Flixiy
Flixiy Logistics Platform — warehousing and logistics services
This policy tells you plainly what data we take from you, why, who sees it, how long we keep it, and what you can do about it.
It covers your use of flixiy.com, the app.flixiy.com platform, and everything that branches off them.
We operate under the Personal Data Protection Law of the Kingdom of Saudi Arabia and its Implementing Regulations.
We collect nothing simply because we can. Every field below does work inside the platform.
Names, titles, emails and mobile numbers of the people your company authorises, together with the scope of each authority — who may issue release orders, who approves billing statements, who handles contractual matters. These details are printed into a contract appendix signed by both parties.
Inbound and outbound requests, receipt and shipment confirmations, stock balances, daily occupancy snapshots and service events — each carrying who created the movement and when, because a movement with no known author is a movement nobody answers for.
Quotations, the frozen text of issued contracts with the signatory's name and title, billing statements, amounts, payments, and the bank account details you pay from.
| Purpose | Lawful basis |
|---|---|
| Creating your account, verifying your email, letting you sign in | Performance of contract / consent |
| Assessing and pricing your request, matching your company's documents | Performance of contract, or steps taken at your request before one |
| Preparing and issuing your contract and preserving its text as signed | Performance of contract |
| Running your stock: inbound, outbound, counts, occupancy | Performance of contract |
| Issuing and collecting billing statements and invoices | Legal obligation (tax and accounting law) / performance of contract |
| Notifying you of what happens to your account, stock and contracts | Performance of contract |
| Protecting the platform: throttling sign-in attempts, detecting abuse | Legitimate interests |
| Improving the platform and fixing its defects | Legitimate interests |
| Responding to a lawful request from a competent authority | Legal obligation |
We do not put your data to a new purpose incompatible with the one it was collected for without telling you and, where consent is required, obtaining it.
We take no automated decision about you with legal or financial effect without a human reviewing it.
We do not sell your data, rent it, trade in it, or use it to advertise anything to anyone. Nothing leaves except to one of the following, and only to the extent needed:
| Recipient | What they see, and why |
|---|---|
| The logistics provider storing your goods | What is needed to run your stock: your company name, inbound and outbound requests, and contact details for whoever follows them up. They do not see your pricing or your financial statements with us. |
| Our hosting provider | Hosts the server the platform runs on. It does not access the data in the ordinary course of its work. |
| Our email provider | Delivers our messages to you, and so sees your address and the message text. |
| A payment gateway (where used) | Processes the payment. Card details do not pass through our servers. |
| Our advisers — accountant, lawyer, auditor | Only as far as their work requires, and under a duty of confidence. |
| Competent government authorities | On a valid lawful request, to satisfy a court order, or where the law requires it. |
| A buyer of the business, on sale or merger | The data transfers with the business. We will tell you beforehand, and this policy continues to apply until replaced by one announced to you. |
Anyone processing data on our behalf is bound by a contract confining their use of it to what we instructed.
Platform data is held on servers in المملكة العربية السعودية, and our accounting records and invoices are held inside the Kingdom of Saudi Arabia as tax law requires.
Where personal data must move outside the Kingdom — for instance because a service provider we rely on sits outside it — it does so only on a lawful basis, after assessing the impact of the transfer, and under contractual and technical safeguards that preserve the same level of protection.
| Data | Period |
|---|---|
| Email verification code | Fifteen minutes, then void |
| Password reset link | Two hours, single use |
| Failed sign-in attempts (IP and browser) | Thirty days, then deleted automatically |
| Backups | Thirty days, then destroyed |
| Your account, company details and documents | For as long as our relationship lasts |
| Contracts, billing statements, invoices, accounting records | At least six years from the end of the tax period, and longer where the law requires a longer period |
| Operational records (inbound, outbound, occupancy) | As long as they support an issued invoice, following its period |
What has outlived its period is destroyed or anonymised so that it no longer identifies anyone.
The Personal Data Protection Law of the Kingdom gives you the following rights:
How to ask: write from the email address registered with us to mohammad@flixiy.com and say what you want. We may ask you to prove your identity — a request carried out without verification is a door opened onto your account for someone else.
When we reply: within thirty days of your request being complete. If we decline any part of it, we tell you the legal reason.
It costs you nothing — unless a request is repeated to a manifestly excessive degree, in which case we tell you the cost before charging it.
Even so, no system is absolutely secure, and we will not promise you what nobody can deliver. What we do promise is to take proper measures, and to tell you if something happens that affects you.
We notify the competent authority within seventy-two hours of becoming aware of the incident, and we notify you without undue delay whenever the incident poses a high risk to your data or your rights — telling you what happened, which of your data it touched, what we did, and what we advise you to do.
We do not bury an incident because it is embarrassing.
We use strictly operational cookies only. They are necessary for the platform to work and cannot be dispensed with:
| Cookie | What it does | Lifetime |
|---|---|---|
sessionid | Keeps your session open after sign-in | Eight hours |
csrftoken | Prevents cross-site request forgery | One year |
| Language cookie | Remembers whether you chose Arabic or English | One year |
We use no advertising trackers, no third-party analytics, and we do not follow you across other sites. That is why you will find no "accept cookies" banner on the platform — a banner offering no choice beneath it is a banner closed without reading.
The platform is a business-to-business service, is not directed at anyone under eighteen, and we do not knowingly collect their data. If we learn that an account belongs to a minor, it is closed and its data destroyed.
We may amend it when our services change or the law changes. Every version carries a version number and an effective date at its head — because a policy replaced without a number is a policy nobody can tell which version you agreed to.
If a change is material we will tell you by your registered email or by a visible notice in the platform before it takes effect.
For any question about your privacy, to exercise one of your rights, or to make a complaint:
We reply within thirty days. If our answer does not satisfy you, you have the right to complain to the competent personal data protection authority in the Kingdom of Saudi Arabia (the Saudi Data and AI Authority — SDAIA).