Privacy Policy

At SUFRA we respect your privacy and protect your personal data in line with Saudi Arabia’s Personal Data Protection Law (PDPL).

Last updated: 2026-08-22

01Data we collect

Account data: name, email, phone and preferred language when you register.

Operational data: the menus, orders, reservations and invoices created as you use the platform.

Guest data: name, phone and optional email when a guest orders or books, plus any dietary preferences or allergies the guest enters.

Technical data: sign-in records, IP address and device type, for security and fault diagnosis.

02Card data — we never store it

Your card details are never stored on SUFRA servers. Payments are processed entirely by our partner Tap Payments, which receives and holds the card data.

When a card is saved for recurring payment, we store only a Tap-issued token, the last four digits and the card type — none of which can be used to take a payment outside the platform.

03Why we process your data (lawful basis)

Performance of a contract: running your account and processing orders, reservations, payments and invoices.

Legal obligation: retaining invoices and tax records as required under Saudi law, including VAT.

Legitimate interest: platform security, fraud prevention and service improvement, where this does not override your rights.

Consent: marketing messages. You may withdraw consent at any time without affecting your service.

04Data sharing

We do not sell your data. We share it only with service providers acting on our behalf and only as needed: Tap Payments for payments, email and SMS providers for notifications, and hosting and storage providers.

Where a restaurant handles a refund or settlement, we share only the related order or reservation data with that restaurant.

We may disclose data where required by applicable law or a competent authority.

05Retention

Account data: for as long as the account is active, then deleted or anonymised within a reasonable period after closure.

Order, invoice and transaction records: retained for the period required by Saudi accounting and tax rules, and not deleted on request where that would conflict with this obligation.

Technical logs: a short period sufficient for security and fault diagnosis.

06Your rights under the PDPL

You have the right to be informed how your data is processed, to access it and obtain a copy, to have it corrected, to request its destruction, and to withdraw consent where processing relies on consent.

These rights may be limited by a legal obligation on us, such as retaining tax records.

We respond within the periods set by the law, and may ask you to verify your identity first.

07Contacting us about your data

For data or privacy requests, write to hello@sufr.ai or use the “Contact us” page, with “Personal data request” in the subject.

If you are not satisfied with our response, you may complain to the competent data protection authority in Saudi Arabia.

08Information security

We apply technical and organisational safeguards including encryption in transit, role-based access control, and isolation of each restaurant’s data from every other.

No method is perfectly secure. Where an incident requires it, we will notify affected people and the competent authority.

09Changes to this policy

We may update this policy as the service or the law changes. The last-updated date appears at the top of this page, and we will notify you of material changes by email or in the platform.