Privacy PolicyLast updated: 01/09/2026

1. Purpose of the Policy

This Privacy Policy explains how Resal collects, uses and discloses your personal data in accordance with the applicable laws, in particular the Saudi Personal Data Protection Law (the “PDPL”) issued by Royal Decree No. (M/19) dated 9/2/1443H, as amended by Royal Decree No. (M/148) dated 5/9/1444H.

2. Scope of the Policy

This Policy applies to the employees, customers, contractors and third parties of Resal Saudi Arabia who have a direct or indirect relationship with Resal for the processing, sharing or retention of personal data.

This document also applies to all individuals in the Kingdom of Saudi Arabia whose personal data is processed by Resal on their behalf.

3. References

  • The Saudi Personal Data Protection Law (PDPL).
  • The General Data Protection Regulation (GDPR) – applicable to international users whose personal data Resal processes outside the Kingdom of Saudi Arabia.

4. Definitions

For the purposes of this Privacy Policy, the following words and expressions shall have the meanings set out opposite them:

  • Personal Data: means any data – whatever its source or form – that may lead to the identification of an individual specifically or directly/indirectly, including but not limited to: name, ID number, addresses, contact numbers, licence numbers, personal records and property, bank account numbers, payment cards, still or moving images, and any other data of a personal nature.
  • Company: refers to Resal Al-Wad for Information Technology, Kingdom of Saudi Arabia, referred to as “Resal”, the “Company”, “we”, “us” or “our”.
  • Account: means a unique account created by or on behalf of the User to access the Resal website/application or any part thereof.
  • You / User: the natural person who uses the Resal website/application, or the legal entity that such person represents or acts on behalf of under a valid authorisation.
  • Service Provider: means any natural or legal person who processes personal data on behalf of Resal, including: payment providers, technical support, analytics companies, anti-fraud entities, notification platforms, booking enablers, telecom aggregators and operators, and merchants and transaction partners.
  • Usage Data: means data collected automatically through the use of the website/application or from their infrastructure, such as the duration of a page visit, the pages visited, or connection data and standard technical protocols.
  • Cookies: small text and technical files stored on the User’s device by the website, containing a record of the User’s interactions and preferences, which the User may accept, reject or customise.
  • Device: means any technical or electronic tool capable of accessing the website/application, such as computers, mobile phones or tablets.
  • Third-Party Social Media Service: refers to any external website or social network through which the User can log in or link in order to create an account to use Resal’s services.
  • Country: refers to the Kingdom of Saudi Arabia.
  • Website: refers to Resal’s official website at: https://www.resal.me.

5. Policy Statement and Processing Controls

5.1 Collection and Use of Personal Data

Resal collects information through three main channels: directly from your inputs, from external sources (such as integrated loyalty programmes), and through automated technologies (such as cookies).

  • Data you provide to Resal: name, mobile number, email address, authentication data, traveller details (for booking services), and the phone numbers to be topped up (for mobile top-up).
  • Purposes of processing: operating accounts, executing payments and points redemption via ResalPay, completing flight and hotel bookings, providing technical support, and complying with legal obligations and commercial record-keeping.

5.2 Sharing of Personal Data

We share only the necessary data with service providers, merchants (to complete ResalPay transactions), telecom operators (to execute mobile top-ups), and regulatory authorities where a legal or judicial requirement so mandates.

5.3 International Data Transfers

We primarily store and process your data within the Kingdom of Saudi Arabia. In certain cases required by the nature of the service (such as an international flight booking or a hotel outside the Kingdom), data may be transferred to external service providers or organisers in accordance with the safeguards and mechanisms approved under the PDPL.

5.4 Retention of Personal Data

We retain your personal data until it is anonymised or destroyed as necessary to provide the service or execute the requested transactions, or for other essential purposes such as compliance with regulatory obligations, record-keeping and dispute resolution. To ensure transparency and compliance, Resal sets the main retention periods as follows:

  • Transaction and operations data: records of transactions relating to booking services, mobile top-up, ResalPay and invoices are retained for ten (10) years from the transaction date, in compliance with the commercial and tax regulations of the Kingdom of Saudi Arabia and for audit, anti-fraud and anti-money-laundering needs.
  • Customer account data: core account data is retained for the duration of the account’s activity and for a period of one (1) to a maximum of three (3) years from the date of account closure or a deletion request, to address any potential legal claims or disputes.
  • Resal Points data: data relating to loyalty points is retained throughout your subscription and activity, and for twelve (12) months from the date of your account’s last interaction or from the points’ expiry date.
  • Marketing consent data: records of consent to receive marketing materials are retained until you withdraw your consent (unsubscribe). Upon unsubscribing, your contact details are automatically moved to the “email/message suppression list” to ensure you are not contacted in the future.

Usage Data is generally retained for a shorter period, unless required for information-security purposes, network performance improvement, or where retention is mandatory under applicable laws and regulations.

5.5 Data Destruction and Security

  • Destruction: upon expiry of the periods specified above, Resal securely destroys the data in accordance with its internal policies or fully anonymises it.
  • Security: we apply strict standards including encryption, multi-factor authentication and compliance with PCI DSS standards to protect payment cards.

5.6 User Rights and How to Exercise Them

As the owner of personal data under the PDPL, you have the right to be informed, the right to access your data, the right to request correction or updating, and the right to request erasure/destruction, through the official channels:

Our team will be pleased to handle your requests and respond with the action taken within a maximum of thirty (30) days from the date of receipt of a complete request. Certain exceptional requests may require additional time (where they are numerous or complex), in which case we will notify you in advance of the extension together with the reasons, in line with the Implementing Regulations of the PDPL.