Skip to content
Ranna

Privacy policy

Last updated:

We respect your privacy and your customers'. This policy explains what data Ranna collects, why, and how we protect it, in line with Saudi Arabia's Personal Data Protection Law (PDPL).

Customers of venues (people who scan the code)

We don't ask for your name, number or an account to use alerts. We store your order number, when it was created and its status, plus a technical identifier for your device (a browser push subscription or an Apple push token) so we can deliver the alert.

If you choose WhatsApp alerts, we use your number only to send alerts about your order, and never send marketing without your explicit consent. Reply "stop" at any time to end messages.

Ratings and comments you write go to the venue you visited.

Venue owners and their teams

We store your phone number and name for sign-in, venue and branch details, and an audit log of sensitive actions for security.

Card payments are processed directly by our payment gateway (Moyasar); we never store card numbers.

How we protect data

All traffic is encrypted (HTTPS), and secrets such as POS integration tokens are encrypted at rest. Each venue's data is accessible only to its team.

We delete device identifiers (push tokens) after the order closes and purge old operational data on a schedule.

Sharing

We don't sell data. We share it only with the providers needed to run Ranna (hosting, Apple and Google for notifications, Meta for WhatsApp, our SMS provider, our payment gateway), and only as much as needed.

Your rights

You may access, correct, or request deletion of your data. Email hello@getranna.com and we'll respond within 30 days.