Privacy Policy
Last updated: 6 October 2026
This policy explains how personal data is collected, used and protected when you use the A to B app, website and provider portal, and the rights available to you. A TO B Partners, in the Kingdom of Saudi Arabia, operates the platform and is the controller responsible for personal data processing.
Provider accounts
Providers register with an email address and manage their business profile, services, packages and photos through their account. We collect the name, email and contact details they provide, business information, specialties, prices, photos, and any business documents they choose to upload as PDFs or images, including document numbers and expiry dates if entered. Providers may add bank-account details in their portal. This information is used to manage the provider relationship, review applications, contact providers and manage their listings; uploading a document or seeing a “reviewed” status is not government verification. Business documents are not shown to customers and are kept in private file storage accessible to the account owner and authorized administrators. The visibility of business profiles and services is subject to the platform’s approval and publication procedures.
Supabase hosts the database and files in Frankfurt, Germany. Data uploaded to these services is therefore stored outside Saudi Arabia. Do not upload documents you are not authorized to share or another person's information without their authorization. Providers may request access, correction or deletion through the contact channel below; some records may need to be retained under applicable requirements, and each request is reviewed individually.
What we collect
Data you give us
- Account details: name, email address and mobile number, depending on the sign-in method and fields you use. Contact details are used to manage and verify your account.
- Date of birth: to check the minimum age requirement of 16.
- Service addresses you save, including city, district, street, access details and coordinates selected on the map.
- Booking details: event date, guest count, and the options you choose.
- Reviews and comments you write about providers.
- Support messages you send us.
Data created by your use
- Booking and payment records.
- Limited technical logs for security and fraud prevention: sign-in time, device type and operating system.
- Location: when you select “use my location” and grant permission, the app requests your device location, which may be precise depending on device settings. Coordinates of the point you confirm are saved with the service address. You may refuse permission and select a point manually on the map. This feature does not track your location in the background.
What we do not collect
- No contacts, no microphone, no advertising identifier, and no tracking of you across other companies' apps or websites.
- We do not request access to your whole photo library; we use the system photo picker, which gives us only the image you pick.
- We do not store card numbers in the app.
Why we use your data
| Purpose | Basis |
| Creating your account and signing you in | Performance of our contract with you |
| Fulfilling your bookings and passing them to the provider | Performance of our contract with you |
| Invoicing, tax and accounting obligations | Legal obligation |
| Preventing fraud and abuse, resolving disputes | Legitimate interest |
Your data is not used to send promotional messages without your consent. You may withdraw consent through privacy settings or by contacting us.
Sharing with the provider
Your data reaches a provider in stages, and only as far as fulfilment requires:
- While browsing: nothing is shared. The provider does not know you viewed their package.
- When you create a request: they receive your first name only, the general area (district and city), the event date and the package details.
- After confirmation, as the date approaches: your mobile number and full delivery address are revealed, because delivery and setup are impossible without them. This starts only a limited period before the event.
- After the service ends: your number and address are hidden from them again.
Disclosure of contact details and service addresses to a provider is subject to access controls and disclosure-event logging.
Other parties
- Supabase: database and file hosting, and authentication services.
- Cloudflare: website hosting and protection, and encrypted file-backup storage. Web services may process your IP address and request data needed to deliver and protect pages.
- Email services: Resend is used for account emails; Google receives support and privacy correspondence.
- OpenStreetMap: the app loads map tiles when displaying a map. The map provider receives network requests and the map-area information needed to serve them.
- Payment services: the payment method and provider are identified in the payment flow when the service is available. We do not store card numbers in the app.
We do not sell your data, and we do not share it for advertising.
Retention
- Account data: for as long as your account exists. Deleted when you delete your account.
- Addresses, favourites and consents: deleted as soon as you delete your account.
- Completed booking and payment records: financial records needed for accounting, legal obligations and disputes are retained according to the requirements applicable to each record type. Account deletion removes direct identifying details, address copies and access notes; amounts, statuses and references needed for record integrity remain.
- Reviews and their photos/tags: removed when the account is deleted. Copies of precise delivery addresses and access notes inside bookings are also erased.
- Security audit logs: used to document actions and review security and access. Copies of personal text covered by account deletion are erased; other logs are reviewed according to their purpose and applicable requirements.
- Complaints and cancellations: free text, event notes and cancellation reasons are erased on account deletion; statuses, dates and amounts remain. Immediate deletion does not cover backups, authentication-provider logs or support/privacy correspondence; these are reviewed separately as part of a privacy request.
Your rights
You may access your data, correct it, request a copy, delete your account, and withdraw any consent you gave. All of these are in the app under Settings → Privacy & Account.
If you have already deleted the app, you can request account deletion from our public web page without reinstalling.
We respond to privacy requests within 30 days. If a legally permitted extension is needed, we inform you of the reason and duration. We may request limited information to verify your identity before fulfilling a request. Never send your password or sign-in code.
You may complain to the competent personal-data protection authority if your concern cannot be resolved through our privacy channel.
Security
- All traffic is encrypted in transit.
- Data access is restricted to authorized people and systems to the extent needed to provide the service.
- Sensitive financial data such as an IBAN is subject to restricted access and the display and audit controls applied to the account.
Children
The app is intended for people aged sixteen and over. Accounts for people under sixteen are not permitted. Contact privacy@atob.group to request deletion of their data.
Changes to this policy
We publish the updated version on this page and notify you of material changes through an appropriate channel before they take effect where notice or consent is required. The date of the last update is at the top of this page.
Contact
For privacy questions: privacy@atob.group