غلّة Ghallah
Loyalty policyGovernance and compliance

Draft pre-launch controls

Loyalty Governance and Compliance

Policies Ghallah and each car-wash owner must apply before, during, and after a loyalty campaign.

Governance version
LOY-GOV-1.0
Draft issue date
29 July 2026
This production-governance draft records the owner's decision, but it is not approved policy and does not authorize value activation until the tax adviser, privacy lead, and independent security reviewer sign the release-bound version.

Owner commercial decisions

  • Loyalty is a sellable Advanced Package capability, not a demo or non-binding promise.
  • Each merchant may select a threshold from 1 to 1,000 to fit its model; it should remain understandable and economically validated. Common examples are 5 or 10 visits or a time-limited campaign.
  • Publication requires Arabic and English name/description, eligible branches/services, period, reward, validity, budget and liability caps, stop posture, and written acceptance criteria.
  • MVP rewards are a fixed-amount discount or a capped eligible free service. No general cash points, cross-merchant transfer, or reward stacking.
  • A published campaign version is immutable. Change creates a new version, while accrued progress and issued rewards remain governed by the version that created them.

Legal bases and consent

  • Optional membership, phone matching, and card identity rely on separate, freely given, specific, provable, withdrawable loyalty-service consent.
  • Invoice completion, discounts, and tax obligations rely on contract and legal obligation, not revocable consent that could erase a financial record.
  • Network security, fraud prevention, rate limiting, and incident records rely on documented legitimate interest with rights balancing and minimization.
  • Treatment/Control measurement relies on assessed legitimate interest and pseudonymized information; Control receives no membership or value and no adverse individual decision.
  • Direct marketing is outside the MVP. It requires future purpose/channel-specific consent, clear sender identity, consent evidence, and free equally easy opt-out.

VAT and invoicing policy

  • A fixed-amount reward is a non-cash commercial discount on the underlying supply and is shown on the invoice. Server-authoritative VAT uses the approved post-discount consideration under the merchant tax decision.
  • A free service is bound to an eligible Catalog service and cap and appears as a transparent supply and commercial reduction with any customer-paid excess. If tax advice requires deemed-supply VAT or merchant-borne VAT, the merchant records it rather than hiding it.
  • A defect rewash is separate quality remediation, not a reward, and creates no loyalty movement. If prior invoice consideration or VAT changes, a lawful credit/debit note is used rather than editing history.
  • Production value cannot activate until the merchant tax treatment and ZATCA configuration are approved. Commercial wording cannot change tax law.

Cybersecurity and privacy by design

  • Release signing and key custody are separated; activation signer is not key custodian and security review is independent of operations.
  • Tenant RLS, least privilege, separate API/worker/reconciler roles, insert-only audit, and BOLA/concurrency/replay tests are mandatory.
  • QR and fallback use at least 128-bit secrets, one-time protected delivery, digest-only storage, rotation, revocation, and fail-closed behavior.
  • Phone lookup is masked and never spending proof; it is permission-scoped and rate-limited without membership disclosure.
  • Data in transit and at rest is encrypted, secrets remain outside Git and golden images, backups are encrypted, tombstones apply before restore serving, and monitoring excludes PII.
  • Applicable ECC 2-2024 controls form the baseline, including statement of applicability, vulnerability management, incident response, continuity, and third-party review.

Incidents and data-subject rights

  • Contain immediately, preserve evidence, assess affected categories/counts, risks and mitigations, and isolate affected services or keys.
  • Notify SDAIA within 72 hours of awareness when the regulatory harm/rights threshold is met; notify affected people without undue delay when harm may result.
  • Provide channels for information, access/copy, correction, destruction, withdrawal, and complaint with proportionate identity verification.
  • A legal hold pauses destruction only through a logged, scoped, reasoned, expiring decision and never suspends rights indefinitely.

Providers and transfers

  • Core production data remains in Saudi Arabia under the approved architecture. No loyalty personal data may move to another provider or region without RoPA, risk, and contract updates.
  • Access from outside Saudi Arabia and onward transfer are treated as international transfers requiring a lawful purpose, minimization, and adequate protection or an approved safeguard such as standard contractual clauses.
  • Raw phone numbers and QR secrets are prohibited from analytics, tickets, Git, Sentry, chats, and public invoice surfaces.

Mandatory policy matrix

PolicyBinding ruleAccountable owner
Campaign termsImmutable version, Arabic/English terms, budget, liability, period, validity, and clear scope.Merchant owner plus a separate publisher where practical
Privacy and DPIAMinimization, purposes/bases, Treatment/Control, rights, providers, transfers, and reassessment.Controller plus privacy lead/independent adviser
ConsentLoyalty separate from marketing; time/method/language/version evidence; equally easy withdrawal.Program owner, with Ghallah as technical processor
VAT and ZATCAFixed discount, free service, and rewash treatment; no invoice history edits; credit/debit notes when required.Taxable merchant plus its tax adviser
SecurityApplicable ECC, separation, HMAC, RLS, external key custody, tests, audit, and response.Security owner plus independent reviewer
Retention and destructionApproved schedule, automatic destruction, scoped legal holds, and restore tombstones.Privacy plus operations
Release and recoveryNormal-off, shadow, one branch, staged scale; kill and rollback preserve obligations.Operations owner and rollback authority

Proposed retention schedule for approval

Periods start at account closure or purpose completion unless stated otherwise. A documented tax/judicial obligation or legal hold pauses destruction only for the scoped category.

Data classPeriodEnd-of-period action
Membership phone/direct identifierMembership life + 90 daysDetach/destroy direct identity while retaining pseudonymous obligations where required
Consent evidence, wording version, and withdrawal5 years after membership end or withdrawalSecure destruction unless a dispute or legal duty remains
Campaign versions, budgets, and publication decisions6 years after campaign endDestroy or anonymize after audit and obligations complete
Invoice-linked visits, rewards, redemptions, and rewashes6 years after the relevant tax periodRetain necessary financial minimum and detach/pseudonymize customer identity
QR and fallbackRaw value never stored; digest while active + 1 year after revocationDestroy operational digest; retain irreversible tombstone only when needed to prevent replay
Recovery and lost-card cases1 year after closureDestroy excess evidence and retain only pseudonymous audit
Security and rate-limit logs1 year, longer for an open incidentPeriodic destruction; raw phone and QR are prohibited
Operational backupsTarget rolling 35-day windowAutomatic expiry; apply and verify tombstones before any restored copy serves traffic
Record of processing activities (RoPA)Activity life + 5 yearsDestroy after the regulatory period and any active request/audit

Production launch gate

Owner adoption records commercial and operational decisions but does not alone authorize production value. Privacy, retention, tax, and independent security decisions must be signed and release-bound with trusted keys, followed by exact backup, shadow, QR, value, and staged rollout evidence.

Official design sources

These sources are reviewed after material change and at least annually. Impact assessment is repeated when purpose, provider, data category, or technology changes.

  • Saudi Personal Data Protection Law - SDAIA
  • PDPL Implementing Regulations - SDAIA
  • Privacy Policy Development Guideline - SDAIA
  • Personal Data Transfer Regulations - SDAIA
  • General VAT Guideline - ZATCA
  • Electronic Invoice Specifications - ZATCA
  • Essential Cybersecurity Controls ECC 2-2024 - NCA
  • E-Commerce Law and Implementing Regulations - Ministry of Commerce

Accountability and contact

Each merchant names operations, privacy, and security-escalation owners. Ghallah preserves an audit trail and does not permit production approval or separation-of-duty bypass.

Compliance email: support@ghallah.net

© 2026 Ghallah
Privacy policyTerms of ServiceHome