Privacy Policy
Effective Date: 16 September 2026
Your privacy matters to us. This statement explains how SHA LIMITED CO, trading as “Sha”, handles personal data about people who order through shaa.com.sa and the iOS app “Sha Shawarma” — our “Online Services”. Sha is the controller of that data under the Saudi Personal Data Protection Law (“PDPL”).
Sha is a Virtual Drive-Thru: order ahead, collect from your car. We are pickup only, so we never ask for a delivery address. The app is the same website inside a web view, and adds no analytics, advertising or crash-reporting software of its own.
1. Information We Collect
- Account: mobile number, first and last name, email if you add one, an internal customer number, a loyalty identifier built from the digits of your mobile number, and your sign-up date.
- Sign-in: the mobile number you enter and confirm. No passwords.
- Orders: store, cart, order, amount, payment result, order history.
- Car details: plate number, colour and model, asked when you say you are on your way, so we can find your car.
- Loyalty: your offers, streaks, points and rewards, and the orders that earn them.
- Messages: what you tell us at info@shaa.com.sa or 920018161.
Only your mobile number is required; without it we cannot open an account or take an order. Name, email and car model are optional. Plate number and colour are needed at collection. Location is optional.
Information Collected Through Automated Means
- Technical: IP address, device type, operating system, browser or app version, date and time.
- Usage: which pages of the ordering journey load and when, through Google Analytics 4 (G-EJQ3QMDLL8) in its standard setup. We added no tracking of individual taps or checkout steps.
- Storage: cookies and browser storage that keep you signed in, hold your cart, keep a summary of a recent order, and hold a Google Analytics identifier.
- Requests to Google: loading a store map sends your IP address to Google, as does your browser's connection to Google's font servers.
Not running: session replay, heatmaps, Microsoft Clarity, Microsoft Advertising, Meta, TikTok or Snapchat pixels, or any advertising SDK. We do not record your screen, mouse or keystrokes, and never read your advertising identifier (IDFA) — so you get no App Tracking Transparency prompt. No CCTV, no AI sensing, no contests or prize draws.
Location Information
We ask for location to find your nearest store, and to know you have arrived so your order can be brought out. Your coordinates are read on your device and compared there with store coordinates; they never reach our servers and we do not store them. While you wait to collect, the page watches your position continuously, stopping when you close the page or the order ends. It never runs in the background.
Location is optional — browse the store list and pick by hand instead. Turn the permission off in your device or browser settings, without asking us. Google Maps and Google Analytics can also guess a rough area from your IP address: far less precise, and separate from this permission.
2. How We Use the Information We Collect
- sign you in and keep you signed in;
- take, prepare and hand over your order;
- take payment and confirm it;
- contact you about an order;
- run our loyalty programme, and personalise the offers, streaks and rewards you see;
- answer questions and handle complaints;
- see in aggregate how the ordering journey performs;
- keep the service secure and prevent fraud and abuse;
- meet our tax, accounting and legal duties.
Our PDPL grounds: the contract you enter when you order (sign-in, orders, payment, order contact, and the loyalty record opened for you at sign-in); your consent (device location); a legal obligation (sales and tax records); our legitimate interests (security, fraud prevention, measuring use).
Marketing. We send no SMS or email campaigns. Your number signs you in and lets us reach you about orders. We tell Qubriux, our loyalty provider, that you have not consented to SMS or email marketing, and it holds that flag. The offers, streaks and rewards you see are personalised from your order history through Qubriux. If we ever start sending promotions, we will ask you to opt in first.
3. How We Share the Personal Information We Collect
These are the only parties that receive your data, each for one job, under contract and on our instructions.
| Who | What they get, and why |
|---|---|
| Checkout.com | Processes card and Apple Pay payments on its own systems. We get back the result, the order, and the card scheme and last four digits for your receipt — never the full card number, expiry date or security code. |
| Apple | Authorises Apple Pay on your device through Apple Wallet, under Apple's own privacy policy. |
| Authorities and advisers | Regulators, courts and our professional advisers, where the law requires it or a legal claim needs it. |
We never sell your data and never build advertising profiles. Azure Active Directory is used only for staff and administrator sign-in, and receives no customer data.
4. Children's Privacy Notice
You need your own mobile number and full legal capacity to hold a Sha account. If you do not have full legal capacity, your guardian must agree, and we will deal with your guardian about your data. The Service is not directed at children, we do not knowingly collect their data, and we run no advertising at all. If you think a child has given us data, write to info@shaa.com.sa and we will delete it.
5. Your Choices
- Location. Grant or refuse, and change your mind any time in your settings.
- Notifications. On the website we may ask to show a browser notification when you reach your store. Refusing changes nothing else.
- Analytics. There is no cookie banner today — the Google scripts load with the page. In a browser, use Google's Analytics Opt-out Add-on, or block analytics cookies for shaa.com.sa, which also signs you out and empties your cart. In the app no add-on can be installed, but Google Analytics never gets your name, number or account identifier, so no analytics record is tied to you.
- Loyalty. Every signed-in customer has a loyalty record, and there is no switch for it today. Deleting your account removes it.
- Marketing. Nothing to opt out of, because we send none.
- Sign-in and cart cookies. Ordering needs them. Block them and you cannot stay signed in or keep a cart.
6. Access to and Correction and Deletion of Personal Information
Under the PDPL you have the right to: know why we collect your data and on what basis; access it; get a copy in a readable, portable format; correct it; have it destroyed once it is no longer needed; withdraw consent where we rely on it, such as device location, as easily as you gave it; and object to processing based on our legitimate interests.
Email info@shaa.com.sa or call 920018161. We may ask about a recent order first, so we do not hand your data to someone else. We answer within 30 days — or up to 30 days more for a complex request or several at once, and we will say why before the first 30 days are up. If a law makes us keep something, we will tell you what and why.
Deleting your account. Do it yourself, in the app or on the website: account menu, Profile, Delete Account, then confirm. Or ask us to do it. Deletion removes your customer record — number, name and email — and permanently unlinks every past order by erasing the phone number and account reference on it. The order records stay as accounting records, stripped of anything that identifies you. The record Qubriux holds is not removed by this step: email us and we will request its deletion and confirm when it is done. Deletion does not cancel an order already being prepared.
If you think we have breached the PDPL, complain to the Saudi Data and Artificial Intelligence Authority (SDAIA) at sdaia.gov.sa. You need not raise it with us first. Complaints should normally be lodged within 90 days of the incident, or of the day you learned of it.
7. Cookies and Similar Technologies
Section 1 lists what is stored on your device: the sign-in cookie, your cart and recent-order summary, and the Google Analytics identifier. There is no consent banner; section 5 sets out your options. The app loads the same website, so the same storage applies, and we do not switch on Google Analytics advertising features.
8. Targeted Advertising
We do not advertise to you, here or anywhere else, and we track nothing across other companies' sites and apps. The only personalisation is the loyalty offers above, worked out from orders you placed with Sha.
9. Links to Other Websites and Social Media
Our footer links to TikTok, Instagram, Snapchat and WhatsApp. They are ordinary links, not pixels, and nothing is sent unless you click. Our homepage also shows an Instagram photo feed; loading those images reveals your IP address to the server hosting them. Payment pages, maps and app store listings belong to other companies too. Once you leave us, their privacy practices apply, not ours.
10. Information Security
We work to stop your data being lost, altered, destroyed or seen by the wrong people. Technical controls, internal rules and limits on staff access sit behind that.
What we can confirm today: traffic between your device and the Online Services runs over HTTPS, so it is encrypted on the way, and card details are entered on our payment provider's systems, never ours.
Access to your account is currently controlled by your mobile number alone. We are adding a one-time SMS code to confirm the number belongs to you. Until then, do not enter a number that is not yours. No online service can be completely secure.
11. How to Contact Us
SHA LIMITED CO
Head Office: P.O. Box 88768, Riyadh, Riyadh 11672
Kingdom of Saudi Arabia
- Email: info@shaa.com.sa
- Phone: 920018161
Say that your message is about privacy, so it reaches the right team quickly.
12. Further Information on Data Protection
Sha operates under the PDPL and its Implementing Regulations, and treats what you give us as confidential.
Data We Collect — section 1. No delivery address, no advertising identifier, no card number.
Data Usage — section 2. A new and incompatible purpose means telling you first, and asking your consent where the law requires it.
Data Retention — you can ask us to destroy your data at any time.
Security and Encryption — section 10.
Breach Notification — if your data is lost, exposed or accessed without authority, we investigate and contain it at once. We notify SDAIA within 72 hours of becoming aware. Where the incident may seriously harm you, we tell you without delay — by a notice in the Online Services and, where we can reach you, a message or a call — what happened, what data was involved, and what you can do. We keep a record of breaches, their causes and our response.
