Privacy Policy
Last updated: 6 October 2026
Scope and approval status
This policy explains how personal data is handled when using FUNDIQI to book hotel facilities and rooms or contact its team. It is drafted with reference to the Saudi Personal Data Protection Law, its Implementing Regulation, the Regulation on Personal Data Transfer Outside the Kingdom, and consumer-data protection requirements under the E-Commerce Law. This version awaits completion of the operator details, approval and review of actual practices; publishing the text alone does not establish full compliance.
Controller and contact details
Legal name of the operating company or establishment (controller): __________. Commercial registration number: __________. Platform name: FUNDIQI. For privacy requests and exercising your rights, email portal@pi-hospitality.com or use the Contact Us form and identify the request as concerning personal data. The legal name and registration number are intentionally blank until supplied by the operator; the trading name alone does not identify the legal entity.
Data and collection sources
We collect information you provide directly: the booking organizer's name, phone and email when supplied; experience, hotel, date, time, guest counts and add-ons; and contact messages, partnership requests and comments you choose to submit. For account creation or sign-in, we receive the account identity, name and verified email from Clerk and your chosen sign-in provider. Stripe provides payment references, status and refund information, not full card details or the card verification code. Operational and security logs may contain request, device and connection-address information, with optional usage data depending on privacy settings.
Purposes and legal grounds
Booking data is used to perform the service or agreement to which you are a party: checking availability, taking payment, issuing the voucher, and handling cancellation, refunds and support. Account data serves the account you choose to create. Transaction records may be retained for statutory and accounting obligations and resolving claims. Optional analytics or any direct marketing require separate, withdrawable consent. Reliance on legitimate interests for service security and fraud prevention requires meeting legal conditions and assessing the impact on your rights; using the website is not blanket consent to every processing purpose.
Required and optional information
You may browse without creating an account or consenting to optional analytics. Information needed to fulfil a booking, process payment or respond to a request is identified in the relevant form; the corresponding service may not be possible without it. Creating an account and submitting messages, comments or partnership requests are your choices. Refusing optional tracking does not block content, browsing or booking, and acknowledging this policy is not marketing consent.
Linking bookings to an account
You can check out as a guest without creating an account. A new booking completed while signed in is linked to your account and appears in My bookings. To add an earlier booking, open My account and paste its secure voucher management link into Link a booking with its voucher; a verified email is required. Matching a guest contact email does not add bookings, and a booking already linked to another account cannot be transferred.
Disclosure and service providers
We do not sell personal data. Necessary booking information is shared with your selected hotel to deliver the visit and verify the booking. FUNDIQI uses Clerk for authentication, Stripe for payments, and hosting, storage and email services to operate the platform and communicate. Google Analytics and Microsoft Clarity may be used when configured and after the required consent. Authorized staff access is limited to their work needs; disclosures to authorities must relate to a lawful request or obligation. Hotels and service providers remain subject to their roles and legal duties for data they receive; this policy does not authorize unrelated uses.
Messages and public comments
The contact form stores your name, email, subject and message so authorized staff can read and respond; support messages and partnership requests are not published to visitors. A comment you choose to submit in a public-comments section may be visible to visitors with the display name you provide. Do not include contact details, sensitive information or other people's personal information in public comments, or send passwords, card numbers or verification codes in support messages.
Cookies, consent and withdrawal
Necessary cookies or local storage support sessions, security, saved choices and booking functions. Optional trackers do not start before consent; choose Necessary only, customize your choice, or change or withdraw it using Privacy settings in the footer. Withdrawal does not stop processing supported by another lawful ground or affect the lawfulness of prior processing. Stopping future tracking does not automatically delete all previously collected data; you may request destruction subject to your rights and statutory limits. Any direct marketing requires separate consent and a clear way to stop it.
Retention and destruction
Retention is purpose-based, not indefinite: booking and payment data through service delivery and settlement, with periods needed for statutory and accounting duties or claims; account data while needed to provide the account service, with closure requests assessed; and support or partnership messages until follow-up and necessary documentation or related disputes are complete. Session validity and saved-choice lifetimes apply to local storage. Once the purpose ends and no lawful retention ground remains, data must be destroyed or irreversibly anonymized, including relevant copies in line with statutory requirements. You may request the retention criteria applied to your data; closing an account does not remove obligations connected with an earlier transaction.
Your rights and how to exercise them
You have the right to know the purposes and lawful grounds, access your personal data, obtain a readable and clear copy, request correction, completion, updating or destruction, and withdraw consent when it is the processing ground, subject to the law and its exceptions. Email portal@pi-hospitality.com or use Contact Us, identifying the right requested. We may request the minimum needed to verify identity and protect others' data, not your password or card details. The statutory period for fulfilling a rights request is no more than 30 days without delay; an extension of up to 30 additional days is permitted in the circumstances allowed by the Regulation, with advance notice and reasons. A statutory exception preventing fulfilment must be explained. Destruction may be limited by a lawful retention obligation or a dispute requiring specified records.
Transfers outside Saudi Arabia
Authentication, payment, hosting, storage, email and analytics providers may process data outside Saudi Arabia depending on their operating locations. Not all data should be assumed to reside in Saudi Arabia, and accepting this policy or tracking is not blanket consent sufficient to authorize every transfer. Transfers require compliance with the PDPL and Transfer Regulation, specified purposes and minimum necessary data, verification of protection levels or lawful safeguards and exceptions, and risk assessments where required. This draft does not approve a final list of countries or transfer mechanisms; the operator must verify and approve them. Details of destinations and safeguards may be requested through the privacy contact.
Security and incidents
Data protection relies on encrypted connections, restricted access, session verification and other technical and organizational measures appropriate to the processing; no service can be guaranteed free of all risk. Incidents must be handled under the law: notify the competent authority within no more than 72 hours of becoming aware of a breach meeting the reporting conditions, and notify the data subject without undue delay where the incident may harm their data or conflict with their rights or interests. This text is not a security certification or confirmation that all operational procedures have been audited.
Children and other people's data
Booking information includes child guest counts when selected; the basic booking fields do not require children's names or identity documents. If personal data about a child or person lacking full legal capacity needs to be collected, their rights and legal-guardian and consent requirements must be respected where required by law. Only provide another person's information with appropriate authority and after informing them of the purpose and policy; entering their email or phone does not establish your ownership of a booking or account.
Complaints and policy updates
For questions or complaints about your data, contact portal@pi-hospitality.com or use Contact Us. You may complain to the competent personal-data protection authority through SDAIA's official channels, following the applicable procedures and time limits; you are not required to rely only on an internal complaint. The policy date is updated when amended. New purposes or material changes must be communicated and fresh consent obtained where required; continued browsing alone is not consent to a new optional purpose.