Draft pre-launch controls
Loyalty Governance and Compliance
Policies Ghallah and each car-wash owner must apply before, during, and after a loyalty campaign.
- Governance version
- LOY-GOV-1.0
- Draft issue date
- 29 July 2026
Owner commercial decisions
- Loyalty is a sellable Advanced Package capability, not a demo or non-binding promise.
- Each merchant may select a threshold from 1 to 1,000 to fit its model; it should remain understandable and economically validated. Common examples are 5 or 10 visits or a time-limited campaign.
- Publication requires Arabic and English name/description, eligible branches/services, period, reward, validity, budget and liability caps, stop posture, and written acceptance criteria.
- MVP rewards are a fixed-amount discount or a capped eligible free service. No general cash points, cross-merchant transfer, or reward stacking.
- A published campaign version is immutable. Change creates a new version, while accrued progress and issued rewards remain governed by the version that created them.
Legal bases and consent
- Optional membership, phone matching, and card identity rely on separate, freely given, specific, provable, withdrawable loyalty-service consent.
- Invoice completion, discounts, and tax obligations rely on contract and legal obligation, not revocable consent that could erase a financial record.
- Network security, fraud prevention, rate limiting, and incident records rely on documented legitimate interest with rights balancing and minimization.
- Treatment/Control measurement relies on assessed legitimate interest and pseudonymized information; Control receives no membership or value and no adverse individual decision.
- Direct marketing is outside the MVP. It requires future purpose/channel-specific consent, clear sender identity, consent evidence, and free equally easy opt-out.
VAT and invoicing policy
- A fixed-amount reward is a non-cash commercial discount on the underlying supply and is shown on the invoice. Server-authoritative VAT uses the approved post-discount consideration under the merchant tax decision.
- A free service is bound to an eligible Catalog service and cap and appears as a transparent supply and commercial reduction with any customer-paid excess. If tax advice requires deemed-supply VAT or merchant-borne VAT, the merchant records it rather than hiding it.
- A defect rewash is separate quality remediation, not a reward, and creates no loyalty movement. If prior invoice consideration or VAT changes, a lawful credit/debit note is used rather than editing history.
- Production value cannot activate until the merchant tax treatment and ZATCA configuration are approved. Commercial wording cannot change tax law.
Cybersecurity and privacy by design
- Release signing and key custody are separated; activation signer is not key custodian and security review is independent of operations.
- Tenant RLS, least privilege, separate API/worker/reconciler roles, insert-only audit, and BOLA/concurrency/replay tests are mandatory.
- QR and fallback use at least 128-bit secrets, one-time protected delivery, digest-only storage, rotation, revocation, and fail-closed behavior.
- Phone lookup is masked and never spending proof; it is permission-scoped and rate-limited without membership disclosure.
- Data in transit and at rest is encrypted, secrets remain outside Git and golden images, backups are encrypted, tombstones apply before restore serving, and monitoring excludes PII.
- Applicable ECC 2-2024 controls form the baseline, including statement of applicability, vulnerability management, incident response, continuity, and third-party review.
Incidents and data-subject rights
- Contain immediately, preserve evidence, assess affected categories/counts, risks and mitigations, and isolate affected services or keys.
- Notify SDAIA within 72 hours of awareness when the regulatory harm/rights threshold is met; notify affected people without undue delay when harm may result.
- Provide channels for information, access/copy, correction, destruction, withdrawal, and complaint with proportionate identity verification.
- A legal hold pauses destruction only through a logged, scoped, reasoned, expiring decision and never suspends rights indefinitely.
Providers and transfers
- Core production data remains in Saudi Arabia under the approved architecture. No loyalty personal data may move to another provider or region without RoPA, risk, and contract updates.
- Access from outside Saudi Arabia and onward transfer are treated as international transfers requiring a lawful purpose, minimization, and adequate protection or an approved safeguard such as standard contractual clauses.
- Raw phone numbers and QR secrets are prohibited from analytics, tickets, Git, Sentry, chats, and public invoice surfaces.
Mandatory policy matrix
| Policy | Binding rule | Accountable owner |
|---|---|---|
| Campaign terms | Immutable version, Arabic/English terms, budget, liability, period, validity, and clear scope. | Merchant owner plus a separate publisher where practical |
| Privacy and DPIA | Minimization, purposes/bases, Treatment/Control, rights, providers, transfers, and reassessment. | Controller plus privacy lead/independent adviser |
| Consent | Loyalty separate from marketing; time/method/language/version evidence; equally easy withdrawal. | Program owner, with Ghallah as technical processor |
| VAT and ZATCA | Fixed discount, free service, and rewash treatment; no invoice history edits; credit/debit notes when required. | Taxable merchant plus its tax adviser |
| Security | Applicable ECC, separation, HMAC, RLS, external key custody, tests, audit, and response. | Security owner plus independent reviewer |
| Retention and destruction | Approved schedule, automatic destruction, scoped legal holds, and restore tombstones. | Privacy plus operations |
| Release and recovery | Normal-off, shadow, one branch, staged scale; kill and rollback preserve obligations. | Operations owner and rollback authority |
Proposed retention schedule for approval
Periods start at account closure or purpose completion unless stated otherwise. A documented tax/judicial obligation or legal hold pauses destruction only for the scoped category.
| Data class | Period | End-of-period action |
|---|---|---|
| Membership phone/direct identifier | Membership life + 90 days | Detach/destroy direct identity while retaining pseudonymous obligations where required |
| Consent evidence, wording version, and withdrawal | 5 years after membership end or withdrawal | Secure destruction unless a dispute or legal duty remains |
| Campaign versions, budgets, and publication decisions | 6 years after campaign end | Destroy or anonymize after audit and obligations complete |
| Invoice-linked visits, rewards, redemptions, and rewashes | 6 years after the relevant tax period | Retain necessary financial minimum and detach/pseudonymize customer identity |
| QR and fallback | Raw value never stored; digest while active + 1 year after revocation | Destroy operational digest; retain irreversible tombstone only when needed to prevent replay |
| Recovery and lost-card cases | 1 year after closure | Destroy excess evidence and retain only pseudonymous audit |
| Security and rate-limit logs | 1 year, longer for an open incident | Periodic destruction; raw phone and QR are prohibited |
| Operational backups | Target rolling 35-day window | Automatic expiry; apply and verify tombstones before any restored copy serves traffic |
| Record of processing activities (RoPA) | Activity life + 5 years | Destroy after the regulatory period and any active request/audit |
Production launch gate
Owner adoption records commercial and operational decisions but does not alone authorize production value. Privacy, retention, tax, and independent security decisions must be signed and release-bound with trusted keys, followed by exact backup, shadow, QR, value, and staged rollout evidence.
Official design sources
These sources are reviewed after material change and at least annually. Impact assessment is repeated when purpose, provider, data category, or technology changes.
- Saudi Personal Data Protection Law - SDAIA
- PDPL Implementing Regulations - SDAIA
- Privacy Policy Development Guideline - SDAIA
- Personal Data Transfer Regulations - SDAIA
- General VAT Guideline - ZATCA
- Electronic Invoice Specifications - ZATCA
- Essential Cybersecurity Controls ECC 2-2024 - NCA
- E-Commerce Law and Implementing Regulations - Ministry of Commerce
Accountability and contact
Each merchant names operations, privacy, and security-escalation owners. Ghallah preserves an audit trail and does not permit production approval or separation-of-duty bypass.
Compliance email: support@ghallah.net