Privacy Policy
Achay Application
Last Updated: February 2, 2026
This Privacy Policy explains how ACHAY BEVERAGE ESTABLISHMENT ("Achay," "we," "us," or "our") collects, uses, stores, and protects your personal information when you use the Achay application (the "Application" or "App"). This policy applies to all users of the Application, whether accessed via mobile devices or web browsers.
By downloading, installing, accessing, or using the Application, you consent to the collection and use of your information as described in this Privacy Policy. If you do not agree with this policy, please do not use the Application.
1. Information We Collect
We collect the following types of information to provide and improve our table reservation services:
1.1 Information You Provide:
- Account Information: Phone number provided during registration, and optionally your name and email address.
- Authentication Data: One-time passwords (OTPs) sent via SMS for account verification and login purposes.
- Reservation Information: Table reservation details including date, time, number of guests, branch location, and any special requests or preferences.
- Payment Information: Payment details processed through our third-party payment gateway. We do not store your full credit/debit card numbers on our servers.
1.2 Information Collected Automatically:
- Device Information: Device type, operating system, unique device identifiers, and mobile network information.
- Usage Data: How you interact with the Application, including pages viewed, features used, and timestamps.
- Location Data: Approximate location data (if you grant permission) to show you nearby branches and provide location-relevant services.
2. How We Use Your Information
We use the collected information for the following purposes:
- Account Management: To create and manage your account, verify your identity via OTP, and maintain account security.
- Reservation Services: To process, confirm, and manage your table reservations at our branches.
- Payment Processing: To facilitate secure payments through our integrated payment gateway.
- Communications: To send you reservation confirmations, reminders, updates, and important service notifications via SMS or push notifications.
- Service Improvement: To analyze usage patterns and improve the Application's features, performance, and user experience.
- Customer Support: To respond to your inquiries and provide assistance.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes in the Kingdom of Saudi Arabia.
Note: We do not share your personal data with third-party restaurants or external businesses. Your data is used exclusively by Achay to provide you with our services.
3. Legal Basis for Processing
We process your personal data based on the following legal grounds, in accordance with the Saudi Arabia Personal Data Protection Law (PDPL):
- Consent: You provide consent when registering for an account and accepting this Privacy Policy.
- Contractual Necessity: Processing is necessary to fulfill the reservation and payment services you request.
- Legitimate Interest: We process data for improving our services, ensuring security, and preventing fraud.
- Legal Obligation: We may process data to comply with legal requirements under Saudi Arabian law.
4. Data Sharing and Disclosure
We do not sell or rent your personal information. We may share your data only with the following parties:
- Payment Gateway Providers: To process your payments securely. These providers have their own privacy policies governing data handling.
- SMS Service Providers: To deliver OTP codes and notification messages to your phone number.
- Push Notification Services: To deliver app notifications to your device (e.g., Apple Push Notification Service, Firebase Cloud Messaging).
- Legal Authorities: When required by law, court order, or governmental regulation in the Kingdom of Saudi Arabia, or to protect our rights, property, or safety.
We may use analytics services in the future to understand application usage and improve our services. If implemented, data shared with analytics providers will be anonymized where possible, and this policy will be updated accordingly.
5. Data Storage and Security
- Storage Location: Your data is stored on secure servers. We take reasonable measures to ensure data is processed and stored in compliance with Saudi Arabian laws.
- Security Measures: We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These include encryption of sensitive information, access controls, and secure communication protocols (SSL/TLS).
- No Absolute Guarantee: While we strive to protect your information, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security of your data.
6. Data Retention
- Active Accounts: We retain your personal data for as long as your account is active and as needed to provide you with our services.
- After Account Deletion: Upon account deletion request, we will delete or anonymize your personal data within 30 days, unless retention is required by law or for legitimate business purposes.
- Transaction Records: Payment and reservation records may be retained for up to 5 years as required by Saudi Arabian commercial and tax regulations.
7. Your Rights
Under the Saudi Arabia Personal Data Protection Law (PDPL), you have the following rights:
- Right to Access: You may request a copy of the personal data we hold about you.
- Right to Correction: You may request correction of inaccurate or incomplete personal data.
- Right to Deletion: You may request deletion of your personal data, subject to legal obligations and legitimate business needs.
- Right to Restrict Processing: You may request that we limit the processing of your personal data under certain circumstances.
- Right to Withdraw Consent: You may withdraw your consent to data processing at any time. This will not affect the lawfulness of processing carried out before the withdrawal.
- Right to Complain: You have the right to file a complaint with the Saudi Data and Artificial Intelligence Authority (SDAIA) if you believe your data rights have been violated.
To exercise any of these rights, please contact us using the information provided in Section 11.
8. Your Choices
You have the following choices regarding your information:
- Push Notifications: You can disable push notifications through your device settings or within the Application's notification settings.
- Location Services: You can enable or disable location access through your device settings at any time.
- Account Deletion: You may request deletion of your account and associated personal data by contacting us. Certain data may be retained as required by law.
9. Children's Privacy
The Application is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected data from a child under 18, we will take steps to delete such information promptly. If you believe that a child has provided us with personal information, please contact us immediately.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will notify you of material changes via the Application or push notifications. The "Last Updated" date at the top of this policy indicates when it was last revised. Your continued use of the Application after changes constitutes acceptance of the updated Privacy Policy.
By using the Achay Application, you acknowledge that you have read, understood, and agree to this Privacy Policy.