Laff Privacy Policy
laf warja Company LLC — Commercial Registration No. 7054919290
Last updated: 2026-08-30 · Version: privacy-2026-08-30.1
DRAFT — pending review by Saudi counsel. This notice is removed only by the founder after counsel sign-off.
1. Who We Are
laf warja Company LLC, a limited liability company incorporated in the Kingdom of Saudi Arabia under Commercial Registration No. 7054919290 (“Laff”, “we”, “us”), is the controller of the personal data described in this policy. Laff operates the Laff / لفّ mobile application and the website laffapp.com (together, the “Service”). Our company website is lafwarja.com.
For privacy requests, questions, and complaints, contact support@laffapp.com. This mailbox is our designated contact for data-subject requests under the Saudi Personal Data Protection Law and its implementing regulations (the “PDPL”).
2. Scope
This policy applies to everyone who uses the Service, including customers and personnel of food-truck businesses (“Operators”). Operators who applied for an operator account were shown a separate operator application privacy notice during onboarding; that notice remains in force as a separately acknowledged document and is not replaced by this policy.
3. Personal Data We Collect
We collect the following categories of personal data. Every category except the SDK-level diagnostic data described below is linked to your account while your account exists. We do not use any of it to track you across other companies’ apps or websites, we do not sell personal data, we do not share data with data brokers, and the app contains no advertising SDKs.
- Email address — your account identity when you sign in with email, Google, or Apple.
- Phone number — your account identity when you sign in with a phone one-time code.
- Physical address — a venue or neighborhood you supply for a catering request.
- Name — the display name you choose for your profile.
- Photos and videos — your profile photo and the media you attach to posts, reels, and reviews.
- Audio data — the audio track in a video you choose to record or upload; Laff transcribes it for publication screening.
- Other user content — posts, reviews, chat and truck-room messages, check-ins, and rankings you create.
- Customer-support data — the details you supply through the private operator support and privacy-request queue.
- Precise location — for customers: your device location, used to show the map and to verify check-in proximity; for Operators: the live GPS location the truck broadcasts to followers.
- Coarse location — the profile city or venue neighborhood you supply.
- User ID — your account identifier and a pseudonymous analytics identifier derived from it.
- Device ID — the APNs/FCM installation token stored under your signed-in account so Laff can route notifications to this app installation.
- Purchase history — pickup orders and catering requests. Payment is made on pickup; the app collects no payment credentials (no card numbers, no bank details).
- Product interaction — first-party analytics events describing how the Service is used.
- Other usage data — usage data generated by Google Sign-In and used for its analytics.
- Health-certificate verification data — for a person working inside a food cart: the health-certificate reference, issuer, verification status, and expiry. Laff does not collect examinations, diagnoses, laboratory results, or treatment records.
- Other operator verification and work-readiness data — the operator lane and applicant capacity; mobile-cart licence reference; applicable commercial registration or unified number; site-authorization reference; relationship to the applicant; and direct-notice or confirmation state.
- Other diagnostic data — unlinked operational diagnostics generated by Firebase Authentication, Firestore, and Messaging for analytics and app functionality.
Except for other usage data, which is used for analytics only, the categories above are collected for app functionality. User ID, Device ID, product interaction, and other operator verification and work-readiness data are also used for analytics; unlinked other diagnostic data is used for app functionality and analytics. Laff treats in-cart worker health-certificate verification data as restricted personal data. We do not request financial or card data, your contacts, your browsing or search history outside the Service, or advertising data of any kind.
4. Purposes of Processing
We process personal data to: (a) operate and provide the Service, including requested bilingual business-name suggestions; (b) improve, develop, and test the Service; (c) personalize content, rankings, and recommendations; (d) secure the Service, prevent fraud and abuse, and enforce our terms; (e) moderate content, including automated screening; (f) analyze usage and perform research; (g) communicate with you about the Service, your account, and your activity; and (h) with your consent, send you marketing communications.
Marketing. Marketing messages are sent only with your consent, and every message offers an easy opt-out. Marketing by SMS is sent only after a confirmed double opt-in and is not sent between 8:00 p.m. and 8:00 a.m., in line with applicable Saudi regulations.
5. Legal Bases
We rely on the legal bases recognized by the PDPL: performance of a contract with you (operating your account and the Service); our legitimate interests (securing, improving, moderating, and analyzing the Service) where those interests do not prejudice your rights; your consent (marketing, and wherever the PDPL requires it); and compliance with legal obligations.
6. Aggregated and Anonymized Data
We may create aggregated, statistical, de-identified, or anonymized data from personal data and from use of the Service — including usage statistics, location heatmaps, market insights, benchmarks, and other derived datasets. Once data has been anonymized so that it no longer identifies you, directly or indirectly, it ceases to be personal data under the PDPL. Laff owns all aggregated and anonymized data and may use, retain, license, publish, and commercially exploit it for any lawful purpose, without restriction, notice, or compensation, provided it does not identify you.
7. Sharing and Disclosure
We share personal data only as follows:
- Service providers (processors). Google LLC provides our cloud infrastructure (Firebase: authentication, database, storage, push notifications, crash reporting). Cloudflare provides speech transcription for automated video moderation: Laff sends the audio track extracted from a user video so that Cloudflare can return a transcript for screening. OpenAI screens written text, speech transcripts, and image bytes for moderation and, when an operator requests it, provides an editable bilingual truck-name suggestion. For a name suggestion, Laff sends only the proposed public name and the source and target language — not an account identifier, licence reference, application identifier, or location. Processors act on our instructions under contractual safeguards.
- Operators and authorized reviewers. Operators receive aggregated analytics about their own trucks (for example, check-in counts, visitor statistics, and heatmaps). Operators also see the social interactions the Service already displays by design — for example, your public check-ins, reviews, and follows relating to their truck. A legal owner, authorized manager, or named Laff reviewer may receive only the operator and worker verification status needed for their unit and role; an ordinary shift worker does not receive another person's raw certificate reference.
- Other users. Content you publish (profile, posts, reviews, check-ins on public surfaces) is visible to other users as the Service is designed to display it.
- Legal compliance. We disclose data where required by law, regulation, or a binding order of a competent authority, or to protect users, the public, our rights, or the integrity of the Service.
- Business transfers. If Laff is involved in a merger, acquisition, financing, reorganization, or sale of all or part of its assets, personal data may be transferred or assigned to the successor or acquirer as part of that transaction, subject to this policy and applicable law.
8. Transfers Outside the Kingdom
Some processing occurs outside the Kingdom of Saudi Arabia: authentication data is hosted by Google in the United States, push notifications are delivered through Google’s global infrastructure, Cloudflare transcribes audio extracted from user videos for moderation, and OpenAI performs automated content screening and requested public truck-name suggestions. We carry out such transfers in accordance with the PDPL and its Regulation on Personal Data Transfer outside the Kingdom, applying the safeguards required by the Saudi Data and Artificial Intelligence Authority (SDAIA), and limiting transfers to the minimum necessary to operate the Service.
9. Retention
We retain personal data for as long as necessary for the purposes above — generally, for the lifetime of your account — and thereafter only as needed to comply with legal obligations, resolve disputes, and enforce agreements. Raw analytics events and similar operational records are additionally subject to automatic time-limited expiry enforced by our systems.
Operator applications remain disabled until Laff publishes and implements a category-specific retention period or clear retention criterion for application references, worker verification, shift assignment, reviewer audit, support, and legal-hold records.
10. Your Rights and Deletion
Under the PDPL you have the right to be informed about our processing, to request access to your personal data, to request correction of inaccurate data, and to request deletion. You can delete your account directly in the app (Settings → account deletion). Account deletion removes your account data, severs the link between your account and its pseudonymous analytics identifier, and purges the raw analytics events associated with it. You may also exercise any right by contacting support@laffapp.com; we will respond within the periods required by the PDPL. If you are dissatisfied, you may escalate to the competent authority (SDAIA).
11. Security
We protect personal data with access controls, server-enforced security rules, private storage paths, role checks, and monitoring. No system can guarantee absolute security; we ask you to protect your sign-in method and notify us of any suspected compromise.
12. Children
The Service is not directed to children under 13 years of age, and we do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided personal data, contact support@laffapp.com and we will delete it.
13. Changes to This Policy
We may update this policy from time to time. We will post the updated version in the app or on the site with a new “Last updated” date, and where required by law we will provide additional notice. Your continued use of the Service after an update constitutes acceptance of the updated policy.
14. Language
This policy is issued in English and Arabic. In the event of any conflict between the two texts, the Arabic text prevails.
15. Contact
laf warja Company LLC — Commercial Registration No. 7054919290, Kingdom of Saudi Arabia. Privacy requests and questions: support@laffapp.com.
سياسة الخصوصية — لفّ (Laff)
شركة laf warja Company LLC — سجل تجاري رقم 7054919290
آخر تحديث: 2026-08-30 · الإصدار: privacy-2026-08-30.1
مسودة — بانتظار مراجعة مستشار قانوني سعودي. لا يُزال هذا الإشعار إلا من قبل المؤسس بعد اعتماد المستشار القانوني.
1. من نحن
شركة laf warja Company LLC، وهي شركة ذات مسؤولية محدودة مؤسسة في المملكة العربية السعودية بموجب السجل التجاري رقم 7054919290 (ويشار إليها بـ«لفّ» أو «نحن»)، هي جهة التحكم في البيانات الشخصية الموضحة في هذه السياسة. تُشغّل لفّ تطبيق «لفّ / Laff» للأجهزة المحمولة والموقع الإلكتروني laffapp.com (ويشار إليهما معًا بـ«الخدمة»). الموقع الإلكتروني للشركة هو lafwarja.com.
للطلبات والاستفسارات والشكاوى المتعلقة بالخصوصية، يُرجى التواصل عبر البريد الإلكتروني support@laffapp.com، وهو قناة التواصل المخصصة لطلبات أصحاب البيانات الشخصية بموجب نظام حماية البيانات الشخصية في المملكة العربية السعودية ولوائحه التنفيذية (ويشار إليه بـ«النظام»).
2. نطاق السياسة
تسري هذه السياسة على جميع مستخدمي الخدمة، بمن فيهم العملاء والعاملون لدى منشآت عربات الطعام المتنقلة (ويشار إلى كل منها بـ«المشغّل»). وقد اطّلع المشغّلون الذين تقدموا بطلب فتح حساب مشغّل على إشعار خصوصية مستقل خاص بطلب المشغّل أثناء إجراءات التسجيل؛ ويظل ذلك الإشعار ساريًا بوصفه وثيقة أُقرّ بها إقرارًا مستقلًا، ولا تحل هذه السياسة محله.
3. البيانات الشخصية التي نجمعها
نجمع فئات البيانات الشخصية التالية، وجميعها مرتبطة بحسابك ما دام الحساب قائمًا باستثناء بيانات التشخيص على مستوى حزم الخدمات الموضحة أدناه. ولا نستخدم أيًا منها لتتبّعك عبر تطبيقات أو مواقع جهات أخرى، ولا نبيع البيانات الشخصية، ولا نشاركها مع وسطاء البيانات، ولا يتضمن التطبيق أي حزم برمجية إعلانية.
- البريد الإلكتروني — هوية حسابك عند تسجيل الدخول بالبريد الإلكتروني أو بحساب Google أو Apple.
- رقم الهاتف — هوية حسابك عند تسجيل الدخول برمز التحقق الهاتفي لمرة واحدة.
- العنوان الفعلي — موقع المناسبة أو الحي الذي تدخله في طلب تموين (كيترينج).
- الاسم — اسم العرض الذي تختاره لملفك الشخصي.
- الصور ومقاطع الفيديو — صورة ملفك الشخصي والوسائط التي ترفقها بالمنشورات والمقاطع القصيرة والمراجعات.
- البيانات الصوتية — المسار الصوتي في مقطع فيديو تختار تسجيله أو رفعه؛ وتحوّله لفّ إلى نص لغرض فحص المحتوى قبل النشر.
- محتوى المستخدم الآخر — المنشورات والمراجعات ورسائل المحادثات وغرف العربات وتسجيلات الحضور والتصنيفات التي تنشئها.
- بيانات دعم العملاء — التفاصيل التي ترسلها عبر قناة دعم المشغّلين وطلبات الخصوصية الخاصة.
- الموقع الجغرافي الدقيق — للعملاء: موقع جهازك، ويُستخدم لعرض الخريطة والتحقق من القرب المكاني عند تسجيل الحضور؛ وللمشغّلين: موقع البث المباشر لنظام تحديد المواقع (GPS) الذي تبثه العربة لمتابعيها.
- الموقع الجغرافي التقريبي — المدينة في ملفك الشخصي أو حي المناسبة الذي تدخله.
- معرّف المستخدم — معرّف حسابك ومعرّف تحليلي مستعار مشتق منه.
- معرّف الجهاز — رمز تثبيت APNs/FCM المحفوظ ضمن حسابك المسجّل لتوجيه إشعارات لفّ إلى هذا التثبيت من التطبيق.
- سجل المشتريات — طلبات الاستلام وطلبات التموين (الكيترينج). ويتم الدفع عند الاستلام؛ ولا يجمع التطبيق أي بيانات دفع (لا أرقام بطاقات ولا بيانات مصرفية).
- التفاعل مع المنتج — أحداث تحليلية من الطرف الأول تصف كيفية استخدام الخدمة.
- بيانات استخدام أخرى — بيانات استخدام تنشئها خدمة تسجيل الدخول من Google وتستخدمها لأغراض تحليلاتها.
- بيانات التحقق من الشهادة الصحية — لكل شخص يعمل داخل عربة الطعام: مرجع الشهادة الصحية وجهتها وحالة التحقق وتاريخ الانتهاء. ولا تجمع لفّ الفحوص الطبية أو التشخيصات أو نتائج المختبر أو سجلات العلاج.
- بيانات أخرى للتحقق من المشغّل وجاهزية العمل — مسار المشغّل وصفة مقدم الطلب؛ ومرجع رخصة العربة المتنقلة؛ والسجل التجاري أو الرقم الموحد عند انطباقه؛ ومرجع تصريح الموقع؛ والصلة بمقدم الطلب؛ وحالة الإشعار أو التأكيد المباشر.
- بيانات تشخيص أخرى — بيانات تشخيص تشغيلية غير مرتبطة بالهوية تنشئها خدمات Firebase للمصادقة وFirestore والإشعارات لأغراض التحليلات وتشغيل التطبيق.
باستثناء بيانات الاستخدام الأخرى التي تُستخدم للتحليلات فقط، تُجمع الفئات أعلاه لأغراض تشغيل التطبيق. وتُستخدم فئات معرّف المستخدم ومعرّف الجهاز والتفاعل مع المنتج وبيانات التحقق الأخرى للمشغّل وجاهزية العمل أيضًا لأغراض التحليلات؛ كما تُستخدم البيانات التشخيصية الأخرى غير المرتبطة بالهوية لأغراض تشغيل التطبيق والتحليلات. وتتعامل لفّ مع بيانات التحقق من الشهادة الصحية للعامل داخل العربة باعتبارها بيانات شخصية مقيّدة. ولا نطلب البيانات المالية وبيانات البطاقات أو جهات الاتصال أو سجل التصفح أو البحث خارج الخدمة أو أي بيانات إعلانية أيًا كان نوعها.
4. أغراض المعالجة
نعالج البيانات الشخصية من أجل: (أ) تشغيل الخدمة وتقديمها، بما في ذلك اقتراح اسم النشاط باللغة الأخرى عند طلبه؛ (ب) تحسين الخدمة وتطويرها واختبارها؛ (ج) تخصيص المحتوى والتصنيفات والتوصيات؛ (د) تأمين الخدمة ومنع الاحتيال وإساءة الاستخدام وإنفاذ شروطنا؛ (هـ) الإشراف على المحتوى، بما في ذلك الفحص الآلي؛ (و) تحليل الاستخدام وإجراء البحوث؛ (ز) التواصل معك بشأن الخدمة وحسابك ونشاطك؛ (ح) وبموافقتك، إرسال الرسائل التسويقية.
التسويق. لا تُرسل الرسائل التسويقية إلا بموافقتك، وتتضمن كل رسالة وسيلة ميسّرة لإلغاء الاشتراك. ولا تُرسل الرسائل التسويقية النصية القصيرة (SMS) إلا بعد موافقة مزدوجة مؤكدة، ولا تُرسل بين الساعة الثامنة مساءً والثامنة صباحًا، وفقًا للأنظمة السعودية ذات الصلة.
5. الأسس النظامية للمعالجة
نستند إلى الأسس النظامية المقررة في النظام: تنفيذ العقد المبرم معك (تشغيل حسابك والخدمة)؛ والمصلحة المشروعة (تأمين الخدمة وتحسينها والإشراف عليها وتحليلها) بما لا يمس حقوقك؛ وموافقتك (للتسويق وحيثما يشترط النظام الموافقة)؛ والامتثال للالتزامات النظامية.
6. البيانات المجمّعة ومجهولة الهوية
يجوز لنا إنشاء بيانات مجمّعة أو إحصائية أو منزوعة الهوية أو مجهولة الهوية من البيانات الشخصية ومن استخدام الخدمة — بما في ذلك إحصاءات الاستخدام، والخرائط الحرارية للمواقع، ورؤى السوق، والمؤشرات المقارنة، وغيرها من مجموعات البيانات المشتقة. ومتى أُخفيت هوية البيانات بحيث لم تعد تدل عليك بشكل مباشر أو غير مباشر، فإنها تخرج عن نطاق البيانات الشخصية بموجب النظام. وتملك لفّ جميع البيانات المجمّعة ومجهولة الهوية، ويجوز لها استخدامها والاحتفاظ بها وترخيصها ونشرها واستغلالها تجاريًا لأي غرض مشروع، دون قيد أو إشعار أو مقابل، شريطة ألا تدل عليك.
7. المشاركة والإفصاح
لا نشارك البيانات الشخصية إلا على النحو التالي:
- مقدمو الخدمات (جهات المعالجة). توفر شركة Google LLC بنيتنا التحتية السحابية (خدمات Firebase: المصادقة وقواعد البيانات والتخزين والإشعارات الفورية وتقارير الأعطال). وتوفر شركة Cloudflare خدمة تحويل الكلام إلى نص لأغراض الإشراف الآلي على الفيديو؛ إذ ترسل لفّ المسار الصوتي المستخرج من فيديو المستخدم كي تعيد Cloudflare نصًا مكتوبًا للفحص. وتفحص شركة OpenAI النصوص المكتوبة ونصوص الكلام والصور المرسلة على هيئة بيانات لأغراض الإشراف، وتقدم — عند طلب المشغّل — اقتراحًا قابلًا للتعديل لاسم العربة باللغة الأخرى. ولإنشاء اقتراح الاسم، لا ترسل لفّ إلا الاسم العلني المقترح ولغتي المصدر والهدف؛ ولا ترسل مع الطلب معرّف الحساب أو مرجع الرخصة أو معرّف الطلب أو الموقع. وتعمل جهات المعالجة بناءً على تعليماتنا وبموجب ضمانات تعاقدية.
- المشغّلون والمراجعون المخولون. يتلقى المشغّلون تحليلات مجمّعة عن عرباتهم (مثل أعداد تسجيلات الحضور وإحصاءات الزوار والخرائط الحرارية). كما يطّلع المشغّلون على التفاعلات الاجتماعية التي تعرضها الخدمة أصلًا بحكم تصميمها — مثل تسجيلات حضورك ومراجعاتك ومتابعاتك العلنية المتعلقة بعربتهم. ولا يتلقى المالك النظامي أو المدير المخول أو مراجع لفّ المسمى إلا حالة التحقق اللازمة لوحدته ودوره؛ ولا يطلع عامل الوردية العادي على مرجع الشهادة الخام لشخص آخر.
- المستخدمون الآخرون. يكون المحتوى الذي تنشره (الملف الشخصي والمنشورات والمراجعات وتسجيلات الحضور على الواجهات العامة) مرئيًا للمستخدمين الآخرين وفق تصميم الخدمة.
- الامتثال النظامي. نفصح عن البيانات متى اقتضى ذلك نظام أو لائحة أو أمر ملزم صادر عن جهة مختصة، أو لحماية المستخدمين أو الجمهور أو حقوقنا أو سلامة الخدمة.
- انتقال الأعمال. إذا كانت لفّ طرفًا في اندماج أو استحواذ أو تمويل أو إعادة هيكلة أو بيع لكل أصولها أو بعضها، فيجوز نقل البيانات الشخصية أو التنازل عنها إلى الخلف أو الجهة المستحوذة في إطار تلك الصفقة، مع مراعاة هذه السياسة والأنظمة واجبة التطبيق.
8. نقل البيانات خارج المملكة
تجري بعض عمليات المعالجة خارج المملكة العربية السعودية: فبيانات المصادقة تُستضاف لدى Google في الولايات المتحدة الأمريكية، وتُسلَّم الإشعارات الفورية عبر البنية التحتية العالمية لشركة Google، وتحول Cloudflare الصوت المستخرج من فيديوهات المستخدمين إلى نص لأغراض الإشراف، ويُجرى لدى شركة OpenAI الفحص الآلي للمحتوى وإنشاء اقتراحات أسماء العربات العلنية التي يطلبها المشغّل. وننفذ عمليات النقل هذه وفقًا للنظام ولائحة نقل البيانات الشخصية خارج حدود المملكة، مع تطبيق الضمانات التي تقررها الهيئة السعودية للبيانات والذكاء الاصطناعي (سدايا)، وقصر النقل على الحد الأدنى اللازم لتشغيل الخدمة.
9. الاحتفاظ بالبيانات
نحتفظ بالبيانات الشخصية ما دامت لازمة للأغراض المبينة أعلاه — وبوجه عام طوال مدة قيام حسابك — وبعد ذلك بالقدر اللازم فقط للامتثال للالتزامات النظامية وتسوية المنازعات وإنفاذ الاتفاقيات. وتخضع أحداث التحليلات الخام والسجلات التشغيلية المماثلة إضافةً إلى ذلك لانتهاء صلاحية تلقائي محدد المدة تفرضه أنظمتنا.
وتظل طلبات المشغّلين معطلة إلى أن تنشر لفّ وتطبق مدة احتفاظ بحسب الفئة أو معيارًا واضحًا للاحتفاظ بمراجع الطلب والتحقق من العامل وإسناد الوردية وسجلات مراجعة القرار والدعم والحجز النظامي.
10. حقوقك وحذف الحساب
يكفل لك النظام الحق في العلم بمعالجتنا لبياناتك، والحق في طلب الاطلاع على بياناتك الشخصية، والحق في طلب تصحيح البيانات غير الدقيقة، والحق في طلب الحذف. ويمكنك حذف حسابك مباشرةً من داخل التطبيق (الإعدادات ← حذف الحساب). ويؤدي حذف الحساب إلى إزالة بيانات حسابك، وقطع الربط بين حسابك ومعرّفه التحليلي المستعار، ومحو أحداث التحليلات الخام المرتبطة به. كما يمكنك ممارسة أي من حقوقك عبر التواصل على support@laffapp.com؛ وسنستجيب خلال المدد المقررة في النظام. وإذا لم تكن راضيًا عن معالجتنا لطلبك، فيحق لك التصعيد إلى الجهة المختصة (سدايا).
11. أمن البيانات
نحمي البيانات الشخصية بضوابط وصول، وقواعد أمنية مفروضة على مستوى الخوادم، ومسارات تخزين خاصة، وتحقق من الأدوار، ومراقبة مستمرة. ولا يمكن لأي نظام ضمان الأمان المطلق؛ لذا نرجو منك حماية وسيلة تسجيل دخولك وإخطارنا بأي اشتباه في اختراق.
12. الأطفال
الخدمة غير موجهة للأطفال دون سن الثالثة عشرة، ولا نجمع عن علمٍ بيانات شخصية من طفل دون تلك السن. وإذا كان لديك ما يحملك على الاعتقاد بأن طفلًا دون الثالثة عشرة قد زوّدنا ببيانات شخصية، فيُرجى التواصل على support@laffapp.com وسنبادر إلى حذفها.
13. تعديل هذه السياسة
يجوز لنا تحديث هذه السياسة من حين لآخر. وسننشر النسخة المحدّثة في التطبيق أو على الموقع مع تاريخ «آخر تحديث» جديد، ونقدم إشعارًا إضافيًا متى اقتضت الأنظمة ذلك. ويُعد استمرارك في استخدام الخدمة بعد التحديث قبولًا للسياسة المحدّثة.
14. اللغة
تصدر هذه السياسة باللغتين الإنجليزية والعربية. وفي حال وجود أي تعارض بين النصين، يُعتد بالنص العربي.
15. التواصل
شركة laf warja Company LLC — سجل تجاري رقم 7054919290، المملكة العربية السعودية. طلبات واستفسارات الخصوصية: support@laffapp.com.