سياسة الخصوصية

تاريخ السريان وآخر تحديث: ٤ سبتمبر ٢٠٢٦

١. مقدمة ونبذة عن تطبيق ڤيني (ViNi)

مرحباً بك في تطبيق ڤيني (ViNi)، التطبيق المتخصص في تقديم القهوة والمشروبات والمخبوزات الطازجة لعملائنا في المملكة العربية السعودية. نحن نولي خصوصيتك وحماية بياناتك الشخصية والمالية أهمية قصوى ونلتزم بالامتثال التام للأنظمة واللوائح المعمول بها وسياسات حماية البيانات العالمية، بما فيها معايير شركة Apple وخدمة Apple Pay وإرشادات متجر التطبيقات App Store (Guideline 5.1.1).

توضح هذه السياسة بشفافية تامة كيفية عمل التطبيق، وما هي البيانات التي نقوم بجمعها، وأسباب جمعها، وكيفية معالجة المدفوعات بأمان، وآلية حماية حقوقك وإمكانية حذف حسابك وبياناتك في أي وقت.

٢. كيف يعمل التطبيق وتجربة الاستخدام

يعمل تطبيق ڤيني على تقديم تجربة طلب سريعة وسلسة من خلال الخطوات التالية:

  • استعراض القائمة: يمكنك تصفح كافة المشروبات الساخنة والباردة والمخبوزات وتخصيص المكونات والحجم.
  • تحديد خيار الاستلام: يتيح التطبيق خيارين رئيسيين لتسليم الطلب:
    1. الاستلام من الفرع (Pick-up): استلام طلبك مباشرة داخل المتجر.
    2. الاستلام من السيارة (Car Pickup / Drive-thru): توصيل الطلب لسيارتك أثناء وقوفك خارج الفرع دون الحاجة للنزول.
  • تسجيل الدخول والتحقق: يتم إنشاء الحساب والتحقق من هوية المستخدم عبر إدخال رقم الجوال السعودي واستقبال رمز التحقق المؤقت (SMS OTP).
  • الدفع وإتمام الطلب: دفع قيمة الطلب بأمان عبر خدمة Apple Pay، أو بطاقات مدى والبطاقات الائتمانية، أو عبر رصيد المحفظة الإلكترونية للتطبيق.
  • متابعة حالة الطلب: استقبال إشعارات فورية مباشرة (قيد المراجعة، جاري التحضير، الطلب جاهز، تم التسليم).

٣. البيانات التي نجمعها وأسباب جمعها

نجمع فقط الحد الأدنى من المعلومات الضرورية لتقديم خدمات التطبيق وإتمام طلباتك بكفاءة:

  • رقم الجوال: لإنشاء الحساب، وتوثيق الدخول عبر رسائل التحقق (OTP)، وتأكيد تفاصيل الطلب والتواصل عند الضرورة.
  • الاسم (اختياري): لتخصيص تجربتك والمناداة بالاسم عند تسليم الطلب داخل الفرع أو السيارة.
  • بيانات السيارة (عند اختيار خدمة الاستلام من السيارة فقط): نقوم بطلب (نوع السيارة، الموديل، اللون، ورقم اللوحة). تُستخدم هذه البيانات حصرياً لتمكين طاقم العمل من التعرّف على مركبتك وتسليم الطلب لك فور وصولك. لا نجمع هذه البيانات إذا اخترت الاستلام من داخل الفرع.
  • المنتجات المفضلة: قائمة المنتجات التي قمت بتفضيلها لتسهيل الوصول إليها وإعادة طلبها.
  • سجل الطلبات: تفاصيل المنتجات والتواريخ لعرضها في شاشة سجل الطلبات وتسهيل إعادة الطلب.
  • رصيد المحفظة ونقاط الولاء: لتسجيل سجل المعاملات المالية الداخلية ونقاط المكافآت المستحقة والمستبدلة.
  • رموز البطاقات المحفوظة (اختياري): عند اختيارك حفظ البطاقة للدفع لاحقاً، يتم تخزين رمز مشفّر (Token) صادر من بوابة الدفع فقط، مع آخر ٤ أرقام من البطاقة ونوعها وتاريخ انتهائها. لا يتم تخزين رقم البطاقة الكامل أو رمز الأمان (CVV) على خوادمنا مطلقاً.
  • معرّف الإشعارات: رمز تقني مشفّر لجهازك لإرسال تحديثات حالة الطلب في الوقت الفعلي.

٤. الدفع الإلكتروني وخدمة Apple Pay (متوافق مع إرشادات Apple 5.1.1)

نولي أمان المعاملات المالية أعلى درجات العناية والالتزام، ونوضح التفاصيل التالية بخصوص خدمة Apple Pay والبطاقات البنكية:

  • عدم تخزين بيانات الدفع: تطبيق ڤيني لا يقوم على الإطلاق بالاطلاع على، أو تخزين، أو معالجة أرقام بطاقاتك الائتمانية الكاملة، أو رمز الأمان (CVV/CVC)، أو أرقام حساب الأجهزة المشفرة الخاصة بخدمة Apple Pay على خوادم التطبيق.
  • آلية تشفير Apple Pay: عند استخدام Apple Pay، تتم معالجة الدفع عبر البنية التحتية الآمنة لشركة Apple، حيث يتم استخدام رقم حساب جهاز رمزي (Device Account Number) مشفر برمز أمان فريد لكل معاملة.
  • بوابات الدفع المعتمدة: تتم معالجة جميع المعاملات البنكية عبر مزود خدمة دفع مرخص ومعتمد من البنك المركزي السعودي (SAMA) ومتوافق بالكامل مع معايير أمان بيانات صناعة بطاقات الدفع العالمية (PCI DSS Level 1).
  • استخدام بيانات المعاملة: المعلومات التي يتلقاها التطبيق تقتصر فقط على إشعار نجاح أو فشل المعاملة، ورقم مرجعي للعملية، وقيمة المبلغ لإصدار الفاتورة الإلكترونية الضريبية وتحديث رصيد نقاطك.
نحن ملتزمون بعدم بيع أو مشاركة أو استغلال أي معلومات دفع مالية مع أي جهات خارجية لأغراض تسويقية أو تجارية على الإطلاق.

٥. حماية وأمن البيانات والبنية التحتية

نطبّق إجراءات أمنية وتقنية رائدة لضمان حماية بياناتك الشخصية من الوصول غير المصرح به أو الفقدان:

  • التشفير الكامل أثناء النقل: جميع الاتصالات ونقل البيانات بين تطبيق الهاتف وخوادمنا محمية بنظام تشفير قوي عبر بروتوكولات HTTPS/TLS 1.3.
  • أمان قواعد البيانات (RLS): نستخدم آليات أمان على مستوى الصفوف (Row Level Security)، مما يضمن استحالة وصول أي مستخدم إلى بيانات أو طلبات أو حسابات مستخدم آخر.
  • المصادقة الآمنة: كلمات المرور والجلسات مشفّرة وفق أفضل الممارسات البرمجية القياسية.

٦. مشاركة البيانات مع جهات خارجية

لا نبيع بياناتك الشخصية لأي طرف ثالث. تتم مشاركة البيانات المحدودة فقط مع مزودي الخدمات الموثوقين واللازمين لتشغيل التطبيق:

  • بوابات الدفع وApple Pay: لمعالجة عملية السداد وإصدار الإيصال المالي بأمان.
  • مزودو خدمة الرسائل النصية القصيرة (SMS Gateway): لإرسال رمز التحقق للدخول.
  • خدمات الإشعارات: لبث إشعارات تحديثات الطلب الحية إلى جهازك.

٧. حقوق المستخدم وحذف الحساب نهائياً

يمنحك تطبيق ڤيني التحكم الكامل في بياناتك، ويحق لك في أي وقت:

  • الاطلاع والتعديل: استعراض سجل طلباتك وتعديل اسمك وسياراتك المحفوظة داخل التطبيق.
  • إلغاء الإشعارات: إيقاف الإشعارات التنبيهية من إعدادات جهازك في أي وقت.
  • حذف الحساب نهائياً: يتيح التطبيق خيار حذف الحساب فورياً ومباشرة من داخل التطبيق عبر: (المزيد ← حذف الحساب)، أو بمراسلتنا عبر البريد الإلكتروني. عند تأكيد الحذف، يتم مسح كافة بياناتك الشخصية، وسياراتك، ونقاطك، ومفضلاتك، وبطاقاتك المحفوظة، وسجلاتك نهائياً من خوادمنا دون رجعة.

٨. التخزين المحلي

يستخدم التطبيق مساحة تخزين محلية مشفرة على هاتفك لتحسين سرعة التصفح وتخزين قائمة المنتجات مؤقتاً. عند قيامك بتسجيل الخروج، يتم مسح البيانات المخزنة محلياً بالكامل منعاً لتداخل البيانات بين الحسابات.

٩. خصوصية الأطفال

تطبيق ڤيني غير مخصص ولا يستهدف الأطفال دون سن 13 عاماً. نحن لا نجمع عن عمد أي بيانات شخصية للأطفال، وفي حال تبين لنا تسجيل طفل دون إذن ولي الأمر، نقوم بحذف الحساب والبيانات فوراً.

١٠. تواصل معنا

لأي استفسار بخصوص سياسة الخصوصية أو ممارسة حقوقك أو تقديم أي ملاحظة، يسعدنا تواصلكم معنا عبر البريد الرسمي:

البريد الإلكتروني المعتمد:
Vini.saudii@gmail.com

Effective & Last Updated: September 4, 2026

1. Introduction & Overview of ViNi App

Welcome to ViNi, a modern specialty coffee and bakery application operating in the Kingdom of Saudi Arabia. Your privacy and the confidentiality of your personal and financial information are of utmost priority to us. We strictly adhere to applicable data protection regulations and international privacy standards, including Apple's App Store Review Guidelines (specifically Guideline 5.1.1 - Legal - Privacy - Data Collection and Storage) and Apple Pay security guidelines.

This Privacy Policy clearly describes how our application works, what information we collect, why we collect it, how payments are securely processed, how your data is protected, and your unconditional right to access and permanently delete your account and personal records at any time.

2. How the Application Operates

The ViNi app is designed to deliver a swift and convenient coffee ordering experience through the following flow:

  • Menu Exploration: Customers can view our coffee beverages, cold brews, and fresh bakery products, selecting desired customizations and sizes.
  • Fulfillment Options: Customers select their preferred pickup method:
    1. In-Store Pickup: Collect your order directly from the store counter.
    2. Car Pickup (Drive-thru / Curbside): Receive your order delivered directly to your vehicle outside the store without having to step out.
  • Secure Login & Registration: Users sign up or authenticate securely using their Saudi mobile phone number via SMS One-Time Password (OTP) verification.
  • Fast & Secure Checkout: Customers pay conveniently and safely using Apple Pay, Mada debit cards, major credit cards, or through our integrated digital in-app wallet balance.
  • Real-time Order Tracking: Instant push notifications inform the customer about their order state progression (Under Review, Preparing, Ready for Pickup, Delivered).

3. Information We Collect and Purpose of Collection

We only collect the minimal personal information essential for providing our services and fulfilling your beverage and bakery orders:

  • Mobile Phone Number: Used to create and authenticate your account through SMS OTP verification, associate your orders, and reach you regarding order status if needed.
  • Name (Optional): Used to personalize your in-app experience and call out your name when serving your coffee in-store or at your vehicle.
  • Vehicle Details (Exclusively for Car Pickup): When you choose "Car Pickup", we ask for your vehicle model, color, and license plate number. This data is strictly used by our baristas to locate your parked vehicle and safely hand over your order. We never request vehicle details if you choose in-store pickup.
  • Order History: Record of purchased products, timestamps, and order identifiers to display in your order history screen and streamline repeat orders.
  • Digital Wallet Balance & Loyalty Points: Stored securely to track earned reward points and in-app wallet credit.
  • Device Push Token (FCM Token): An encrypted device token used solely to dispatch real-time status updates concerning your order.

4. Electronic Payments & Apple Pay (Guideline 5.1.1 Compliance)

We treat payment data with the highest degree of security and compliance with international banking standards:

  • No Storage of Sensitive Card or Apple Pay Data: ViNi never views, captures, processes, or stores your full credit/debit card numbers, CVV/CVC security codes, or confidential Apple Pay payment tokens on our servers.
  • Apple Pay Security & Tokenization: When paying with Apple Pay, Apple employs device-specific Account Numbers and dynamic one-time security codes. Your actual payment card details are never exposed to our application or stored anywhere on our infrastructure.
  • Certified Payment Gateways: Payment transactions are handled directly through authorized payment service providers (such as Moyasar) regulated by the Saudi Central Bank (SAMA) and certified under global PCI-DSS Level 1 security standards.
  • Transaction Records: ViNi only receives verification confirmation of payment success, an authorization reference ID, and the transaction amount necessary for issuing official electronic tax invoices and attributing loyalty points.
We strictly guarantee that we never sell, rent, or distribute financial or transaction details to third parties for advertising, marketing, or commercial exploitation.

5. Data Security & Technical Safeguards

We employ robust enterprise-grade security protocols to protect your information from unauthorized access, alteration, or disclosure:

  • End-to-End Transport Encryption: All data transmissions between the ViNi mobile application and our backend servers are encrypted using high-grade HTTPS / TLS 1.3 encryption.
  • Database Row-Level Security (RLS): Our database implements strict server-side Row Level Security policies, ensuring that each authenticated customer has access strictly to their own profile, cars, and order history.
  • Protected Infrastructure: All databases, credentials, and API communication adhere to rigorous access control and monitoring.

6. Third-Party Data Sharing

We do not sell personal data. Limited necessary data is securely shared strictly with vetted service providers essential for operating the application:

  • Payment Processors & Apple Pay: To execute transactions securely without retaining card credentials.
  • SMS Gateways: To deliver verification OTP codes during login.
  • Push Notification Services: To dispatch real-time order notifications to your device.

7. User Rights & Complete Account Deletion

ViNi empowers you with comprehensive control over your personal data:

  • Access and Updates: You can review your previous orders, adjust your profile name, and manage your saved vehicles directly in the app.
  • Notification Preferences: You can toggle or disable push notifications at any time via your device operating system settings.
  • Permanent Account Deletion: You have the absolute right to delete your account and all associated personal data immediately from within the app by going to: (More → Delete Account), or by contacting our support team via email. Upon confirmation, your personal identity records, saved cars, favorites, saved card tokens, wallet transactions, and order history will be permanently erased from our production servers.

8. Local Device Storage

The application maintains local cached data on your device to ensure quick startup, faster menu loading, and offline responsiveness. All localized cache files are completely purged upon signing out to prevent cross-account data leakage.

9. Children's Privacy

ViNi is not intended for or marketed to children under the age of 13. We do not knowingly collect personal information from minors. If we learn that personal information of a child has been collected, we will take immediate steps to delete that account and data.

10. Contact Us & Official Privacy Link

If you have any questions, inquiries, or feedback regarding this Privacy Policy or our compliance with Apple Pay guidelines, please reach out to us at our official contact email:

Official Support Email:
Vini.saudii@gmail.com