Last updated: September 1, 2026
This Privacy Policy explains how alraqm alsaabi Establishment For Trading, national number 7012576893, Jeddah, Saudi Arabia ("NeraPOS", "we", "us", or "our") collects, uses, stores, discloses, and protects personal data when you visit www.nerapos.com or use the NeraPOS website, applications, point-of-sale system, and related services.
Our Role
NeraPOS is the data controller when it determines why and how account-registration, subscription, billing, support, website, security, and service-usage data is processed. For personal data that a customer enters into NeraPOS about its customers, suppliers, workers, or other persons, the customer normally determines the purposes and means of processing and NeraPOS processes that data on the customer's behalf as a data processor. Each customer is responsible for its own notices, lawful basis, instructions, and compliance when using NeraPOS to process such data.
Information We Collect
Information You Provide
We may collect account and contact information such as your name, email address, phone number, business details, billing address, support requests, and information you enter while using NeraPOS. Business data may include products, customers, suppliers, employees, transactions, inventory, reports, documents, and configuration settings.
Technical and Usage Information
We may automatically collect IP address, browser and device type, operating system, pages and features used, dates and times of access, diagnostic information, and security logs. We use cookies and similar technologies for authentication, preferences, security, analytics, and operation of the service.
Sources and Required Information
We receive data directly from you and authorized users, automatically from devices and service activity, from a business that invites you to its account, and from integrations you choose to connect. Required registration, authentication, and payment information is identified when collected. If it is not provided, we may be unable to create an account, process a subscription, provide a requested feature, or respond to a request. Optional profile, integration, and marketing information may be omitted unless needed for a feature you choose.
Payments
HyperPay and its participating payment providers process payment transactions. NeraPOS may receive transaction references, payment status, amount, currency, and limited billing details, but does not intend to store complete card numbers or card security codes. HyperPay's processing is also governed by its own privacy notice and applicable law.
How We Use Information
We process account, service, business, integration, and payment-status data as necessary to enter into and perform our contract with you, including providing NeraPOS, authenticating users, processing subscriptions, delivering support, and operating requested integrations. We process records needed to comply with Saudi legal, accounting, tax, regulatory, and lawful-authority requirements. Where permitted, we process limited technical, usage, security, and communications data for our legitimate interests in securing, administering, troubleshooting, and improving the service, provided those interests do not override the rights and interests of affected persons. We rely on consent where applicable law requires it, including for optional marketing or optional access to a connected third-party account, and consent may be withdrawn without affecting earlier lawful processing.
Google Workspace and Google Sheets Data
When a business administrator voluntarily connects a Google account, NeraPOS accesses the connected Google account email address, OAuth access and refresh tokens, spreadsheet identifiers and URLs, and limited spreadsheet metadata such as worksheet names. NeraPOS requests Google Sheets read/write permission so the administrator can create a spreadsheet, select a destination spreadsheet, add worksheet tabs, and clear or write cell ranges containing only the NeraPOS datasets and columns selected by that administrator. Synchronization may be started manually or run on the schedule selected by the business.
NeraPOS does not import or read spreadsheet cell contents, browse unrelated Google files, delete Google spreadsheet files, or use Google user data for advertising, credit decisions, data brokerage, or the development, improvement, or training of generalized artificial intelligence or machine-learning models.
Google OAuth tokens are encrypted at rest and are transmitted only over encrypted HTTPS connections. Access and settings are isolated by business. We do not sell Google user data or disclose it to advertising platforms, data brokers, or information resellers. Personnel may access Google user data only with the user's explicit authorization for support, when necessary for security, or when required by law.
Users may disconnect Google Sheets from NeraPOS at any time. Disconnecting removes the stored Google access token, refresh token, and connected account email and disables automatic synchronization. Spreadsheet identifiers, synchronization settings, and operational logs may remain until the NeraPOS account is deleted or the business requests their deletion, subject to legal, security, accounting, and recordkeeping obligations. Users may also revoke NeraPOS access from their Google Account security settings.
The use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How We Share Information
We may disclose information to authorized users of the relevant customer account; hosting, backup, infrastructure, security, communications, analytics, support, and software providers; HyperPay and participating payment providers; optional integration providers selected by the customer, including Google; professional advisers; and government, regulatory, judicial, or law-enforcement authorities when legally required. These recipients receive only the data reasonably needed for their role and are subject to applicable confidentiality, security, and data-protection obligations. We may also disclose information as part of a lawful merger, acquisition, restructuring, or transfer of the business.
The general sharing and analytics purposes in this policy do not permit Google user data to be used or transferred for advertising, data brokerage, credit decisions, lending, surveillance, or generalized AI or machine-learning training. Google user data is handled only as described in the Google Workspace section above.
Data Retention and Deletion
We retain data while the account or subscription is active and afterward only as needed for reactivation, support, security, disputes, and Saudi legal, accounting, tax, and regulatory duties. An unpaid account becomes inactive after its paid or trial period ends. The system may send inactivity warnings after approximately 6, 9, and 11 continuous months. After 12 continuous inactive months, selected non-regulatory files may be removed. Permanent deletion is not automatic: after at least 24 continuous inactive months, an administrator may review the account for deletion. Accounts containing protected transaction, accounting, tax, ZATCA, or other records are not eligible for deletion while those records must be preserved.
Operational and security logs are retained for periods proportionate to their purpose. Payment, invoice, accounting, tax, and compliance records are retained for the period required by applicable law. Backups are maintained on rolling schedules and deleted or overwritten through the normal backup cycle, subject to security, disaster-recovery, and legal-preservation requirements. When data is no longer required, it is securely deleted or anonymized.
Your Rights
Subject to the Saudi Personal Data Protection Law and its exceptions, you may have the right to be informed about processing, access your personal data, obtain a copy in a clear and readable format, and request correction, completion, updating, or destruction of data that is no longer required. Where processing relies on consent, you may withdraw it. To protect accounts and other persons, we may verify your identity and authority before acting on a request.
Privacy Requests and Complaints
If you wish to exercise your personal-data rights or submit a complaint about how NeraPOS processes your personal data, please contact us through:
Email: [email protected]
Mobile and WhatsApp: +966 54 878 6834
We will review your privacy request or complaint and respond within 30 days of receiving it. Where permitted by applicable law, we may extend this period by up to an additional 30 days if the request requires unexpected or unusual effort or if we receive multiple requests from you. We will notify you in advance of an extension and explain the reason.
This procedure and response period apply only to requests concerning personal-data rights and privacy complaints. Feature requests, technical support, billing inquiries, and other customer-service matters are handled through our ordinary support channels and are not subject to this privacy response period.
If you are dissatisfied with our response to your privacy request or complaint, or if we do not respond within the applicable period, you may submit a complaint to the competent authority in accordance with the Saudi Personal Data Protection Law.
Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, alteration, disclosure, loss, or destruction. These include access controls, encrypted transmission, encrypted storage for sensitive OAuth credentials, monitoring, and business-scoped access. No electronic transmission or storage method is completely secure.
Hosting and International Transfers
NeraPOS production hosting and backups are currently located in Germany. Using the service therefore involves transferring and processing personal data outside Saudi Arabia. We limit transfers to what is necessary to provide, secure, support, and back up the service and apply the safeguards required by the Saudi Personal Data Protection Law and its transfer regulations, including contractual, technical, and organizational protections as applicable. We may change infrastructure or provider locations for operational, security, or service reasons, but will update this Policy and provide any notice or obtain any approval required by law before a material change affecting personal-data transfers.
Children's Privacy
NeraPOS is intended for businesses, merchants, sole proprietors, organizations, and adult professionals. It is not directed to children, and persons under 18 may not create or administer an account. If a customer lawfully records information relating to a minor in its business records, that customer is responsible for having the required authority and safeguards.
Third-Party Services and Links
NeraPOS may link to or integrate with third-party services. Those services operate under their own terms and privacy policies. This policy does not govern information you provide directly to a third party.
Changes to This Policy
We may update this policy to reflect changes to our service, data practices, or legal obligations. We will publish the revised policy at this URL, update the date above, and provide additional notice or request consent where required.
Contact Us
For privacy questions or requests, contact:
NeraPOS Team — alraqm alsaabi Establishment For Trading
National number: 7012576893
Email: [email protected]
Mobile and WhatsApp: +966 54 878 6834
Address: Jeddah, Saudi Arabia
