This English text is a convenience translation; the Arabic version is the binding original and prevails on any conflict. Effective date: 25 July 2026.
Privacy Policy
Effective date: 25 July 2026
The short version (read this first)
Qarari is software used by online-store owners. We do not own the store's customers or deal with them directly; we are a tool the store owner hires to understand their store and make better decisions. Plainly:
- Who we are. "Qarari" is a product of Dal Dom Group for Business Services, a Saudi company.
- Our role. We are a data Processor — we process data on the store owner's behalf and on their instructions. The store owner is the Controller (the one who decides about their customers' data). So if you are a shopper who bought from a store that uses Qarari, the store is who governs your data, and we are the service they hired.
- What data we touch. The store's orders, products and stock; shoppers' on-site browsing events (with consent only); and the merchant's account/contact and billing details.
- Why. To compute demand forecasts, reorder timing, measured offer results, and behavioral patterns — for that store only.
- What we do NOT do. We do not sell data, do not rent it, and do not leak one store's data to another. The only thing shared across stores is aggregate, anonymized sector indicators that cannot be traced to any store or person.
- Your rights. You may access, correct, and delete your data; exercise them through the store you dealt with, or by writing to privacy@qarari.net.
The rest of this document explains each point in detail.
Summary table: what data, why, who sees it, how long
| Data | Why we touch it | Who sees it | How long |
|---|---|---|---|
| Orders (order, status, value, line items) | To compute forecasts, reorder timing, and offer results for your store | The store's merchant only, plus our technical team when needed to run and support the service | For the store's subscription, then deleted on the merchant's written request |
| Products & inventory (prices, stock levels) | Stockout alerts and reorder decisions | The merchant only + our technical team | For the subscription, then deleted on request |
| Shopper browsing events (pages, cart — with consent only) | To measure offers and understand buying patterns for your store | The merchant only, in anonymized/aggregate form | Anonymous mapping auto-deleted after 13 months |
| Customer identifiers (phone and email as received from the Platform, plus its own customer reference and the customer's country; the name is not stored) | To message the customer on the merchant's behalf (cart reminder/offers), link their orders, and determine their legal basis | Isolated; phone and email encrypted; not read by our team in analysis; revealed only to fulfil a lawful merchant request | For the subscription; erased on a deletion request |
| Product cost / margin (entered by the merchant) | To compute net profit in the merchant's reports | The merchant only; encrypted at our end | For the subscription, then deleted on request |
| Merchant account (store name, contact email) | To run the account, billing, support | Our team | For the subscription + a statutory billing period |
| Offer-experiment data | To measure each offer's profit impact vs. doing nothing | The merchant only, anonymized | Auto-deleted after the experiment ends (60-day window + 90 days); only non-identifying aggregates remain |
| IP address | To derive the city only | Our team, transiently in operational logs | Not kept in analytics data — discarded after the city is derived |
1. Who we are and our role
- Responsible entity. "Qarari" (qarari.net) is a product of Dal Dom Group for Business Services (Unified Number 7027532691, VAT 302013762100003, Maroof 373566), registered in the Kingdom of Saudi Arabia. Registered national address: Building 3384, Street 14A, Al Badi District, Secondary No. 8243, Postal Code 32415, Dammam, Kingdom of Saudi Arabia (Short Address: EMAA3384).
- Our legal role — plainly. We are the Processor: the party that processes data on the merchant's behalf and on their instructions. The merchant is the Controller: the one who decides about their customers' and store visitors' data. This relationship is governed by the Data Processing Agreement (
dpa.md) annexed to the Terms of Service. - What this means for a shopper. If you are a shopper, your primary relationship is with the store you bought from, which decides about your data. We act on its direction. You may exercise your rights through it, or write to us directly and we will assist it in fulfilling your request.
- Governing frame. The Saudi Personal Data Protection Law (PDPL) and its regulations are the basis. The service architecture is GDPR-ready for serving future EU merchants (Sections 4 and 8).
2. What data we collect
We collect only what serves the service — no more (data minimization):
- Order data: orders, statuses, values, and line items, from the Platform's official APIs (Salla first, then others).
- Product and inventory data: products, prices, stock levels.
- Shopper browsing events — with consent only: on-site events (pages, cart) collected via a consent-gated pixel (measurement tag). These events are stripped of personal identifiers at the ingestion boundary before any storage, and carry only an internal id that does not reveal any specific person. *(Precise disclosure: the consent-capture surface — the pixel consent banner — is still being built and is not yet live; until it is, no marketing message is ever sent to EU/UK shoppers — see Sections 4 and 5.)*
- Customer identifiers: phone and email as received from the Platform, isolated in a restricted identity store and encrypted at rest (Section 5), together with the Platform's own customer reference and the customer's country, which are stored unencrypted and used to link that customer's orders and to determine their legal basis (Section 4). We do not store the customer's name: where a Platform's payload carries one it is dropped before storage, and there is no field for it. The keys used in analysis are irreversible pseudonymized digests.
- Product cost / margin: values the merchant enters to compute their net profit, encrypted at rest at our end.
- Merchant account data: store name and contact email, to run the account, billing, and support.
What we do NOT do (honestly):
- We do not sell or rent your data to anyone, for any commercial purpose, ever.
- We do not leak one store's data to another. Each store is isolated. The only thing shared is aggregate sector indicators, no cell of which is shown unless at least five distinct stores contributed — so it can't be traced to a store or person.
- We do not store the IP address in our analytics data. It is used transiently to derive the city and then discarded, may appear briefly in operational server logs, and is used only as a one-way hash to distinguish report opens.
- We do not make automated decisions that affect a shopper's rights. Our outputs are recommendations the merchant decides on.
3. Why we process this data (purposes)
We process data solely to run the Service described in the Terms:
- Forecasts and reorder decisions: forecasting demand per product, flagging stockout risk and reorder timing — for the merchant.
- Measured offers: running the merchant's offers on their store and measuring their profit impact vs. doing nothing.
- Behavioral patterns: surfacing the store's buying patterns (day-of-week, payday cycle, seasons) — for that store alone.
- Messaging on the merchant's behalf: cart reminders and offers to the merchant's customers within the lawful-basis gates (Section 4).
- Billing, support, and running the account.
- Aggregate, anonymized sector indicators (Section 2) — collective benchmarking that identifies no one.
4. Legal basis for processing (honestly)
We determine the legal basis by the customer's country, not their network address:
| Case | Legal basis |
|---|---|
| Plain cart reminder (no offer) | Legitimate interest: a continuation of a purchase the customer began, with objection/unsubscribe always honored |
| Offer messages (marketing) | Explicit consent — required in all cases |
| EU/UK customers (GDPR) | No marketing without recorded explicit consent; the reminder itself needs prior opt-in |
| GCC customers (PDPL) | Reminder rides legitimate interest (opt-out honored); marketing rides consent |
| Merchant account & billing data | Contract performance and legal obligation |
*(Precise disclosure: because the consent-capture surface is still being built, marketing messages to GDPR regions are effectively blocked today — not sent on a weak basis. This is a deliberate protection, not a gap.)*
5. Who we share data with, and security
We do not sell or share data for commercial purposes. We rely on a small number of trusted subprocessors to run the service only, and remain responsible for their performance:
| Subprocessor | Purpose | Location/region |
|---|---|---|
| Hetzner Online GmbH | Server and database hosting | Germany (EU) |
| Resend, Inc. | Transactional and marketing email delivery (the channel currently active) | United States — under contractual transfer safeguards (Section 8) |
| Cloudflare, Inc. | DNS management (DNS only) | Global |
| WhatsApp Business messaging provider | WhatsApp messaging where you enable the WhatsApp channel for your store; the specific provider is named to you at activation | Determined by the provider at activation |
Commerce platforms (Salla — active; and Zid, Shopify, WooCommerce where Qarari is installed from them) are the source of your store data via their official APIs and the billing channel; they act as your store's platform under their own terms, not as our subprocessor.
How we protect your data (actually implemented today):
- At-rest encryption — LIVE: the customer's personal data (email and phone) and the cost/margin data are encrypted at rest with AES-256-GCM under a dedicated key and a random encryption IV per value (database migration 046). These values are stored encrypted, not as readable text. The analytics store keeps a derived numeric copy of the cost figure that is not encrypted this way, because encrypted values cannot be summed; its at-rest protection is the disk-level control named in the disclosure below.
- Credential encryption — LIVE: platform access tokens are stored encrypted (AES-256-GCM under isolated subkeys) and are never written to audit logs.
- Identity isolation and pseudonymization — LIVE: raw data is isolated in a restricted store; analysis paths read only pseudonymized copies restricted to a strict column allowlist (no email, phone, or external identifiers).
- Per-store data isolation — LIVE: every API is scoped to a single store; one store's data never mixes with another's.
- Stripping at the boundary — LIVE: browsing events are stripped of identifiers before storage; the IP address is discarded after the city is derived.
- Anonymity in aggregated outputs — LIVE: any sector indicator is withheld unless at least 5 stores contributed.
*(Precise disclosure — no overclaiming: the consent-capture surface (pixel banner) is still being built and is not yet live. This policy does not claim it is. Accordingly, marketing to GDPR regions is blocked until it is. We hold no external security certification we do not possess. And disk/volume-level encryption of our stored data as a whole is still in progress, not finished. It is a control on the hosting infrastructure, separate from the application-level encryption in item 1 above, which is live.)*
6. Retention and deletion (precisely)
We keep data only while it has a purpose, then delete it. We do not promise an unimplemented automatic store-wide purge. In detail:
- Store data (orders, products, customer identifiers, cost): kept for the store's subscription. Upon uninstallation, synchronization stops immediately and access credentials are invalidated. Store-wide deletion is executed on the merchant's written request (privacy@qarari.net) within thirty (30) days of the request.
- Standing automatic deletion schedules (actually in force):
- Anonymous identity mappings (anonymous id → internal id): auto-deleted after 13 months.
- Offer-experiment data: auto-deleted a fixed period after the experiment ends (60-day measurement window + 90 days), with automated verification of completed deletion; only non-identifying aggregates survive, plus a maximum backstop (15 months) on analytical copies.
- Consent and messaging records: an append-only ledger, kept as evidence of the lawful basis and of unsubscribe requests.
- IP address: not kept in analytics data; may appear briefly in operational logs (Section 2).
- Backups: operational backups are retained for no more than thirty (30) days. If we restore data from a backup, we re-apply to that copy every erasure held in our permanent register (Section 7.2) before it goes back into service, and it does not go back unless all of them ran without failure. The register carries one entry per person whose data we erased, so two things fall outside it: an erasure we carried out after the restored backup was taken, whose entry sits inside that same backup, and a store-wide scrub of a merchant's own account details, which is not written to the register at all. Where either happens we erase the data again as soon as we identify it, and you can make the request again at any time.
7. Your rights and how to exercise them
As a data subject you have the rights the PDPL (and GDPR where it applies) guarantees: access your data, correct it, delete it, object to its processing, and withdraw your consent.
How this works in practice: because we are a Processor acting for the store, your request is usually routed through the store you dealt with (the Controller), or you write to us directly at privacy@qarari.net and we assist the store in fulfilling it. The technical machinery is built and actually in place on our side:
- Access/export: we assemble your complete data — across all linked identities (including merged identities) — from identity, message, consent, suppression, and experiment-participation records.
- Erasure: we erase your raw personal data across all linked identities, including the anonymous mappings in the analytics store and experiment artifacts, and log every request in a permanent register.
- Both are available today via a Merchant-scoped API; a Merchant-facing UI is being built.
- We respond without undue delay and within a maximum of thirty (30) days of a completed request, consistent with the PDPL and its regulations.
If you believe your rights were not respected, you may complain to the Saudi Data & AI Authority (SDAIA), or the competent supervisory authority in your country where GDPR applies.
8. Cross-border transfers and data location
Your data is hosted and processed on servers in Germany (EU) at Hetzner, and some data is processed by other subprocessors outside the Kingdom (e.g. Resend in the United States). Because the primary hosting location is outside the Kingdom, transfers of personal data are carried out under the Personal Data Transfer Regulation of the Saudi Data & AI Authority (SDAIA), relying on Standard Contractual Clauses (SCCs) or equivalent approved transfer safeguards. For EU/EEA merchants, their data remains within the EU by virtue of the hosting location.
9. Children
The Service is aimed at store owners, not children. We do not knowingly collect data from anyone below the statutory age, and we do not ask shoppers for age data. Responsibility for the store's audience lies with the merchant (Controller). If we learn a child's data was collected without a lawful basis, we delete it. The reference age is eighteen (18) under Saudi regulations, and sixteen (16) where the EU GDPR applies.
10. Changes to this policy
We may update this policy to track the product or the law. We notify merchants of material changes a reasonable period before they take effect, and show the last-updated date at the top. Continued use of the Service after the effective date constitutes notice of the updated version.
11. Contact
- Privacy and data-subject requests: privacy@qarari.net
- Support: support@qarari.net
- Data Protection Officer (DPO): no dedicated officer is appointed at this time (not required at the current scale); privacy matters are directed to privacy@qarari.net.
- Entity: Dal Dom Group for Business Services, Kingdom of Saudi Arabia (Unified Number 7027532691).