Commercial Registration No.: 4030135728
Privacy Policy
Last Updated: 1 November 2024
1. Introduction
At ALBAIK, we value your privacy.
This Privacy Policy (this Policy) has been adopted by ALBAIK Food Systems Company and our affiliates (including our licensees operating ALBAIK Restaurants in the Kingdom of Saudi Arabia (KSA)) – collectively referred to in this Policy as ALBAIK.
This Policy explains how we collect, use and safeguard personal information about our Customers and others who use ALBAIK web sites and mobile apps (our Online Applications) in compliance with the KSA Personal Data Protection Law and its implementing regulations (the PDPL).
By using instore technologies and/or using our Online Applications, you agree to the practices described in this policy.
We may collect personal data about you when you use the Online Applications.
We strive to create a seamless and secure experience for all our users, and we are dedicated to maintaining transparency in how your personal data is handled. Your trust is at the core of what we do, and this Policy reflects our commitment to safeguarding your privacy.
2. Who We Are
ALBAIK is the entity responsible for processing your personal data collected when you use the Online Applications. As the Data Controller, our role is to ensure that all your personal data is managed securely and used solely for permitted purposes in accordance with the PDPL.
If you have any questions about this Policy or how your personal data is managed, you can reach out to us through the following:
- Email: crd@albaik.com.sa
- Address: 4217 Umm AlQura Street, AlRehab District, PO Box 54895, Jeddah 21524, KSA
- Phone: 800 244 2245
3. How do we collect your Personal Data?
We collect personal data in various ways to ensure that your experience within our Online Applications is smooth, efficient, and secure. The methods by which we collect your personal data include:
Directly from You
- When you visit the Online Applications, create an account, place an order or update your profile information, you provide us with personal details such as your name, contact information and delivery address.
- When you engage with customer support or participate in promotions, you may also share additional personal information with us voluntarily.
Automatically through the Online Applications
- As you navigate and interact with our Online Applications, we automatically collect data related to your device, such as your IP address, operating system and browsing activity.
- We also use cookies and similar tracking technologies to understand how you interact with our Online Applications.
Location-Based Data
- When you use location-based services within the Online Applications (e.g., for deliveries), we collect your location data (using GPS coordinates, Wi-Fi, Bluetooth and/or mobile tower proximity) to facilitate accurate delivery services and suggest nearby ALBAIK Restaurants. You can control this through your device’s settings.
Third Parties Sources
- We may receive additional information about you from third-party service providers such as payment processors, social media platforms (if you choose to log in via social media) and analytics partners.
All data collected is processed in compliance with the PDPL and is used solely for the purposes outlined in this policy. We ensure that all methods of data collection are secure and transparent, giving you full control over your personal information.
4. Types of Personal Data Collected
We may collect personal data about you when you use the Online Applications. This personal data is collected in order to provide you with an optimal and personalized experience. The types of personal data that we collect may include:
Contact Information
- What we collect: Your username, phone number and email address which you provide to us.
- Why we collect it: To process your orders, send you notifications, updates and provide customer support. This information helps us ensure that you receive order confirmations and timely communication.
Location Data
- What we collect: The location of ALBAIK Restaurants you visit, your delivery address(es), city and geolocation (longitude and latitude) using GPS, Wi-Fi, Bluetooth and/or mobile tower proximity.
- Why we collect it: We use this information to enable us to:
- Adapt the available menu of offered products and services to your location;
- Deliver your orders accurately and improve location-based services, such as finding the nearest restaurant for efficient delivery;
- Validate attendance of pick-up customers in the applicable ALBAIK Restaurant; and subject to you giving us permission, use this information for marketing purposes including communicating with you about products and services if ALBAIK and our business partners that we believe may interest you.
Device Information
- What we collect: The information we collect may include your Internet Protocol (IP) address; computer/mobile device operating system and browser type; type of mobile device; mobile device settings; the unique device identifier (UDID) or mobile equipment identifier (MEID) for your mobile device; device and component serial numbers; advertising identifier (e.g., IDFAs and IFAs) or similar identifier; the referring website or application; the linked sites, third-party websites, applications or social media where you share Online Applications’ content; and activity related to your use of our Online Applications such as the pages you visit on our web sites or in our mobile apps.
- Why we collect it: We use this information for purposes such as to:
- Ensure compatibility with your device and optimize the performance of our Online Applications;
- Personalize the user experience on our Online Applications;
- Deliver content (including advertising) tailored to our users' interests and the manner in which our users browse our Online Applications or ALBAIK in-restaurant technologies;
- Troubleshoot and help diagnose technical and service problems;
- Administer our Online Applications;
- Identify users of our Online Applications;
- Enhance security and identify a device for fraud prevention purposes;
- To target advertising or to personalize users’ experiences;
- Gather demographic information about our users;
- To determine usage patterns and how we may tailor our services to better meet the needs of our users and manage our business.
Order Information
- What we collect: Your order history, selected items, payment method, delivery preferences, and other users involved with an order.
- Why we collect it: To process your orders efficiently, track your preferences, and improve the overall ordering experience. This data also allows you to easily reorder your favorite meals.
Payment Information
- What we collect: Payment method, pseudonymized credit card details (such as last four digits) and payment history.
- Why we collect it: We store your payment details securely to facilitate a smooth checkout process for your current and future orders. Your payment information is handled in accordance with strict security measures.
Usage Data
- What we collect: Information on how you use the Online Applications, including features you interact with, pages viewed and actions taken.
- Why we collect it: This helps us understand how you engage with the app, identify areas for improvement and provide you with a more personalized user experience.
General Note
- We only collect personal data that is necessary for providing our services either through the Online Applications.
- We may use the information we obtain about you in ways other than as stated above for which we shall provide specific notice at the time of collection.
- All personal data which we collect and store is handled in compliance with the PDPL.
- Your privacy is paramount to us; and we implement strong safeguards to protect your personal information.
5. Legal Basis for Collecting and Processing Data
ALBAIK collects and processes personal data based on specific legal grounds to ensure that our data practices are transparent and lawful under the PDPL. The legal reasons for collecting and processing your personal data through the Online Applications are as follows:
- Performance of a contract: We collect and process your personal data to fulfill our contractual obligations to you; this includes processing your orders, managing payments, providing customer support and delivering your food. Without this data, we would be unable to perform these essential services for you.
- Your explicit consent: In certain cases, we rely on your explicit consent to process your personal data, such as when you sign up to receive marketing communications or personalized offers. You can withdraw your consent at any time by updating your preferences in the Online Applications or by contacting us directly.
- Compliance with legal obligations: We may process your data to comply with legal and regulatory obligations, including record-keeping, fraud prevention and responding to legitimate requests from public authorities (e.g., tax authorities or law enforcement agencies).
- Legitimate business interests: We may process your personal data based on our legitimate business interests, provided such processing does not override your rights and freedoms. These legitimate interests include:
- Improving and optimizing the performance of the Online Applications;
- Enhancing user experience and developing new features;
- Protecting the security of the Online Applications and our services as well as preventing fraud;
- Communicating with you about your account and any updates related to the Online Applications and/or our products and services;
- Understanding customer preferences through product analysis, menu engineering and usage data to enhance our offerings and provide targeted promotions that better serve our customers’ needs.
6. Purpose of Data Collection
When you use the Online Applications, we collect personal data to ensure that we provide you with the best possible experience. The data collected helps us to:
- Deliver Our Services: We collect data necessary to process your order, deliver your order to your location, enable you to pick-up your oder, and/or ensure the smooth operation of the Online Applications.
- Improve the Functionality of the Online Applications: We analyze user data to enhance performance, fix bugs and implement features that improve user experience.
- Provide Personalized Experiences: Your preferences and previous interactions help us tailor the content, offers and notifications you see.
- Communicate with You: We use your contact details to send order confirmations, provide customer support and notify you of updates or promotions.
- Ensure Security: Your data helps us to protect the app and its users from fraud, unauthorized access, and other security risks.
General Note
- We only collect personal data that is necessary for providing our services through the Online Applications.
- We may use the information we obtain about you in ways other than as stated above for which we shall provide specific notice at the time of collection.
- All personal data which we collect and store is handled in compliance with the PDPL.
- Your privacy is paramount to us; and we implement strong safeguards to protect your personal information.
7. Data Use and Processing
We use the personal data collected through interaction through the Online Applications to provide you with high-quality service and enhance your overall experience. Your personal data may be processed as follows:
- We use your contact, location and order information to process your order, serve your meal and/or deliver your meal accurately and provide customer support as needed.
- Your usage and device data help us monitor the Online Applications’ performance, identify areas for improvement and fix any technical issues. We also use this data to personalize your Online Applications experience, such as tailoring product recommendations and promotions to suit your preferences.
- We use your contact details to send order confirmations, notify you of your order status and inform you of any important updates to the Online Applications and/or our products and services. You may also receive promotional offers or discounts via push notifications, email or SMS, based on your preferences.
- To ensure the safety of your personal data and prevent fraud, we use device and transaction data to monitor any suspicious activities and secure your account. Our security measures are designed to protect both your personal data and our platform from unauthorized access.
- We process your personal data in accordance with the PDPL and any other applicable laws and regulations. This includes responding to requests from legal authorities when required.
- We analyze aggregated, anonymized data to gain insights into user behavior and preferences. This helps us to continuously improve the Online Applications’ features and services, making them more relevant and useful to you.
We are committed to ensuring that your personal data is processed securely and only used for the purposes outlined in this Policy. Your personal data is not used for any purposes beyond those which are necessary to provide you with a seamless and secure ALBAIK experience.
In the event of a data breach involving your personal data, or if there is a suspicion of unauthorized access or compromise of your personal data, we will notify you promptly. This notification will be provided without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with the DPDPL. We will also inform you of any steps we are taking to (i) mitigate the impact of the breach and (ii) secure your personal data.
8. Data Sharing with Third Parties
ALBAIK does not sell or otherwise share personal data about you except as set out in this Policy
At ALBAIK, we take your privacy seriously and ensure that your personal data is only shared with trusted third parties when absolutely necessary for providing our products and services. All third parties with whom we share your data are bound by confidentiality agreements.
We ensure that all third parties with whom we may share your personal data:
- Are bound by confidentiality/non-disclosure agreements;
- Are required to adhere to strict data protection standards;
- Are required to comply fully with the PDPL.
Your data may be shared with:
- Delivery Partners: We share your location, contact information and order details with our delivery partners to ensure that your meals are delivered accurately and on time; any such disclosure of personal information is strictly limited to that which is necessary for the delivery.
- Payment Processors: Your payment information is securely processed by third-party payment providers who handle your payment details under strict security protocols to complete transactions efficiently and safely.
- Service Providers and Vendors: We work with selected service providers to support the functionality of our Online Applications, such as hosting services, customer support platforms and analytics tools. These third parties may have limited access to your personal data, but only for the purposes of providing services on our behalf and improving the performance of our Online Applications
- Legal Authorities: We may be required to disclose your personal data to comply with mandatory legal obligations, court orders, regulatory requirements and government requests, as required by the law of the KSA (including the PDPL). In such cases, we will use our commercially reasonable endeavors to ensure that any personal data so disclosed is limited to the extent legally required to be disclosed and is handled responsibly and with due consideration for your privacy by the recipient.
9. Data Retention
We retain your personal data only for as long as it is necessary to fulfill the purposes outlined in this privacy policy, or as required by applicable laws and regulations in the KSA (including the PDPL).
- Account Information: We store your account details, such as your name, username, contact information and order history, for as long as your Online Applications account remains active. This data is used to enhance your Inline Applications experience and improve our services. If you choose to delete your Online Applications account, we will deactivate and delete your personal data unless we are required to retain it for legal or regulatory reasons.
- Order and Payment Data: We retain your order and payment information for as long as is necessary to complete your transactions and to comply with applicable financial and tax laws. In cases where data needs to be retained for legal purposes, it will be securely stored and restricted from further processing.
- Legal Retention Periods: In some cases, we are required to retain certain personal data for a specified period in order to comply with the laws and regulations of the KSA (including the PDPL) and/or applicable regulatory requirements. For example, financial data may be retained for tax compliance purposes. In cases where data needs to be retained for legal purposes, it will be securely stored and restricted from further processing.
- Deletion of Data: You have the right to request the deletion of your personal data at any time. Please note that your personal data can only be deleted through the deactivation of your Online Applications account. Upon receiving such a request to delete your data, we may assist you to deactivate your Online Applications account provided that we are not obliged to retain any of your personal data for legal purposes. We may notify you of any legal reasons that prevent us from immediately deactivating your Online Services account.
- Actions Upon Termination: Upon deactivation of your Online Applications account, your personal data will be securely deleted unless we are required by law to retain it.
Our goal is to handle your personal data responsibly and minimize retention to only that which is necessary. Be assured that we take all necessary precautions to ensure your personal data is securely stored and protected during any retention period.
10. User Rights
In accordance with the PDPL, you have specific rights regarding your personal data.
ALBAIK is committed to enabling you to exercise these rights in a clear and transparent manner. Here is a detailed overview of your rights:
- Right to Information: You have the right to be informed about the personal data we collect, the reasons for collecting it, how it will be used, and the legal grounds for collecting your data Please refer to sections 3, 4, 5, 6 and 8 of this Policy.
- Right to Access: You have the right to access the personal data we hold about you. You can obtain a copy of your personal data and understand how it is being processed and stored. Please submit a request by contacting us at privacy@albaik.com.sa.
- Right to Rectification: If your personal data is inaccurate or incomplete, you have the right to request corrections. You can update inaccurate data to keep your records accurate and current directly through the Online Applications or contact us to make corrections at privacy@albaik.com.sa.
- Right to Data Portability: You have the right to receive a copy of your personal data in a structured, machine-readable format. Please contact us to obtain an electronic copy of your data for portability purposes at privacy@albaik.com.sa.
- Right to Erasure (Right to be Forgotten): You can request the deletion of your personal data in the following circumstances:
- When your data is no longer needed for the purposes for which it was collected; or
- If you withdraw consent and there is no other legal basis for processing; or
- If you object to the processing, and there are no overriding legitimate grounds
To delete your personal data, please contact us at privacy@albaik.com.sa.
Please note that your personal data can only be deleted through the deactivation of your Online Applications account. Upon receiving such a request to delete your data, we may assist you to deactivate your Online Applications account provided that we are not obliged to retain any of your personal data for legal purposes. We may notify you of any legal reasons that prevent us from immediately deactivating your Online Services account.
- Right to Withdraw Consent: If we rely on your consent to process personal data, you can withdraw that consent at any time. Once consent is withdrawn, we will stop processing your personal data, unless required by law. You can manage this within the Online Applications or contact us directly at privacy@albaik.com.sa.
- Right to File a Complaint: If you believe your rights have been violated or if you are concerned about how your personal data is being handled, you have the right to lodge a complaint. Please refer to section 11 of this Policy.
11. Complaints and Dispute Resolution
ALBAIK is committed to addressing any concerns or complaints you may have regarding the handling of your personal data. If you believe your rights under the Data Law have been violated or if you are unsatisfied with how your personal data has been processed, you should follow the process for lodging a complaint as set out below.
Complaint to ALBAIK:
In the first instance, you should raise your complaint directly with ALBAIK using any of the following contact methods:
- Email: privacy@albaik.com.sa
- Phone: 800 244 2245
The ALBAIK team will investigate your complaint and respond as quickly as possible, generally within 30 days of receipt of your complaint.
Escalation to the Saudi Data and Artificial Intelligence Authority
If you are not satisfied with the resolution of your complaint as proposed by ALBAIK or if we fail to respond to you within 30 days of receipt of your complaint or you still consider that we are not complying with the PDPL, then you may escalate the complaint by filing a complaint with the Saudi Data and Artificial Intelligence Authority (SDAIA), Riyadh, Kingdom of Saudi Arabia (website: www.sdaia.gov.sa), which is the regulatory body responsible for overseeing data protection in the KSA.
You can contact SDAIA through the following means:
- Website: www.sdaia.gov.sa
- Phone: 8001221111
Dispute Resolution
In the event of a dispute concerning the processing of your personal data, we aim to resolve the matter amicably. If a satisfactory resolution cannot be reached through internal processes or SDAIA, we may explore other legal avenues, including mediation or arbitration, depending on the nature of the dispute and applicable law.
We are committed to resolving complaints in a fair and transparent manner, and we will cooperate fully with any official investigations or legal requirements to ensure your rights are protected.
12. Policy Accessibility and Updates
At ALBAIK, we are committed to making our privacy policy clear and easily accessible to all users of the Online Applications.
We also ensure that this Policy remains up to date with any changes in law, regulations or internal practices. Below are the details regarding the accessibility and regular updates of our privacy policy:
Policy Accessibility
This Policy is available to you at all times through the following methods:
- ALBAIK Mobile App: you can access this Policy at any time through the “MY ALBAIK section of the app.
- ALBAIK Website: you can access this Policy at any time on our website at https://www.albaik.com.
We strive to ensure that the language and structure of this Policy are clear, transparent, and easy to understand for all users, including those who may have specific accessibility needs. For any additional support in understanding this Policy, you can reach out to our support team at privacy@albaik.com.sa.
Updates to the Privacy Policy
From time to time, we may need to update this privacy policy to reflect changes in the law, our data collection practices or our internal procedures. Whenever significant changes are made, we will:
- Notify You of Changes: Any major updates to this Policy will be communicated to you through the Online Applications via notifications or by email (if we have your contact information on file).
- Highlight Important Changes: We will summarize any key changes to this Policy and indicate the effective date of the new policy.
Reviewing and Understanding Updates
You are encouraged to regularly review this Policy to stay informed about how your data is being processed. The "Last Updated" date at the top of the privacy policy will indicate when the most recent changes were made.
If you continue to use the Online Services after being notified of updates to this Policy, it will be assumed that you have accepted the changes. If you do not agree with any changes, you may discontinue the use of the Online Applications or contact us for further clarification.
Contact Information
For any questions, concerns, or complaints regarding your personal data, you can contact us through the following:
- Email Address: privacy@albaik.com.sa
- Phone Number: 800 244 2245
- Website: www.albaik.com
You may also contact us to request access to your data, exercise your privacy rights, or lodge complaints regarding how your personal data is processed.
Legal Registration:
Company Name: ALBAIK FOOD SYSTEMS COMPANY
Commercial Registration Number: 4030135728