Quick Summary
- ✓ We collect only what we need to provide our services
- ✓ Your data is encrypted and protected
- ✓ We never sell your personal information
- ✓ You can access, correct, or delete your data anytime
- ✓ We comply with Saudi Arabia's PDPL
1. Who We Are
SPOT is a booking platform for beauty, wellness, and spa services in Saudi Arabia. We connect you with salons, spas, barbershops, and wellness centers to book appointments easily.
This Privacy Policy explains how we collect, use, and protect your personal information in compliance with the Saudi Arabia Personal Data Protection Law (PDPL).
By using SPOT, you agree to this policy. If you do not agree, please do not use our services.
2. Information We Collect
We collect different types of information to provide and improve our services:
A. Information You Give Us
- Account details: Name, email, phone number, password
- Profile information: Date of birth, gender, profile photo
- Preferences: Language, notification settings, favorite services
- Communications: Messages you send to support or merchants
B. Information From Your Bookings
- Booking history: Services booked, dates, times, locations
- Payment records: Transaction amounts, payment method used (card details are handled securely by our payment provider)
- Reviews: Ratings and comments you leave for merchants
- Cancellations: Booking cancellations and reasons
C. Information Collected Automatically
- Device information: Phone model, operating system, app version
- Location data: Your location to show nearby merchants (only when you allow it)
- Usage data: How you use the app, features you access, search queries
- Technical data: IP address, device identifiers, crash reports
3. How We Use Your Information
We use your information for these specific purposes:
Account Management
To create and manage your account, verify your identity, and keep your profile updated.
Booking Services
To process your bookings, send confirmations, reminders, and handle cancellations or changes.
Payment Processing
To process payments, refunds, and manage your subscription.
Location Services
To show merchants near you and help you find services in your area.
Communications
To send booking updates, reminders, and important account notifications.
Service Improvement
To understand how you use the app and make it better for everyone.
Safety & Security
To protect against fraud, unauthorized access, and ensure platform safety.
Legal Compliance
To comply with Saudi Arabian laws and regulations.
4. Legal Basis for Processing
Under the Saudi Personal Data Protection Law (PDPL), we process your data based on:
- Your consent: For marketing, analytics, and optional features
- Contract performance: To provide services you requested (bookings, account)
- Legal obligations: To comply with Saudi laws and regulations
- Legitimate interests: For security, fraud prevention, and service improvement
5. Who We Share Your Data With
We share your information only when necessary:
| Who | What We Share | Why |
|---|---|---|
| Merchants | Name, phone, booking details | To provide your booked services |
| Payment providers | Payment details | To process your payments securely |
| Service providers | Technical data | To operate and improve our app |
| Legal authorities | As required | When required by Saudi law |
6. Subprocessors & infrastructure
We rely on carefully selected subprocessors and infrastructure partners to operate the Platform—for example payment processing, messaging, analytics, application stability, hosting, and similar functions. We do not publish a public directory of specific vendor names; limiting disclosure helps protect our systems, integrations, and your data from unnecessary exposure.
Each subprocessor is engaged under written terms that require appropriate confidentiality, security measures, and processing limits consistent with this Policy and applicable law, including the PDPL. If you require more information about the categories of subprocessors we use or the safeguards in place, contact our Privacy Team.
7. International Data Transfers
Some of our service providers are located outside Saudi Arabia. When we transfer your data internationally, we ensure protection through:
- Standard contractual clauses approved for data protection
- Ensuring the receiving country has adequate data protection laws
- Obtaining your explicit consent when required by PDPL
- Implementing additional security measures for sensitive data
8. How Long We Keep Your Data
We keep your information only as long as necessary:
| Data type | Retention |
|---|---|
| Account information | While account is active + 2 years |
| Booking history | 3 years |
| Payment records | 7 years (legal requirement) |
| Reviews | Until you delete them |
| Support messages | 3 years |
| Analytics data | 2 years |
| Security logs | 1 year |
9. Your Rights Under PDPL
Saudi Arabia's Personal Data Protection Law gives you important rights over your data:
Right to Access
Request a copy of all your personal data we hold
Right to Correction
Ask us to fix any incorrect or incomplete data
Right to Deletion
Request we delete your data when no longer needed
Right to Portability
Receive your data in a format you can transfer
Right to Object
Object to certain types of data processing
Right to Withdraw Consent
Take back any consent you previously gave us
10. How to Exercise Your Rights
To exercise any of your rights:
- Email us at privacy@slotex.sa
- Use the "Privacy Settings" in the app
- Contact our support team at support@slotex.sa
We will respond to your request within 30 days. If we need more time, we will let you know.
11. How We Protect Your Data
We take security seriously and use multiple layers of protection:
- Encryption: Your data is encrypted when stored and when sent over the internet
- Secure payments: Card details are handled by certified payment providers (PCI-DSS compliant)
- Access controls: Only authorized staff can access your data, and only when needed
- Regular audits: We regularly check our security systems
- Secure storage: Your password is stored using strong encryption (bcrypt)
12. Children's Privacy
SPOT is not intended for children under 18 years old. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us immediately and we will delete it.
13. Cookies & Similar Technologies
Our app and website use cookies and similar technologies to:
- Keep you logged in
- Remember your preferences
- Understand how you use our services
- Improve app performance
You can control analytics tracking in Settings > Privacy Settings.
14. Marketing Communications
We may send you marketing messages about promotions, new features, and special offers. You can opt out at any time:
- In the app: Settings > Notification Settings
- By clicking "Unsubscribe" in any marketing email
- By contacting us at privacy@slotex.sa
Note: You will still receive important account and booking notifications even if you opt out of marketing.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we make significant changes:
- We will notify you through the app or by email
- We will update the "Last Updated" date at the top
- For major changes, we may ask for your consent again
16. Questions & Complaints
If you have questions or concerns about your privacy, or want to make a complaint:
Data Controller
Responsible for your data
- Company
- Slotex Technologies
- Location
- Kingdom of Saudi Arabia
- Privacy Email
- privacy@slotex.sa
- Support Email
- support@slotex.sa
Regulated by: Saudi Data and Artificial Intelligence Authority (SDAIA)