Privacy Policy

Effective: 24 July 2026 · Version 2.1

سياسة الخصوصية

سارية من ٢٤ يوليو ٢٠٢٦ · النسخة ٢٫١

١. مقدمة ونطاق السياسة

تشرح هذه السياسة كيفية جمع مؤسسة نوكس لتقنيات البرمجيات ("نُوكس"، "نحن") للبيانات الشخصية واستخدامها وحمايتها، وفقاً لـنظام حماية البيانات الشخصية الصادر بالمرسوم الملكي رقم م/١٩ بتاريخ ١٤٤٣/٢/٩هـ ولوائحه التنفيذية.

تنطبق هذه السياسة على فئتين من المستخدمين:

  • التجار: مالكو المتاجر الذين يسجّلون في منصة نوكس عبر nooks.space. نُوكس هي المتحكم في البيانات فيما يخص بيانات حسابات التجار.
  • العملاء النهائيون: الأشخاص الذين يستخدمون التطبيقات بهوية التاجر للطلب. التاجر هو المتحكم في البيانات فيما يخص بياناتهم، ونُوكس هي المعالج نيابة عن التاجر بموجب اتفاقية معالجة بيانات موضّحة في اتفاقية معالجة البيانات (DPA).

للاطلاع على سياسة الخصوصية المخصصة للعملاء النهائيين، راجع التطبيق المخصص لكل تاجر.

٢. البيانات التي نجمعها عن التجار

  • بيانات الحساب: الاسم الكامل، البريد الإلكتروني، رقم الجوال، الاسم التجاري للمتجر، رقم السجل التجاري، وعنوان النشاط.
  • بيانات الفوترة: سجل الاشتراك، معرّف العميل في مُيسَّر، آخر ٤ أرقام من البطاقة، تاريخ انتهاء الاشتراك. لا نخزّن أرقام بطاقات كاملة أبداً.
  • بيانات الربط مع الأطراف الثالثة: رمز الدخول لحساب فودكس، إعدادات Moyasar، شهادات Apple Pay، رموز الدفع الإلكتروني.
  • بيانات الاستخدام: سجلات الدخول للوحة التحكم، عنوان IP، نوع المتصفح، البصمة الرقمية للجهاز.
  • بيانات التواصل: رسائل البريد الإلكتروني المتبادلة مع فريق الدعم.
  • بيانات الفريق: أسماء وأرقام جوال المدراء الذين يُضافون إلى الحساب.

٣. البيانات التي نعالجها نيابة عن التجار

عندما يُسجّل عميل في تطبيق تاجر، يكون التاجر هو المتحكم في بياناته. نقوم بمعالجة الفئات التالية بالنيابة عنه:

  • رقم الجوال، الاسم، البريد الإلكتروني الاختياري للعميل.
  • سجلات الطلبات، عناوين التوصيل، إحداثيات GPS.
  • رموز الدفع الصادرة من Moyasar (لا توجد بيانات بطاقة كاملة لدينا).
  • رموز الإشعارات الفورية (Apple/Google).
  • سجلات OTP وزمنها (٣٠ يوماً).
  • صور الشكاوى المُرفقة، رصيد المحفظة، نقاط الولاء.

تستخدم منصة نوكس هوية عميل واحدة مرتبطة برقم الجوال عبر جميع التجار المشغَّلين على المنصة، بحيث يستطيع العميل تسجيل الدخول بنفس رقم جواله في أي متجر يعمل بنظام نوكس دون إنشاء حساب جديد في كل مرة. هذه الهوية تقنية بحتة (لتسهيل الدخول)؛ بيانات الطلبات والولاء والمحفظة لكل تاجر تبقى منفصلة ولا يطّلع عليها تاجر آخر.

٤. الأساس القانوني للمعالجة

  • تنفيذ العقد: معظم المعالجة لازمة لتقديم خدمة المنصة.
  • الموافقة: تتبّع الموقع، حملات البريد الإلكتروني.
  • الإشعارات الترويجية: يرسلها التاجر (وهو المتحكم في بيانات عملائه) عبر أدوات المنصة إلى مستخدمي تطبيقه الذين فعّلوا الإشعارات، ويلتزم التاجر بموجب شروط الاستخدام بالحصول على أي موافقة يتطلبها النظام. يستطيع المستخدم إيقافها في أي وقت بتعطيل إشعارات التطبيق من إعدادات جهازه.
  • المصلحة المشروعة: منع الاحتيال، أمن النظام، تحسين الخدمة.
  • الالتزام القانوني: الاحتفاظ بالسجلات المالية وفقاً لمتطلبات هيئة الزكاة والضريبة والجمارك.

٥. مشاركة البيانات (المعالجون الفرعيون)

لا نبيع بياناتك الشخصية. نشاركها فقط مع شركاء فنيين لتشغيل الخدمة:

  • Supabase — استضافة قاعدة البيانات (مراكز بيانات في أوروبا/آسيا).
  • Moyasar — معالجة المدفوعات (مرخصة من البنك المركزي السعودي).
  • Foodics — تكامل نقاط البيع.
  • Foodics DMS — توصيل الطلبات.
  • المدار التقني (Corbit) — إرسال الرسائل النصية ورموز التحقق.
  • Resend — إرسال البريد الإلكتروني المعاملاتي.
  • Apple Push (APNs) و Firebase (FCM) — تسليم الإشعارات الفورية.
  • Vercel و Railway — استضافة الخوادم.
  • Sentry — تتبّع أخطاء التطبيق (بدون بيانات شخصية).
  • Mapbox — تحويل العناوين إلى إحداثيات.
  • الجهات الحكومية: عند الطلب القانوني وفقاً للأنظمة السعودية.

يتم نقل بعض البيانات إلى خوادم خارج المملكة العربية السعودية (الاتحاد الأوروبي، آسيا، الولايات المتحدة). هذا النقل يتم بموجب بنود تعاقدية مكافئة للبنود التعاقدية القياسية الصادرة عن الهيئة السعودية للبيانات والذكاء الاصطناعي (سدايا)، مع تقييمات موثّقة لمخاطر النقل وفقاً للائحة نقل البيانات الشخصية الصادرة عن سدايا.

٦. أمن البيانات

  • تشفير TLS 1.2+ لجميع الاتصالات.
  • كلمات المرور مُجزّأة (hashed) بخوارزمية Argon2id عبر Supabase Auth — لا نخزّنها كنص صريح أبداً.
  • رموز الدفع والربط مع الأطراف الثالثة (Moyasar، Foodics) ومفاتيح API الخاصة بالتجار مشفّرة أثناء التخزين بمعيار AES-256-GCM.
  • على الأجهزة الجوّالة، تُحفظ رموز الجلسات في iOS Keychain / Android Keystore.
  • لا نخزّن أرقام بطاقات أبداً — يتم ترميز جميع المدفوعات بالكامل عبر Moyasar وفق معايير PCI-DSS.
  • ضوابط وصول صارمة على قاعدة البيانات (Row-Level Security)، تدقيق دوري للسجلات.
  • نسخ احتياطية تلقائية يومية.
  • عند اكتشاف أي خرق للبيانات يؤثر على بياناتك، نلتزم بإخطارك خلال ٧٢ ساعة وفق متطلبات النظام.

٧. الاحتفاظ بالبيانات

  • بيانات الحساب النشط: طوال فترة الاشتراك.
  • السجلات المالية والطلبات: ٧ سنوات (متطلبات هيئة الزكاة والضريبة والبنك المركزي السعودي).
  • سجلات OTP: ٣٠ يوماً.
  • رموز الإشعارات الفورية: حتى إلغاء تثبيت التطبيق أو إيقاف الإشعارات.
  • عند حذف الحساب: تُحذف البيانات الشخصية خلال ٣٠ يوماً، وتُجهَّل سجلات الطلبات (تبقى للأغراض المحاسبية بدون بيانات تعريفية).

٨. حقوقك (PDPL)

  • حق الوصول: طلب نسخة من بياناتك.
  • حق التصحيح: تعديل البيانات غير الدقيقة.
  • حق الحذف: طلب الحذف، باستثناء ما يلزم الاحتفاظ به قانونياً.
  • حق الاعتراض: رفض المعالجة لأغراض التسويق المباشر.
  • حق سحب الموافقة: في أي وقت.
  • حق نقل البيانات: الحصول على نسخة بصيغة قابلة للقراءة الآلية.

لممارسة أي من هذه الحقوق، تواصل مع: privacy@nooks.space — نلتزم بالرد خلال ٣٠ يوماً.

٩. القاصرون

الخدمة غير موجّهة للأشخاص دون سن ١٨. إذا اكتشفنا جمع بيانات لقاصر دون موافقة وليّ الأمر، نحذفها فوراً.

١٠. الملفات التعريفية والتتبّع

نستخدم ملفات تعريف ضرورية فقط لتشغيل الجلسة وتذكّر اللغة. لا نستخدم ملفات تعريف للإعلانات المستهدفة. تعمل أداة رصد الأخطاء (Sentry) فقط بعد ضغطك على "السماح بالكل" في بانر الموافقة. للتفاصيل، راجع سياسة ملفات تعريف الارتباط.

١١. إخطار التغييرات

عند تغيير جوهري، نُخطرك عبر البريد الإلكتروني ولوحة التحكم قبل ١٤ يوماً. الاستمرار في استخدام الخدمة بعد التغيير يُعدّ موافقة. نحفظ نسخاً سابقة من السياسة عند الطلب.

١٢. مسؤول حماية البيانات الشخصية والتواصل

مسؤول حماية البيانات الشخصية المعيَّن لدى نُوكس هو عبدالله عادل الصاعدي، ويمكن التواصل معه مباشرة عبر privacy@nooks.space. تُرسَل طلبات أصحاب البيانات واستفسارات الخصوصية إلى هذا البريد.

نُوكس مُسجّلة لدى الهيئة السعودية للبيانات والذكاء الاصطناعي (سدايا) في السجل الوطني لحماية البيانات الشخصية برقم 3260007240.

١٣. القانون الواجب التطبيق

تخضع هذه السياسة لأنظمة المملكة العربية السعودية. عند التعارض بين النسخة العربية والإنجليزية، تسود النسخة العربية.

Privacy Policy

Effective: 24 July 2026 · Version 2.1

1. Introduction & Scope

This Policy explains how Nooks Software Technologies Est. ("Nooks," "we," "us") collects, uses, and protects personal data, in compliance with the Saudi Personal Data Protection Law (PDPL) issued by Royal Decree No. M/19 dated 9/2/1443H and its Implementing Regulations.

This Policy covers two distinct user populations:

  • Merchants: business owners who sign up to the Nooks platform via nooks.space. Nooks is the data controller for merchant account data.
  • End-Customers: individuals who use a merchant's white-label app to place orders. The merchant is the data controller for their data; Nooks is the data processor on the merchant's behalf under our Data Processing Addendum (DPA).

Each merchant's app contains its own customer-facing privacy notice covering processing of end-customer data.

2. Data We Collect About Merchants

  • Account data: full name, email, mobile, business trade name, commercial registration number, and business address.
  • Billing data: subscription history, Moyasar customer ID, last 4 digits of card, expiry date. We never store full PAN.
  • Integration data: Foodics access tokens, Moyasar settings, Apple Pay certificates, payment provider credentials.
  • Usage data: dashboard login logs, IP address, browser type, device fingerprint.
  • Communications: emails exchanged with our support team.
  • Team data: names and mobile numbers of managers added to the merchant account.

3. Data We Process On Behalf Of Merchants

When an end-customer signs up to a merchant's app, the merchant is the controller. We process the following on their behalf:

  • Customer mobile, name, optional email.
  • Order history, delivery addresses, GPS coordinates.
  • Payment tokens issued by Moyasar (no full card data on our side).
  • Push notification tokens (Apple/Google).
  • OTP request logs and timestamps (30 days).
  • Complaint photos, wallet balance, loyalty points.

The Nooks platform uses a single phone-number-based customer identity across all merchants running on Nooks, so a customer can sign in to any Nooks-powered store with the same mobile number without creating a new account each time. This identity is purely technical (to simplify sign-in); each merchant's order, loyalty, and wallet data remain separate and are not visible to other merchants.

4. Legal Basis for Processing

  • Contract performance: most processing is necessary to deliver the platform.
  • Consent: location tracking, email campaigns.
  • Promotional notifications: sent by the merchant — who is the data controller for their own customers — through platform tools, to app users who have enabled notifications. Under our Terms the merchant is responsible for obtaining any consent the law requires. Users can stop them at any time by disabling notifications for the app in their device settings.
  • Legitimate interest: fraud prevention, system security, service improvement.
  • Legal obligation: retaining financial records as required by ZATCA and SAMA.

5. Sharing With Sub-Processors

We do not sell your personal data. We share it only with technical partners necessary to operate the service:

  • Supabase — database hosting (data centers in Europe/Asia).
  • Moyasar — payment processing (licensed by SAMA).
  • Foodics — POS integration.
  • Foodics DMS — order delivery.
  • Corbit (المدار التقني) — SMS and OTP delivery.
  • Resend — transactional email.
  • Apple Push (APNs) and Firebase (FCM) — push notification delivery.
  • Vercel and Railway — server hosting.
  • Sentry — anonymized error tracking.
  • Mapbox — geocoding addresses.
  • Government authorities: upon valid legal request under Saudi law.

Some data is transferred to servers outside Saudi Arabia (EU, Asia, US). This transfer is carried out under contractual clauses equivalent to SDAIA's Standard Contractual Clauses, supported by documented transfer risk assessments prepared in line with SDAIA's Personal Data Transfer Regulations.

6. Data Security

  • TLS 1.2+ encryption for all communications.
  • Passwords are hashed with Argon2id via Supabase Auth — we never store them in plain text.
  • Payment/integration tokens (Moyasar, Foodics) and merchant API keys are encrypted at rest with AES-256-GCM.
  • On mobile devices, session tokens are stored in iOS Keychain / Android Keystore.
  • We never store full PAN — all payments are tokenized end-to-end via Moyasar per PCI-DSS standards.
  • Strict database access controls (Row-Level Security), regular log audits.
  • Daily automated backups.
  • If a breach affecting your data is detected, we commit to notifying you within 72 hours per PDPL requirements.

7. Data Retention

  • Active account data: for the duration of the subscription.
  • Financial and order records: 7 years (ZATCA and SAMA requirements).
  • OTP logs: 30 days.
  • Push tokens: until app uninstall or notifications disabled.
  • On account deletion: personal data deleted within 30 days; order records anonymized (preserved for accounting purposes without identifying data).

8. Your Rights (PDPL)

  • Right of access: request a copy of your data.
  • Right to rectification: correct inaccurate data.
  • Right to erasure: request deletion, except where retention is legally required.
  • Right to object: opt out of direct marketing processing.
  • Right to withdraw consent: at any time.
  • Right to data portability: receive a machine-readable copy.

To exercise any of these rights, contact: privacy@nooks.space — we will respond within 30 days.

9. Minors

The service is not directed at individuals under 18. If we discover we have collected data on a minor without guardian consent, we will delete it immediately.

10. Cookies & Tracking

We use only strictly-necessary cookies for session and language preference. We do not use cookies for targeted advertising. Error monitoring (Sentry) only runs after you click "Allow all" on the consent banner. For details, see our Cookie Policy.

11. Notification of Changes

For material changes, we will notify you by email and dashboard banner at least 14 days in advance. Continued use of the service after the change constitutes acceptance. We retain past versions of this policy upon request.

12. Data Protection Officer & Contact

Nooks' appointed Data Protection Officer is Abdullah Adel Alsaedi, reachable directly at privacy@nooks.space. Data-subject requests and privacy enquiries should be sent to this address.

Nooks is registered with the Saudi Data & AI Authority (SDAIA) in the National Register of Personal Data Protection under No. 3260007240.

13. Governing Law

This Policy is governed by the laws of the Kingdom of Saudi Arabia. In case of any conflict between the Arabic and English versions, the Arabic version prevails.

← Back to home