العربية

Flixiy

Privacy Policy

Flixiy Logistics Platform — warehousing and logistics services

Version 1.1 Effective: 28/08/2026 Last updated: 28/08/2026

1 Who we are, and what this policy covers

This policy tells you plainly what data we take from you, why, who sees it, how long we keep it, and what you can do about it.

Data controller
Flixiy Logistics Platform
Privacy contact
info@flixiy.com

It covers your use of flixiy.com, the app.flixiy.com platform, and everything that branches off them.

We operate under the Personal Data Protection Law of the Kingdom of Saudi Arabia and its Implementing Regulations.

A business-to-business service. Flixiy serves companies, not consumers. The personal data we handle is, for the most part, data about your employees and delegates in their professional capacity — not about their private lives.

2 What we collect

We collect nothing simply because we can. Every field below does work inside the platform.

2.1 Your account

  • Full name, email address, mobile number, job title.
  • Your password — which we cannot see and could not retrieve: it is stored one-way hashed with Argon2, and its plain text is kept nowhere.
  • Your chosen language, the time your email was verified, and your last sign-in.

2.2 Your company and its documents

  • Trade name, unified company number, VAT number, national address, contact details.
  • The documents you upload: commercial registration, national address certificate, VAT certificate, and any others you add.

2.3 Your delegates

Names, titles, emails and mobile numbers of the people your company authorises, together with the scope of each authority — who may issue release orders, who approves billing statements, who handles contractual matters. These details are printed into a contract appendix signed by both parties.

If you enter another person's details (an employee or a delegate), it is you who informs them, and you are responsible for having the authority to enter those details.

2.4 Your stock operations

Inbound and outbound requests, receipt and shipment confirmations, stock balances, daily occupancy snapshots and service events — each carrying who created the movement and when, because a movement with no known author is a movement nobody answers for.

2.5 Contracting and billing

Quotations, the frozen text of issued contracts with the signatory's name and title, billing statements, amounts, payments, and the bank account details you pay from.

2.6 Technical and security data

  • On a failed sign-in attempt only: the username tried, the IP address and the browser type. We keep these for thirty days, then delete them automatically. We never record the failed password — it is usually a correct password for some other system.
  • A record of every message we sent you: address, subject, body, and whether it left or failed — so that "did your message reach me?" has an answer.
  • Strictly operational cookies (see section 11).

2.7 What we do not collect

  • We do not ask individual users for a national ID, iqama or passport number.
  • We do not receive or store payment card details.
  • We do not collect sensitive data — no health, religious or belief data, no affiliations, no biometric or genetic data.
  • We do not track you across other websites, and we run no advertising analytics.

3 Why we collect it — and the lawful basis for each purpose

PurposeLawful basis
Creating your account, verifying your email, letting you sign inPerformance of contract / consent
Assessing and pricing your request, matching your company's documentsPerformance of contract, or steps taken at your request before one
Preparing and issuing your contract and preserving its text as signedPerformance of contract
Running your stock: inbound, outbound, counts, occupancyPerformance of contract
Issuing and collecting billing statements and invoicesLegal obligation (tax and accounting law) / performance of contract
Notifying you of what happens to your account, stock and contractsPerformance of contract
Protecting the platform: throttling sign-in attempts, detecting abuseLegitimate interests
Improving the platform and fixing its defectsLegitimate interests
Responding to a lawful request from a competent authorityLegal obligation

We do not put your data to a new purpose incompatible with the one it was collected for without telling you and, where consent is required, obtaining it.

We take no automated decision about you with legal or financial effect without a human reviewing it.

4 Where the data reaches us from

  • From you directly — when you register, complete your company profile, upload its documents and create your requests.
  • From your company — when its account manager adds you as a user or a delegate.
  • From the service provider (the warehouse) — when it confirms receiving or shipping your goods, we receive what it recorded of that operational event.
  • From our team — when we create an account for you at your request and send you an invitation to activate it.

5 Who we disclose to — and who we never do

We do not sell your data, rent it, trade in it, or use it to advertise anything to anyone. Nothing leaves except to one of the following, and only to the extent needed:

RecipientWhat they see, and why
The logistics provider storing your goodsWhat is needed to run your stock: your company name, inbound and outbound requests, and contact details for whoever follows them up. They do not see your pricing or your financial statements with us.
Our hosting providerHosts the server the platform runs on. It does not access the data in the ordinary course of its work.
Our email providerDelivers our messages to you, and so sees your address and the message text.
A payment gateway (where used)Processes the payment. Card details do not pass through our servers.
Our advisers — accountant, lawyer, auditorOnly as far as their work requires, and under a duty of confidence.
Competent government authoritiesOn a valid lawful request, to satisfy a court order, or where the law requires it.
A buyer of the business, on sale or mergerThe data transfers with the business. We will tell you beforehand, and this policy continues to apply until replaced by one announced to you.

Anyone processing data on our behalf is bound by a contract confining their use of it to what we instructed.

6 Where your data is held

Platform data is held on servers in المملكة العربية السعودية, and our accounting records and invoices are held inside the Kingdom of Saudi Arabia as tax law requires.

Where personal data must move outside the Kingdom — for instance because a service provider we rely on sits outside it — it does so only on a lawful basis, after assessing the impact of the transfer, and under contractual and technical safeguards that preserve the same level of protection.

7 How long we keep it

DataPeriod
Email verification codeFifteen minutes, then void
Password reset linkTwo hours, single use
Failed sign-in attempts (IP and browser)Thirty days, then deleted automatically
BackupsThirty days, then destroyed
Your account, company details and documentsFor as long as our relationship lasts
Contracts, billing statements, invoices, accounting recordsAt least six years from the end of the tax period, and longer where the law requires a longer period
Operational records (inbound, outbound, occupancy)As long as they support an issued invoice, following its period

What has outlived its period is destroyed or anonymised so that it no longer identifies anyone.

Why not everything is deleted on request. If you ask us to delete your data we delete what the law does not require us to keep. Contracts, invoices and the records supporting them we keep for the statutory period — deleting them would be a breach, not a service, and they are also your own evidence if a dispute arises.

8 Your rights — and how to exercise them

The Personal Data Protection Law of the Kingdom gives you the following rights:

  • The right to be informed — to know what we collect about you, why, and who sees it. This document is the instrument of that right.
  • The right of access — to ask for a copy of what we hold about you.
  • The right to a readable copy — in a clear and portable format.
  • The right to correction — to correct what is incomplete, inaccurate or out of date. Most of your data you can correct yourself inside the platform.
  • The right to destruction — to ask us to delete what is no longer needed for the purpose it was collected for, so far as the law does not require us to keep it.
  • The right to withdraw consent — wherever processing rests on your consent. Withdrawal does not undo what happened before it.

How to ask: write from the email address registered with us to mohammad@flixiy.com and say what you want. We may ask you to prove your identity — a request carried out without verification is a door opened onto your account for someone else.

When we reply: within thirty days of your request being complete. If we decline any part of it, we tell you the legal reason.

It costs you nothing — unless a request is repeated to a manifestly excessive degree, in which case we tell you the cost before charging it.

9 How we protect your data

  • Encrypted in transit — every connection to the platform runs over HTTPS, with secure transport enforced (HSTS).
  • Passwords hashed one-way with Argon2 — we could not recover them if we wanted to.
  • Email verification is mandatory before the first sign-in, by a short-lived code.
  • Sign-in attempts are throttled, which stops automated guessing.
  • Role-based permissions — a user sees only their own company's spaces and data; a provider sees only its own warehouses.
  • A record of who did what and when on movements that carry consequences.
  • Backups tested by restoring them — a backup never tried is a backup nobody knows works.

Even so, no system is absolutely secure, and we will not promise you what nobody can deliver. What we do promise is to take proper measures, and to tell you if something happens that affects you.

10 If there is a data breach

We notify the competent authority within seventy-two hours of becoming aware of the incident, and we notify you without undue delay whenever the incident poses a high risk to your data or your rights — telling you what happened, which of your data it touched, what we did, and what we advise you to do.

We do not bury an incident because it is embarrassing.

11 Cookies

We use strictly operational cookies only. They are necessary for the platform to work and cannot be dispensed with:

CookieWhat it doesLifetime
sessionidKeeps your session open after sign-inEight hours
csrftokenPrevents cross-site request forgeryOne year
Language cookieRemembers whether you chose Arabic or EnglishOne year

We use no advertising trackers, no third-party analytics, and we do not follow you across other sites. That is why you will find no "accept cookies" banner on the platform — a banner offering no choice beneath it is a banner closed without reading.

12 Children

The platform is a business-to-business service, is not directed at anyone under eighteen, and we do not knowingly collect their data. If we learn that an account belongs to a minor, it is closed and its data destroyed.

13 Changes to this policy

We may amend it when our services change or the law changes. Every version carries a version number and an effective date at its head — because a policy replaced without a number is a policy nobody can tell which version you agreed to.

If a change is material we will tell you by your registered email or by a visible notice in the platform before it takes effect.

14 Contact and complaints

For any question about your privacy, to exercise one of your rights, or to make a complaint:

Email
info@flixiy.com

We reply within thirty days. If our answer does not satisfy you, you have the right to complain to the competent personal data protection authority in the Kingdom of Saudi Arabia (the Saudi Data and AI Authority — SDAIA).

Flixiy Logistics Platform · Privacy Policy · Version 1.1
This document is issued in Arabic and English; the Arabic text prevails in the event of any discrepancy.