قراري
This English text is a convenience translation; the Arabic version is the binding original and prevails on any conflict. Effective date: 25 July 2026.

Privacy Policy

Effective date: 25 July 2026


The short version (read this first)

Qarari is software used by online-store owners. We do not own the store's customers or deal with them directly; we are a tool the store owner hires to understand their store and make better decisions. Plainly:

The rest of this document explains each point in detail.


Summary table: what data, why, who sees it, how long

DataWhy we touch itWho sees itHow long
Orders (order, status, value, line items)To compute forecasts, reorder timing, and offer results for your storeThe store's merchant only, plus our technical team when needed to run and support the serviceFor the store's subscription, then deleted on the merchant's written request
Products & inventory (prices, stock levels)Stockout alerts and reorder decisionsThe merchant only + our technical teamFor the subscription, then deleted on request
Shopper browsing events (pages, cart — with consent only)To measure offers and understand buying patterns for your storeThe merchant only, in anonymized/aggregate formAnonymous mapping auto-deleted after 13 months
Customer identifiers (phone and email as received from the Platform, plus its own customer reference and the customer's country; the name is not stored)To message the customer on the merchant's behalf (cart reminder/offers), link their orders, and determine their legal basisIsolated; phone and email encrypted; not read by our team in analysis; revealed only to fulfil a lawful merchant requestFor the subscription; erased on a deletion request
Product cost / margin (entered by the merchant)To compute net profit in the merchant's reportsThe merchant only; encrypted at our endFor the subscription, then deleted on request
Merchant account (store name, contact email)To run the account, billing, supportOur teamFor the subscription + a statutory billing period
Offer-experiment dataTo measure each offer's profit impact vs. doing nothingThe merchant only, anonymizedAuto-deleted after the experiment ends (60-day window + 90 days); only non-identifying aggregates remain
IP addressTo derive the city onlyOur team, transiently in operational logsNot kept in analytics data — discarded after the city is derived

1. Who we are and our role

  1. Responsible entity. "Qarari" (qarari.net) is a product of Dal Dom Group for Business Services (Unified Number 7027532691, VAT 302013762100003, Maroof 373566), registered in the Kingdom of Saudi Arabia. Registered national address: Building 3384, Street 14A, Al Badi District, Secondary No. 8243, Postal Code 32415, Dammam, Kingdom of Saudi Arabia (Short Address: EMAA3384).
  2. Our legal role — plainly. We are the Processor: the party that processes data on the merchant's behalf and on their instructions. The merchant is the Controller: the one who decides about their customers' and store visitors' data. This relationship is governed by the Data Processing Agreement (dpa.md) annexed to the Terms of Service.
  3. What this means for a shopper. If you are a shopper, your primary relationship is with the store you bought from, which decides about your data. We act on its direction. You may exercise your rights through it, or write to us directly and we will assist it in fulfilling your request.
  4. Governing frame. The Saudi Personal Data Protection Law (PDPL) and its regulations are the basis. The service architecture is GDPR-ready for serving future EU merchants (Sections 4 and 8).

2. What data we collect

We collect only what serves the service — no more (data minimization):

  1. Order data: orders, statuses, values, and line items, from the Platform's official APIs (Salla first, then others).
  2. Product and inventory data: products, prices, stock levels.
  3. Shopper browsing events — with consent only: on-site events (pages, cart) collected via a consent-gated pixel (measurement tag). These events are stripped of personal identifiers at the ingestion boundary before any storage, and carry only an internal id that does not reveal any specific person. *(Precise disclosure: the consent-capture surface — the pixel consent banner — is still being built and is not yet live; until it is, no marketing message is ever sent to EU/UK shoppers — see Sections 4 and 5.)*
  4. Customer identifiers: phone and email as received from the Platform, isolated in a restricted identity store and encrypted at rest (Section 5), together with the Platform's own customer reference and the customer's country, which are stored unencrypted and used to link that customer's orders and to determine their legal basis (Section 4). We do not store the customer's name: where a Platform's payload carries one it is dropped before storage, and there is no field for it. The keys used in analysis are irreversible pseudonymized digests.
  5. Product cost / margin: values the merchant enters to compute their net profit, encrypted at rest at our end.
  6. Merchant account data: store name and contact email, to run the account, billing, and support.

What we do NOT do (honestly):

3. Why we process this data (purposes)

We process data solely to run the Service described in the Terms:

  1. Forecasts and reorder decisions: forecasting demand per product, flagging stockout risk and reorder timing — for the merchant.
  2. Measured offers: running the merchant's offers on their store and measuring their profit impact vs. doing nothing.
  3. Behavioral patterns: surfacing the store's buying patterns (day-of-week, payday cycle, seasons) — for that store alone.
  4. Messaging on the merchant's behalf: cart reminders and offers to the merchant's customers within the lawful-basis gates (Section 4).
  5. Billing, support, and running the account.
  6. Aggregate, anonymized sector indicators (Section 2) — collective benchmarking that identifies no one.

4. Legal basis for processing (honestly)

We determine the legal basis by the customer's country, not their network address:

CaseLegal basis
Plain cart reminder (no offer)Legitimate interest: a continuation of a purchase the customer began, with objection/unsubscribe always honored
Offer messages (marketing)Explicit consent — required in all cases
EU/UK customers (GDPR)No marketing without recorded explicit consent; the reminder itself needs prior opt-in
GCC customers (PDPL)Reminder rides legitimate interest (opt-out honored); marketing rides consent
Merchant account & billing dataContract performance and legal obligation

*(Precise disclosure: because the consent-capture surface is still being built, marketing messages to GDPR regions are effectively blocked today — not sent on a weak basis. This is a deliberate protection, not a gap.)*

5. Who we share data with, and security

We do not sell or share data for commercial purposes. We rely on a small number of trusted subprocessors to run the service only, and remain responsible for their performance:

SubprocessorPurposeLocation/region
Hetzner Online GmbHServer and database hostingGermany (EU)
Resend, Inc.Transactional and marketing email delivery (the channel currently active)United States — under contractual transfer safeguards (Section 8)
Cloudflare, Inc.DNS management (DNS only)Global
WhatsApp Business messaging providerWhatsApp messaging where you enable the WhatsApp channel for your store; the specific provider is named to you at activationDetermined by the provider at activation

Commerce platforms (Salla — active; and Zid, Shopify, WooCommerce where Qarari is installed from them) are the source of your store data via their official APIs and the billing channel; they act as your store's platform under their own terms, not as our subprocessor.

How we protect your data (actually implemented today):

  1. At-rest encryption — LIVE: the customer's personal data (email and phone) and the cost/margin data are encrypted at rest with AES-256-GCM under a dedicated key and a random encryption IV per value (database migration 046). These values are stored encrypted, not as readable text. The analytics store keeps a derived numeric copy of the cost figure that is not encrypted this way, because encrypted values cannot be summed; its at-rest protection is the disk-level control named in the disclosure below.
  2. Credential encryption — LIVE: platform access tokens are stored encrypted (AES-256-GCM under isolated subkeys) and are never written to audit logs.
  3. Identity isolation and pseudonymization — LIVE: raw data is isolated in a restricted store; analysis paths read only pseudonymized copies restricted to a strict column allowlist (no email, phone, or external identifiers).
  4. Per-store data isolation — LIVE: every API is scoped to a single store; one store's data never mixes with another's.
  5. Stripping at the boundary — LIVE: browsing events are stripped of identifiers before storage; the IP address is discarded after the city is derived.
  6. Anonymity in aggregated outputs — LIVE: any sector indicator is withheld unless at least 5 stores contributed.

*(Precise disclosure — no overclaiming: the consent-capture surface (pixel banner) is still being built and is not yet live. This policy does not claim it is. Accordingly, marketing to GDPR regions is blocked until it is. We hold no external security certification we do not possess. And disk/volume-level encryption of our stored data as a whole is still in progress, not finished. It is a control on the hosting infrastructure, separate from the application-level encryption in item 1 above, which is live.)*

6. Retention and deletion (precisely)

We keep data only while it has a purpose, then delete it. We do not promise an unimplemented automatic store-wide purge. In detail:

  1. Store data (orders, products, customer identifiers, cost): kept for the store's subscription. Upon uninstallation, synchronization stops immediately and access credentials are invalidated. Store-wide deletion is executed on the merchant's written request (privacy@qarari.net) within thirty (30) days of the request.
  2. Standing automatic deletion schedules (actually in force):
  1. Consent and messaging records: an append-only ledger, kept as evidence of the lawful basis and of unsubscribe requests.
  2. IP address: not kept in analytics data; may appear briefly in operational logs (Section 2).
  3. Backups: operational backups are retained for no more than thirty (30) days. If we restore data from a backup, we re-apply to that copy every erasure held in our permanent register (Section 7.2) before it goes back into service, and it does not go back unless all of them ran without failure. The register carries one entry per person whose data we erased, so two things fall outside it: an erasure we carried out after the restored backup was taken, whose entry sits inside that same backup, and a store-wide scrub of a merchant's own account details, which is not written to the register at all. Where either happens we erase the data again as soon as we identify it, and you can make the request again at any time.

7. Your rights and how to exercise them

As a data subject you have the rights the PDPL (and GDPR where it applies) guarantees: access your data, correct it, delete it, object to its processing, and withdraw your consent.

How this works in practice: because we are a Processor acting for the store, your request is usually routed through the store you dealt with (the Controller), or you write to us directly at privacy@qarari.net and we assist the store in fulfilling it. The technical machinery is built and actually in place on our side:

  1. Access/export: we assemble your complete data — across all linked identities (including merged identities) — from identity, message, consent, suppression, and experiment-participation records.
  2. Erasure: we erase your raw personal data across all linked identities, including the anonymous mappings in the analytics store and experiment artifacts, and log every request in a permanent register.
  3. Both are available today via a Merchant-scoped API; a Merchant-facing UI is being built.
  4. We respond without undue delay and within a maximum of thirty (30) days of a completed request, consistent with the PDPL and its regulations.

If you believe your rights were not respected, you may complain to the Saudi Data & AI Authority (SDAIA), or the competent supervisory authority in your country where GDPR applies.

8. Cross-border transfers and data location

Your data is hosted and processed on servers in Germany (EU) at Hetzner, and some data is processed by other subprocessors outside the Kingdom (e.g. Resend in the United States). Because the primary hosting location is outside the Kingdom, transfers of personal data are carried out under the Personal Data Transfer Regulation of the Saudi Data & AI Authority (SDAIA), relying on Standard Contractual Clauses (SCCs) or equivalent approved transfer safeguards. For EU/EEA merchants, their data remains within the EU by virtue of the hosting location.

9. Children

The Service is aimed at store owners, not children. We do not knowingly collect data from anyone below the statutory age, and we do not ask shoppers for age data. Responsibility for the store's audience lies with the merchant (Controller). If we learn a child's data was collected without a lawful basis, we delete it. The reference age is eighteen (18) under Saudi regulations, and sixteen (16) where the EU GDPR applies.

10. Changes to this policy

We may update this policy to track the product or the law. We notify merchants of material changes a reasonable period before they take effect, and show the last-updated date at the top. Continued use of the Service after the effective date constitutes notice of the updated version.

11. Contact

© 2026 قراري · Qarari