1. Entity Name and Activity

Marn Information Technology Business Company (“Marn”) operates MarnPOS, a cloud-based Point of Sale and payments platform serving merchants across the Kingdom of Saudi Arabia.

FieldValue
Company NameMarn Information Technology Business Company
Commercial Registration No.1010895874
Registered AddressRiyadh, Kingdom of Saudi Arabia
Privacy Contact[email protected]

2. Privacy Contact

For any complaints, questions, or requests regarding this Policy — including exercising your rights as a data subject — please contact us at [email protected].

You also have the right to lodge a complaint directly with the Saudi Data and Artificial Intelligence Authority (SDAIA), the Competent Authority under the Personal Data Protection Law.

FieldValue
Last Updated30 August 2026

3. Scope of This Policy

This Policy explains how Marn collects, uses, and protects personal data — data by which a natural person can be identified, directly or indirectly.

It does not apply to data about merchants and other organisations as legal entities, to anonymised or aggregated data, or to third-party websites, applications, or services that we may link to or integrate with (which operate under their own policies).

This Policy applies to the personal data of natural persons who use MarnPOS or whose data is collected through the platform.

4. Personal Data We Collect

We collect personal data in two ways: directly from the data subject — when you interact with MarnPOS, contact our support teams, or otherwise provide information to us — and automatically through your use of the platform — such as device information, session metadata, and system logs generated when MarnPOS is used.

Where Marn acts as Controller of personal data, that data is collected only directly from the data subject or automatically through use of the platform. Marn does not collect personal data indirectly from third parties for its own purposes.

Separately, where a merchant operates a service on the MarnPOS platform (for example, a loyalty programme), the merchant is the Controller of the personal data collected through that service, and Marn processes that data on the merchant’s instructions.

We collect only the personal data we need to provide and operate the MarnPOS service. Personal data may include the following broad categories:

  • Account and identification data — such as name, contact details, role, and business identifiers used to set up and manage MarnPOS accounts.
  • Loyalty programme data — where a merchant operates a loyalty programme on the MarnPOS platform, end customers may provide their name and mobile number at the point-of-sale terminal. Marn processes this data on the merchant’s instructions.
  • Service usage and support data — records of interactions with the platform and with our support teams.
  • Technical and security data — such as IP address, device information, and information about how you interact with our website and applications.
  • Marketing preferences — where you have chosen to receive marketing communications.

Providing certain personal data is required to open and use the MarnPOS service. If the required data is not provided, Marn may not be able to create or operate the account or deliver the requested service. Marketing preferences and other optional data are not required to use the service.

Payment card data. Marn does not store, process, or transmit payment card data. Card payments are handled directly by licensed payment processors under their own privacy notices.

Sensitive personal data. Marn does not collect or process sensitive personal data.

Minors. MarnPOS is designed for business use. Marn does not knowingly collect personal data from individuals under 18. If you believe a minor’s data has been collected, please contact [email protected] and we will erase it.

5. Legal Basis for Processing

Marn processes personal data for the following main purposes, on the applicable legal bases under the Personal Data Protection Law:

  • Providing and operating the services and managing accounts — legitimate interest.
  • Managing customer and merchant relationships and providing support — legitimate interest.
  • Protecting systems, preventing fraud, and managing risks — legitimate interest.
  • Complying with legal and regulatory requirements — legal obligation.
  • Operating merchants’ loyalty programmes — where Marn processes personal data on the merchant’s instructions, the merchant (as Controller) determines the applicable legal basis.
  • Improving services and communications — legitimate interest.
  • Direct marketing communications (email, SMS, or similar) — consent.

Where processing relies on consent, you may withdraw it at any time by contacting [email protected]. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

6. Sharing Personal Data

Marn may disclose personal data to the following categories of recipients, for the purposes described in this Policy:

  • Technology and cloud service providers who host, operate, or support the MarnPOS platform on our behalf.
  • Professional service providers, including auditors and legal or financial advisors, where necessary.
  • Payment service providers licensed by the competent authorities in the Kingdom of Saudi Arabia, where required to process transactions.
  • Governmental and regulatory authorities, where required by law or in response to a lawful request.
  • Other parties in connection with a business transaction, such as a sale or transfer of Marn’s business or assets.

Marn does not sell personal data.

7. Storage, Retention & Security

Retention periods. We retain personal data for the periods necessary to achieve the purposes for which it was collected, or for the periods required by law. Indicative retention periods include:

Data CategoryRetention Period
Merchant user account dataDuration of account + 1 year
Transaction and invoicing data (where it includes personal data)Per ZATCA requirements (typically 6 years)
End-customer loyalty dataFor the duration of the loyalty programme; ended on consent withdrawal
Support correspondence2 years
System and security logsMinimum 12 months (aligned with NCA Essential Cybersecurity Controls, Control 3-12-2)
Backup data30 days rolling

Where is data stored? MarnPOS data is hosted on cloud infrastructure. The cross-border transfer position is addressed in Section 9.

Security. Marn implements appropriate administrative, organisational, and technical measures to protect personal data against unauthorised access, use, disclosure, alteration, or destruction.

Destruction. When personal data reaches the end of its retention period, it is destroyed or anonymised using secure methods.

8. Your Rights as a Data Subject

Under the Personal Data Protection Law you have the right to:

  • Be informed of how your personal data is used.
  • Access your personal data.
  • Request correction of inaccurate or incomplete data.
  • Request deletion of your data.
  • Receive your data in a clear, readable format.
  • Withdraw consent at any time, for any purpose based on consent.
  • Lodge a complaint with the Saudi Data and Artificial Intelligence Authority (SDAIA).

Data subjects may exercise their rights under the Personal Data Protection Law through the contact channels specified in this Privacy Policy. Marn may verify the identity of the requester before processing the request.

Marn will act on data subject requests within 30 days of receipt. Where a request is complex, this period may be extended by a further 30 days, and Marn will notify the data subject of the extension and the reasons for it before the initial 30-day period expires. These timelines reflect Article 3 of the Implementing Regulation of the Personal Data Protection Law.

Where personal data has been collected through a merchant’s loyalty programme, the merchant is the Controller of that data and is responsible for handling requests to exercise rights. Such requests should be directed to the relevant merchant.

9. Cross-Border Data Transfers

Certain personal data may be processed or stored outside the Kingdom of Saudi Arabia where necessary, in accordance with the Personal Data Protection Law and the applicable regulations and requirements, and subject to the implementation of the appropriate legal safeguards.

10. Personal Data Breach

In the event of a personal data breach, Marn will:

  • Notify the Saudi Data and Artificial Intelligence Authority (SDAIA) within 72 hours of becoming aware of the breach, where the breach poses a risk to data subjects.
  • Notify affected data subjects without undue delay where the breach is likely to cause significant risk or harm to them.

These timelines and notification obligations reflect Article 24 of the Implementing Regulation of the Personal Data Protection Law.

11. Changes to This Policy

This Policy may be updated from time to time to reflect changes in our operations or regulatory requirements. The date of the latest update appears in Section 2. Significant changes will be communicated via a notice on the Marn website or by email to the address most recently provided to us.