How LogiFlow collects, uses, and protects your data in compliance with Saudi Arabia's Personal Data Protection Law (PDPL)
Last Updated: December 2024
LogiFlow is an enterprise-grade logistics management system designed for Saudi Arabian cement transportation companies. This Privacy Policy explains how we collect, use, store, and protect personal data in compliance with the Saudi Personal Data Protection Law (PDPL).
We are committed to protecting your privacy and ensuring the security of all personal information processed through our platform.
Purpose: Employment management, payroll processing, legal compliance
Purpose: Fleet management, delivery tracking, safety compliance
Purpose: Order fulfillment, delivery services, business operations
Purpose: System access, authentication, security audit trails
Driver location is collected ONLY during active deliveries when drivers explicitly grant location permission. GPS coordinates are recorded every 30 seconds while in transit for real-time tracking, ETA calculations, and route optimization. Location data is retained for 90 days post-delivery, then automatically anonymized or deleted.
You can view your personal data through your profile page or by contacting your system administrator.
You can update incorrect data through your profile settings. For historical data corrections, contact your administrator. All changes are logged with timestamps.
You can request account deletion through your administrator. Personal data is anonymized within 30 days of deletion request. Transactional data is retained for 7 years as required by Saudi law.
Drivers can stop location tracking at any time by clicking "Stop Tracking" in the driver portal. You can opt out of marketing communications in your settings.
You can export your data in JSON format. Contact your administrator with a formal request, and the export will be provided within 30 days.
LogiFlow implements Role-Based Access Control (RBAC) with five levels: Admin (full access), Manager (module-level), Operator (limited operations), Viewer (read-only), and Driver (assigned shipments only).
All database tables use Supabase Row Level Security (RLS) to enforce multi-tenant isolation. Users can only access their company's data.
All system access and data modifications are logged with timestamps and user information. Audit logs are retained for 12 months and reviewed regularly by security teams.
For questions about this Privacy Policy or to exercise your data protection rights, contact us:
We will respond to all privacy-related inquiries within 30 days as required by PDPL.