Privacy Policy

Last updated: March 22, 2026

PDPL compliantSaudi Arabia

Quick Summary

  • ✓ We collect only what we need to provide our services
  • ✓ Your data is encrypted and protected
  • ✓ We never sell your personal information
  • ✓ You can access, correct, or delete your data anytime
  • ✓ We comply with Saudi Arabia's PDPL

1. Who We Are

SPOT is a booking platform for beauty, wellness, and spa services in Saudi Arabia. We connect you with salons, spas, barbershops, and wellness centers to book appointments easily.

This Privacy Policy explains how we collect, use, and protect your personal information in compliance with the Saudi Arabia Personal Data Protection Law (PDPL).

By using SPOT, you agree to this policy. If you do not agree, please do not use our services.

2. Information We Collect

We collect different types of information to provide and improve our services:

A. Information You Give Us

  • Account details: Name, email, phone number, password
  • Profile information: Date of birth, gender, profile photo
  • Preferences: Language, notification settings, favorite services
  • Communications: Messages you send to support or merchants

B. Information From Your Bookings

  • Booking history: Services booked, dates, times, locations
  • Payment records: Transaction amounts, payment method used (card details are handled securely by our payment provider)
  • Reviews: Ratings and comments you leave for merchants
  • Cancellations: Booking cancellations and reasons

C. Information Collected Automatically

  • Device information: Phone model, operating system, app version
  • Location data: Your location to show nearby merchants (only when you allow it)
  • Usage data: How you use the app, features you access, search queries
  • Technical data: IP address, device identifiers, crash reports

3. How We Use Your Information

We use your information for these specific purposes:

Account Management

To create and manage your account, verify your identity, and keep your profile updated.

Booking Services

To process your bookings, send confirmations, reminders, and handle cancellations or changes.

Payment Processing

To process payments, refunds, and manage your subscription.

Location Services

To show merchants near you and help you find services in your area.

Communications

To send booking updates, reminders, and important account notifications.

Service Improvement

To understand how you use the app and make it better for everyone.

Safety & Security

To protect against fraud, unauthorized access, and ensure platform safety.

Legal Compliance

To comply with Saudi Arabian laws and regulations.

4. Legal Basis for Processing

Under the Saudi Personal Data Protection Law (PDPL), we process your data based on:

  • Your consent: For marketing, analytics, and optional features
  • Contract performance: To provide services you requested (bookings, account)
  • Legal obligations: To comply with Saudi laws and regulations
  • Legitimate interests: For security, fraud prevention, and service improvement

5. Who We Share Your Data With

We share your information only when necessary:

WhoWhat We ShareWhy
MerchantsName, phone, booking detailsTo provide your booked services
Payment providersPayment detailsTo process your payments securely
Service providersTechnical dataTo operate and improve our app
Legal authoritiesAs requiredWhen required by Saudi law

6. Subprocessors & infrastructure

We rely on carefully selected subprocessors and infrastructure partners to operate the Platform—for example payment processing, messaging, analytics, application stability, hosting, and similar functions. We do not publish a public directory of specific vendor names; limiting disclosure helps protect our systems, integrations, and your data from unnecessary exposure.

Each subprocessor is engaged under written terms that require appropriate confidentiality, security measures, and processing limits consistent with this Policy and applicable law, including the PDPL. If you require more information about the categories of subprocessors we use or the safeguards in place, contact our Privacy Team.

7. International Data Transfers

Some of our service providers are located outside Saudi Arabia. When we transfer your data internationally, we ensure protection through:

  • Standard contractual clauses approved for data protection
  • Ensuring the receiving country has adequate data protection laws
  • Obtaining your explicit consent when required by PDPL
  • Implementing additional security measures for sensitive data
You can request information about specific transfers by contacting our Privacy Team.

8. How Long We Keep Your Data

We keep your information only as long as necessary:

Data typeRetention
Account informationWhile account is active + 2 years
Booking history3 years
Payment records7 years (legal requirement)
ReviewsUntil you delete them
Support messages3 years
Analytics data2 years
Security logs1 year

9. Your Rights Under PDPL

Saudi Arabia's Personal Data Protection Law gives you important rights over your data:

Right to Access

Request a copy of all your personal data we hold

Right to Correction

Ask us to fix any incorrect or incomplete data

Right to Deletion

Request we delete your data when no longer needed

Right to Portability

Receive your data in a format you can transfer

Right to Object

Object to certain types of data processing

Right to Withdraw Consent

Take back any consent you previously gave us

10. How to Exercise Your Rights

To exercise any of your rights:

  • Email us at privacy@slotex.sa
  • Use the "Privacy Settings" in the app
  • Contact our support team at support@slotex.sa

We will respond to your request within 30 days. If we need more time, we will let you know.

11. How We Protect Your Data

We take security seriously and use multiple layers of protection:

  • Encryption: Your data is encrypted when stored and when sent over the internet
  • Secure payments: Card details are handled by certified payment providers (PCI-DSS compliant)
  • Access controls: Only authorized staff can access your data, and only when needed
  • Regular audits: We regularly check our security systems
  • Secure storage: Your password is stored using strong encryption (bcrypt)

12. Children's Privacy

SPOT is not intended for children under 18 years old. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us immediately and we will delete it.

13. Cookies & Similar Technologies

Our app and website use cookies and similar technologies to:

  • Keep you logged in
  • Remember your preferences
  • Understand how you use our services
  • Improve app performance

You can control analytics tracking in Settings > Privacy Settings.

14. Marketing Communications

We may send you marketing messages about promotions, new features, and special offers. You can opt out at any time:

  • In the app: Settings > Notification Settings
  • By clicking "Unsubscribe" in any marketing email
  • By contacting us at privacy@slotex.sa

Note: You will still receive important account and booking notifications even if you opt out of marketing.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we make significant changes:

  • We will notify you through the app or by email
  • We will update the "Last Updated" date at the top
  • For major changes, we may ask for your consent again

16. Questions & Complaints

If you have questions or concerns about your privacy, or want to make a complaint:


Data Controller

Responsible for your data

Company
Slotex Technologies
Location
Kingdom of Saudi Arabia
Privacy Email
privacy@slotex.sa
Support Email
support@slotex.sa

Regulated by: Saudi Data and Artificial Intelligence Authority (SDAIA)