Privacy policy
1. Introduction
Makein Company, in its capacity as the owner and operator of the Tote platform, respects the privacy of the application's users and is committed to protecting the personal data collected or processed when using the application or benefiting from its services.
This policy explains how customers' personal data is collected, the purposes of its use, sharing mechanisms, retention periods, and the rights associated with it, in compliance with the laws and regulations in force in the Kingdom of Saudi Arabia.
The customer’s use of the application, creation of an account, completion of an order, or utilization of any of the platform’s services constitutes an acknowledgment of having reviewed and agreed to this policy within the limits permitted by applicable laws.
2. Definitions
For the purposes of this policy, the following terms shall have the meanings assigned to them below, unless the context requires otherwise:
The Platform / The Application: Tote application.
The Company: Makein Company.
The Customer: Any person who uses the application, creates an account, or requests a product or service through the platform.
The Merchant / The Store: The establishment or store registered on the platform to display and sell its products or services.
Personal Data: Any data that would lead to the specific identification of the customer, or make their identification possible, whether directly or indirectly.
Processing: Any operation performed on personal data, whether by automated or manual means, such as collecting, recording, storing, updating, using, sharing, or destroying.
Service Providers: Entities contracted by the Company to provide supporting services, such as payment, hosting, messaging, technical support, analytics, or delivery services.
3. Data We May Collect
The Company may collect and process the following categories of data depending on the nature of the customer’s use of the application:
3.1 Account and Identification Data
Name
Mobile number
Email address
Encrypted password or login credentials
Verification or authentication information when required
3.2 Order and Transaction Data
Order details
Requested products or services
Order value
Time and date of the order
Order status
Cancellation or refund data
Relevant invoices or financial notifications
3.3 Payment Data
Payment data may be processed through approved payment providers and may include:
Payment method
Transaction status
Transaction reference or number
Limited financial data necessary to complete the transaction
Unless required otherwise by law or technical integration, the Company does not retain full sensitive bank card data when processed through approved payment providers.
3.4 Location Data
When location services are activated, we may collect:
The customer's current location
Delivery address
Saved locations
Data associated with identifying the nearest store or improving delivery services
3.5 Technical and Usage Data
Device type
Operating system
Internet Protocol (IP) address
Browser type or application version
Interaction history within the application
Access and usage times
Crash and performance data
3.6 Communication and Support Data
Messages and inquiries
Reports and complaints
Feedback and ratings
Recordings or correspondence related to customer service when required for statutory or operational purposes
4. How Data is Collected
Personal data may be collected through one or more of the following means:
Directly from the customer upon registration, completing an order, or contacting support.
When using the application, browsing its content, or interacting with its services.
Through the merchant, to the extent necessary to execute the order, handle a complaint, or process a refund.
Through payment, delivery, verification, or analytics service providers.
Through cookies or similar technical tools, if any, within the limits permitted by the usage environment.
5. Purposes of Data Use
The Company collects and processes personal data for the following purposes:
Creating and managing the account, and verifying the user's identity.
Enabling the customer to use the application and complete orders.
Processing payments, cancellations, and refunds.
Executing orders and coordinating with stores and delivery providers.
Sending notifications related to orders, the account, or support.
Improving the user experience and raising the quality of services.
Monitoring technical glitches and enhancing performance and security.
Resolving complaints, reports, and disputes.
Complying with statutory, regulatory, and legal requirements.
Detecting and mitigating fraud, misuse, or security risks.
Preparing internal reports, operational analyses, and statistics.
6. Legal Basis for Data Processing
Personal data is processed in accordance with recognized legal bases, which may include:
The customer's consent, when required.
The execution of a service or order to which the customer is a party.
Compliance with statutory or regulatory requirements.
Realizing the legitimate interests of the Company, provided they do not prejudice the customer's rights or conflict with applicable laws.
7. Data Sharing and Disclosure
The Company may share or disclose personal data within the necessary limits and for legitimate purposes with the following entities:
The Merchant / Store concerned with the order, to the extent necessary to execute, process, or service the order.
Payment Providers, to complete and verify financial transactions.
Delivery Providers, to execute drop-off or pickup services.
Technical Service Providers, such as hosting, technical support, SMS text messaging, notifications, analytics, and security tools.
Competent Government, Judicial, or Regulatory Authorities, whenever requested in accordance with applicable laws.
Advisors, Auditors, or Operational Partners, within necessary limits and under appropriate obligations of confidentiality and compliance.
The Company does not sell customers' personal data as standalone data for purely commercial purposes without a statutory justification.
8. Data Retention
The Company retains personal data for the period necessary to achieve the purposes for which it was collected, or for the duration required by statutory, accounting, tax, or regulatory requirements, or for the purposes of establishing rights, resolving disputes, or maintaining security and operational compliance.
When the legitimate or statutory need to retain the data ends, it will be destroyed or anonymized in accordance with appropriate procedures.
9. Data Protection and Information Security
The Company implements reasonable technical, organizational, and administrative measures to protect personal data from unauthorized access, use, alteration, disclosure, or unlawful destruction. This includes access controls, technical protection, privilege reviews, and operational security procedures.
However, absolute information security cannot be guaranteed under all circumstances. The customer acknowledges the inherent risks of the digital environment, while the Company commits to exercising reasonable care.
10. Customer Rights
Subject to the laws and regulations in force in the Kingdom of Saudi Arabia, the customer may enjoy the following rights regarding their personal data:
The right to be informed about how their personal data is collected and the legal basis for its processing.
The right to access their personal data or request to review it.
The right to request the correction or updating of inaccurate or incomplete data.
The right to request the destruction of data when the statutory justification for retaining it no longer exists, provided this does not conflict with statutory obligations.
The right to withdraw consent in cases where processing is based on consent, without affecting the lawfulness of the prior processing.
Any other rights prescribed by relevant regulations.
The Company may request necessary information to verify the identity of the applicant before responding to any request.
11. Messages and Notifications
The Company may send notifications and messages to the customer regarding:
Account creation or confirmation.
Order status.
Payments and refunds.
Technical support and customer service.
Material updates concerning the service or policies.
Marketing messages, if enabled and in compliance with regulations and the choices available to the customer.
12. Third-Party Links and Services
The application may include services, links, or integrations belonging to third parties, such as payment providers, stores, or delivery providers. The practices of those entities are subject to their own policies, and the Company is not responsible for their privacy practices outside the scope of its direct services.
13. Minors' Privacy
The platform does not intentionally target or collect personal data from minors in violation of applicable laws. If the Company becomes aware that data has been collected in a manner that complies with regulations, it will take appropriate measures to address or delete it as required by law.
14. Amendments to the Policy
The Company reserves the right to amend this policy from time to time. Amendments shall become effective from the date they are published via the application or by any appropriate means. The customer’s continued use of the platform after updates come into effect constitutes approval of them within the limits permitted by regulations.
15. Contact Us
For inquiries or requests regarding privacy or personal data, the customer can communicate with the platform via the approved support channels inside the Tote application or through official communication means.