Privacy policy
Last updated: 4 October 2026
Draft for legal review. The highlighted parts must be filled with the company details before publishing.
This policy explains how [Company legal name] ("Reloop", "we"), commercial registration no. [CR number], handles personal data when the Reloop platform is used to manage delivery and return shipments, in line with the Personal Data Protection Law of the Kingdom of Saudi Arabia and its implementing regulations.
This policy is available in Arabic and English. If the two versions differ, the Arabic version prevails.
1. Who we are and how to contact us
Controller: [Company legal name], national address: [National address].
Questions and privacy requests: [Privacy email, e.g. privacy@your-domain].
2. Our role in processing data
- Store account data (user name, email and sign-in data): Reloop is the controller.
- Data of shipment recipients and return senders (the store's customers): the store is the controller. Reloop processes it on the store's behalf and only to carry out the shipment. The store is responsible for having a lawful basis to share it with us and for informing its customers.
3. Data we process
- Store accounts: name, email, password (stored with one-way hashing), sign-in times, and IP address for security.
- Shipment data: recipient or sender name, mobile number, address, city and district, national short address if provided, content description, weight and dimensions, value, and store references.
- Tracking and delivery data: shipment statuses and times, failed-delivery reasons, and proof of delivery if the carrier provides it.
- Financial data: store statements, payments and their references. We do not store payment card details.
- Technical records: request and error logs, and an audit trail of every change made in the system.
4. Why we process it
- To create shipments, hand them to the carrier and track them until delivery or return.
- To issue waybills, statements and claims, and to follow up payments.
- To manage and protect store accounts and prevent unauthorised access and misuse.
- To meet legal obligations such as keeping accounting and tax records.
Legal basis: performing the agreement with the store, legal obligations, and our legitimate interest in protecting the service. We do not use store customers' data for marketing, we do not sell any personal data, and Reloop does not send messages to store customers.
5. Who we share it with
- Carriers under contract with us: only what is needed to pick up, deliver or return the shipment.
- Technical service providers: cloud hosting (Google Cloud), and an email provider to send store account invitations and password reset links (it receives only the user's name and email).
- The in-app assistant: when enabled, customer names, mobile numbers and addresses are masked before anything is sent to the AI provider.
- Government authorities when there is a lawful request.
6. Where data is stored
The database and its backups are stored on Google Cloud in the Dammam region, inside the Kingdom of Saudi Arabia. Some service providers (such as the email provider) may have servers outside the Kingdom. Only the minimum necessary data is transferred to them, in line with the legal rules on transferring data outside the Kingdom.
7. How long we keep it
We keep shipment data and financial records for the duration of the relationship with the store, and afterwards for the period required by accounting and tax laws. Technical integration logs are deleted or archived automatically after one year. A store may ask us to delete or mask its customers' data once the purpose has ended, unless a legal obligation or an open claim prevents it.
8. How we protect it
- All connections are encrypted (HTTPS).
- Passwords are stored with one-way hashing, and repeated sign-in attempts are temporarily blocked.
- Each store sees only its own data, and staff permissions are limited by role.
- Every change in the system is recorded, and backups are tested daily.
- Integration keys are stored encrypted.
If a data breach affects you, we notify the competent authority and you within the legal deadlines.
9. Your rights
You have the right to:
- Be informed about how your data is processed.
- Access your data and obtain a copy of it.
- Correct or update your data.
- Ask for it to be destroyed once the purpose has ended, unless a legal obligation prevents it.
- Withdraw your consent where processing is based on it.
If you are a customer of one of the stores (a recipient or a return sender), you can contact the store directly or contact us and we will pass your request to the store. We answer requests within the legal deadline. If you are not satisfied with our answer, you may file a complaint with the Saudi Data and Artificial Intelligence Authority (SDAIA).
10. Changes to this policy
We may update this policy and show the date of the last update at the top of the page. If a change is material, we inform stores before it applies.