1. Controller and contact
Rihla Mumayyazah is the controller of personal data collected through this platform for reservation, operations, customer service and permitted analytics purposes. Privacy questions and requests can be sent to rihlamumiyaza@gmail.com.
2. Scope
This notice applies to website visitors, customers, travellers and people whose details are included in a reservation request, together with operational data associated with referrals, tickets and customer-service requests. Staff-account data is governed by separate internal access controls.
3. Personal data we collect
We may collect a name, mobile number, a separate WhatsApp number where provided, nationality, identity-document type and number, route and travel dates, selected service, branch or agent attribution, reservation and attendance state, collection/payment status, consent evidence, and limited technical data needed for security and first-party referral measurement. We do not store payment-card details because this platform does not offer online payment.
4. How we collect data
We collect data directly when a reservation form or service request is submitted, and from authorized staff when they record or correct operational information while serving a customer. We also record limited technical events when referral links or platform interfaces are used, using random or pseudonymous identifiers instead of direct identity wherever practicable.
5. Purposes and legal bases
We process data needed to receive a reservation request, calculate the authoritative price, contact the customer, perform the requested service, issue a ticket, prevent duplicate active reservations, verify travellers at authorized arrival, handle changes and cancellations, maintain operational and security records, and meet applicable legal obligations. Service processing is based on carrying out arrangements requested by the customer or the applicable service agreement and on legal obligations where they apply. Consent is used where it is the appropriate legal basis. Marketing consent is always separate, optional and withdrawable.
6. Mandatory and optional data
Fields marked as required are needed to process the reservation and perform operational verification, including core contact and traveller information. If required data is not provided, we may be unable to create the request, issue the ticket or complete arrival verification. A separate WhatsApp number is optional when the mobile number is suitable, and marketing consent is always optional and does not affect the service.
7. Who can access personal data
Staff receive only the minimum access required by their role. A sales agent can access reservations assigned to that agent within the permitted workflow; a branch manager can access operational data for the assigned branch; marketing receives disclosure-controlled aggregate reports and no passenger-level personal data. The CEO and developer have broader audited executive access. Identity-document numbers are encrypted and shown in full only for an authorized operational arrival check or audited executive access.
8. Processors and disclosures
We use Supabase for database, authentication, storage and realtime services, and Vercel for web hosting, distribution and server execution. These providers process data to supply the technical services used by the platform. We do not sell personal data. We disclose personal data to another party only when needed to provide the service, based on valid consent, or where required by law or a binding request from a competent authority.
9. Processing and transfers outside Saudi Arabia
The primary database is hosted in the Seoul, South Korea region. Web hosting and delivery may involve Vercel infrastructure and provider processing locations outside Saudi Arabia. Transfers are limited to what is necessary to provide the service and are handled in accordance with the Saudi Personal Data Protection Law and the Regulation on Personal Data Transfer outside the Kingdom, using the protection level and appropriate safeguards required for the destination and processing activity.
10. Retention and destruction
Private customer-link and QR access expires seven days after the completed journey. Operational identity-document data, including encrypted value, fingerprint and last four characters, is removed 90 days after a reservation reaches a terminal state under the platform retention policy. Raw analytics is retained for no more than 40 Riyadh calendar days and is then converted to anonymous aggregate statistics without visitor or session identifiers. Records that must be retained by law are kept for the required period and then securely destroyed so they cannot be restored.
11. First-party analytics and referrals
We use first-party analytics to measure referral-link visits, reservation stages and interface performance. We do not use this data to create advertising profiles about travellers and do not send passenger personal data to an advertising platform. Short-lived pseudonymous identifiers are used for raw events; raw records are deleted under the retention schedule while anonymous aggregate statistics are retained.
12. Interface experiments
We may run limited presentation experiments, such as button wording or section order, to improve clarity. These experiments do not change a customer's price, eligibility, legal rights or reservation-approval outcome, and identity-document or sensitive data is not used to make an automated decision about an individual.
13. Security measures
We use encryption for stored contact and identity-document values, separate keyed fingerprints for duplicate prevention, database-level access controls, multi-factor authentication for privileged accounts, append-only audit records for sensitive operations, high-entropy private and ticket credentials, role separation, session timeouts, and defined retention controls.
14. Your rights and how to exercise them
You have the right to be informed of the legal basis and purpose of collection, to access personal data held about you, to request a readable and clear copy, to request correction, completion or updating, and to request destruction when the data is no longer needed, subject to lawful retention cases. Submit an access, correction or destruction request to rihlamumiyaza@gmail.com. We verify the requester before disclosing personal data or changing a reservation record.
15. Withdrawing consent and marketing
You may withdraw optional marketing consent at any time through the private request channel or by contacting rihlamumiyaza@gmail.com. Withdrawal of marketing consent does not stop processing that remains necessary to perform an active reservation or satisfy a legal obligation.
16. Complaints
Send a privacy concern first to rihlamumiyaza@gmail.com so it can be investigated and answered. A personal data subject may also use the official channels of the Saudi Data & AI Authority (SDAIA), the competent personal-data-protection authority in Saudi Arabia.
17. Changes to this notice
The current version of this notice is published on this page. If a material change affects processing purposes, data categories or data-subject rights, the notice is updated before the changed processing is applied to new collection, and the applicable policy version is retained with required consent evidence.
Response to rights requests
Rihla Mumayyazah accepts data-rights requests at rihlamumiyaza@gmail.com. We verify the requester’s identity before disclosing, correcting or destroying personal data. We act on a request without delay and within no more than 30 days after receipt. Where implementation requires disproportionate effort or the same person submits multiple requests, the period may be extended by no more than a further 30 days, with advance notice explaining the reason for the extension.
Complaints and objections
A complaint or objection about personal-data processing or the exercise of your rights may be sent to Rihla Mumayyazah Privacy at rihlamumiyaza@gmail.com. The complaint is recorded, reviewed and answered through the contact channel you provide. If you are dissatisfied with the outcome, you may complain to the Saudi Data & AI Authority (SDAIA), the Competent Authority that receives PDPL complaints. Under the Implementing Regulations, a complaint to the Competent Authority may be submitted within 90 days from the incident or from becoming aware of it, subject to the Authority’s ability to accept a later complaint where factual reasons prevented timely filing.
Privacy channels and update record
Electronic privacy channel: rihlamumiyaza@gmail.com. Website: https://rihla-mumayyazah-platform.vercel.app. This version of the Privacy Notice is effective 25 August 2026. If we materially change the purposes of processing, data categories, disclosures, transfers or retention periods, this page will be updated before the change takes effect where prior notice is required.
Compensation
A Data Subject who suffers material or moral harm as a result of a violation of the Personal Data Protection Law or its Regulations may claim compensation through the applicable legal procedures.