every item — nothing is shared with data brokers or used for advertising. Every item below is linked to the user. Re-check this table whenever a screen starts collecting something new.

Apple data type Collected? What in the app Purpose
Contact info — name, email address, phone number, physical address Yes Sign-up, My details, the partner's agency App functionality
Location — precise location Yes Share my location during a trip (expo-location, foreground and background), a tour leader's check-in App functionality
Identifiers — user ID Yes The account id App functionality
Identifiers — device ID Yes The device push token (push_subscriptions) App functionality
Photos or videos Yes A passport photo taken or picked for scanning (expo-camera, expo-image-picker); documents uploaded App functionality
Purchases — purchase history Yes Bookings and payments App functionality
Financial info — payment info No Card and UPI details are entered on Razorpay's page and never reach the company's servers; only Razorpay's payment id is kept —
User content — other user content; customer support Yes Requests to the office, messages, uploaded documents App functionality, customer support
Other data Yes Date of birth, gender, nationality, passport and identity numbers; battery level sent with a shared position App functionality
Sensitive info Owner to decide A Hajj or Umrah booking can reveal a religious belief. The cautious answer is Yes (App functionality). App functionality
Health and fitness, browsing history, search history, contacts, audio, usage data, diagnostics, crash data No No analytics, crash or advertising SDK in the app —

Service providers that process data for the company (declared as the company's own collection, not as sharing): Supabase (database and sign-in), Google Workspace (the Shared Drive for documents, Firebase for push), Resend (email), Meta (WhatsApp messages), Razorpay (payments), and the passport reader — extract-passport sends the passport image to OpenAI, Anthropic or OCR.space, whichever is configured. The privacy page names Meta (the website pixel) and "payment processors" but not these providers by name — owner to review.

Account deletion in App Store Connect (App Privacy → "Account deletion"): answer that the app offers it, in-app, at Me → Request account deletion, as a request the company completes within 30 days; the web page is https://alhudatravels.in/privacy#delete-account. Google Play asks the same in Data safety → Data deletion: the app lets people request deletion in the app, and the web link above works without the app; a request the business completes is accepted.

9. Export compliance

The app uses only the encryption built into iOS and HTTPS (TLS) to talk to Supabase, Razorpay and the website. That is exempt: ITSAppUsesNonExemptEncryption is false in app.json, so App Store Connect does not ask on each build. No French encryption declaration is needed.

10. Checklist

  • [ ] Apple Developer Program, organisation, D-U-N-S 581610345 (owner)
  • [ ] App Store Connect app record: bundle id in.alhudatravels.app, SKU alhuda-travels-ios
  • [ ] App Store Connect API key (.p8) on the release Mac only
  • [ ] eas credentials for iOS; APNs key uploaded to Firebase; iOS app added to Firebase
  • [ ] account-delete function and migration 20261004090000 deployed (Account deletion)
  • [ ] Production build, TestFlight, tested on an iPhone
  • [ ] Demo accounts created in production with invented details
  • [ ] Listing, screenshots from the demo account, age rating, App Privacy answers
  • [ ] Privacy page reviewed by the owner (service providers, deletion section)
  • [ ] Submit for review