Privacy Policy
This Privacy Policy outlines how KBM Technologies, a limited liability company duly established in the Kingdom of Saudi Arabia (“KSA”) trading as “Caters” (“Caters”, “we”, “us”, or “our”), collects, uses, discloses, stores, and protects personal data of individuals using the mobile device application (the “App”) and the website in KSA. Please read this Privacy Policy to understand how we collect, use and protect your personal data when you use our services via our products (including our website, App, etc.). By using our products and services, you agree that we may collect, use, store, transfer and process your personal data in accordance with this Privacy Policy.
1. Our Contact details
We are KBM Technologies Company located at King Fahad St, Al-Qairawan District, Postal Code 13534, Riyadh, Kingdom of Saudi Arabia. If you have any enquiries or if you would like to contact us and/or the Data Protection Officer directly about this Privacy Policy or our processing of your personal information, including requesting the exercise of your rights as outlined below, please contact us at Privacy@caters.sa.
2. Scope of this Policy
This Privacy Policy applies to the personal data we process relating to customers, vendor representatives, and other users who access or interact with our website, App(s), and related services in the KSA. It also applies where we process personal data of individuals residing in the KSA from outside the KSA.
This Privacy Policy does not apply to third-party websites, applications, or services that are not owned or controlled by us. Where our platform contains links to third-party services, their privacy practices and policies will apply independently.
3. Personal Data We collect
In performing our services, we collect the following categories of personal data:
Account and contact data,such as your name, email address, mobile number, delivery addresses, and similar identifiers provided when creating and managing your account or placing orders.
Order and transaction data, including order contents, selected vendors, special instructions, preferences, and customer support interactions, to facilitate transactions and provide support services.
Location data, such as GPS-based location information, where you have granted permission or where permitted by law, to enhance ordering and delivery functionality.
Technical and usage data, including IP address, device identifiers, browser and operating system information, and analytics data generated through cookies or similar technologies. This may include navigational and clickstream data (such as pages viewed, features used, and time spent on the platform) and server log data collected automatically when you access our services.
We use technical and usage data for diagnostics, security, analytics, service improvement, and measurement of advertising effectiveness, in accordance with applicable law. Where required, IP addresses and related log data are treated as personal data and processed in accordance with this Privacy Policy.
For payment processing purposes, although we don’t handle the payment process directly, we collect limited payment related information or receive payment status details from our licensed payment service provider. We do not store full payment card details on our systems.
Whether provision of data collection is mandatory or optional:
We clearly indicate where the provision of personal data is mandatory to create an account, place orders, or comply with legal obligations, and where providing personal data is optional. If you choose not to provide mandatory information, we may be unable to provide certain services.
4. How We Collect Personal Data and for What Purposes
We collect personal data directly from you through our applications and websites, including through account registration forms, order placement, and customer support interactions, to operate and support our platform. This includes creating user accounts, processing orders, facilitating payment through licensed payment service providers providing customer support, and communicating service-related updates.
We also collect personal data indirectly through cookies, log files, analytics tools, and service integrations (such as payment service providers) to maintain platform security, prevent fraud, perform analytics, and improve user experience.
Our collection methods are transparent and proportionate, and our purposes are limited to what is necessary for operating our technology platform. Where we rely on consent, consent is not made a condition of receiving a service unless the processing is directly and intrinsically related to that service.
5. How We Use Personal Data
We use personal data to operate and manage our platform, including account creation and authentication, order processing and confirmation, payment facilitation through licensed payment service providers, and sharing necessary order details with vendors to fulfill catering services.
We also use personal data to personalize and improve our services, support user preferences, enhance performance and security, and conduct analytics. We may communicate with you regarding service updates, policy changes, security alerts, and transactional notifications.
Marketing communications are sent only with your explicit consent, and you may opt out at any time. We may use aggregated or de-identified data that does not identify individuals for analytical and statistical purposes.
6.Legal Basis for Processing
We process personal data in accordance with one or more lawful basis recognized under the KSA Personal Data Protection Law (“PDPL”), including:
Your explicit consent (for example, for certain marketing communications);
Performance or execution of a contract to which you are a party (such as processing orders and facilitating payments);
Compliance with legal or regulatory obligations;
Legitimate interests that do not prejudice your rights or interests (including fraud prevention, service security, and service improvement);
Public interest or vital interests, where applicable; and
Processing of publicly available data, where permitted under the PDPL and subject to applicable safeguards.
Where processing is based on consent, you may withdraw your consent at any time without affecting processing carried out on other lawful bases or transactions which were completed prior to withdrawing the consent.
7. User-Generated Content
If you submit reviews, ratings, or other content publicly on the platform, that content and any personal data you choose to include may be visible to other users or the public.
Please do not include personal data in user-generated content that you do not want to make public.
8. Cookies and Similar Technologies
We use cookies and similar technologies to operate, secure, and improve our services. These technologies help us remember your preferences, keep you signed in, perform analytics, prevent fraud, and support relevant content and advertising, subject to applicable law and your consent choices.
You may manage cookies through your browser or device settings. Disabling cookies may affect the functionality of certain features of the platform.
9. Marketing Communications
We will not send you any communications for the purpose of direct marketing without obtaining your prior explicit consent. If you consent to receive such direct marketing communications, you have at any time a right to opt out by contacting us via Privacy@caters.sa.
10. How we disclose your Personal Data
We may disclose your personal data to vendors to fulfill your orders, including your name, contact details, delivery address, order contents, and relevant instructions, strictly as necessary for the vendor to provide catering services. We disclose personal data to our processors and service providers (for example, hosting providers, analytics, customer support, communications, and payment processors) under written agreements that bind them to PDPL compliant security, confidentiality, and processing obligations. We will disclose personal data where required to comply with applicable law or regulatory obligations, to respond to lawful requests from public authorities, to protect our rights and platform security, or to pursue or defend legal claims.
We do not sell personal data, and we will not disclose personal data to third parties for their direct marketing without your explicit consent. If we engage advertising or analytics partners, any cookies or tags used will be subject to this Policy and applicable law, and data used for advertising will be handled in compliance with consent and PDPL requirements.
11.Payment Processing
Payments made through the Caters platform are processed by a Saudi Central Bank licensed payment service provider (currently Tap Payments) under a compliant marketplace or direct vendor settlement structure. This ensures that customer funds are settled directly to vendors and that Caters does not engage in regulated payment services.
We do not store full payment card details on our systems. Payment data is handled by the licensed provider in accordance with applicable security and regulatory standards.
12. International Data Transfers
We may transfer your personal data with our affiliates or subcontract the processing of your data to, or otherwise share your data with, service providers located inside or outside the KSA. Such third parties may be engaged in, among other things, the provision of services to you, the processing of transactions, payments and/or the provision of support services. We will fulfil any requirements in relation to the international transfers of personal data under applicable laws.
When we transfer your personal data, we transfer them to countries that have been deemed to provide an adequate level of protection for personal data pursuant to the PDPL. In the absence of an adequacy decision, whoever we transfer your personal data to outside your jurisdiction will ensure a similar degree of protection is afforded to your personal data by ensuring appropriate safeguards are in place. Appropriate safeguards may include Binding Corporate Rules (BCRs) and Standard Contractual Clauses (SCC’s).
13. Storage Location, Retention, and Secure Destruction
We will only retain your personal information for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting or reporting requirements.
14. Security Measures
We implement appropriate organizational, administrative, and technical security measures, including encryption, access controls, secure development practices, and monitoring mechanisms, consistent with applicable National Cybersecurity Authority controls or recognized best practices.
While we take reasonable steps to protect personal data, no system is completely secure. If you believe your account or interaction with the platform is compromised, please contact us immediately using our contact details provided above.
15. Breach Notification
In the event of a personal data breach that may cause harm or affect data subject rights, we will notify the competent authority (SDAIA) and Ministry of Commerce within 72 hours and affected individuals.
16. Account Deletion
You may request deletion of your Caters account via the application settings. If you have pending transactions or outstanding amounts, you will need to complete those before deletion. Deleting your account will result in deletion of associated personal data unless we must retain certain information to comply with law, to defend legal claims, to prevent fraud, or to protect ourselves or others, in which case we will retain only what is necessary and for no longer than required. Once deleted under this Privacy Policy, your data cannot be recovered.
How to delete your account:
Open the Caters app and log in to your account.
Go to Settings and select “Account”.
Tap “Delete Account” and confirm your request.
If you have questions, please contact customer support using our contact details.
17. Your Rights
You have the following rights in relation to the personal information we hold about you:
Right to request access to any personal information we hold about you as well as related information, including the purposes for processing the personal information, the recipients or categories of recipients with whom the personal information has been shared, where possible, the period for which the personal information will be stored, the source of the personal information, and the existence of any automated decision.
Right to request your personal information from us in a readable and clear format.
Right to request destruction of your personal information.
Right to obtain without undue delay the rectification of any inaccurate personal information we hold about you. In this instance you may request us to restrict processing of your personal information that is incorrect.
Right to request to know what personal information is held about you.
Right to prevent or restrict processing of your personal information.
Right to request to withdraw your request. If we rely on consent to process your personal information, you may at any time withdraw such consent. However, this will not affect the lawfulness of the processing, based on your consent, conducted prior to such withdrawal, or where we have other legitimate reasons for processing your personal information. You can exercise your right to withdraw consent by contacting us at Privacy@caters.sa.
Right to lodge a complaint with the Saudi data protection authority (SDAIA) using the contact details below in respect of our processing activities regarding your personal information.
Right to claim compensation for material or moral damage if you are harmed as a result of any violation stipulated under the applicable laws.
19. Changes to This Privacy Policy
We may occasionally amend this Privacy Policy to reflect our activities and user feedback, and we reserve the right to make changes to this Privacy Policy at any time. The use of your information is subject to the Privacy Policy and Terms of Use in effect at the time of use. The provisions contained in this Privacy Policy supersede all previous notices or policies regarding our privacy practices with respect to the Sites.
Please check the “Last Updated” to see when this Privacy Policy was last revised. We encourage you to check frequently to see the current Privacy Policy to be informed of how we are committed to protecting your information and providing you with improved content on our Sites in order to enhance your experience.
20. Effective Date and Last Updated
The effective date of this Privacy Policy is 08 March 2026 and the date of the latest update is 17 May 2026.
CATERS
Premier marketplace for luxury event catering, connecting discerning clients with the finest catering restaurants.
CONTACT US
support@cater.sa
+966 53 098 2222
Riyadh, Saudi Arabia
QUICK LINKS