This policy sets out what personal data Faltah collects, why, how long we keep it, and how you exercise your rights over it. Written to the Saudi Personal Data Protection Law (PDPL) and its implementing regulations.
Last updated: 11 September 2026
Faltah is the controller of personal data processed through the app, this website and the Faltah OS platform. For any privacy enquiry or request, contact hello@faltahapp.com.
Account data: name, mobile number, email address and language preference. Verification data: national ID or Iqama number and its verification outcome (couriers and merchants only). Shipment data: pickup and delivery addresses, recipient name and number, parcel description, weight and dimensions. Financial data: IBAN for paying out earnings, and the payment reference held by our payment provider — we never store your card details. Location data: the courier's coordinates during an active shipment only. Technical data: device type, app version and crash logs. We do not collect IP addresses.
To perform our contract with you: creating the shipment, matching it to a courier, collecting the payment into escrow and releasing it after delivery. To comply with a legal obligation: ZATCA tax invoicing and financial record-keeping. And under legitimate interest: fraud prevention, identity verification and service improvement. We do not use your data for third-party advertising and we do not sell it.
A courier's location is broadcast only while they have an active assigned shipment, and stops the moment it is delivered. Only the sender and recipient can see it. A condensed route is retained as evidence in case of a dispute and is deleted automatically 30 days after the shipment ends.
We share only the minimum necessary: the other party to your shipment (first name, rating and in-app contact), our payment provider Moyasar to process the transaction, our infrastructure provider Supabase to host the data, and licensed carriers when a shipment is rerouted to them. We may disclose data where a competent authority lawfully requires it. We do not sell personal data to anyone.
Account data: for as long as the account is active. Verification documents: deleted as soon as the account is closed. Tracking routes: 30 days. Financial records and invoices: ten years, to meet tax record-keeping requirements — retained after being separated from your identity.
You can delete your account from inside the app: Settings → Delete Account. On deletion we anonymise you immediately: your name becomes "Deleted User", and your email, mobile, avatar, ID number and IBAN are erased from your profile; verification documents and device tokens are deleted; your sessions are revoked and sign-in is blocked. Operational and financial records (shipments, transactions, invoices) remain after being detached from your identity, because deleting them would breach tax retention obligations. We cannot complete deletion while you have a shipment in transit or an unsettled balance — the reason is shown to you plainly so you can settle it first.
You have the right to be informed how your data is processed, to access it, to request a copy in a readable format, to have it corrected or updated, and to request its destruction. Most can be exercised directly in the app, or by writing to hello@faltahapp.com, and we respond within 30 days. You also have the right to lodge a complaint with the competent data protection authority in the Kingdom.
Data is encrypted in transit and at rest. Access is governed by row-level security policies in the database, so no user can read rows that are not theirs. Handover codes are cryptographically generated and attempt-limited. Passwords are stored as irreversible hashes. We never store card data.
The service is not directed at anyone under 18 and we do not knowingly collect their data. If we learn that we have, we delete it immediately.
Faltah's database, authentication, file storage and serverless functions are hosted on Supabase Cloud, which runs on Amazon Web Services infrastructure. The processing region is outside the Kingdom, so this is a cross-border transfer under the Personal Data Protection Law and the SDAIA regulations made under it. The safeguards we rely on for that transfer are: a data processing agreement with Supabase incorporating standard contractual clauses; encryption at rest using AES-256 on all database volumes, backups and stored files; and TLS 1.3 for every connection between your device, our applications and the database. Access to production data is restricted to named administrators and is logged. We do not sell personal data, and we do not transfer it to any third country beyond the hosting arrangement described here. If the processing region or the provider changes, this policy is updated before the change takes effect.
We may update this policy. We will notify you in the app before any material change takes effect, and the last-updated date above always reflects the current version.