This Privacy Policy explains how Pathly Establishment, a sole establishment registered with the Ministry of Commerce of the Kingdom of Saudi Arabia under Commercial Registration (National Number) 7054446799, owned by Alnuri Abdullah Alharbi, with its registered address at Street 26, Riyadh, Kingdom of Saudi Arabia ("Pathly", "we", "us" or "our"), collects, uses, shares and protects your personal data when you use the Pathly mobile application, the Pathly website, the Pathly Business Dashboard and related services (together, the "Service").
Pathly is the controller of your personal data. We process it in accordance with the Personal Data Protection Law of the Kingdom of Saudi Arabia (Royal Decree M/19 of 1443H, as amended) and its Implementing Regulations (together, the "PDPL"), and, where applicable, the data-protection laws of the country in which you live. This Policy should be read together with our Terms of Use and End User License Agreement, available at https://pathly.sa/terms.html (the "Terms"). Capitalised words not defined here have the meaning given in the Terms.
By creating an account or using the Service you acknowledge that you have read this Policy. Where we rely on your consent, we ask for it separately and you may withdraw it at any time.
Summary: What You Need to Know
This summary is provided for convenience only. The full Policy below prevails if there is any inconsistency.
1Scope of This Policy
This Policy applies to personal data we process about:
(a)individuals who register for and use the Pathly app ("Users");
(b)individuals who register, operate or are named as contacts for a business account on the Business Dashboard ("Business Users");
(c)individuals who apply to an Opportunity posted by a Business ("Applicants"); and
(d)visitors to the Pathly website.
"Personal data" means any information relating to an identified or identifiable individual, as defined in the PDPL.
This Policy does not apply to the practices of third parties that we do not control, including Businesses that receive your application data (see Section 7), Apple, or websites linked from the Service.
2Personal Data We Collect
Part A: Data you give us
Account and identity data. Your mobile telephone number, the one-time verification code exchange, your display name, profile photo and bio, your account settings, and the date your account was created. Your telephone number is required to create an account; the other items are optional or can be changed.
Content you create. Photos, videos, text, moods, stories, reactions, comments and reposts you publish; the time you publish them; and any people, places or things visible in them. Remember that posts are visible to the people who follow you and are automatically deleted 72 hours after publication.
Messages. The content of one-to-one messages you send and receive, the time they are sent, delivery and read status, and records of Coffees sent or received in a conversation. Messages are not end-to-end encrypted; see Section 9.
Social connections. The accounts you follow, the accounts that follow you, the accounts you block, and the posts you react to, comment on or repost.
Application data. When you apply to an Opportunity: your name, registered telephone number, profile photo, any note you write, the date of your application, and status updates made by the Business.
Business registration data. For Business Users: the business name, category, description, location pin and address, opening hours, photos, contact name, telephone number, email address, commercial registration or other verification details we request, and the Opportunities you post.
Purchases. When you buy a subscription, Diamonds or a Coffee through Apple, we receive from Apple a transaction identifier, the product purchased, the price tier, the date, the subscription status (trial, active, expired, cancelled, refunded) and a signed receipt that lets us verify your entitlement. We do not receive or store your card number, bank details or Apple ID password.
Communications with us. Support requests, abuse reports, appeals, data-subject requests and any other correspondence, including the content of the reported post or message and any screenshots you send.
Part B: Data we collect automatically
Device and app data. Device model, operating-system version, app version, language and region settings, time zone, screen size, and whether "Reduce Motion" or other accessibility settings are enabled (used only to adapt the interface).
Identifiers. A random installation identifier generated by Firebase, a push-notification token, and your IP address. We do not collect the Apple advertising identifier (IDFA) and we do not track you across other companies' apps or websites.
Usage data. The features you use, the screens you open, the posts you view (which generates the "Seen by" record shown to the post owner), the time and duration of sessions, and interactions with notifications.
Location data. With your permission, your device's precise or approximate location, used to show businesses and opportunities near you and to sort them by distance. We do not keep a history of your movements. You can turn location access off at any time in your device settings; the map and proximity features will then not work.
Diagnostics. Crash reports, performance data and error logs, which may include device data and the state of the app at the time of the error.
Website cookies. The Pathly website and the Business Dashboard use only strictly necessary cookies to keep you signed in and to protect against fraud. We do not use analytics or advertising cookies. You can control cookies in your browser settings.
Part C: Data we receive from others
From other Users. Content in which you appear or are mentioned, reports made about you, and messages sent to you.
From Businesses. Status updates on your applications.
From Apple and Google Firebase. Purchase and subscription information (from Apple) and authentication and push-delivery information (from Firebase).
Sensitive data. We do not ask for, and you should not provide, sensitive personal data as defined in the PDPL, such as data about your religion, health, ethnic origin, criminal record, or biometric or genetic data. If you choose to include such information in a post, mood, profile or message, you do so at your own discretion and you consent to our processing it for the purposes of providing the Service.
3Why We Use Your Personal Data and Our Legal Basis
Under the PDPL we may process your personal data where you have consented, where it is necessary to perform a contract with you, where it is necessary to comply with a legal obligation, where it serves your actual interest and contacting you is impossible or difficult, or where we have a legitimate interest that does not override your rights and does not involve sensitive data. We use your data for the following purposes:
(a)To provide the Service (performance of the Terms): creating and verifying your account by SMS one-time code; displaying your profile and Content to your followers; enforcing the 50-following limit and the 72-hour expiry; delivering messages, reactions, reposts and gifts; showing the "Seen by" list to post owners; showing businesses and opportunities near you; submitting your applications to Businesses and showing you their status; and providing the Business Dashboard.
(b)To process purchases (performance of the Terms and legal obligation): verifying Apple receipts, activating and renewing Pathly Premium, crediting Diamonds and Coffees, restoring purchases, and keeping the financial records required by Saudi tax and commercial law.
(c)To keep the Service safe (legitimate interest and legal obligation): detecting and preventing spam, fraud, abuse, harassment, illegal content and security threats; reviewing reported Content and messages; enforcing our Terms; blocking users; and cooperating with law-enforcement and regulatory authorities.
(d)To communicate with you (performance of the Terms and legitimate interest): sending verification codes, push notifications about activity on your account, service announcements, changes to the Terms or this Policy, and responses to your requests.
(e)To improve the Service (legitimate interest): analysing aggregated usage and diagnostics to fix bugs, improve performance and design new features. We use aggregated or de-identified data for this wherever possible.
(f)To comply with the law (legal obligation): responding to lawful requests from courts and authorities, keeping records required by law, and fulfilling your data-protection rights.
(g)With your consent: using your precise location; sending you push notifications; sending you marketing messages (which we currently do not do); and any other purpose we describe to you when we ask for your consent. You may withdraw consent at any time as described in Section 11.
Automated decision-making. We use automated tools to detect spam and abusive content, which may result in Content being hidden or an account being restricted. Any such decision that has a significant effect on you can be appealed to a human reviewer at Pathly04@gmail.com.
No advertising. We do not use your personal data to show you third-party advertising, and we do not share it with advertising networks or data brokers.
4Who Can See Your Information Inside the Service
Your profile (display name, photo, bio and follower/following counts) is visible to any User of the Service. Your telephone number is never shown to other Users, except when you choose to apply to an Opportunity (see Section 7).
Your posts, moods, stories and reposts are visible to the accounts that follow you, and, where the Repathly feature is used, to the followers of anyone who reposts your Content, until the 72-hour expiry.
Your reactions and comments are visible to the owner of the post and to others who can see the post.
"Seen by." When you view a post, the owner of that post can see your display name and photo in the list of viewers and the total number of views. This cannot be turned off while you use the Service.
Messages and gifts are visible only to you and the other participant in the conversation, and to Pathly staff in the circumstances described in Section 9.
Business listings and Opportunities are public to all Users.
5How We Share Personal Data
We share personal data only as described below. We do not sell personal data.
Service providers (processors). Companies that process data on our behalf under contracts that require them to protect it and use it only on our instructions:
(a)Google Firebase (Google LLC and its affiliates): telephone-number authentication and SMS one-time codes, application database and file storage for your Content and messages, push notifications (Firebase Cloud Messaging), crash reporting and performance monitoring, and hosting.
(b)Apple Inc.: App Store distribution, in-app purchases, subscription management and receipt validation.
(c)Google Maps Platform (Google LLC): rendering the business map and calculating distances.
(d)Google Cloud / Firebase Hosting: hosting the Business Dashboard, Admin Dashboard and website.
(e)Google (Gmail / Google Workspace): sending business registration outcomes and support replies.
Businesses. When you apply to an Opportunity, we share your name, registered telephone number, profile photo and note with that Business, which may also export it. See Section 7.
Other Users. As described in Section 4.
ALIF Solutions and other contractors. Our development, maintenance and support contractors may access personal data where necessary to operate, maintain or debug the Service, under confidentiality and data-processing obligations.
Legal and safety. Courts, regulators, law-enforcement agencies and other authorities in the Kingdom of Saudi Arabia or elsewhere, where we believe disclosure is required by law or is necessary to protect the rights, property or safety of Pathly, our Users or the public, to investigate fraud, abuse or illegal activity, or to enforce our Terms.
Business transfers. A buyer, successor or partner in connection with a merger, acquisition, financing, reorganisation or sale of all or part of our business, subject to this Policy or to a notice of any material change.
With your consent or at your direction.
6International Transfers
Pathly is based in the Kingdom of Saudi Arabia. Some of our service providers, including Google Firebase and Apple, store and process data on servers located outside the Kingdom. Our Firebase project is hosted in the United Kingdom (Google Cloud region europe-west2, London), and Apple and Google may process limited data in other locations where they operate.
We transfer personal data outside the Kingdom only where permitted by the PDPL and the Personal Data Transfer Regulations issued by SDAIA. This includes transfers to countries or organisations that SDAIA has recognised as providing an adequate level of protection, transfers under standard contractual clauses or binding rules approved by SDAIA, transfers necessary to perform our contract with you, and transfers to which you have expressly consented. We apply appropriate safeguards in each case and limit the data transferred to what is necessary.
You may request information about the safeguards we use by contacting Pathly04@gmail.com.
7Applicants and Businesses
What Businesses receive. When you apply to an Opportunity, the Business receives your name, registered telephone number, profile photo and any note you submit. The Business can view this in its Applications inbox, update your application status, and export the applicant list as a file.
Businesses are independent controllers. Once a Business receives your application data, it is responsible under the PDPL for how it uses, stores and protects that data. Our Terms require Businesses to use it only to evaluate your application and communicate with you about it, to keep it secure, not to use it for marketing or any unrelated purpose, and to delete it when no longer needed. However, Pathly does not control Businesses and is not responsible for their privacy practices. Contact the Business directly to exercise your rights over data it holds, and contact us at Pathly04@gmail.com if you believe a Business has misused your data.
Business Users. We process the personal data of Business Users (contact names, telephone numbers, email addresses and verification details) to review registrations, provide the Business Dashboard, communicate about the account and enforce our Terms. Business names, locations, opening hours, photos, contact details intended for customers and Opportunities are published to all Users.
8Retention: How Long We Keep Personal Data
Posts, moods, stories and reposts are permanently deleted from our database and media storage 72 hours after publication, together with their reactions, comments and view records. Copies may persist in backups for up to 30 days before being overwritten.
Messages are kept until you delete the conversation or delete your account. Deleting your copy of a conversation does not delete the other participant's copy.
Account data (telephone number, profile, connections, settings) is kept while your account is active and deleted within 30 days after you delete your account, except as described in 8.6.
Application data is retained in the Business Dashboard until the Business deletes it, the Opportunity is closed for more than 12 months, or you delete your account, whichever is first. Data already exported by a Business is subject to the Business's own retention.
Purchase records are kept for the period required by Saudi tax and commercial law, currently six years from the end of the relevant financial year.
Safety and legal records. Content, messages and account information that have been reported, flagged, removed or are subject to a legal request or dispute may be retained for up to 12 months, or longer where required by law or to establish, exercise or defend legal claims. Records of accounts terminated for breach may be kept to prevent re-registration.
Logs and diagnostics are kept for up to 12 months.
Support correspondence is kept for 24 months after the matter is closed.
When data is no longer needed, we delete it or irreversibly anonymise it.
9Messages, Monitoring and Safety
Messages are transmitted using encryption in transit and stored encrypted at rest, but they are not end-to-end encrypted. This means Pathly is technically able to access message content.
We access message content only: (a) when a participant reports a message to us; (b) through automated tools that scan for spam, malware, child-safety violations and other illegal content; (c) where required by law, court order or a lawful request from an authority; or (d) where necessary to investigate a serious safety concern or a breach of our Terms.
Please do not share passwords, verification codes, payment details or identity documents in messages.
10Security
We implement technical and organisational measures appropriate to the risk, including encryption of data in transit (TLS) and at rest, access controls and role-based permissions for staff and contractors, logging of administrative access, secure development practices, and regular review of our providers' security certifications.
No system is completely secure. If we become aware of a breach of personal data that is likely to cause harm to you, we will notify SDAIA within the period required by the PDPL and will notify you without undue delay where the law requires it.
You are responsible for keeping your device secure, for protecting your telephone number from SIM-swap fraud, and for not sharing verification codes with anyone.
11Your Rights
Under the PDPL you have the right to:
(a)be informed about how we process your personal data (this Policy);
(b)access your personal data and obtain a copy of it in a readable format;
(c)correct inaccurate, incomplete or outdated personal data;
(d)delete your personal data, subject to legal retention requirements;
(e)withdraw consent where processing is based on consent, without affecting the lawfulness of processing before withdrawal;
(f)object to processing based on our legitimate interests in certain circumstances; and
(g)lodge a complaint with the Saudi Data & AI Authority (SDAIA) if you believe we have breached the PDPL.
If you live outside the Kingdom of Saudi Arabia, you may have additional rights under your local law, such as the right to data portability or the right to restrict processing. We will honour those rights where they apply.
How to exercise your rights.
(a)In the App you can edit your profile, change your telephone number, delete individual posts before they expire, delete conversations, block Users, manage location and notification permissions, and delete your account entirely, all from the settings screen.
(b)For anything else, contact us at Pathly04@gmail.com or write to the address in Section 16. We will respond within 30 days of receiving a valid request, or tell you if we need more time as the PDPL permits. We may need to verify your identity by sending a code to your registered telephone number.
(c)Exercising your rights is free of charge unless requests are manifestly unfounded, excessive or repetitive, in which case we may charge a reasonable fee or decline the request as the PDPL permits.
Deleting your account. When you delete your account, your profile, posts, connections and the messages you sent are removed from the Service as described in Section 8. Your active subscription is not cancelled by deleting your account; you must cancel it in your Apple ID settings. Unused Diamonds and Coffees are forfeited.
12Children
The Service is not directed to children under 13 and we do not knowingly collect personal data from them. If we learn that we have collected personal data from a child under 13, we will delete it and terminate the account.
Users aged 13 to 17 may use the Service only with the consent of a parent or legal guardian. Parents and guardians may contact us at Pathly04@gmail.com to review, correct or delete their child's personal data or to withdraw consent.
13Notifications and Marketing
We send push notifications about activity on your account (new followers, reactions, comments, messages, gifts, application status changes) and about the Service (security alerts, changes to the Terms or this Policy). You can turn notifications off in your device settings. Security and legal notices may still be sent by SMS.
We do not currently send marketing messages. If we introduce them, we will ask for your consent first and you will be able to opt out at any time.
14Apple App Privacy Disclosure
In accordance with Apple's App Privacy requirements, the following summarises the categories of data the App collects and links to your identity:
(a)Contact info: phone number, name.
(b)User content: photos and videos, messages, other user content (posts, moods, reactions, comments), customer support communications.
(c)Identifiers: user ID, device ID (Firebase installation ID, push token).
(d)Location: precise or coarse location (only with permission; used for app functionality, not tracking).
(e)Purchases: purchase history (subscription and virtual-item transactions received from Apple).
(f)Usage data: product interaction (including post views).
(g)Diagnostics: crash data, performance data.
These categories are used for app functionality, analytics of our own Service and security. The App does not use data for tracking as defined by Apple, and does not request permission to track.
15Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will notify you by an in-app notice, a push notification or a message to your registered telephone number before the changes take effect, and we will ask for your consent again where the law requires it. The "Last updated" date shows when the Policy was last changed. Continued use of the Service after a change takes effect means you acknowledge the updated Policy.
16Contact Us and Complaints
If you have questions about this Policy or want to exercise your rights, contact our privacy team:
Pathly Establishment
Owner: Alnuri Abdullah Alharbi
Commercial Registration (National Number): 7054446799
Street 26, Riyadh, Kingdom of Saudi Arabia
Telephone: +966 57 066 6610
Privacy requests, abuse reports and general support: Pathly04@gmail.com
The owner, Alnuri Abdullah Alharbi, is responsible for personal-data matters at Pathly.
If you are not satisfied with our response, you have the right to complain to the Saudi Data & AI Authority (SDAIA), the competent authority under the PDPL, through its official channels.
This Privacy Policy forms part of your agreement with Pathly. Please also read our Terms of Use and End User License Agreement at https://pathly.sa/terms.html.