1.Who we are
nuqta taghyeer Company For Marketing Services ("we") operates MultiOne and is the controller of the personal data of the people who sign up for and use it. For data about your own customers (people who message your Page, buy from your store or visit it), you are the controller and we process it on your behalf, as explained under "Your customers' data" below.
2.Data we collect
We collect only what the features you use need:
- Account: your email address, the name of your workspace, your role in it and the email addresses of teammates you invite.
- Sign-in with Google (optional): your name, email address and profile picture from your Google account.
- Platform connections: when you connect Meta, TikTok, Snapchat, Google Ads, Salla, Threads or X through the platform's official login, we receive access tokens (and refresh tokens where the platform issues them), the account's ID, name and picture, and the list of permissions you granted. We never ask for, see or store your passwords on those platforms.
- Advertising data: your ad accounts, campaigns, ad sets and ads, their status and budgets, and performance metrics such as spend, impressions, clicks, conversions and revenue.
- Messages (only if you switch on an inbox): conversations with your customers on Messenger, Instagram and, once available, TikTok and WhatsApp: the sender's name, username and profile picture as the platform provides them (on WhatsApp, their phone number and profile name), the message text, links to attachments, timestamps, read status and the replies your team sends. Details are under "Messages in the unified inbox" below.
- Store data (only if you connect Salla): your store's name and web address, daily sales totals and your orders: order number, date, status, total, currency, traffic source, campaign parameters (UTM) and the Salla customer ID. We do not import buyers' names, email addresses or phone numbers.
- Content you create: your brand kit (logo, colours, style and product descriptions), the images you generate, and the ads, posts, captions, media and replies you publish or send through MultiOne.
- Email reports: the recipient email addresses you add to scheduled reports.
- Activity records: a log of changes made through MultiOne (for example a paused campaign or a new budget) with the email address of the teammate who made them, and your publishing history.
- Technical data: IP address, browser type and times of access in the security logs of our hosting and sign-in providers, and the cookies described below.
We do not ask for sensitive personal data such as health information or religious beliefs. If one of your customers includes it in a message, it is kept only as part of that conversation.
3.How we use data, and on what basis
We use personal data only for these purposes, each on a legal basis recognised by the PDPL:
- To provide MultiOne (performance of our contract with you): signing you in, syncing and showing your dashboards, sending the reports you schedule, publishing and posting what you ask us to, showing and sending inbox messages, attributing orders to campaigns and generating images.
- To run your account (performance of our contract): sign-in codes, team invitations and important notices about your account, the service or these policies. We do not send you marketing email without your consent.
- To keep MultiOne secure and reliable (our legitimate interest): preventing abuse and unauthorised access, investigating errors and keeping audit records. We rely on this basis only where it does not override your rights, and never for sensitive data.
- Consent: you connect each platform through its own consent screen, choose what to grant and can withdraw that consent at any time by disconnecting. Where the law requires consent for any other processing, we ask for it first.
- Legal obligations: keeping the records the law requires, such as tax records, and answering lawful requests from competent authorities.
We never sell personal data, and we never use it to advertise to you or to anyone else.
4.Data from connected platforms
We reach Meta, TikTok, Snapchat, Google Ads, Salla, Threads and X only through their official APIs, with the permissions you approve on their consent screens, and we use what we receive only to provide MultiOne's features to your workspace.
Data from Google, Meta, TikTok, Snapchat, Salla and other platforms is never used to train AI models and is never sold. When you publish, post or reply through MultiOne, the content goes to the platform you chose and is then also governed by that platform's own privacy policy.
5.Google user data (Limited Use)
MultiOne's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, for the Google user data we receive (your Google sign-in profile and your Google Ads account data):
- We use it only to provide and improve the features you use in MultiOne.
- We transfer it to others only as needed to provide those features (to the service providers listed below), to comply with the law, or as part of a merger or acquisition with notice to you.
- We never use it for advertising, and we never sell it.
- No person reads it unless you ask us to (for example for support), it is needed for security or to comply with the law, or it has been aggregated and anonymised for internal operations.
- We never use it to develop, improve or train generalised or non-personalised AI or machine-learning models.
6.AI image generation
When you generate an ad image, we send OpenAI only what that image needs: your brand kit (brand name, colours, style and product descriptions, and logo), the instruction you write and, if you add one, a reference image. We never send it data from your ad accounts, from Google, from your store, from your inbox or from any other connected platform. OpenAI's API terms state that it does not use this data to train its models. Generated images are drafts: review them before you use them.
7.Your customers' data
Some features handle personal data about your own customers: people who message your Facebook Page or your Instagram, TikTok or WhatsApp accounts, buyers in your Salla store and, if store tracking is switched on for your store, your store's visitors. For this data you are the controller and we are your processor: we process it only to provide MultiOne to you, on your instructions and under our Terms of service. You are responsible for telling your customers about it and for having a legal basis. If one of your customers contacts us, we will refer them to you and help you answer.
8.Messages in the unified inbox
If you switch on an inbox, MultiOne receives the conversations of the account you chose (your Facebook Page on Messenger, your Instagram professional account and, once each platform approves the feature for MultiOne, your TikTok Business account and your WhatsApp Business number) so that your team can read and answer them in one place. We use this data only for that purpose. For each conversation we store:
- The messages: the text your customers send and the replies your team sends. When a customer shares a location or a contact card, we keep the place's name and map link, or the contact's name and phone number, as part of the message. Attachment files your customers send are not copied into MultiOne: we keep the platform's link or reference, and the file is fetched from the platform when your team opens it (platforms keep them for a limited time, after which they can no longer be opened). A file your team sends is held briefly in MultiOne's storage until the platform has received it, then deleted.
- Who wrote: the customer's ID on the platform and, as the platform provides them, their name, username and profile picture (on WhatsApp, their phone number and the profile name they chose).
- Times and status: when each message was sent, whether your replies were read or failed, unread counts, whether the conversation is open or closed and which teammate it is assigned to.
- Your team: the email address of the teammate who sent each reply.
- Recent history: when you switch an inbox on, we import a limited number of recent conversations; after that, new messages arrive from the platform as they are sent.
Only your workspace's owners and admins can open the inbox. Conversations are kept while the connection exists: switching an inbox off stops new messages but keeps those already received, and disconnecting the platform in Settings → Connections deletes the inbox with all its conversations and messages straight away. If one of your customers asks for their conversation to be deleted, contact us and we will help you. Deleting in MultiOne does not delete the conversation on the platform itself, which keeps its own copy under its own policy. We never use messages for advertising, never sell them and never use them to train AI models, and no one at MultiOne reads them unless you ask us to (for example for support), security requires it or the law requires it.
9.WhatsApp Business
This section applies once WhatsApp Business is available in MultiOne. You connect your number through Meta's own sign-up window, and MultiOne works as a Meta Tech Provider:
- Your account stays yours: your WhatsApp Business Account, phone number and display name belong to your business under Meta's terms. MultiOne keeps an access token for that account and the number's two-step verification PIN, both encrypted like every other token, plus the IDs of the account and the number and the details Meta shows about the number (the number as displayed, its verified name, quality rating and messaging limit).
- Meta bills you directly: Meta charges WhatsApp message fees to the payment method on your WhatsApp Business Account. MultiOne neither pays nor re-invoices them.
- Your messages: WhatsApp conversations are stored, shown, kept and deleted exactly as described under "Messages in the unified inbox". They pass through the WhatsApp Business Platform, which Meta operates under its own terms, and we use data from WhatsApp only to support your conversations with the people you message.
- Message templates: the templates you create (name, category, language and content) are kept in your workspace and submitted to Meta for its approval.
- Your customers' opt-in: before you start a conversation with anyone (for example to send an offer or an order update), you must have their phone number and their agreement to receive WhatsApp messages from your business, collected in line with the WhatsApp Business Messaging Policy and the PDPL. The agreement must name your business and say what kind of messages they will receive. Collecting it, and keeping a record of it, is your responsibility.
- Stopping messages: your customers can stop your messages at any time by blocking your number in WhatsApp or by asking you to stop, in WhatsApp or anywhere else. You must honour every such request and stop messaging that person.
10.Store tracking for ad attribution
Store tracking is switched off today. When it is switched on for a Salla store connected to MultiOne, a MultiOne script on that store's storefront helps the merchant see which ads led to its orders, for example the first and the last ad a buyer clicked. The script records:
- Visits from a tagged link: when a visitor arrives through a link that carries campaign parameters (UTM) or an ad platform's click identifier (Meta's fbclid, TikTok's ttclid, Google's gclid, gbraid or wbraid, Snapchat's ScCid): the time, those parameters and that identifier, the path of the landing page (without its query string) and the domain of the referring site.
- A random visitor ID: generated in the browser and kept in a first-party cookie named mo_vid for up to 400 days, with a copy in the browser's local storage. It contains nothing about the visitor.
- The link to a customer and an order: while a visitor is signed in to the store, the store's customer number, and on the order-confirmation page, the order number. Both are linked to the visitor ID, so visits from different devices of the same signed-in customer can be connected.
- What it does not record: names, email addresses, phone numbers, addresses, payment details, device identifiers, the browser's user agent or the other pages a visitor browses.
- IP addresses: our server uses the visitor's IP address only in passing, to limit abusive traffic. It keeps a short code derived from it in memory and never writes the IP address to our database or our logs; our hosting provider's security logs may record it, as for any website.
The visit and link records are deleted after 90 days, and straight away if the store is disconnected; the result (which campaign each order is credited to) stays with the store's order data while the store is connected. We process these records on the merchant's behalf: the merchant is the controller and must have a legal basis under the PDPL, such as its legitimate interest in measuring its advertising (which the PDPL allows only where it does not prejudice visitors' rights and interests and no sensitive data is involved) or its visitors' consent. The script starts when the page loads and does not wait for a cookie banner. The merchant must also disclose this tracking in its own store's privacy policy. Visitors can clear or block cookies and site data in their browser at any time, and should send any request about this data to the merchant.
12.Transfers outside Saudi Arabia
Our providers' servers are outside the Kingdom (in India, Singapore and the United States), so your data is transferred outside Saudi Arabia to provide the service. We transfer only the data each provider needs, and we rely on the safeguards the PDPL and its regulations allow, including contractual clauses that require each provider to protect the data to a standard no lower than the PDPL's.
13.How long we keep data
- Account and workspace data: for as long as your account is open.
- Connections and everything imported through them (tokens, ad accounts, campaigns, metrics, orders, conversations and messages): while the connection exists. Disconnecting a platform in Settings → Connections deletes that connection and this data straight away.
- Removing the app on the platform's side: if you remove MultiOne from your Meta account or uninstall it from your Salla store, the platform notifies us and we delete that connection and its data. Data-deletion requests from Meta are handled the same way.
- Media uploaded for publishing: deleted once publishing finishes; files that are never published expire 24 hours after upload and are then removed.
- Store-tracking records (visits and their links to customers and orders): deleted after 90 days.
- Brand kits, generated images and their reference images, publishing history, report settings and the change log: kept while your workspace exists.
- Closing your account: when you ask us in writing, we delete your account, your workspaces and their data within 30 days, except records the law requires us to keep. Copies in our database provider's routine backups are overwritten shortly afterwards.
- Security logs of our hosting and sign-in providers expire under those providers' retention periods.
14.Your rights
Under the PDPL you have the right to:
- be informed how your data is collected and used (this policy);
- access the personal data we hold about you;
- receive a copy of it in a clear, readable format;
- have inaccurate or incomplete data corrected or completed;
- have data we no longer need deleted;
- withdraw your consent at any time, without affecting processing carried out before;
- complain to the Saudi Data and Artificial Intelligence Authority (SDAIA).
To use any of these rights, email privacy@multionesa.com from the address you sign in with. We reply within 30 days and may first ask you to confirm your identity. You can also disconnect any platform yourself at any time in Settings → Connections.
15.How we protect data
- Platform access tokens are encrypted with AES-256-GCM, stay on our servers and are never sent to any browser.
- Row-level security in our database keeps each workspace's data separate, and each teammate sees only what their role allows.
- All traffic to MultiOne is encrypted in transit (HTTPS).
- We use no passwords: you sign in with a one-time code sent to your email, or with Google.
- Access to our production systems is limited to the people who need it to run the service.
If a personal-data breach occurs, we will notify SDAIA within 72 hours of becoming aware of it, as the PDPL requires, and tell affected users without undue delay when it could harm them: what happened, which data was involved and what we are doing about it.
17.Children
MultiOne is a business service for people aged 18 and over. We do not knowingly collect data from children; if you believe a child has given us personal data, contact us and we will delete it.
18.Changes to this policy
When we change this policy, we publish the new version on this page with a new date. If a change materially affects how we use your data, we will tell account owners by email or in the app before it takes effect.
19.Data deletion
Step-by-step instructions for deleting your data, including after removing MultiOne from Meta, are on the data deletion page.
20.Contact us
For any privacy question or request, email privacy@multionesa.com. The controller is:
- Company: nuqta taghyeer Company For Marketing Services