Privacy Policy

Privacy Policy

Logistics • Delivery • E-Commerce • Public Services

Vehicle Guidance • Marketplace • Booking • Professional Services



Effective Date: May 6, 2026

Last Updated: May 6, 2026

Document Version: 2.0

Unified National Number: 7034653712

Jurisdiction: Kingdom of Saudi Arabia



1. Introduction

This Privacy Policy (the “Policy”) describes how Almasdar In Vehicle Guidance Establishment (“SourcesIn,” “we,” “us,” or “our”) collects, uses, processes, stores, transfers, discloses, protects, and deletes Personal Data when individuals, businesses, government entities, or other organizations (collectively, “you” or “Users”) access or use the SourcesIn Platform, websites, mobile applications, dashboards, APIs, and related digital services (collectively, the “Service”).

SourcesIn operates a multi-service digital platform providing logistics and delivery services, e-commerce and marketplace services, vehicle guidance and routing services, public service facilitation, professional service listings, business directory and company profile services, booking and reservation tools, and related supporting technologies in the Kingdom of Saudi Arabia and authorized jurisdictions.

This Policy is published in compliance with the Personal Data Protection Law of the Kingdom of Saudi Arabia (Royal Decree M/19 of 9/2/1443H), its Implementing Regulations issued by the Saudi Data and Artificial Intelligence Authority (SDAIA), the Anti-Cyber Crime Law, the E-Commerce Law (Royal Decree M/126), the Electronic Transactions Law, and all other applicable laws and regulations of the Kingdom of Saudi Arabia.

By accessing, registering on, or using the Service, you acknowledge that you have read, understood, and agreed to the practices described in this Policy. If you do not agree with any part of this Policy, you must not use the Service.


Operating Entity

Legal Name (EN): Almasdar In Vehicle Guidance Establishment

Legal Name (AR): مؤسسة المصدر إن لتوجيه المركبات

Unified National Number: 7034653712

Country of Registration: Kingdom of Saudi Arabia

Website: https://sourcesin.com

Data Protection Contact: privacy@sourcesin.com

https://sourcesin.com/data-deletion

General Contact: info@sourcesin.com


2. Interpretation and Definitions

2.1 Interpretation

Words with capitalized initial letters carry the meanings defined in this Section. The following definitions shall have the same meaning regardless of whether they appear in the singular or plural form.

2.2 Definitions


Account

A unique account created for you to access the Service or any part of it, including User Accounts and Business Accounts.


Application

The SourcesIn software, including websites, mobile applications, dashboards, APIs, and any digital channels operated by the Company.


Business User

Any company, establishment, merchant, supplier, restaurant, retailer, driver, courier, fleet operator, transport provider, agency, professional, government entity, or organization using the Service to list, sell, advertise, deliver, or provide goods or services.


Company / We / Us / Our

Almasdar In Vehicle Guidance Establishment (SourcesIn), Unified National Number 7034653712, Kingdom of Saudi Arabia.


Consumer / End User

Any natural person who uses the Service to browse, search, order, book, request, purchase, or receive goods, services, deliveries, or information.


Country

The Kingdom of Saudi Arabia.


Courier / Driver

An independent contractor, employee of a logistics partner, or third-party delivery agent who fulfills delivery and transport orders through the Service.


Delivery Services

Logistics, last-mile delivery, courier, freight, parcel, food delivery, grocery delivery, document delivery, and related transport services facilitated through the Platform.


E-Commerce Services

Online marketplace services through which Business Users list and sell products or services, and Consumers browse, order, pay for, and receive goods or services.


Personal Data

Any information relating to an identified or identifiable natural person, in accordance with the Personal Data Protection Law of Saudi Arabia.


Platform

The full SourcesIn ecosystem, including the website, applications, dashboards, APIs, business tools, listings, vehicle guidance services, and related digital services.


Public Services

Services provided in cooperation with public bodies, government portals, or in furtherance of public interest, including listings of public utilities, official directories, vehicle guidance, and information services.


Sensitive Data

Personal Data revealing racial or ethnic origin, religious beliefs, criminal records, biometric data, genetic data, health data, financial data, location data, or any other category classified as sensitive under applicable law.


Service Provider

Any natural or legal person processing data on behalf of the Company, including hosting, payment, mapping, analytics, communication, and support providers.


Usage Data

Data collected automatically through use of the Service, including device data, log data, interaction data, and analytics data.


Vehicle Guidance Services

Routing, navigation, fleet support, vehicle directory, transport assistance, and related guidance services provided through the Platform.


You

The individual accessing the Service or the legal entity on whose behalf such individual is acting.


3. Scope of Services Covered

This Policy applies to all categories of services offered by SourcesIn, including without limitation:


3.1 Logistics and Delivery Services

Last-mile delivery for parcels, documents, food, groceries, and consumer goods.

Same-day, scheduled, and on-demand delivery requests.

Freight, fleet, and bulk transport services.

Driver and courier onboarding, dispatch, and tracking.

Real-time order tracking, route optimization, and delivery status notifications.

Proof-of-delivery, electronic signatures, and delivery confirmation records.


3.2 E-Commerce and Marketplace Services

Product and service listings by Business Users.

Online ordering, checkout, invoicing, and payment processing.

ZATCA-compliant electronic invoicing (Phase 1 and Phase 2).

Order management, returns, refunds, exchanges, and customer support.

Reviews, ratings, and reputation features.

Promotions, loyalty programs, vouchers, and gift cards.


3.3 Vehicle Guidance and Transport Services

Vehicle routing, navigation assistance, and location-based guidance.

Fleet management support and vehicle directory listings.

Transport coordination, ride booking, and dispatch services.

Map integration through Google Places, Google Maps, and authorized providers.


3.4 Public and Professional Services

Listings of professionals, public utilities, official directories, and authorized service providers.

Service requests directed to public-facing entities or licensed professionals.

Booking, reservation, and appointment scheduling tools.

Government-related information services where authorized.


3.5 Business and Operational Services

Business account management, dashboards, and analytics.

Multi-branch and multi-user management for organizations.

Marketing, advertising, and promotional tools.

Customer relationship management (CRM) features for Business Users.

API access and developer integrations.


4. Categories of Personal Data We Collect

We collect Personal Data only to the extent necessary to provide and improve the Service, comply with legal obligations, and protect the rights and safety of all parties. The categories of data we may collect include:


4.1 Identification and Contact Data

Full legal name, national identifier (Iqama or National ID where lawfully required for verification), date of birth.

Email address, mobile number, alternative phone numbers, and WhatsApp number.

Postal address, residential address, billing address, and delivery addresses.

City, region/province, postal code, and country.

Profile picture, username, and account credentials.


4.2 Business and Commercial Data

Business legal name (Arabic and English), trade name, and brand identity.

Commercial Registration (CR) number, Unified National Number, and license details.

Tax Registration Number (TRN) and VAT registration details for ZATCA compliance.

Business activity classification, sector, sub-category, and ISIC codes where applicable.

Authorized representative names, identifiers, signatures, and powers of attorney.

Bank account information for settlements and payouts (where applicable).

Business documents, certificates, photographs, logos, and supporting attachments.


4.3 Order, Delivery, and Logistics Data

Order content, item descriptions, quantities, weights, dimensions, and special handling instructions.

Pickup and drop-off addresses, delivery windows, and recipient details.

Delivery instructions, gate codes, building information, and contact preferences.

Real-time and historical location of deliveries and assigned couriers.

Proof-of-delivery records, photographs, signatures, and confirmation codes.

Returns, refunds, complaints, and resolution records.


4.4 Payment and Financial Data

Payment method type, last four digits of cards, and tokenized payment references.

Transaction history, invoice numbers, settlement records, and refund history.

Bank transfer details, IBAN (where required), and remittance information.

Wallet balances, loyalty points, vouchers, and credit notes.

Full payment card numbers, CVV codes, and full account credentials are processed exclusively by certified payment service providers (PCI-DSS compliant) and are not stored in our systems unless explicitly stated and lawfully permitted.


4.5 Location and Vehicle Data

Precise GPS coordinates of devices (with user permission) for delivery, routing, and guidance.

Approximate location derived from IP address, Wi-Fi networks, or cellular data.

Vehicle registration plate, type, model, year, and capacity (for couriers and fleet partners).

Driver license details, vehicle insurance information, and inspection certificates.

Trip routes, distances, durations, speeds, and stop history.


4.6 Device and Technical Data

IP address, device identifiers (IMEI, IDFA, advertising IDs), and MAC address.

Device model, operating system, browser type and version, and language preferences.

App version, crash logs, diagnostic data, and performance metrics.

Cookies, local storage tokens, session identifiers, and authentication tokens.


4.7 Usage and Behavioral Data

Pages and screens viewed, features used, search queries, and click patterns.

Time and date of access, session duration, and navigation paths.

Referral sources, marketing campaign data, and conversion events.

Preferences, saved items, wishlists, and personalization data.


4.8 Communications Data

Messages exchanged through in-app chat, support tickets, email, SMS, or WhatsApp.

Call recordings (where lawfully permitted and disclosed) for support and quality assurance.

Notifications, alerts, and feedback submissions.


4.9 Identity Verification Data

Government-issued identification documents (National ID, Iqama, Passport) for KYC and onboarding.

Selfie or liveness checks for fraud prevention (where required).

Address verification documents and proof-of-residence.

Business verification documents and authorized signatory confirmation.


4.10 Data from Third-Party Sources

Authentication data from Meta, Facebook, Google, Apple, or other login providers (with your consent).

Data from public registries, government portals, or authorized verification services.

Data from advertising and analytics partners, subject to your consent.


5. Purposes and Legal Bases for Processing

We process Personal Data only when we have a valid legal basis under applicable law. The legal bases on which we rely include:

(a) your explicit consent;

(b) performance of a contract with you;

(c) compliance with a legal obligation;

(d) protection of vital interests;

(e) performance of a task in the public interest; and

(f) our legitimate interests, balanced against your rights and freedoms.


5.1 Service Delivery and Operations

Creating and managing User Accounts and Business Accounts.

Authenticating users, securing logins, and protecting accounts.

Processing orders, deliveries, bookings, listings, and service requests.

Coordinating between Consumers, Business Users, drivers, and partners.

Generating ZATCA-compliant electronic invoices, QR codes, and tax documentation.

Providing routing, navigation, and vehicle guidance based on real-time location.


5.2 Customer Support and Communications

Responding to inquiries, complaints, disputes, and service requests.

Sending transactional notifications (order confirmations, delivery updates, receipts).

Sending service-related announcements, security alerts, and policy updates.

Conducting customer satisfaction surveys and quality assurance reviews.


5.3 Safety, Security, and Fraud Prevention

Detecting, preventing, and investigating fraud, abuse, money laundering, and unlawful activity.

Verifying identities and validating commercial registrations.

Monitoring driver and courier conduct for safety and service quality.

Maintaining audit logs, security records, and incident response data.

Protecting the Service, our infrastructure, and the rights of users and third parties.


5.4 Legal and Regulatory Compliance

Complying with the Personal Data Protection Law and SDAIA regulations.

Complying with ZATCA, Ministry of Commerce, SAMA, CITC, and other regulators.

Responding to lawful requests from courts, law enforcement, and government authorities.

Maintaining records required for tax, accounting, anti-money laundering, and consumer protection.


5.5 Improvement and Analytics

Measuring usage, performance, and reliability of the Service.

Conducting research, analytics, and product development.

Personalizing recommendations, search results, and user experience.

Training and improving algorithms, including AI and machine learning models, using aggregated and anonymized data.


5.6 Marketing and Promotions

Sending marketing messages, offers, and promotional content (subject to your consent and applicable law).

Personalizing advertisements within the Service.

Managing referral programs, loyalty rewards, and partner promotions.

You may withdraw consent for marketing communications at any time without affecting the lawfulness of prior processing.


6. Disclosure and Sharing of Personal Data

We disclose Personal Data only when necessary, with appropriate safeguards, and in accordance with applicable law. The categories of recipients are described below.


6.1 Sharing With Service Providers and Processors

We engage trusted third parties to process Personal Data on our behalf under written agreements imposing strict confidentiality, security, and limited-purpose obligations. Categories include:

Hosting, cloud, and infrastructure providers (e.g., Hostinger International Ltd.).

Payment service providers and acquirers (PCI-DSS certified) for transaction processing.

Mapping, geolocation, and routing providers (e.g., Google Maps, Google Places).

Communication providers for SMS, email, push notifications, and WhatsApp Business.

Analytics, monitoring, and performance providers.

Identity verification, KYC, and fraud prevention providers.

Customer support, ticketing, and live-chat platforms.


6.2 Sharing Between Consumers and Business Users

To complete an order, delivery, booking, or service request, we share necessary information between Consumers and the relevant Business Users, drivers, couriers, or service providers. Examples:

Sharing the Consumer’s name, phone number, and delivery address with the assigned courier and merchant.

Sharing the merchant’s name, location, and contact details with the Consumer.

Sharing order content, instructions, and timing with the fulfillment party.

Both parties undertake to handle such information solely for the purpose of completing the transaction and in compliance with applicable law.


6.3 Sharing With Logistics, Transport, and Delivery Partners

Authorized fleet operators, courier companies, and last-mile delivery partners.

Independent drivers operating through the Platform.

Cross-border shipping partners and customs brokers (where applicable).

Insurance providers covering shipments or vehicles.


6.4 Sharing With Public Authorities and Regulators

ZATCA, the Saudi Customs Authority, and tax authorities (for invoicing and customs).

Ministry of Commerce, Ministry of Transport, and licensing authorities.

SDAIA and the National Data Management Office, where applicable.

Law enforcement, judicial bodies, and competent authorities pursuant to lawful orders.

Public bodies cooperating in the delivery of public services through the Platform.


6.5 Sharing With Affiliates and Group Entities

We may share data with our affiliates, parent entities, subsidiaries, and group companies, subject to appropriate safeguards and the terms of this Policy.


6.6 Sharing in Corporate Transactions

In the event of a merger, acquisition, restructuring, financing, joint venture, sale, or transfer of assets, Personal Data may be transferred as part of the transaction, subject to the protections of this Policy and applicable law. Users will be notified of any material change in the controller of their data.


6.7 Sharing With Your Consent

We may share data with additional parties when you have provided clear, informed, and specific consent.


6.8 Sharing of Aggregated or Anonymized Data

We may share aggregated or de-identified data that cannot reasonably be used to identify you for analytics, research, benchmarking, market reporting, or business development purposes.


7. Cross-Border Data Transfers

Personal Data may be transferred to, stored in, or processed in countries outside the Kingdom of Saudi Arabia, where our Service Providers, infrastructure, or affiliates operate.

Where such transfers occur, SourcesIn ensures appropriate safeguards in accordance with the Personal Data Protection Law and SDAIA regulations, including:

Conducting transfer impact assessments and verifying adequacy of the destination jurisdiction.

Executing Standard Contractual Clauses or equivalent data transfer agreements.

Limiting transfers to the minimum data necessary for the stated purpose.

Obtaining regulatory approvals where required by Saudi law.


8. Data Retention and Deletion

We retain Personal Data only for as long as necessary to fulfill the purposes for which it was collected, comply with our legal and regulatory obligations, resolve disputes, prevent fraud, and enforce our agreements.


8.1 Standard Retention Periods

Data Category

Retention Period

Account and profile data

Duration of the Account + 24 months after closure

Order, delivery, and transaction records

Minimum 10 years (ZATCA & accounting compliance)

E-invoices and tax records

Minimum 6 years (ZATCA requirement)

Identity verification (KYC) data

Duration of the relationship + 5 years (AML)

Communications and support tickets

Up to 3 years from resolution

Location and trip data

Up to 12 months in identifiable form

Marketing data and preferences

Until consent is withdrawn

Cookies and analytics data

Up to 13 months

Security and fraud-prevention logs

Up to 5 years

Anonymized or aggregated data

Indefinitely (no longer Personal Data)


Where retention periods overlap, the longest applicable period prevails. Upon expiration of the retention period, data is securely deleted, anonymized, or archived under restricted access in accordance with our data lifecycle policies.


9. Your Rights as a Data Subject

Subject to applicable law, you have the following rights regarding your Personal Data:

Right to Be Informed: to receive clear information about how your data is processed.

Right of Access: to obtain a copy of the Personal Data we hold about you.

Right to Rectification: to correct inaccurate or incomplete data.

Right to Erasure: to request deletion of your data, subject to legal retention obligations.

Right to Restrict Processing: to limit how your data is processed in certain circumstances.

Right to Object: to object to processing based on legitimate interests or for direct marketing.

Right to Data Portability: to receive your data in a structured, machine-readable format.

Right to Withdraw Consent: where processing is based on consent, you may withdraw it at any time.

Right to Lodge a Complaint: with the Saudi Data and Artificial Intelligence Authority (SDAIA) or competent authority.


To exercise any of these rights, contact us at privacy@sourcesin.com. We will respond within thirty (30) days, except where the law permits an extension. We may request reasonable verification of your identity before fulfilling the request.


10. Account and Data Deletion

Users may request deletion of their Personal Data and SourcesIn account at any time by contacting privacy@sourcesin.com or by submitting a request through https://sourcesin.com/data-deletion. Upon verified request, SourcesIn will delete or anonymize the user’s Personal Data unless retention is required by applicable laws or regulatory obligations.


10.1 Consumer Account Deletion

Consumers may request deletion of their account and associated Personal Data by:

Sending an email to privacy@sourcesin.com or info@sourcesin.com with the subject “Account Deletion Request.”

Submitting a request through the Data Deletion page at https://sourcesin.com/data-deletion

Users may also delete their account through the app or website Profile section by selecting “Delete Account”..


10.2 Business Account Deletion

Business Users may request deletion of their business account, listings, and associated data by submitting a request through privacy@sourcesin.com, including:

Business legal name and Commercial Registration number.

Registered email address and authorized representative information.

Reason for deletion and confirmation of authorization.


10.3 Meta / Facebook Login Data Deletion

If you connected your account through Meta, Facebook, Instagram, or WhatsApp Business, you may also disconnect SourcesIn directly from your Facebook account by visiting Facebook Settings → Apps and Websites → SourcesIn → Remove. To request deletion of associated Meta Platform Data, contact privacy@sourcesin.com.


10.4 Limitations on Deletion

We may retain certain information after a deletion request when required for:

Compliance with ZATCA, accounting, and tax obligations (minimum 6 years).

Anti-money laundering and counter-terrorism financing recordkeeping.

Resolution of pending disputes, claims, or legal proceedings.

Fraud prevention and protection of the rights of third parties.

Compliance with court orders or regulatory directives.


11. Information Security

SourcesIn implements appropriate technical, administrative, and organizational measures to protect Personal Data against unauthorized access, alteration, disclosure, loss, or destruction, including:


11.1 Technical Safeguards

Encryption of data in transit using TLS/HTTPS protocols.

Encryption of sensitive data at rest using industry-standard algorithms.

Access controls based on the principle of least privilege.

Multi-factor authentication for administrative access.

Continuous security monitoring, intrusion detection, and threat intelligence.

Regular vulnerability assessments and penetration testing.

Backup, disaster recovery, and business continuity procedures.


11.2 Administrative Safeguards

Confidentiality and data protection obligations imposed on all personnel.

Mandatory privacy and security training for staff.

Documented information security policies and incident response plans.

Vendor due diligence and data processing agreements with all Service Providers.


11.3 Data Breach Notification

In the event of a confirmed Personal Data breach that is likely to result in significant harm, SourcesIn will notify affected individuals and SDAIA within seventy-two (72) hours of becoming aware of the breach, in accordance with the Personal Data Protection Law and its Implementing Regulations.

Despite the above measures, no method of electronic transmission or storage is one hundred percent (100%) secure. We cannot guarantee absolute security and encourage users to maintain strong, unique passwords and to safeguard their account credentials.


12. Cookies and Tracking Technologies

The Service uses cookies, pixels, SDKs, local storage, and similar technologies to operate, secure, analyze, and improve the Platform. The categories of technologies we use include:

Strictly Necessary: required for authentication, security, load balancing, and core functionality.

Functional: remembering preferences, language, region, and personalization settings.

Analytical: measuring usage, performance, and identifying improvements (subject to consent).

Marketing: delivering relevant advertisements and measuring campaign effectiveness (subject to consent).


You may manage cookies through your browser or device settings, or through the cookie consent banner where applicable. Disabling certain cookies may affect functionality.


13. Children’s Privacy

The Service is not directed to children under the age of eighteen (18) without verifiable parental or guardian consent. We do not knowingly collect Personal Data from children. If we become aware that we have collected data from a child without appropriate consent, we will delete such data without undue delay.

Parents or guardians who believe a child has provided Personal Data without authorization should contact privacy@sourcesin.com.


14. Third-Party Links and Integrations

The Service may contain links, integrations, or content from third parties, including merchants, delivery partners, payment providers, and social media platforms. SourcesIn is not responsible for the privacy practices, content, or security of such third parties. We encourage you to review the privacy policies of any third party before providing them with Personal Data.


15. Artificial Intelligence and Automated Processing

SourcesIn uses artificial intelligence, machine learning, and automated decision-making technologies to enhance and personalize the Service, including:

Routing optimization and delivery time estimation.

Fraud detection, risk scoring, and anomaly identification.

Personalized search results, product recommendations, and pricing.

Customer support chatbots and intelligent ticket routing.

Content moderation and safety monitoring.


Where automated decisions produce legal or similarly significant effects on you, you have the right to request human review, express your point of view, and contest the decision. Contact privacy@sourcesin.com to exercise this right.


16. Changes to This Privacy Policy

We may update this Policy periodically to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes, we will notify users by posting the updated Policy on the Service, updating the “Last Updated” date, and where appropriate, sending an email or in-app notification.

Continued use of the Service after the effective date of an updated Policy constitutes acceptance of the changes. If you do not agree with the updated Policy, you should stop using the Service and request account deletion.


17. Governing Law and Dispute Resolution

This Policy is governed by and construed in accordance with the laws and regulations of the Kingdom of Saudi Arabia, including the Personal Data Protection Law and its Implementing Regulations. Any dispute arising from or relating to this Policy shall be resolved through:

Good-faith negotiation between the parties in the first instance.

Mediation through authorized Saudi mediation centers, where applicable.

The competent courts and judicial authorities of the Kingdom of Saudi Arabia, with venue in the Eastern Province unless otherwise required by law.


18. Contact Information

For any inquiries, complaints, or requests relating to this Privacy Policy or the processing of your Personal Data, please contact us through any of the channels below.


Data Protection Contact Details

Controller: Almasdar In Vehicle Guidance Establishment (SourcesIn)

Arabic Name: مؤسسة المصدر إن لتوجيه المركبات

Unified National Number: 7034653712

Privacy Email: privacy@sourcesin.com

General Email: info@sourcesin.com

Website: https://sourcesin.com

Data Deletion Page: https://sourcesin.com/data-deletion/index.html

Country: Kingdom of Saudi Arabia


If you are unable to resolve a concern through SourcesIn, you have the right to lodge a complaint with the Saudi Data and Artificial Intelligence Authority (SDAIA) or the competent regulatory authority.


End of Privacy Policy

© 2026 Almasdar In Vehicle Guidance Establishment. All rights reserved.

Document prepared in compliance with the Personal Data Protection Law of the Kingdom of Saudi Arabia.