Privacy Policy — Wateer
Version 11 · Effective date: 29 September 2026
1. Who we are
The Wateer platform is operated by Masarat Wateer for Information Technology Company (LLC), registered in the Kingdom of Saudi Arabia under Commercial Registration No. 1010795924, with its head office in Riyadh.
Wateer is a software platform for issuing, delivering, and managing digital invoices and receipts, serving merchants and their customers.
This policy explains how we collect, use, and protect your personal data, what your rights are, and how to exercise them. It complies with the Personal Data Protection Law issued by Royal Decree M/148 dated 05/09/1444 AH and its Implementing Regulation.
It covers our website, applications, interfaces, and every channel through which we collect your data.
2. Our legal role
Our role changes with your relationship to us:
| Situation | Wateer's role | Controller |
|---|---|---|
| You registered an account with Wateer directly | Controller | Wateer |
| You received an invoice from a merchant using Wateer, with no account | Processor on the merchant's behalf | The merchant |
| You are a subscribed merchant | Controller for your own data; processor for your customers' data | Depends on the data |
Where we act as a processor, we act on the merchant's documented instructions and within what the law permits. Requests about that data go to the merchant, and we will help you reach them.
3. Data Protection Officer
| Name | Yazeed Hassan Mohammed Zaidan |
| Role | Data Protection Officer |
| [email protected] | |
| Address | Masarat Wateer for Information Technology Company, Riyadh, Kingdom of Saudi Arabia |
You may write to the DPO directly about anything concerning your personal data, this policy, or the exercise of your rights.
4. Data we collect
Personal data is any information, whatever its source or form, that identifies you or makes you identifiable, directly or indirectly.
4.1 Data you give us
| Category | Contents | Mandatory / optional |
|---|---|---|
| Account data | Name, mobile number, email address | Mandatory to create an account |
| Credentials | Username and password | Mandatory to use the account |
| Merchant data | Commercial registration, VAT number, activity, address | Mandatory for merchants only |
| Identity verification | National ID, residency permit, or passport | Mandatory where the law requires it, or when you exercise a right that requires verification |
| Receipts you add yourself | The photo or PDF of the receipt, and the details you enter or edit (store, amount, VAT, currency, category, notes, labels) | Optional |
| Correspondence | What you provide when contacting support | Optional |
If you do not provide it: the items marked mandatory are necessary to deliver the service; without them we cannot create the account or provide the service. Withholding optional data does not affect your core service.
4.2 Data collected automatically
- Transaction and receipt data: the goods or services purchased, date and time, amount and payment method, merchant name and location, and the associated e-invoice data.
- Usage data: pages viewed, searches, time spent, navigation paths.
- Device data: operating system and version, manufacturer, browser type, device identifiers, IP address.
- Approximate location: the city or country inferred from your IP address. We do not collect your device's precise location without your explicit permission from your device settings, which you can withdraw at any time.
- App error reports: when the app hits an error, a technical report (error type, screen, app and device version) — never your receipts, amounts, name or mobile number. With your consent to Error analysis to improve the experience, it also carries a recording of the steps before the error with all text and images masked (see section 7.2).
- Cookies: see section 9.
4.3 Data from external sources
If you choose to sign in through a third-party service (such as Google or Apple), we receive the registration data you authorise it to share. Those services are governed by their own privacy policies.
4.4 What we do not collect
- We do not collect or store credit card or bank account numbers. Payment data is processed directly by the payment service provider and never passes through our systems. We receive only the outcome of the transaction and its reference.
- We do not request access to your contacts. We access the camera, photos, or files only when you choose to add a receipt, and then use only the photo or file you choose.
- The tax QR code printed on a receipt is read on your device.
- We do not collect sensitive, health, or biometric data.
5. Purposes and legal bases
We process your data only where a valid legal basis exists:
| Purpose | Description | Legal basis |
|---|---|---|
| Delivering digital invoices and receipts | Getting your invoice to you, storing it, keeping it retrievable | Contract |
| Account creation and management | Creating your account and running its features | Contract |
| Customer support | Answering your questions and resolving issues | Contract |
| Responding to lawful requests | Complying with judicial and regulatory orders | Legal obligation |
| Platform security and fraud prevention | Protecting accounts, detecting abuse, keeping systems sound | Legitimate interest |
| App error reports | Detecting and fixing app faults from technical reports that carry no personal content (see section 7.2) | Legitimate interest |
| Loyalty programme | Enrolling you and running the programme | Consent |
| Email marketing | Sending offers and news | Consent |
| SMS marketing | Sending offers by SMS | Consent |
| WhatsApp marketing | Sending offers via WhatsApp | Consent |
| Error analysis to improve the experience | Measuring platform performance, and a masked recording of the steps before an app error (see section 7.2) | Consent |
| AI receipt extraction | Reading a receipt you added yourself, at your request, and improving and developing the service (see section 7.1) | Consent |
What this means in practice:
- Contract: necessary to deliver the service. No separate consent is asked, and it cannot be refused while continuing to use the service.
- Legal obligation: required of us by law; neither we nor you have a choice.
- Legitimate interest: relied on for platform security and app error reports only, after a documented balancing of our interest against your rights. You may object.
- Consent: entirely optional, never pre-ticked, and withdrawable at any time. Withdrawal does not affect the lawfulness of processing before it, and does not affect your core service.
6. Who we share your data with
We do not sell your personal data, rent it, or trade in it.
We may disclose it, to the extent necessary, to:
| Category | Purpose |
|---|---|
| The merchant you purchased from | Issuing your invoice and after-sales service |
| Hosting and cloud storage providers | Running the platform and storing data |
| Payment service providers | Settling payments (your card data never passes through our systems) |
| Messaging providers | Sending SMS, email, and WhatsApp messages |
| Analytics providers | Measuring performance, with your consent |
| Error-reporting provider (Sentry) | Receiving app error reports, and masked step recordings with your consent (see section 7.2) |
| Consent management provider | Recording your consents and issuing verifiable receipts |
| AI model providers | Reading the receipt you ask us to extract, with your consent (see section 7.1) |
| Competent authorities | Courts, government and tax authorities, and law enforcement, where legally required |
Every processor operates under a contract binding it to the limits of processing, to confidentiality, and to protective measures. An up-to-date list of processors is available at privacy.wateer.sa.
7. Transfers outside the Kingdom
We are committed to processing your data inside the Kingdom. It is not transferred abroad except in the cases permitted by the Personal Data Protection Law, its Implementing Regulation, and the Regulation on Personal Data Transfer outside the Kingdom — and then only after the required technical and organisational safeguards are in place, and only to the minimum extent necessary.
7.1 AI receipt extraction
This feature is one of two cases in which data leaves the Kingdom (the other is section 7.2):
- When: only when you tap the extract button on a receipt you added yourself, and after your explicit consent on first use. Receipts delivered to you by merchants on the Wateer network are never sent.
- What is sent: the receipt photo or file only. We do not send your name, your mobile number, or any identifier of your account.
- Where: an AI model hosted outside the Kingdom, namely Google's Gemini model, reached through a technical intermediary (OpenRouter).
- What happens to the result: it is saved as a draft for you to review, and nothing is written to your receipt until you save it. The data read from the receipt's tax QR code remains the reference, and the AI never changes it.
- Improving the service: with your consent, we may use the receipt image, its data, the reading, your corrections, and your rating of it to improve and develop the service, including training and evaluating reading models.
- Withdrawal: you can withdraw consent at any time at privacy.wateer.sa; no receipt is sent afterwards. Withdrawal does not affect what happened before it.
7.2 App error reports
- What: when the MyWateer app hits an error, a technical report: error type, the screen and control involved, app version, device model and operating system. Report contents are filtered before sending, and receipts, amounts, merchant names, your name and your mobile number are never included.
- Step recording, with your consent only: if you consent to Error analysis to improve the experience, the report also carries a short recording of the steps before the error, with all text and images masked, so your receipts and data do not appear in it. Nothing is recorded unless an error occurs.
- Where: Sentry, an error-reporting provider whose servers are in Germany (European Union).
- Retention: 90 days, then deleted.
- Your control: step recording stops when you withdraw that consent in the app's Account settings or at privacy.wateer.sa. You may object to basic error reports at [email protected].
8. Retention periods
We keep your data for as long as the purpose requires, or for as long as the law requires, whichever is longer:
| Category | Period | Basis |
|---|---|---|
| Invoices and transaction records | 10 years | Commercial Books Law |
| Accounting and tax records | 6 years after the end of the tax period | VAT Implementing Regulation |
| Account, profile, and identity data | Subscription term + 90 days | Operational window for recovery and dispute resolution |
| Login and security audit logs | 12 months | Platform security and incident investigation |
| Call recordings | 180 days | Service quality and complaint resolution |
| Consent evidence records and receipts | Processing period + 5 years | Proof of compliance and the claim window |
| Analytics data | 14 months | Seasonal trend analysis |
| App error reports and masked step recordings | 90 days | Fixing app faults |
| AI receipt extraction results | For as long as the receipt stays in your account, then as in section 8.1 | Improving the service, with your consent |
When a period ends, we securely delete the data or convert it into a form that does not identify you. Withdrawing consent or deleting your account does not override statutory retention periods; in that case we keep only the minimum required.
8.1 What happens when you delete your account
When we carry out a deletion request, we destroy the data that identifies you and keep a record that is no longer linked to you:
- We destroy: your name, mobile number, and email address, and we release the mobile number so that it does not link you to your past records if you register again.
- We delete: receipt photos and files, your notes, free text, your comments on AI results, the full text the model read from the paper, and links to the original invoices.
- We check what remains: every remaining text (such as item names and the store name) goes through an automated check that removes mobile numbers, email addresses, national ID and residency numbers, bank account numbers (IBAN), and card numbers.
- We keep: the non-identifying transaction data (store and its VAT number, amounts, VAT, currency, date, category, items), and the AI readings and their corrections after that check, for statistics and to improve the service, including training reading models.
9. Cookies
What follows describes what we actually use, not what we might:
| Category | What it is | Needs your consent? |
|---|---|---|
| Strictly necessary | Session and sign-in cookies, and protection of forms against forgery | No — the platform cannot run without them, and they cannot be refused while continuing to use it |
| Usage analytics | Measuring and improving site performance using an analytics tool we host on our own servers, which sets no cookies on your device and does not track you across other sites | Yes |
We do not currently use functional or marketing cookies, advertising pixels, or third-party tracking tools. App error reports (section 7.2) use no cookies and do not track you across apps or sites. If that changes, we will update this policy and ask for your consent before activating any of them.
On your first visit we present a clear choice: nothing beyond the strictly necessary is activated before you consent, no box is pre-ticked, and refusing is as easy as accepting. You can change your choice at any time at privacy.wateer.sa or in your browser settings.
10. Your rights
Under the Personal Data Protection Law, you have the right to:
| Right | What it means |
|---|---|
| Be informed | Know the legal basis for collecting your data and the purpose of it |
| Access | See the data we hold about you |
| Obtain a copy | Receive your data in a clear, machine-readable format |
| Rectification | Correct what is inaccurate, incomplete, or out of date |
| Destruction | Have your data deleted once it is no longer needed, subject to statutory retention (see section 8.1) |
| Withdraw consent | Stop any consent-based processing, at any time |
| Object | Object to processing based on legitimate interest |
How to exercise them: at privacy.wateer.sa after verifying your identity with your mobile number, or by writing to [email protected].
When we respond: within thirty (30) days of receiving the request. We may ask you to prove your identity first, to protect your data.
If we refuse: we will tell you why, on what legal basis, and how to appeal.
Complaints: if you believe your rights have been breached, write to [email protected] first. In all cases you may lodge a complaint with the Saudi Data & AI Authority (SDAIA) as the competent supervisory authority — you are not required to come to us first.
11. Information security
We apply appropriate technical, organisational, and physical measures, including:
- Encryption of data in transit and at rest
- Role-based access controls on a least-privilege basis
- Audit logs for sensitive operations
- Regular backups and a recovery plan
- Periodic security review and incident response procedures
Even so, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Your part: keep your credentials confidential and never share them. No member of our staff will ever ask you for your password or a verification code — any such request is an attempted fraud. Report it to us immediately.
12. Data breaches
If your personal data is leaked, damaged, or accessed without authorisation:
- We notify the Saudi Data & AI Authority within seventy-two (72) hours of becoming aware of the incident.
- We notify you without undue delay where the breach would cause damage to your data or conflict with your rights or interests.
- The notification states the nature of the incident, the data affected, the steps taken, and what you can do to limit the impact.
13. Minors and persons lacking capacity
Our services are not directed at anyone under eighteen or at persons lacking legal capacity. In those cases a parent or legal guardian consents on their behalf.
We do not knowingly collect minors' data. If you learn that we have collected a minor's data without their guardian's consent, write to [email protected] immediately and we will take the steps needed to delete it.
14. Call and correspondence monitoring
We may record support calls and electronic correspondence for quality, training, compliance, and fraud prevention. We tell you when recording begins, and you may object and continue through another channel. Recordings are kept for the period stated in section 8.
15. Automated decisions
We do not make decisions producing legal effects for you based solely on automated processing, and we do not profile you for evaluation purposes. AI receipt extraction (section 7.1) is a suggestion you review, and it is applied to your receipt only after you save it. If that changes, we will amend this policy, notify you in advance, and explain your right to human review.
16. Social media
We may communicate with you through social media platforms. What you post on our public pages may be visible to the public, so take care when sharing your data there. Those platforms are governed by their own policies, not this one.
17. Updates to this policy
We may update this policy. We notify you of material changes in advance by email or through an in-platform notice. The current version is always published with its version number and effective date, and previous versions remain available for reference.
18. Language
This policy is issued in Arabic and English. In the event of any discrepancy, the Arabic text prevails.
19. Contact us
| Purpose | Channel |
|---|---|
| Privacy, data protection, exercising rights | [email protected] |
| Privacy centre | privacy.wateer.sa |
| Support and general complaints | [email protected] |
| Marketing opt-out | [email protected] or the unsubscribe link in every message |
| Supervisory authority | Saudi Data & AI Authority (SDAIA) |