Privacy Policy
Logistics • Delivery • E-Commerce • Public Services
Vehicle Guidance • Marketplace • Booking • Professional Services
Effective Date: May 6, 2026
Last Updated: May 6, 2026
Document Version: 2.0
Unified National Number: 7034653712
Jurisdiction: Kingdom of Saudi Arabia
1. Introduction
This Privacy Policy (the “Policy”) describes how Almasdar In Vehicle Guidance Establishment (“SourcesIn,” “we,” “us,” or “our”) collects, uses, processes, stores, transfers, discloses, protects, and deletes Personal Data when individuals, businesses, government entities, or other organizations (collectively, “you” or “Users”) access or use the SourcesIn Platform, websites, mobile applications, dashboards, APIs, and related digital services (collectively, the “Service”).
SourcesIn operates a multi-service digital platform providing logistics and delivery services, e-commerce and marketplace services, vehicle guidance and routing services, public service facilitation, professional service listings, business directory and company profile services, booking and reservation tools, and related supporting technologies in the Kingdom of Saudi Arabia and authorized jurisdictions.
This Policy is published in compliance with the Personal Data Protection Law of the Kingdom of Saudi Arabia (Royal Decree M/19 of 9/2/1443H), its Implementing Regulations issued by the Saudi Data and Artificial Intelligence Authority (SDAIA), the Anti-Cyber Crime Law, the E-Commerce Law (Royal Decree M/126), the Electronic Transactions Law, and all other applicable laws and regulations of the Kingdom of Saudi Arabia.
By accessing, registering on, or using the Service, you acknowledge that you have read, understood, and agreed to the practices described in this Policy. If you do not agree with any part of this Policy, you must not use the Service.
Operating Entity
Legal Name (EN): Almasdar In Vehicle Guidance Establishment
Legal Name (AR): مؤسسة المصدر إن لتوجيه المركبات
Unified National Number: 7034653712
Country of Registration: Kingdom of Saudi Arabia
Website: https://sourcesin.com
Data Protection Contact: privacy@sourcesin.com
https://sourcesin.com/data-deletion
General Contact: info@sourcesin.com
2. Interpretation and Definitions
2.1 Interpretation
Words with capitalized initial letters carry the meanings defined in this Section. The following definitions shall have the same meaning regardless of whether they appear in the singular or plural form.
2.2 Definitions
Account
A unique account created for you to access the Service or any part of it, including User Accounts and Business Accounts.
Application
The SourcesIn software, including websites, mobile applications, dashboards, APIs, and any digital channels operated by the Company.
Business User
Any company, establishment, merchant, supplier, restaurant, retailer, driver, courier, fleet operator, transport provider, agency, professional, government entity, or organization using the Service to list, sell, advertise, deliver, or provide goods or services.
Company / We / Us / Our
Almasdar In Vehicle Guidance Establishment (SourcesIn), Unified National Number 7034653712, Kingdom of Saudi Arabia.
Consumer / End User
Any natural person who uses the Service to browse, search, order, book, request, purchase, or receive goods, services, deliveries, or information.
Country
The Kingdom of Saudi Arabia.
Courier / Driver
An independent contractor, employee of a logistics partner, or third-party delivery agent who fulfills delivery and transport orders through the Service.
Delivery Services
Logistics, last-mile delivery, courier, freight, parcel, food delivery, grocery delivery, document delivery, and related transport services facilitated through the Platform.
E-Commerce Services
Online marketplace services through which Business Users list and sell products or services, and Consumers browse, order, pay for, and receive goods or services.
Personal Data
Any information relating to an identified or identifiable natural person, in accordance with the Personal Data Protection Law of Saudi Arabia.
Platform
The full SourcesIn ecosystem, including the website, applications, dashboards, APIs, business tools, listings, vehicle guidance services, and related digital services.
Public Services
Services provided in cooperation with public bodies, government portals, or in furtherance of public interest, including listings of public utilities, official directories, vehicle guidance, and information services.
Sensitive Data
Personal Data revealing racial or ethnic origin, religious beliefs, criminal records, biometric data, genetic data, health data, financial data, location data, or any other category classified as sensitive under applicable law.
Service Provider
Any natural or legal person processing data on behalf of the Company, including hosting, payment, mapping, analytics, communication, and support providers.
Usage Data
Data collected automatically through use of the Service, including device data, log data, interaction data, and analytics data.
Vehicle Guidance Services
Routing, navigation, fleet support, vehicle directory, transport assistance, and related guidance services provided through the Platform.
You
The individual accessing the Service or the legal entity on whose behalf such individual is acting.
3. Scope of Services Covered
This Policy applies to all categories of services offered by SourcesIn, including without limitation:
3.1 Logistics and Delivery Services
• Last-mile delivery for parcels, documents, food, groceries, and consumer goods.
• Same-day, scheduled, and on-demand delivery requests.
• Freight, fleet, and bulk transport services.
• Driver and courier onboarding, dispatch, and tracking.
• Real-time order tracking, route optimization, and delivery status notifications.
• Proof-of-delivery, electronic signatures, and delivery confirmation records.
3.2 E-Commerce and Marketplace Services
• Product and service listings by Business Users.
• Online ordering, checkout, invoicing, and payment processing.
• ZATCA-compliant electronic invoicing (Phase 1 and Phase 2).
• Order management, returns, refunds, exchanges, and customer support.
• Reviews, ratings, and reputation features.
• Promotions, loyalty programs, vouchers, and gift cards.
3.3 Vehicle Guidance and Transport Services
• Vehicle routing, navigation assistance, and location-based guidance.
• Fleet management support and vehicle directory listings.
• Transport coordination, ride booking, and dispatch services.
• Map integration through Google Places, Google Maps, and authorized providers.
3.4 Public and Professional Services
• Listings of professionals, public utilities, official directories, and authorized service providers.
• Service requests directed to public-facing entities or licensed professionals.
• Booking, reservation, and appointment scheduling tools.
• Government-related information services where authorized.
3.5 Business and Operational Services
• Business account management, dashboards, and analytics.
• Multi-branch and multi-user management for organizations.
• Marketing, advertising, and promotional tools.
• Customer relationship management (CRM) features for Business Users.
• API access and developer integrations.
4. Categories of Personal Data We Collect
We collect Personal Data only to the extent necessary to provide and improve the Service, comply with legal obligations, and protect the rights and safety of all parties. The categories of data we may collect include:
4.1 Identification and Contact Data
• Full legal name, national identifier (Iqama or National ID where lawfully required for verification), date of birth.
• Email address, mobile number, alternative phone numbers, and WhatsApp number.
• Postal address, residential address, billing address, and delivery addresses.
• City, region/province, postal code, and country.
• Profile picture, username, and account credentials.
4.2 Business and Commercial Data
• Business legal name (Arabic and English), trade name, and brand identity.
• Commercial Registration (CR) number, Unified National Number, and license details.
• Tax Registration Number (TRN) and VAT registration details for ZATCA compliance.
• Business activity classification, sector, sub-category, and ISIC codes where applicable.
• Authorized representative names, identifiers, signatures, and powers of attorney.
• Bank account information for settlements and payouts (where applicable).
• Business documents, certificates, photographs, logos, and supporting attachments.
4.3 Order, Delivery, and Logistics Data
• Order content, item descriptions, quantities, weights, dimensions, and special handling instructions.
• Pickup and drop-off addresses, delivery windows, and recipient details.
• Delivery instructions, gate codes, building information, and contact preferences.
• Real-time and historical location of deliveries and assigned couriers.
• Proof-of-delivery records, photographs, signatures, and confirmation codes.
• Returns, refunds, complaints, and resolution records.
4.4 Payment and Financial Data
• Payment method type, last four digits of cards, and tokenized payment references.
• Transaction history, invoice numbers, settlement records, and refund history.
• Bank transfer details, IBAN (where required), and remittance information.
• Wallet balances, loyalty points, vouchers, and credit notes.
Full payment card numbers, CVV codes, and full account credentials are processed exclusively by certified payment service providers (PCI-DSS compliant) and are not stored in our systems unless explicitly stated and lawfully permitted.
4.5 Location and Vehicle Data
• Precise GPS coordinates of devices (with user permission) for delivery, routing, and guidance.
• Approximate location derived from IP address, Wi-Fi networks, or cellular data.
• Vehicle registration plate, type, model, year, and capacity (for couriers and fleet partners).
• Driver license details, vehicle insurance information, and inspection certificates.
• Trip routes, distances, durations, speeds, and stop history.
4.6 Device and Technical Data
• IP address, device identifiers (IMEI, IDFA, advertising IDs), and MAC address.
• Device model, operating system, browser type and version, and language preferences.
• App version, crash logs, diagnostic data, and performance metrics.
• Cookies, local storage tokens, session identifiers, and authentication tokens.
4.7 Usage and Behavioral Data
• Pages and screens viewed, features used, search queries, and click patterns.
• Time and date of access, session duration, and navigation paths.
• Referral sources, marketing campaign data, and conversion events.
• Preferences, saved items, wishlists, and personalization data.
4.8 Communications Data
• Messages exchanged through in-app chat, support tickets, email, SMS, or WhatsApp.
• Call recordings (where lawfully permitted and disclosed) for support and quality assurance.
• Notifications, alerts, and feedback submissions.
4.9 Identity Verification Data
• Government-issued identification documents (National ID, Iqama, Passport) for KYC and onboarding.
• Selfie or liveness checks for fraud prevention (where required).
• Address verification documents and proof-of-residence.
• Business verification documents and authorized signatory confirmation.
4.10 Data from Third-Party Sources
• Authentication data from Meta, Facebook, Google, Apple, or other login providers (with your consent).
• Data from public registries, government portals, or authorized verification services.
• Data from advertising and analytics partners, subject to your consent.
5. Purposes and Legal Bases for Processing
We process Personal Data only when we have a valid legal basis under applicable law. The legal bases on which we rely include:
(a) your explicit consent;
(b) performance of a contract with you;
(c) compliance with a legal obligation;
(d) protection of vital interests;
(e) performance of a task in the public interest; and
(f) our legitimate interests, balanced against your rights and freedoms.
5.1 Service Delivery and Operations
• Creating and managing User Accounts and Business Accounts.
• Authenticating users, securing logins, and protecting accounts.
• Processing orders, deliveries, bookings, listings, and service requests.
• Coordinating between Consumers, Business Users, drivers, and partners.
• Generating ZATCA-compliant electronic invoices, QR codes, and tax documentation.
• Providing routing, navigation, and vehicle guidance based on real-time location.
5.2 Customer Support and Communications
• Responding to inquiries, complaints, disputes, and service requests.
• Sending transactional notifications (order confirmations, delivery updates, receipts).
• Sending service-related announcements, security alerts, and policy updates.
• Conducting customer satisfaction surveys and quality assurance reviews.
5.3 Safety, Security, and Fraud Prevention
• Detecting, preventing, and investigating fraud, abuse, money laundering, and unlawful activity.
• Verifying identities and validating commercial registrations.
• Monitoring driver and courier conduct for safety and service quality.
• Maintaining audit logs, security records, and incident response data.
• Protecting the Service, our infrastructure, and the rights of users and third parties.
5.4 Legal and Regulatory Compliance
• Complying with the Personal Data Protection Law and SDAIA regulations.
• Complying with ZATCA, Ministry of Commerce, SAMA, CITC, and other regulators.
• Responding to lawful requests from courts, law enforcement, and government authorities.
• Maintaining records required for tax, accounting, anti-money laundering, and consumer protection.
5.5 Improvement and Analytics
• Measuring usage, performance, and reliability of the Service.
• Conducting research, analytics, and product development.
• Personalizing recommendations, search results, and user experience.
• Training and improving algorithms, including AI and machine learning models, using aggregated and anonymized data.
5.6 Marketing and Promotions
• Sending marketing messages, offers, and promotional content (subject to your consent and applicable law).
• Personalizing advertisements within the Service.
• Managing referral programs, loyalty rewards, and partner promotions.
You may withdraw consent for marketing communications at any time without affecting the lawfulness of prior processing.
6. Disclosure and Sharing of Personal Data
We disclose Personal Data only when necessary, with appropriate safeguards, and in accordance with applicable law. The categories of recipients are described below.
6.1 Sharing With Service Providers and Processors
We engage trusted third parties to process Personal Data on our behalf under written agreements imposing strict confidentiality, security, and limited-purpose obligations. Categories include:
• Hosting, cloud, and infrastructure providers (e.g., Hostinger International Ltd.).
• Payment service providers and acquirers (PCI-DSS certified) for transaction processing.
• Mapping, geolocation, and routing providers (e.g., Google Maps, Google Places).
• Communication providers for SMS, email, push notifications, and WhatsApp Business.
• Analytics, monitoring, and performance providers.
• Identity verification, KYC, and fraud prevention providers.
• Customer support, ticketing, and live-chat platforms.
6.2 Sharing Between Consumers and Business Users
To complete an order, delivery, booking, or service request, we share necessary information between Consumers and the relevant Business Users, drivers, couriers, or service providers. Examples:
• Sharing the Consumer’s name, phone number, and delivery address with the assigned courier and merchant.
• Sharing the merchant’s name, location, and contact details with the Consumer.
• Sharing order content, instructions, and timing with the fulfillment party.
Both parties undertake to handle such information solely for the purpose of completing the transaction and in compliance with applicable law.
6.3 Sharing With Logistics, Transport, and Delivery Partners
• Authorized fleet operators, courier companies, and last-mile delivery partners.
• Independent drivers operating through the Platform.
• Cross-border shipping partners and customs brokers (where applicable).
• Insurance providers covering shipments or vehicles.
6.4 Sharing With Public Authorities and Regulators
• ZATCA, the Saudi Customs Authority, and tax authorities (for invoicing and customs).
• Ministry of Commerce, Ministry of Transport, and licensing authorities.
• SDAIA and the National Data Management Office, where applicable.
• Law enforcement, judicial bodies, and competent authorities pursuant to lawful orders.
• Public bodies cooperating in the delivery of public services through the Platform.
6.5 Sharing With Affiliates and Group Entities
We may share data with our affiliates, parent entities, subsidiaries, and group companies, subject to appropriate safeguards and the terms of this Policy.
6.6 Sharing in Corporate Transactions
In the event of a merger, acquisition, restructuring, financing, joint venture, sale, or transfer of assets, Personal Data may be transferred as part of the transaction, subject to the protections of this Policy and applicable law. Users will be notified of any material change in the controller of their data.
6.7 Sharing With Your Consent
We may share data with additional parties when you have provided clear, informed, and specific consent.
6.8 Sharing of Aggregated or Anonymized Data
We may share aggregated or de-identified data that cannot reasonably be used to identify you for analytics, research, benchmarking, market reporting, or business development purposes.
7. Cross-Border Data Transfers
Personal Data may be transferred to, stored in, or processed in countries outside the Kingdom of Saudi Arabia, where our Service Providers, infrastructure, or affiliates operate.
Where such transfers occur, SourcesIn ensures appropriate safeguards in accordance with the Personal Data Protection Law and SDAIA regulations, including:
• Conducting transfer impact assessments and verifying adequacy of the destination jurisdiction.
• Executing Standard Contractual Clauses or equivalent data transfer agreements.
• Limiting transfers to the minimum data necessary for the stated purpose.
• Obtaining regulatory approvals where required by Saudi law.
8. Data Retention and Deletion
We retain Personal Data only for as long as necessary to fulfill the purposes for which it was collected, comply with our legal and regulatory obligations, resolve disputes, prevent fraud, and enforce our agreements.
8.1 Standard Retention Periods
Data Category
Retention Period
Account and profile data
Duration of the Account + 24 months after closure
Order, delivery, and transaction records
Minimum 10 years (ZATCA & accounting compliance)
E-invoices and tax records
Minimum 6 years (ZATCA requirement)
Identity verification (KYC) data
Duration of the relationship + 5 years (AML)
Communications and support tickets
Up to 3 years from resolution
Location and trip data
Up to 12 months in identifiable form
Marketing data and preferences
Until consent is withdrawn
Cookies and analytics data
Up to 13 months
Security and fraud-prevention logs
Up to 5 years
Anonymized or aggregated data
Indefinitely (no longer Personal Data)
Where retention periods overlap, the longest applicable period prevails. Upon expiration of the retention period, data is securely deleted, anonymized, or archived under restricted access in accordance with our data lifecycle policies.
9. Your Rights as a Data Subject
Subject to applicable law, you have the following rights regarding your Personal Data:
• Right to Be Informed: to receive clear information about how your data is processed.
• Right of Access: to obtain a copy of the Personal Data we hold about you.
• Right to Rectification: to correct inaccurate or incomplete data.
• Right to Erasure: to request deletion of your data, subject to legal retention obligations.
• Right to Restrict Processing: to limit how your data is processed in certain circumstances.
• Right to Object: to object to processing based on legitimate interests or for direct marketing.
• Right to Data Portability: to receive your data in a structured, machine-readable format.
• Right to Withdraw Consent: where processing is based on consent, you may withdraw it at any time.
• Right to Lodge a Complaint: with the Saudi Data and Artificial Intelligence Authority (SDAIA) or competent authority.
To exercise any of these rights, contact us at privacy@sourcesin.com. We will respond within thirty (30) days, except where the law permits an extension. We may request reasonable verification of your identity before fulfilling the request.
10. Account and Data Deletion
Users may request deletion of their Personal Data and SourcesIn account at any time by contacting privacy@sourcesin.com or by submitting a request through https://sourcesin.com/data-deletion. Upon verified request, SourcesIn will delete or anonymize the user’s Personal Data unless retention is required by applicable laws or regulatory obligations.
10.1 Consumer Account Deletion
Consumers may request deletion of their account and associated Personal Data by:
• Sending an email to privacy@sourcesin.com or info@sourcesin.com with the subject “Account Deletion Request.”
• Submitting a request through the Data Deletion page at https://sourcesin.com/data-deletion
• Users may also delete their account through the app or website Profile section by selecting “Delete Account”..
10.2 Business Account Deletion
Business Users may request deletion of their business account, listings, and associated data by submitting a request through privacy@sourcesin.com, including:
• Business legal name and Commercial Registration number.
• Registered email address and authorized representative information.
• Reason for deletion and confirmation of authorization.
10.3 Meta / Facebook Login Data Deletion
If you connected your account through Meta, Facebook, Instagram, or WhatsApp Business, you may also disconnect SourcesIn directly from your Facebook account by visiting Facebook Settings → Apps and Websites → SourcesIn → Remove. To request deletion of associated Meta Platform Data, contact privacy@sourcesin.com.
10.4 Limitations on Deletion
We may retain certain information after a deletion request when required for:
• Compliance with ZATCA, accounting, and tax obligations (minimum 6 years).
• Anti-money laundering and counter-terrorism financing recordkeeping.
• Resolution of pending disputes, claims, or legal proceedings.
• Fraud prevention and protection of the rights of third parties.
• Compliance with court orders or regulatory directives.
11. Information Security
SourcesIn implements appropriate technical, administrative, and organizational measures to protect Personal Data against unauthorized access, alteration, disclosure, loss, or destruction, including:
11.1 Technical Safeguards
• Encryption of data in transit using TLS/HTTPS protocols.
• Encryption of sensitive data at rest using industry-standard algorithms.
• Access controls based on the principle of least privilege.
• Multi-factor authentication for administrative access.
• Continuous security monitoring, intrusion detection, and threat intelligence.
• Regular vulnerability assessments and penetration testing.
• Backup, disaster recovery, and business continuity procedures.
11.2 Administrative Safeguards
• Confidentiality and data protection obligations imposed on all personnel.
• Mandatory privacy and security training for staff.
• Documented information security policies and incident response plans.
• Vendor due diligence and data processing agreements with all Service Providers.
11.3 Data Breach Notification
In the event of a confirmed Personal Data breach that is likely to result in significant harm, SourcesIn will notify affected individuals and SDAIA within seventy-two (72) hours of becoming aware of the breach, in accordance with the Personal Data Protection Law and its Implementing Regulations.
Despite the above measures, no method of electronic transmission or storage is one hundred percent (100%) secure. We cannot guarantee absolute security and encourage users to maintain strong, unique passwords and to safeguard their account credentials.
12. Cookies and Tracking Technologies
The Service uses cookies, pixels, SDKs, local storage, and similar technologies to operate, secure, analyze, and improve the Platform. The categories of technologies we use include:
• Strictly Necessary: required for authentication, security, load balancing, and core functionality.
• Functional: remembering preferences, language, region, and personalization settings.
• Analytical: measuring usage, performance, and identifying improvements (subject to consent).
• Marketing: delivering relevant advertisements and measuring campaign effectiveness (subject to consent).
You may manage cookies through your browser or device settings, or through the cookie consent banner where applicable. Disabling certain cookies may affect functionality.
13. Children’s Privacy
The Service is not directed to children under the age of eighteen (18) without verifiable parental or guardian consent. We do not knowingly collect Personal Data from children. If we become aware that we have collected data from a child without appropriate consent, we will delete such data without undue delay.
Parents or guardians who believe a child has provided Personal Data without authorization should contact privacy@sourcesin.com.
14. Third-Party Links and Integrations
The Service may contain links, integrations, or content from third parties, including merchants, delivery partners, payment providers, and social media platforms. SourcesIn is not responsible for the privacy practices, content, or security of such third parties. We encourage you to review the privacy policies of any third party before providing them with Personal Data.
15. Artificial Intelligence and Automated Processing
SourcesIn uses artificial intelligence, machine learning, and automated decision-making technologies to enhance and personalize the Service, including:
• Routing optimization and delivery time estimation.
• Fraud detection, risk scoring, and anomaly identification.
• Personalized search results, product recommendations, and pricing.
• Customer support chatbots and intelligent ticket routing.
• Content moderation and safety monitoring.
Where automated decisions produce legal or similarly significant effects on you, you have the right to request human review, express your point of view, and contest the decision. Contact privacy@sourcesin.com to exercise this right.
16. Changes to This Privacy Policy
We may update this Policy periodically to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes, we will notify users by posting the updated Policy on the Service, updating the “Last Updated” date, and where appropriate, sending an email or in-app notification.
Continued use of the Service after the effective date of an updated Policy constitutes acceptance of the changes. If you do not agree with the updated Policy, you should stop using the Service and request account deletion.
17. Governing Law and Dispute Resolution
This Policy is governed by and construed in accordance with the laws and regulations of the Kingdom of Saudi Arabia, including the Personal Data Protection Law and its Implementing Regulations. Any dispute arising from or relating to this Policy shall be resolved through:
• Good-faith negotiation between the parties in the first instance.
• Mediation through authorized Saudi mediation centers, where applicable.
• The competent courts and judicial authorities of the Kingdom of Saudi Arabia, with venue in the Eastern Province unless otherwise required by law.
18. Contact Information
For any inquiries, complaints, or requests relating to this Privacy Policy or the processing of your Personal Data, please contact us through any of the channels below.
Data Protection Contact Details
Controller: Almasdar In Vehicle Guidance Establishment (SourcesIn)
Arabic Name: مؤسسة المصدر إن لتوجيه المركبات
Unified National Number: 7034653712
Privacy Email: privacy@sourcesin.com
General Email: info@sourcesin.com
Website: https://sourcesin.com
Data Deletion Page: https://sourcesin.com/data-deletion/index.html
Country: Kingdom of Saudi Arabia
If you are unable to resolve a concern through SourcesIn, you have the right to lodge a complaint with the Saudi Data and Artificial Intelligence Authority (SDAIA) or the competent regulatory authority.
End of Privacy Policy
© 2026 Almasdar In Vehicle Guidance Establishment. All rights reserved.
Document prepared in compliance with the Personal Data Protection Law of the Kingdom of Saudi Arabia.