Privacy Policy
Privacy Policy
Last Updated: 01 / 01 / 2026
Sumaya Rihan (“we,” “our,” or “us”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit or make a purchase from https://sumayarihan.com (the “Website”).
This policy is prepared in accordance with the Saudi Personal Data Protection Law (PDPL) and applicable regulations in the Kingdom of Saudi Arabia.
1. Information We Collect
We collect personal data that you voluntarily provide and data that is automatically collected when you use our Website.
1.1 Personal Data You Provide
When you place an order, create an account, or contact us, we may collect:
- Full name
- Phone number
- Email address
- Billing and shipping address
- Payment details (processed securely via third-party payment providers; we do not store card details)
- Order history and preferences
1.2 Automatically Collected Data
When you browse our Website, we may automatically collect:
- IP address
- Device type and browser
- Pages visited and interaction data
- Cookies and similar tracking technologies
2. Purpose of Data Collection
We collect and use your personal data for legitimate business purposes, including:
- Processing and delivering orders
- Managing payments and refunds
- Communicating order updates and customer support
- Improving website functionality and user experience
- Complying with legal and regulatory obligations in Saudi Arabia
- Preventing fraud and ensuring security
We do not collect more data than necessary for these purposes.
3. Legal Basis for Processing (Saudi PDPL)
Under Saudi PDPL, we process personal data based on:
- Your consent
- Performance of a contract (e.g., order fulfillment)
- Compliance with legal obligations
- Legitimate business interests that do not override your rights
4. Sharing of Personal Data
We do not sell or rent your personal data.
We may share your information only with:
- Payment gateways and banks for transaction processing
- Shipping and logistics partners for order delivery
- IT and hosting service providers
- Government authorities when required by Saudi law
All third parties are required to protect your data and use it only for specified purposes.
5. Data Storage and Security
Your personal data is stored securely using:
- Encrypted servers
- Access control measures
- Industry-standard security practices
We take reasonable technical and organizational measures to prevent unauthorized access, loss, or misuse of your data.
6. Data Retention
We retain personal data only for as long as necessary to:
- Fulfill the purposes outlined in this policy
- Meet legal, accounting, or regulatory requirements in Saudi Arabia
After this period, data is securely deleted or anonymized.
7. Your Rights Under Saudi PDPL
As a user in Saudi Arabia, you have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request deletion of your personal data (where legally permitted)
- Withdraw consent at any time
- Know how your data is being used
To exercise these rights, contact us using the details below.
8. Cookies Policy
Our Website uses cookies to:
- Improve site performance
- Remember user preferences
- Analyze traffic and usage patterns
You can control or disable cookies through your browser settings. Disabling cookies may affect website functionality.
9. Third-Party Links
Our Website may contain links to third-party websites. We are not responsible for the privacy practices or content of those websites. We encourage users to review their privacy policies.
10. Children’s Privacy
Our Website is not intended for individuals under the age of 18. We do not knowingly collect personal data from children.
11. International Data Transfers
If personal data is transferred outside Saudi Arabia, such transfers will comply with Saudi PDPL requirements and ensure adequate data protection measures.
12. Changes to This Privacy Policy
We reserve the right to update this Privacy Policy at any time. Changes will be posted on this page with the updated date. Continued use of the Website constitutes acceptance of the revised policy.