كيف عرفتناKaif Araftna
سياسة الخصوصية

سياسة الخصوصية لتطبيق «كيف عرفتنا»

توضح هذه السياسة البيانات التي يعالجها تطبيق «كيف عرفتنا» لمتاجر سلة، ولماذا نعالجها، وأين تُحفظ، ومتى تُحذف، وما حقوقك تجاهها.

باختصار

  • لا نخزّن اسم العميل ولا جواله ولا بريده ولا عنوانه ولا عنوان IP الخاص به.
  • نحتفظ بمعرّف العميل في سلة فقط (رقم تعريفي داخلي، وليس رقم جواله): لنتحقق أن الإجابة من صاحب الطلب ولنربطها بطلبه، ولنعرف هل العميل جديد أو عائد.
  • الإجابة على السؤال اختيارية، ويمكن للعميل إغلاق البطاقة.
  • رموز الربط مع سلة مشفّرة بخوارزمية AES-256-GCM.
  • عند حذف التطبيق من المتجر نحذف جميع بيانات المتجر من قاعدة بياناتنا مباشرة.
  • لا نبيع البيانات، ولا نستخدمها للإعلانات، ولا نضع ملفات تعريف ارتباط (cookies) أو أدوات تتبّع من طرف ثالث. البطاقة تستمع لحدث «اكتمال الطلب» في سلة داخل صفحة الشكر لقراءة رقم الطلب فقط، ولا ترسل منه أي بيانات لطرف ثالث.

1.من نحن ونطاق السياسة

«كيف عرفتنا» (Kaif Araftna) تطبيق لمتاجر منصة سلة. يعرض على عملاء المتجر بعد إتمام الطلب بطاقة صغيرة في صفحة الشكر تسأل «كيف عرفت عن متجرنا؟»، ويربط الإجابة بالطلب، ويجمعها مع كوبونات المؤثرين وروابط التسويق بالعمولة وروابط UTM، ليعرض للتاجر مصدر الطلبات، وعائد كل مؤثر، وطلبات وإيرادات كل قناة داخل لوحة تحكم سلة.

تنطبق هذه السياسة على بيانات التاجر (صاحب المتجر) وعلى بيانات عملاء المتجر التي نعالجها من خلال التطبيق فقط. ولا تنطبق على طريقة تعامل سلة أو المتجر نفسه مع البيانات، فلكلٍّ منهما سياسته الخاصة.

2.دور كل طرف

  • التاجر هو المتحكم في بيانات متجره وبيانات عملائه: هو من يثبّت التطبيق ويحدد إعداداته والمؤثرين والحملات.
  • نحن المعالج: نعالج هذه البيانات نيابة عن التاجر ووفق تعليماته، ولغرض تقديم خدمة التطبيق له فقط.
  • أما بيانات حساب التاجر اللازمة لتشغيل الخدمة (مثل اسم المتجر وحالة الاشتراك) فنعالجها لتقديم الخدمة التي اشترك فيها.

3.البيانات التي نعالجها

بيانات المتجر والاشتراك

المصدر: سلة، عند التثبيت وعند تحديث الاشتراك.

  • رقم المتجر واسمه واسم المستخدم ونطاقه.
  • باقة المتجر في سلة، والعملة، ونوع المتجر (تجريبي أو فعلي).
  • البريد الإلكتروني للمتجر كما تعيده سلة (لإرسال الملخص الأسبوعي إذا فعّلته).
  • الصلاحيات الممنوحة للتطبيق.
  • حالة اشتراكك في التطبيق (الباقة، التجربة، تواريخ البداية والانتهاء) وسجل أحداث الاشتراك التي ترسلها سلة.

رموز الربط مع سلة

المصدر: سلة، عند تفويض التطبيق.

  • رمز الوصول ورمز التحديث (access / refresh tokens) وتاريخ انتهائهما والصلاحيات المرتبطة بهما.
  • تُحفظ مشفّرة دائمًا، وتُستخدم فقط لقراءة طلبات متجرك وبيانات التسويق فيه، ومعلومات المتجر (مثل اسمه وبريده)، وحالة اشتراكك في التطبيق من سلة.

بيانات الطلبات

المصدر: إشعارات سلة (Webhooks)، واستيراد طلبات آخر 90 يومًا عند التثبيت، ومزامنة ليلية لآخر 3 أيام.

  • رقم الطلب الداخلي ورقمه المرجعي، وحالته (بما فيها الإلغاء والاسترجاع)، وتاريخه.
  • مبلغ الطلب وعملته، وكود الكوبون المستخدم.
  • معرّف العميل في سلة (رقم تعريفي داخلي، وليس رقم جواله)، ويُستخدم لمعرفة هل العميل جديد أو عائد.
  • مصدر الطلب ونوع الجهاز كما ترسلهما سلة، وقيم UTM وبيانات الحملة المرتبطة بالطلب.

إجابات الاستبيان

المصدر: عميل المتجر في صفحة الشكر، باختياره.

  • القناة التي اختارها (مثل سناب شات أو قوقل أو مشهور/مؤثر).
  • المؤثر الذي اختاره من القائمة (اختياري).
  • نص قصير اختياري عند اختيار «أخرى»، بحد أقصى 60 حرفًا بعد تنظيفه.
  • معرّف العميل في سلة (للعميل المسجّل) للتحقق أنه صاحب الطلب، ولغة البطاقة، ووقت الإجابة.
  • إذا وصلت الإجابة قبل وصول الطلب نفسه من سلة، تُحفظ مؤقتًا حتى 3 ساعات بانتظار الطلب.

بيانات التسويق من متجرك

المصدر: قسم التسويق في متجرك على سلة.

  • الكوبونات: الكود، والحالة، واسم المسوّق كما أدخلته في سلة، والحملة المرتبطة، وتاريخ الانتهاء، وإحصاءات الاستخدام والمبيعات.
  • التسويق بالعمولة: الكود، والعنوان، واسم المسوّق، والحملة المرتبطة، والحالة، والإحصاءات.
  • لا نخزّن البريد الإلكتروني للمسوّق.

سجل المؤثرين والحملات

المصدر: التاجر، من لوحة التطبيق (باقة النمو فما فوق).

  • اسم المؤثر ومعرّفه ومنصته ورابط التسويق وأكواده وملاحظاتك.
  • الحملات: وقت نشر الإعلان وتكلفته وملاحظاتك.
  • ملاحظة: اسم المؤثر النشط ومعرّفه ومنصته تظهر لعملاء متجرك داخل البطاقة ليبحثوا عنه ويختاروه.

الإعدادات والاستخدام

المصدر: التاجر، والتطبيق نفسه.

  • نص السؤال بالعربي والإنجليزي، والخيارات وترتيبها، والخيارات الخاصة.
  • مدة نسبة الطلب لآخر حملة (افتراضيًا 72 ساعة).
  • إعدادات الملخص الأسبوعي، وبريد بديل إن أدخلته.
  • عدد الردود في الشهر لمقارنته بحد الباقة.

بيانات تشغيلية

المصدر: تشغيل التطبيق.

  • سجل إشعارات سلة لمنع التكرار: رقم المتجر، واسم الحدث، وبصمة SHA-256 لمحتوى الإشعار، وحالته.
  • سجل مهام المزامنة: أرقام تعريفية وأعداد ورموز أخطاء مختصرة.
  • سجلات التطبيق: أرقام تعريفية وأسماء أحداث فقط، مع إخفاء تلقائي لأي حقل حساس.

في متصفح العميل

التخزين المحلي (localStorage) في متصفح عميل المتجر.

  • مفتاح صغير بصيغة kaif:done:<store>:<order> قيمته «1»، حتى لا تظهر البطاقة مرة ثانية لنفس الطلب على نفس الجهاز.
  • لا نستخدم ملفات تعريف الارتباط (cookies)، ولا ترسل البطاقة أي ملفات تعريف ارتباط مع طلباتها.
  • تسجّل البطاقة مستمعًا في واجهة التحليلات الخاصة بسلة داخل المتجر (باسم KaifAraftnaTracker) فقط لقراءة رقم الطلب من حدث «اكتمال الطلب» (Order Completed) في صفحة الشكر. تتجاهل أي حدث آخر مثل مشاهدات الصفحات، ولا ترسل منه أي بيانات أخرى.

جلسة لوحة التحكم

عند فتح التطبيق من لوحة تحكم سلة.

  • نتحقق من هوية التاجر عبر سلة مباشرة، دون حساب أو كلمة مرور منفصلة.
  • الجلسة موقّعة وتحمل رقم المتجر ورقم المستخدم فقط، وتبقى في ذاكرة الصفحة، وصلاحيتها ساعة واحدة كحد أقصى.

4.ما لا نجمعه

  • اسم العميل، أو رقم جواله، أو بريده الإلكتروني، أو عنوانه.
  • عنوان IP أو معرّف المتصفح (User Agent): يُستخدم عنوان IP لحظيًا فقط لتحديد عدد الطلبات المسموح بها وحماية الخدمة من إساءة الاستخدام، ولا يُحفظ في قاعدة بياناتنا ولا في سجلات التطبيق. وقد تحتفظ سجلات منصة Cloudflare ببيانات الاتصال التقنية (ومنها عنوان IP) لفترة قصيرة ضمن تشغيلها للخدمة.
  • بيانات الدفع، أو منتجات الطلب ومحتويات السلة.
  • أي أدوات تحليلات أو إعلانات أو تتبّع من طرف ثالث في البطاقة أو في لوحة التطبيق.

وتُقلَّص إشعارات سلة عند استقبالها إلى الحقول اللازمة فقط قبل أي معالجة لاحقة.

5.أغراض المعالجة

  • عرض بطاقة السؤال في صفحة الشكر، وحفظ الإجابة وربطها بطلبها.
  • نسبة كل طلب إلى قناة واحدة بأولوية ثابتة (إجابة العميل، ثم كوبون المؤثر، ثم رابط المسوّق، ثم روابط UTM)، وإعداد التقارير: طلبات وإيرادات كل قناة، وعائد كل مؤثر.
  • معرفة هل العميل جديد أو عائد، باستخدام معرّفه في سلة.
  • تصدير الطلبات مع مصدر كل طلب إلى ملف CSV (الباقة الاحترافية).
  • إدارة الاشتراك والتجربة المجانية وحد الردود الشهري لكل باقة.
  • حماية الخدمة: التحقق من توقيع إشعارات سلة، وتحديد عدد الطلبات، والتحقق من أن المجيب هو صاحب الطلب.
  • الرد على طلبات الدعم عند تواصلك معنا.
  • إرسال ملخص أسبوعي بالبريد للتاجر، فقط إذا فعّله من إعدادات التطبيق.

لا نستخدم البيانات لأي غرض آخر، ولا نبيعها، ولا نؤجرها، ولا نستخدمها لعرض الإعلانات أو لبناء ملفات تعريفية عن العملاء.

6.الأساس النظامي

  • بيانات عملاء المتجر: نعالجها نيابة عن التاجر ووفق تعليماته. والتاجر، بصفته المتحكم، مسؤول عن الأساس النظامي لجمعها وعن إبلاغ عملائه، مثلًا بذكر ذلك في سياسة الخصوصية الخاصة بمتجره. الإجابة على السؤال اختيارية تمامًا.
  • بيانات التاجر: نعالجها لتنفيذ الخدمة التي اشترك فيها، ولمصلحتنا المشروعة في تأمين الخدمة ومنع إساءة استخدامها.
  • صممنا معالجة البيانات في التطبيق لتتوافق مع مبادئ نظام حماية البيانات الشخصية في المملكة العربية السعودية ولوائحه التنفيذية، ومنها تقليل البيانات وتحديد الغرض وحذف البيانات عند انتهاء الحاجة إليها.

7.مشاركة البيانات والمعالجون الفرعيون

لا نشارك البيانات إلا مع الجهات التالية، وبالقدر اللازم لتشغيل الخدمة:

  • Cloudflare, Inc.: استضافة التطبيق وتشغيله (Workers)، وقاعدة البيانات (D1)، وطوابير المعالجة، ومهام الخلفية (Workflows)، وسجلات التشغيل، وإرسال الملخص الأسبوعي بالبريد (Cloudflare Email Service) لمن فعّله، ويصلها عندها بريد المستلم ومحتوى الملخص (أرقام مجمّعة عن متجرك).
  • سلة: المنصة التي يعمل عليها التطبيق؛ نستقبل منها البيانات ونقرأها عبر واجهاتها الرسمية، وتُعرض لوحة التطبيق داخل لوحة تحكم سلة.
  • الجهات الرسمية: إذا ألزمنا بذلك نظام أو أمر صادر من جهة مختصة.

8.مكان حفظ البيانات

تُحفظ قاعدة بيانات التطبيق لدى Cloudflare في منطقة غرب أوروبا، وتمر الطلبات عبر شبكة Cloudflare العالمية. لذلك قد تُعالج البيانات خارج المملكة العربية السعودية، وذلك لغرض تشغيل الخدمة فقط وبالحد الأدنى من البيانات الموضح أعلاه.

9.أمن البيانات

  • التحقق من توقيع كل إشعار يصل من سلة (HMAC-SHA256) قبل قبوله، ورفض غير الموقّع منها وتجاهل المكرر.
  • تشفير رموز الربط مع سلة بخوارزمية AES-256-GCM، مع ربط كل رمز مشفّر بمتجره.
  • عزل بيانات كل متجر: كل استعلام مقيّد برقم المتجر، ولوحة التطبيق تأخذ رقم المتجر من جلسة موقّعة تم التحقق منها عبر سلة فقط.
  • الاتصال مشفّر عبر HTTPS، وتحديد عدد الطلبات على الواجهات العامة للبطاقة.
  • سجلات التطبيق لا تحتوي على رموز أو بيانات شخصية، مع إخفاء تلقائي للحقول الحساسة.

لا توجد وسيلة نقل أو تخزين آمنة بشكل مطلق، لكننا نطبق هذه الإجراءات ونراجعها باستمرار. وفي حال وقوع حادثة تؤثر على بيانات متجرك، سنبلغك دون تأخير وبما يتوافق مع الأنظمة المعمول بها.

10.مدة الاحتفاظ والحذف

  • نحتفظ ببيانات المتجر طوال فترة تثبيت التطبيق.
  • عند حذف التطبيق من المتجر نحذف مباشرة جميع بيانات المتجر من كل جداول قاعدة البيانات: الطلبات، والإجابات، وسجل المؤثرين والحملات، والإعدادات، وبيانات التسويق، ورموز الربط، وسجلات الاشتراك والمهام. ونوقف مهام المزامنة الجارية، ونمسح رموز الربط من الخدمة المسؤولة عن تحديثها.
  • نُبقي بعد الحذف علامة تقنية واحدة فقط (رقم المتجر ووقت الحذف) لنتجاهل أي إشعارات متأخرة من سلة، وتُزال عند إعادة التثبيت.
  • الإجابات المؤقتة التي لم يصل طلبها تُحذف بعد 3 ساعات.
  • سجل منع تكرار الإشعارات يُحذف بعد 30 يومًا، وسجل مهام المزامنة بعد 90 يومًا، وكلاهما يُحذف أيضًا عند حذف التطبيق.
  • يمكنك حذف أي مؤثر أو حملة من لوحة التطبيق في أي وقت.

بقايا مؤقتة لدى مزود الاستضافة: تحتفظ خدمة Cloudflare Workflows بنتائج خطوات مهام الاستيراد المنتهية لمدة محدودة (حتى 30 يومًا) ولا تحذفها عند إيقاف المهمة. لذلك صممنا هذه النتائج لتحمل أرقامًا تعريفية وأعدادًا فقط (مثل أرقام الطلبات والكوبونات وعدد الصفحات)، دون أكواد كوبونات أو أسماء مسوّقين أو بيانات طلبات. كما قد تبقى النسخ الاحتياطية التلقائية لقاعدة البيانات وسجلات التشغيل لدى Cloudflare لمدة محدودة (حتى 30 يومًا) ثم تُحذف تلقائيًا.

ولطلب حذف بيانات متجرك دون حذف التطبيق، راسلنا على info@saudi-menu.com.

11.حقوق عملاء المتجر

  • الإجابة اختيارية، ويمكنك إغلاق البطاقة دون الإجابة.
  • لطلب الاطلاع على إجابتك أو تصحيحها أو حذفها، تواصل مع المتجر الذي اشتريت منه بصفته المتحكم في بياناتك، أو راسلنا مع ذكر اسم المتجر ورقم الطلب، وسننسّق مع المتجر لتنفيذ طلبك. ولأننا لا نخزّن اسمك أو وسائل التواصل معك، نحتاج رقم الطلب للوصول إلى الإجابة.
  • يمكنك مسح التخزين المحلي لمتصفحك في أي وقت لإزالة المفتاح الذي يمنع ظهور البطاقة مرة ثانية.
  • يحق لك تقديم شكوى إلى الجهة المختصة بحماية البيانات الشخصية في المملكة العربية السعودية (الهيئة السعودية للبيانات والذكاء الاصطناعي «سدايا»).

12.حقوق التاجر

  • الاطلاع على بيانات متجرك وتقاريرها في لوحة التطبيق، وتصديرها إلى CSV في الباقة الاحترافية.
  • تعديل إعدادات السؤال والخيارات، وتعديل أو حذف المؤثرين والحملات.
  • حذف جميع بيانات متجرك بحذف التطبيق، أو بمراسلتنا.
  • طلب نسخة من بياناتك أو الاستفسار عن معالجتها عبر البريد.

13.التعديلات على السياسة

قد نحدّث هذه السياسة عند تغيّر التطبيق أو الأنظمة. سننشر أي تحديث على هذه الصفحة مع تعديل تاريخ السريان أعلاه.

14.التواصل

لأي سؤال أو طلب يتعلق بالخصوصية: info@saudi-menu.com. يُفضّل ذكر رقم متجرك (أو اسم المتجر ورقم الطلب إذا كنت عميلًا).


Privacy Policy

Kaif Araftna Privacy Policy

This policy explains what data the Kaif Araftna app for Salla stores processes, why, where it is kept, when it is deleted, and your rights over it. The Arabic version above is the primary version.

In short

  • We never store the buyer’s name, phone, email, address or IP address.
  • We keep only the buyer’s Salla customer ID (an internal ID, not a phone number): to check the answer comes from the order’s owner, to link it to the order, and to tell new from returning customers.
  • Answering is optional, and the buyer can close the card.
  • Salla access tokens are encrypted with AES-256-GCM.
  • Uninstalling the app deletes all of the store’s data from our database right away.
  • We do not sell data, use it for advertising, or set cookies or third-party trackers. On the thank-you page the card listens to Salla’s “Order Completed” event only to read the order number, and sends nothing from it to any third party.

1.Who we are and scope

Kaif Araftna («كيف عرفتنا») is an app for stores on the Salla platform. After checkout it shows buyers a small card on the thank-you page asking “How did you hear about us?”, links the answer to the order, and combines it with influencer coupons, affiliate links and UTM links, so the merchant can see where orders came from, the return of each influencer, and the orders and revenue of each channel inside the Salla dashboard.

This policy covers merchant data and shopper data that we process through the app only. It does not cover how Salla or the store itself handles data; each has its own policy.

2.Roles

  • The merchant is the controller of the store’s data and its shoppers’ data: the merchant installs the app and sets its settings, influencers and campaigns.
  • We are the processor: we process that data on the merchant’s behalf, on the merchant’s instructions, and only to provide the app’s service.
  • Merchant account data needed to run the service (such as the store name and subscription status) is processed to provide the service the merchant subscribed to.

3.Data we process

Store and subscription data

Source: Salla, on install and on subscription updates.

  • Store id, name, username and domain.
  • The store’s Salla plan, currency and store type (demo or live).
  • The store email address as returned by Salla (used to send the weekly digest if you turn it on).
  • The permissions granted to the app.
  • Your app subscription status (plan, trial, start and end dates) and the subscription events Salla sends.

Salla connection tokens

Source: Salla, when the app is authorized.

  • Access and refresh tokens, their expiry and granted scopes.
  • Always stored encrypted, and used only to read your store’s orders, marketing data, store information (such as its name and email) and your app subscription status from Salla.

Order data

Source: Salla webhooks, an import of the last 90 days of orders on install, and a nightly sync of the last 3 days.

  • Internal order id and reference number, status (including canceled and refunded) and date.
  • Order amount and currency, and the coupon code used.
  • The Salla customer ID (an internal ID, not a phone number), used to tell whether the buyer is new or returning.
  • Order source and device as sent by Salla, UTM values and campaign data attached to the order.

Survey answers

Source: the buyer on the thank-you page, by choice.

  • The chosen channel (for example Snapchat, Google or Influencer).
  • The influencer picked from the list (optional).
  • Optional short text when “Other” is chosen, at most 60 characters after sanitizing.
  • The Salla customer ID (for logged-in buyers) to check they own the order, card language and answer time.
  • If an answer arrives before Salla delivers the order itself, it is held for up to 3 hours waiting for the order.

Your store’s marketing data

Source: the Marketing section of your Salla store.

  • Coupons: code, status, marketer name as entered in Salla, linked campaign, expiry date, usage and sales statistics.
  • Affiliate marketing: code, title, marketer name, linked campaign, status and statistics.
  • We do not store marketer email addresses.

Influencer and campaign ledger

Source: the merchant, in the app dashboard (Growth and above).

  • Influencer name, handle, platform, affiliate link, codes and your notes.
  • Campaigns: air time, fee and your notes.
  • Note: an active influencer’s name, handle and platform are shown to your buyers inside the card so they can search for and pick them.

Settings and usage

Source: the merchant and the app itself.

  • Question text in Arabic and English, options and their order, and custom options.
  • The campaign crediting window (72 hours by default).
  • Weekly digest settings and an alternative email if you enter one.
  • The monthly response count, compared with the plan limit.

Operational data

Source: running the app.

  • Webhook de-duplication log: store id, event name, a SHA-256 fingerprint of the delivery, and its status.
  • Sync job log: ids, counts and short error codes.
  • App logs: ids and event names only, with sensitive fields redacted automatically.

In the buyer’s browser

Local storage (localStorage) in the buyer’s browser.

  • A small key kaif:done:<store>:<order> with the value “1”, so the card does not show again for the same order on the same device.
  • We do not use cookies, and the card sends no cookies with its requests.
  • The card registers a listener with Salla’s storefront analytics interface (named KaifAraftnaTracker) only to read the order number from the “Order Completed” event on the thank-you page. It ignores every other event, such as page views, and sends nothing else.

Dashboard session

When the app is opened from the Salla dashboard.

  • We verify the merchant directly with Salla, with no separate account or password.
  • The session is signed, carries only the store id and user id, lives in page memory, and lasts one hour at most.

4.What we do not collect

  • The buyer’s name, phone number, email address or postal address.
  • IP address or browser user agent: the IP address is used momentarily only to rate-limit requests and protect the service from abuse; it is not saved in our database or in the app’s logs. Cloudflare’s platform logs may keep technical connection data (including the IP address) for a short time as part of running the service.
  • Payment details, order items or cart contents.
  • Any third-party analytics, advertising or tracking tools in the card or the app dashboard.

Salla webhooks are reduced to the fields we need as soon as they are received, before any further processing.

5.Purposes

  • Showing the question card on the thank-you page, and saving the answer linked to its order.
  • Crediting each order to one channel by a fixed priority (the buyer’s answer, then the influencer coupon, then the affiliate link, then UTM links), and building the reports: orders and revenue per channel, and the return per influencer.
  • Telling new from returning customers, using their Salla customer ID.
  • Exporting orders with their source to a CSV file (Pro plan).
  • Managing the subscription, the free trial and each plan’s monthly response limit.
  • Protecting the service: verifying Salla webhook signatures, rate limiting, and checking that the person answering owns the order.
  • Answering support requests when you contact us.
  • Sending the merchant a weekly email digest, only if they turn it on in the app settings.

We do not use the data for any other purpose, and we do not sell it, rent it, use it to show ads, or build profiles of buyers.

6.Legal basis

  • Shopper data: processed on the merchant’s behalf and instructions. The merchant, as controller, is responsible for the legal basis for collecting it and for informing its buyers, for example in the store’s own privacy policy. Answering the question is entirely optional.
  • Merchant data: processed to deliver the service the merchant subscribed to, and for our legitimate interest in securing the service and preventing abuse.
  • We designed the app’s processing to follow the principles of the Saudi Personal Data Protection Law (PDPL) and its implementing regulations, including data minimization, purpose limitation and deleting data once it is no longer needed.

7.Sharing and sub-processors

We share data only with the following, and only as needed to run the service:

  • Cloudflare, Inc.: hosting and running the app (Workers), the database (D1), processing queues, background jobs (Workflows), server logs, and sending the weekly email digest (Cloudflare Email Service) to merchants who turn it on, in which case it receives the recipient email and the digest content (aggregated figures about your store).
  • Salla: the platform the app runs on; we receive and read data through its official interfaces, and the app dashboard is shown inside the Salla dashboard.
  • Authorities: when required by law or by an order from a competent authority.

8.Where data is kept

The app’s database is hosted by Cloudflare in the Western Europe region, and requests pass through Cloudflare’s global network. Data may therefore be processed outside the Kingdom of Saudi Arabia, only to run the service and limited to the data described above.

9.Security

  • Every webhook from Salla is signature-checked (HMAC-SHA256) before it is accepted; unsigned deliveries are rejected and duplicates are ignored.
  • Salla connection tokens are encrypted with AES-256-GCM, each bound to its store.
  • Per-store isolation: every query is scoped to the store id, and the dashboard takes the store id only from a signed session verified through Salla.
  • All traffic is encrypted over HTTPS, and the card’s public endpoints are rate limited.
  • App logs contain no tokens or personal data, and sensitive fields are redacted automatically.

No method of transmission or storage is perfectly secure, but we apply these measures and keep reviewing them. If an incident affects your store’s data, we will notify you without undue delay and as required by applicable law.

10.Retention and deletion

  • We keep store data for as long as the app is installed.
  • When the app is uninstalled, we immediately delete all of the store’s data from every database table: orders, answers, the influencer and campaign ledger, settings, marketing data, connection tokens, and subscription and job logs. We also stop running sync jobs and clear the tokens from the service that refreshes them.
  • After deletion we keep a single technical marker (the store id and the uninstall time) so late webhooks from Salla are ignored; it is removed if the app is reinstalled.
  • Held answers whose order never arrives are deleted after 3 hours.
  • The webhook de-duplication log is deleted after 30 days and the sync job log after 90 days; both are also deleted on uninstall.
  • You can delete any influencer or campaign from the app dashboard at any time.

Short-lived copies at the hosting provider: Cloudflare Workflows keeps the step results of finished import jobs for a limited time (up to 30 days) and does not delete them when a job is stopped. We therefore designed those results to carry only ids and counts (such as order and coupon ids and page counts), never coupon codes, marketer names or order data. Automatic database backups and server logs at Cloudflare may also remain for a limited time (up to 30 days) before they are deleted automatically.

To have your store’s data deleted without uninstalling, email info@saudi-menu.com.

11.Shopper rights

  • Answering is optional, and you can close the card without answering.
  • To access, correct or delete your answer, contact the store you bought from, as the controller of your data, or email us with the store name and order number and we will coordinate with the store. Because we do not store your name or contact details, we need the order number to find the answer.
  • You can clear your browser’s local storage at any time to remove the key that stops the card from showing again.
  • You may lodge a complaint with the Saudi data protection authority, the Saudi Data and AI Authority (SDAIA).

12.Merchant rights

  • View your store’s data and reports in the app dashboard, and export them to CSV on the Pro plan.
  • Change the question and options, and edit or delete influencers and campaigns.
  • Delete all of your store’s data by uninstalling the app, or by emailing us.
  • Request a copy of your data or ask how it is processed by email.

13.Changes to this policy

We may update this policy when the app or the law changes. Any update will be posted on this page with a new effective date.

14.Contact

For any privacy question or request: info@saudi-menu.com. Please include your store ID (or, if you are a buyer, the store name and order number).