Draft — under legal review
This text is a draft that our legal counsel has not approved yet, and it may change before it takes effect.
Privacy Policy
Last updated: Version: 2026-09-24
This policy explains how we collect, use and protect your personal data when you use the trainer.sa website and apps, in line with the Personal Data Protection Law issued by Royal Decree No. (M/19) dated 9/2/1443H and its implementing regulations.
1. Who is responsible for your data
[Legal name as registered in the commercial registry] is the controller of your personal data on the platform. You can reach our data protection officer using the details at the end of this policy.
2. The data we collect
Data you give us
- Account details: your name, mobile number, city, preferred language and, if you add it, your email address.
- Booking details: the service and time, the address of in-person sessions, and your notes to the trainer, which may include information about your health if you choose to share it.
- Communication: messages with trainers or trainees, reviews, reports and support conversations.
- For trainers: national ID or residence permit (iqama), professional certificates, bio, photos and intro video, service area and bank account (IBAN).
Data we collect automatically
- Device and app: device type, app version, installation ID and notification token.
- Approximate location: when you allow it, to find trainers near you.
- Security logs: such as log-in times and the devices used.
Payment data
Your card details are processed by a licensed payment gateway, and we never store your full card number. If you choose to save a card, we keep only a secure token and the last four digits.
3. Why we use your data
- To provide the service: creating your account, completing bookings and payments, and letting trainees and trainers communicate.
- Verification and safety: verifying trainers, preventing fraud and handling reports.
- Legal obligations: invoices, financial and tax records, and responding to requests from the competent authorities.
- Service notifications: booking confirmations, appointment reminders and security alerts.
- Marketing: only with your consent, which you can withdraw at any time.
- Improving the platform: aggregated usage statistics, with your consent where required.
4. Who we share your data with
- The other party to a booking: we share with the trainer only what they need to deliver the session, and they see the exact session address only after accepting the booking.
- Service providers: the payment gateway and banks, the text-message provider for one-time codes, and hosting and technology providers, under contracts that require them to protect the data and not use it for their own purposes.
- Public authorities: where the law requires us to.
We never sell your personal data.
5. Where your data is stored
Your data is stored in Saudi Arabia. We transfer data outside the Kingdom only when needed, for example to services that deliver notifications to devices, in line with the legal rules on data transfers and limited to the minimum necessary. Notifications never include the content of your messages.
6. How long we keep it
We keep data for as long as we need it for the purpose it was collected for, or for as long as the law requires, for example:
- One-time codes: 24 hours.
- Messages: 24 months after the last booking between the two parties.
- Documents from rejected trainer applications: 30 days.
- Invoices and financial records: the period set by law.
After that, we delete the data or anonymise it so that it can no longer identify you.
7. Your rights
The law gives you the right to:
- Be informed of how your data is collected and why it is processed.
- Access your data and obtain a copy of it in a clear, readable format.
- Have your data corrected, completed and updated.
- Ask for your data to be destroyed when it is no longer needed. Account deletion takes effect after a grace period of 14 days, during which you can change your mind.
- Withdraw your consent to processing that is based on consent.
- Complain to the Saudi Data and Artificial Intelligence Authority (SDAIA).
You can use most of these rights from "My account", and we respond to requests within the time the law sets. The practical steps are in Your account and personal data.
8. How we protect your data
We encrypt the connection between your device and the platform, encrypt sensitive documents such as identity documents and bank details, and limit access to the members of our team who need it, logging every access. We will never ask you for your one-time code or card details by message or phone.
9. Children
The platform is intended for people aged 18 and over. When booking sessions for a child, a parent or guardian provides only the details needed, and the account stays in the parent's or guardian's name.
10. Cookies and storage on your device
Our public pages don't set cookies when you visit them. If you change the site's appearance (light or dark), we remember your choice in your browser. Once you log in, we use only strictly necessary cookies to keep you logged in and protect your account.
11. Changes to this policy
We may update this policy from time to time. We will tell you about material changes before they take effect and record your acceptance together with the version you accepted.
12. Contact us
For any question about your data or to use your rights, contact our support team from inside the app, or email our data protection officer at [data protection email].