Privacy Policy

Effective July 30, 2026

The Arabic version of this document is the governing text. This translation is provided for convenience, and the Arabic prevails in case of any conflict.

1. Who we are and the capacity we act in#

Uqail (the “Platform”) is a platform that lets merchants build and run an online store. This policy sets out the personal data the Platform processes, the purposes it is processed for, the legal basis for each purpose, the parties it is disclosed to, where it is stored and for how long, and the rights of data subjects and how to exercise them.

The Platform processes personal data in two distinct capacities, and the difference affects how rights are exercised. It is the Controller of data about merchants, their representatives, and their staff, because it determines the purposes and means of that processing. It is a Processor of data about a merchant's own customers, which reaches the Platform because the merchant runs their store on it, because the merchant determines the purposes and means of that processing and the Platform acts on the merchant's instructions.

A shopper asking about their personal data should therefore begin with the store they bought from, which is the Controller of that data.

2. What this policy covers#

This policy applies to the Uqail platform: the studio where a merchant builds and manages a store, the storefronts the Platform generates and hosts, and its websites. It does not apply to the independent practices of any merchant who uses the Platform, or to those of any third party it links to.

3. Personal data we collect#

Personal data is collected directly from the data subject on account creation and through use of the Platform, and indirectly from a merchant where the merchant enters their customers' data or where that data arises from a customer's dealings with the merchant's store.

First, data about merchants, their representatives, and their staff, processed by the Platform as Controller.

  • Account data: name, email address, phone number, password credentials, and preferred language.
  • Business data: store name, commercial registration details, tax registration, and business address.
  • Verification data: the identity and business documents required to activate payments, including national identity verification where the payment provider requires it. The Platform passes these to the payment provider and keeps only the record that a document was submitted and its status, never the document itself.
  • Billing data: subscription plan, invoices, and payment status. Card details are handled by the payment provider and never reach the Platform's systems.
  • Support data: messages sent to the Platform, including anything typed into the in-product support assistant, and the conversation history attached to them.
  • Technical data: IP address, browser and device information, and log records of actions taken in the studio.

Second, data about a merchant's customers, processed by the Platform as Processor on that merchant's behalf and on their instructions.

  • Order data: name, contact details, delivery address, order contents, and order status.
  • Payment status: whether a payment succeeded or failed. Card details are handled by the payment provider and never reach the Platform's systems.
  • Technical data: IP address, device information, and storefront usage records.

4. Purposes of processing#

The Platform processes personal data for the following purposes and no others:

  • Operating the Platform: creating and running the store, processing orders, and generating storefronts.
  • Activating and operating payments, which requires passing verification data to the payment provider.
  • Issuing invoices and keeping the accounting records the law requires.
  • Supporting merchants, whether through the in-product assistant or by a reply from a member of staff.
  • Keeping the Platform secure, detecting abuse, and investigating incidents.
  • Improving the Platform, using aggregated usage data rather than the content of any store.
  • Sending service messages about the account. Marketing email is separate, and a data subject may unsubscribe from it at any time without affecting service messages.

The Platform does not sell personal data, does not use a merchant's customer data to market its own products to those customers, and does not make automated decisions that produce a legal effect for a data subject.

The Personal Data Protection Law requires every processing activity to rest on a legal basis, and requires the data subject to be informed of it. The basis the Platform relies on for each purpose is as follows:

  • Running the account, the store, order processing, and support: performance of an agreement to which the data subject is a party, namely the Terms of Service.
  • Verifying a merchant's identity and business ahead of payment activation: a legal obligation arising from anti-money-laundering law and the regulatory requirements of the licensed payment provider.
  • Issuing invoices and keeping accounting and tax records: a legal obligation.
  • Securing the Platform, detecting abuse, and investigating incidents: the Platform's legitimate interests, following a legitimate interests assessment confirming that the processing does not prejudice the rights of data subjects and goes no further than necessary.
  • Improving the Platform using aggregated usage data: legitimate interests, on the same footing.
  • Sending marketing messages: the data subject's consent, which may be withdrawn at any time.
  • A merchant's customer data: the merchant, as Controller, determines the legal basis for processing it, and the Platform processes it as Processor on the merchant's instructions.

The Platform does not rely on legitimate interests as a basis for processing any sensitive personal data. Identity verification data is processed on the basis of a legal obligation or explicit consent, never legitimate interests.

6. Disclosure and recipients#

The Platform discloses personal data to service providers who process it on its instructions and only for the purposes set out below. Disclosure to these categories is recurring, because it is inherent in operating the Platform, unless stated otherwise.

  • Payment providers, to activate merchant payment accounts, run verification, and process transactions. Some process data inside the Kingdom and some outside it.
  • Cloud hosting and infrastructure providers, to run the Platform and store data.
  • Email and messaging providers, to deliver service messages and support replies.
  • An artificial intelligence provider, which processes the questions merchants type into the in-product support assistant, together with the help articles the assistant answers from, in order to generate a reply. What reaches it is limited to the text of the question and the conversation history.
  • Analytics providers, to understand aggregate platform usage.
  • Professional advisers, and government or judicial authorities where disclosure is legally required. Disclosure to this category is occasional rather than recurring.

Every one of these providers is bound by a contract that limits them to processing personal data on the Platform's instructions and requires them to protect it and not to use it for their own purposes.

Merchants should not enter identity documents, card numbers, passwords, or their customers' personal data into the support assistant. None of it is needed to answer a question.

7. Transfers outside the Kingdom#

Some service providers process data outside the Kingdom of Saudi Arabia. The Platform transfers personal data outside the Kingdom only after confirming that:

  • the transfer does not prejudice national security or the vital interests of the Kingdom;
  • the receiving party guarantees an adequate level of protection for personal data, no lower than the level required by the Law and its implementing regulations; and
  • the transfer is limited to the minimum amount of data needed to achieve its purpose.

The Platform documents that assessment, binds the receiving party to it by contract, and repeats it whenever a service provider changes or its processing locations change.

8. Where data is stored and how long it is kept#

Personal data is stored on cloud infrastructure operated by hosting providers under contract with the Platform, with encrypted backups held in the same environment.

The country where the data centres used to store personal data are located is to be named here before publication. It is one of the facts a reviewer supplies.

The Platform keeps personal data only for as long as the purpose it was collected for requires, or for as long as the law requires, whichever is longer.

  • Account and store data: for as long as the account is active, and for a limited period after closure so it can be restored if the closure was a mistake.
  • Order and transaction records: for the period commercial and tax law require accounting records to be retained.
  • Verification records: for as long as the payment provider and financial regulation require.
  • Support conversations: long enough to resolve the request and understand recurring problems, then destroyed.
  • Technical logs: a short period, unless retained longer for a specific security investigation.

When a retention period ends, personal data is destroyed so that it cannot be recovered, or anonymized so that it can no longer identify anyone.

9. How we protect it#

The Platform applies organizational and technical measures to protect personal data, including encryption in transit and at rest, access controls that limit staff access to what their role requires, tenant isolation so one merchant's data is not reachable from another merchant's account, and logging of administrative access.

Because no system is perfectly secure, the Platform also maintains procedures for detecting and investigating incidents, and undertakes to notify the Saudi Data and Artificial Intelligence Authority and affected data subjects in the cases and within the periods the law prescribes.

10. Rights of the data subject#

The Personal Data Protection Law of the Kingdom of Saudi Arabia grants a data subject the following rights:

  • The right to be informed, which includes being informed of the legal basis for collecting their personal data and the purpose of collecting it.
  • The right to access their personal data held by the Controller.
  • The right to obtain their personal data in a readable and clear format, so that it can be transferred to another party.
  • The right to request that their personal data be corrected, completed, or updated.
  • The right to request the destruction of personal data that is no longer needed.
  • The right to withdraw consent where processing rests on it, without affecting the lawfulness of processing carried out before the withdrawal.
  • The right to lodge a complaint with the Saudi Data and Artificial Intelligence Authority.
  • The right to claim compensation for damage suffered as a result of a breach of the Law or its implementing regulations.

These rights are exercised by writing to the Platform at the address in the contact section. None of them may be waived or limited by agreement.

Where a request concerns data a merchant holds about one of their customers, the Platform will direct the requester to that merchant, who is the Controller of that data while the Platform merely acts on their instructions.

11. Complaints and response times#

The Platform's data protection unit receives requests to exercise rights and complaints about personal data. Write to it at privacy@uqail.com.

  • The Platform acknowledges receipt of a request within two business days.
  • It decides the request and communicates the outcome and the reasons for it within thirty days of receipt.
  • Where a request needs longer because of its complexity or the volume of data it covers, the Platform says so, and why, before that period expires.

A requester who is not satisfied with the response, or who receives no response within the stated period, may lodge a complaint with the Saudi Data and Artificial Intelligence Authority, the authority supervising the Personal Data Protection Law.

12. Data protection officer#

The Platform has appointed a data protection officer responsible for overseeing the application of this policy, monitoring compliance with the Personal Data Protection Law and its implementing regulations, liaising with the Saudi Data and Artificial Intelligence Authority, and considering requests from data subjects.

Direct contact details for the data protection officer are to be inserted here before publication; they are one of the facts a reviewer supplies. Until then, write to privacy@uqail.com.

13. Changes to this policy and change log#

This policy is updated whenever the Platform's practices or the applicable law change. The effective date at the top of the page identifies the version being read. Where a change materially affects the rights of data subjects, they are told before it takes effect, through the studio or by email.

Change log:

  • First version, on the effective date shown above: policy issued.

14. Contact#

For any question about this policy, or to exercise the rights it sets out, write to privacy@uqail.com. For help with a store, write to support@uqail.com or use the help centre in the studio.

This policy is to be read together with the Terms of Service, which govern use of the Platform.