Privacy
Privacy Policy
Last updated: 30 July 2026
TRANSITO is committed to protecting personal data in line with the Saudi Personal Data Protection Law (PDPL). This policy explains what we collect, why, who we share it with, and your rights.
Data we collect
We collect what a subscribing company provides to operate its account, and what its actual use of the platform produces:
- Account data: company name, CR number, VAT number, and company users’ details (name, email, phone, role).
- Operational data: bookings, vehicles, drivers, clients, invoices and accounting entries the company creates inside its own account.
- Location data: the driver app sends coordinates during an active trip only, with the driver’s consent via the browser permission.
- Technical data: sign-in logs, IP address and browser type — for security and abuse detection.
How we use data
- Operating the service and delivering the contracted platform features.
- Issuing tax invoices per ZATCA requirements.
- Government integrations the company enables (such as WASL) — only the legally required fields are sent.
- Service improvement through aggregated usage metrics that identify no individual.
We do not sell personal data and we do not use it for advertising.
Tenant isolation
Each company’s data lives in its own separate database schema. No company can access another company’s data, and the same isolation applies to files, caches and sessions.
Data sharing
We share data only with:
- Operational service providers (cloud hosting, payment gateways, SMS/WhatsApp providers) to the extent needed to deliver the service.
- Government authorities where the law requires it (ZATCA, WASL) or under a court order.
- The flight-tracking provider when a company enables the feature — only the flight number and date are sent.
Retention and deletion
We retain data for the duration of the subscription. On termination the company may export its data, after which it is deleted per the retention schedule — except records the law requires us to keep (such as tax invoices, ten years).
Audit logs are immutable by design and are retained for security and accountability.
Security
- HTTPS encryption on all connections.
- Integration credentials encrypted at rest.
- Passwords hashed with bcrypt — never stored in plain text.
- Role-based access control enforced server-side on every request.
- Regular backups with tested restores.
Your rights
Under the PDPL you have the right to know what we collect, to access your data, to request correction or deletion unless the law requires retention, and to withdraw consent where processing relies on it.
To exercise these rights or for any question: info@transitohq.com
Changes to this policy
For any material change we will notify subscribing companies at their registered email before it takes effect, and the "Last updated" date above will change.