Privacy and Cookie Policy
User Privacy and Data Confidentiality Policy
Version 1 | Last updated: 5 September 2026
The Arabic version of this document is the original, authoritative and governing version for interpretation and application. The English version is provided for convenience only. In the event of any conflict, inconsistency or ambiguity between the two versions, the Arabic version shall prevail to the extent permitted by the laws and regulations of the Kingdom of Saudi Arabia.
This is a privacy notice, not blanket consent. OTNZA requests separate consent where consent is the legally required basis for processing.
1. Controller and Scope
Otnza Company for Communications and Information Technology LLC controls personal data collected for user registration, Platform operation, support, security and compliance. A merchant may independently control data required to fulfil its order. This notice is made available through the OTNZA website or Platform in accordance with applicable legal requirements and applies to the website, applications and support channels.
2. Data We Collect
- Identity and contact details supplied by the user.
- Account and verification data; passwords are stored in protected hashed form and card security codes are not accessed.
- Order, payment, invoice, shipping, return, support and review data.
- Device, technical log, network address and cookie identifiers where used.
- Fraud, security and compliance indicators where necessary.
3. Sources
Data comes from the user, Platform use, merchants, OTNZA's current contracted payment service provider HyperPay, delivery, verification and support providers, and competent or lawfully available sources where needed for compliance or fraud prevention. OTNZA may also receive payment-transfer or refund status data from a bank or payment provider where required to service the order.
4. Mandatory and Optional Data
Collection forms identify mandatory fields. Without registration, delivery or payment data, the account or order may not be completed. Marketing, survey and optional feature data is not required for the core service.
5. Purposes and Legal Bases
- Contract performance: accounts, orders, payment, delivery, returns and support.
- Legal obligation: invoicing, accounting, records and authority requests.
- Legitimate interests: security, fraud prevention, service performance and improvement after balancing rights.
- Consent: non-essential marketing, cookies or uses requiring separate consent; withdrawal is prospective.
6. Sharing
Only necessary data is shared with the relevant merchant, OTNZA's current contracted payment service provider HyperPay, delivery, hosting, messaging, verification, support and professional providers, advisers and competent authorities. Limited transaction-reference data may pass through the bank receiving funds into OTNZA's account - currently Alinma Bank - to the extent necessary for collection, settlement and refunds. Personal data is not sold, and processors and service providers are subject to appropriate contractual and security safeguards according to their role.
7. Payment Data
Sensitive card data goes directly to the payment provider where it hosts or processes payment elements; the current provider is HyperPay. OTNZA may retain a payment token, last four digits, method type, transaction status and collection/refund references for order, support, accounting and settlement purposes, but not the full card number or security code. After successful collection, the payment provider transfers funds to OTNZA under its banking arrangements; this does not mean OTNZA stores sensitive card data or operates a user wallet.
8. International Transfers
Limited hosting or access may occur outside Saudi Arabia through international technology providers after establishing a lawful transfer basis and required safeguards, assessments and approvals. Relevant country and recipient-category information may be requested.
9. Retention and Destruction
OTNZA applies data minimisation and assigns each category a purpose and retention trigger. The periods below are standard operational maximums unless a binding law, claim or documented investigation requires a shorter or longer period. At expiry, active data is erased, securely destroyed or irreversibly anonymised. Deletion is paused only for a defined legal hold and resumes when the hold ends. Backups remain protected until their scheduled rotation and deletion.
9.1. Standard Retention Schedule| Data category | Maximum standard period | Purpose / note |
|---|---|---|
| Incomplete registration | 90 days after last activity | Completion or abuse prevention; then deletion unless an investigation exists. |
| User account and profile | Account life + 2 years after closure | Account operation, support, claims and security; unnecessary fields are deleted or isolated earlier when the purpose ends, while order and financial records are retained separately under their applicable periods. |
| Orders, contracts, invoices, credit notes and settlements | 10 years from the relevant financial year-end | Commercial, tax, accounting and audit records, or a longer current statutory period. |
| Payment references, tokens and masked digits | 10 years for a financial reference forming part of a commercial or financial record; technical tokens only until the operational need ends or for a shorter period | Reconciliation, disputes and audit. OTNZA does not store full card numbers or security codes where payment is provider-hosted, and unnecessary technical tokens are deleted when their purpose ends. |
| Delivery and proof | 5 years after delivery or claim closure, whichever is later | Performance and loss/damage claims. |
| Returns, warranty, complaints and support | 5 years after closure or warranty end, whichever is later | Customer service and claim evidence. |
| Privacy/marketing choices and notice versions | Processing period + 5 years | Evidence of choice, displayed notice version and withdrawal. |
| Login, security and technical logs | Up to 2 years | Security, investigation and continuity; shorter where sufficient. |
| Non-essential cookies | Up to 12 months or the period shown in the preference tool | Analytics, personalisation or marketing according to choice. |
| Fraud, chargeback and investigation | Up to 5 years after final closure, or for the duration of an active investigation or claim, or longer where binding law or a binding provider requirement applies | Rights, compliance and repeat prevention with restricted access and periodic necessity review. |
| Data incidents, impact assessments and audits | 5 years after closure or longer if required by law | Response and remediation evidence. |
| Rotating backups | Up to 90 days after active deletion | Recovery and continuity; isolated and not reused except lawful restoration. |
| Irreversibly anonymised data | May be retained without a fixed period | No longer personal data after effective anonymisation. |
10. Security
Appropriate controls include access management, least privilege, encryption in transit, backups, monitoring, vulnerability management and incident response. No method is absolutely secure and this Policy is not a guarantee that an incident can never occur.
11. Cookies
Necessary cookies operate the account, basket and security. Non-essential analytics or advertising cookies are activated according to the consent control where required, and choices can later be changed.
12. Marketing
Marketing uses consent or another lawful basis and includes an easy opt-out. Opting out does not stop necessary order, security or invoice communications.
13. Rights
Rights include information, access, a copy, correction, destruction, consent withdrawal and complaint or objection where applicable. OTNZA verifies identity and responds within 30 days, extendable once by a further 30 days where needed with notice.
14. Automated Processing
Automated signals may support fraud detection, search ranking and recommendations. No solely automated decision with a material legal effect is made without safeguards or review required by law.
15. Minors
The Platform does not target independent accounts for persons under 18. If such data is collected without an appropriate basis, OTNZA will verify, restrict or destroy it as appropriate.
16. Data Incidents
OTNZA documents and assesses incidents, notifies the competent authority within the legally required period where thresholds are met, and notifies affected persons without undue delay where rights or interests may be harmed.
17. Requests and Complaints
Contact [email protected], https://www.otnza.com (also accessible at https://otnza.com), or 920034600. An unresolved complaint may be submitted to the Saudi competent personal-data authority.
18. Updates
Updates carry a version and effective date, with notice of material changes. Existing consent is not reused for a new incompatible purpose where new consent is required.