01 Introduction and scope
Twsila ("Twsila", "we", "us") operates a transport marketplace in the Kingdom of Saudi Arabia. This Privacy Policy explains what personal data we process, why we process it, who we share it with, how long we keep it, and the rights available to you when you use the Twsila Passenger mobile application to book transport services.
Twsila Passenger is the customer application for requesting transport services. You create a transport request, receive offers from captains, agree a price, track the trip, and pay. This policy applies to the Passenger application and to related back-end services, notifications, invoices, and customer support channels connected to it.
Twsila is the party responsible for the personal data described here.
02 Data we collect
The table below describes the categories of personal data processed in the Passenger application and the purpose of each category.
| Category | What this includes | Why we process it |
|---|---|---|
| Account and identity | Name, mobile number, one-time verification code, preferred language, country, profile photo if you add one | Create and secure your account, verify that the number belongs to you, sign you in |
| Location | Precise or approximate device location, pickup and destination points, selected map places, saved addresses, route and distance | Show nearby options, set pickup and destination, estimate distance and price, allow you to follow the trip |
| Transport request | Service type (persons, goods, furniture, frozen, drinking water, cisterns, car aid), vehicle preference, dates and times, item description, quantity, weight, notes, requested budget | Publish your request to eligible captains and enable them to price it correctly |
| Photos you select | Images chosen through the operating system photo picker, or captured with the camera, that describe the items to be transported | Let captains assess the load and provide an accurate offer. Only the images you select are uploaded |
| Offers and trip records | Offers received, accepted price, assigned captain and vehicle, trip status and timestamps, completion and cancellation records, ratings and reviews you submit | Operate the trip, resolve disputes, maintain service quality and safety |
| Payment and transaction | Fare amount, payment method type, transaction reference, authorisation result, invoice records. Card details are entered inside the payment gateway and are not stored by Twsila | Collect payment for trips, issue invoices, handle refunds and chargebacks, meet accounting obligations |
| Device and technical | Device model, operating system version, application version and flavour, language, network status, push notification token, IP address, crash and diagnostic logs | Deliver notifications, keep the service compatible and stable, detect abuse, investigate faults |
| Support and communications | Messages to customer support, complaint details, call or contact requests you initiate from the app | Respond to you and keep a record of the issue and its resolution |
| Approximate country | Country derived from your IP address at first launch | Preselect the correct country code and language for onboarding |
The Passenger application does not embed an advertising, analytics, or ad-attribution SDK.
03 Device permissions
Permissions are requested only when a feature needs them, and each one can be changed in your device settings at any time.
| Permission | Purpose | If you decline |
|---|---|---|
| Location (precise / approximate) | Maps, pickup and destination, distance and price estimation, trip tracking | You must enter addresses manually; nearby and navigation features are limited |
| Camera | Take a photo of items to transport | You can still choose an existing photo instead |
| Selected photos | Attach specific images through the operating system photo picker | Requests can be submitted without images where optional |
| Notifications | Offers, trip status, payment results, security and service messages | You will need to open the app to see updates |
| Ignore battery optimisation | Prevent the system from suspending time-critical trip updates | Notifications and status updates may be delayed |
| Network state | Detect connectivity and adapt to poor networks | Not applicable. Required for the app to function |
Photos and videos
The Passenger application uses the operating system photo picker. You choose the specific images that are shared with the app, and the application does not request broad or continuous access to your media library. On Android, the broad media and storage permissions are explicitly removed from the application.
On iOS, the media capture component also declares microphone access because it supports video capture. Twsila does not record or transmit audio.
04 How we use data and our legal bases
| Purpose | Legal basis |
|---|---|
| Register accounts, verify mobile numbers, and authenticate sign-in | Performance of a contract |
| Publish transport requests, match customers with captains, and exchange offers | Performance of a contract |
| Calculate routes, distance, availability, and price | Performance of a contract |
| Process payments and issue invoices for trips | Performance of a contract; legal obligation |
| Send trip, payment, and security notifications | Performance of a contract |
| Provide customer support and handle disputes | Performance of a contract; legitimate interest |
| Prevent fraud, misuse, and unsafe conduct; enforce our terms | Legitimate interest; legal obligation |
| Maintain security, diagnose faults, and improve reliability | Legitimate interest |
| Access precise location, camera, selected photos, and notifications | Your consent, given through the device permission prompt |
| Retain tax, accounting, and regulatory records | Legal obligation |
We do not use personal data for automated decisions that produce legal effects without human involvement, and we do not use it for profiling for advertising purposes.
05 Sharing with captains
The service only works if a limited amount of information is exchanged between you and the captain assigned to your trip. We share the minimum necessary at each stage.
| Stage | Shown to captains | Shown to you |
|---|---|---|
| Open request | Service type, general pickup and destination area, dates, item details, attached photos, requested budget | Offers received, offered price, captain rating, vehicle type |
| After the offer is accepted | Your first name, contact number, exact pickup and destination, trip notes | Captain name and photo, contact number, vehicle and plate details, live trip progress |
| After completion | Rating and review you leave | Invoice, trip summary, rating you leave for the captain |
Contact numbers are shared only for the duration required to complete the trip and must be used solely for that trip.
We may also disclose personal data:
- to competent authorities, courts, or regulators where disclosure is required by law or legal process;
- where reasonably necessary to protect the rights, property, or safety of users, the public, or Twsila, including fraud and abuse prevention;
- to professional advisers under confidentiality obligations; and
- in connection with a merger, acquisition, financing, or transfer of business assets, subject to equivalent protection of your data.
06 Service providers and processors
We use a small number of established providers to run the platform. They act on our instructions, receive only the data needed for their function, and are bound by contractual confidentiality and security obligations.
| Provider | Function | Data involved |
|---|---|---|
| Google Firebase | Phone-number authentication, one-time codes, push notifications, app infrastructure | Mobile number, notification token, device and app identifiers |
| Google Maps Platform | Maps, place search, geocoding, and route calculation | Location coordinates, entered addresses, search terms, IP address |
| Moyasar | Payment processing for trip fares | Payment credentials entered by you, amount, transaction result |
| Cloud hosting provider (AWS) | Hosting of application servers, databases, and file storage | All service data described in this policy |
| ip-api.com | Country lookup at first launch to preselect country and language | IP address |
| SMS and telecom providers | Delivery of verification codes and service messages | Mobile number, message content |
Each provider processes data under its own privacy terms in addition to our instructions. Providers are reviewed before onboarding and are not permitted to use the data for their own purposes.
07 Payments
Payments for trip fares are processed by our payment gateway, Moyasar. Card and payment credentials are entered within the gateway's secure interface and are transmitted directly to it.
Twsila receives and stores only:
- the amount, currency, and the trip the payment relates to;
- the payment method type and, where provided, a masked reference such as the last digits of a card;
- the transaction identifier and the authorisation, capture, or refund result; and
- invoice records generated for you.
Twsila does not store full card numbers, expiry data, or security codes. Payment records are retained as required by applicable tax and commercial regulations.
08 Data retention
We keep personal data only for as long as it is needed for the purposes described in this policy, and then delete or anonymise it. The following periods are indicative; the actual period depends on the category of data and any legal requirement that applies to it.
| Data | Retention |
|---|---|
| Account and profile data | While the account is active, and for a limited period after closure to handle disputes and prevent re-registration abuse |
| Trip and request records | For the period required for dispute resolution, safety, and financial reporting |
| Payment and invoice records | For the period required by applicable tax and commercial regulations |
| Photos attached to a request | For the trip lifecycle and any related dispute period |
| Precise location traces | For the trip and a limited period afterwards for safety and dispute purposes |
| Support correspondence | For a limited period after the issue is resolved |
| Technical and diagnostic logs | Short retention, typically weeks to months |
09 Account and data deletion
How to delete your account and personal data
Option 1: In the app. Open Profile, then choose the delete-account option and confirm.
Option 2: By email. Send a request to info@twsila.tech with the subject "Account Deletion Request", stating that the request relates to the Twsila Passenger application and the mobile number registered to the account.
We verify that the request comes from the account holder before acting on it, and confirm the outcome to you. Requests are normally completed within 30 days.
What is deleted
Your profile, contact details, saved addresses, uploaded photos, device tokens, and preferences are deleted or irreversibly anonymised.
What may be retained
A limited set of records is retained where the law requires it or where we have an overriding legitimate interest, specifically: financial and invoice records needed for tax and accounting purposes; records of a dispute, safety incident, or fraud investigation until it is concluded; and minimal data needed to enforce a suspension. Retained records are separated from your profile and are not used to contact you.
10 Your rights
Subject to the Personal Data Protection Law of the Kingdom of Saudi Arabia and any other law that applies to you, you have the right to:
- be informed of the legal basis and purpose for collecting your personal data;
- access your personal data and request a copy in a readable format;
- request correction of data that is inaccurate, incomplete, or out of date;
- request deletion of data that is no longer necessary for the purpose it was collected for;
- withdraw consent where processing is based on consent, including by revoking a device permission;
- object to or restrict processing that relies on our legitimate interests; and
- complain to the competent supervisory authority.
To exercise a right, email info@twsila.tech. We may ask for information needed to verify your identity so that we do not disclose data to the wrong person. We respond within the period required by applicable law, normally within 30 days, and we do not charge a fee for a reasonable request.
11 Security
We apply administrative, technical, and physical safeguards proportionate to the sensitivity of the data, including encryption in transit, access control on the principle of least privilege, network and application isolation, credential management, logging and monitoring, and review of providers before they are engaged. Payment credentials are handled by our payment gateway rather than by Twsila.
No system can be guaranteed to be completely secure. If a personal data breach occurs that is likely to cause you harm, we will notify you and the competent authority as required by applicable law. Please keep your device and verification codes protected, and contact us immediately if you believe your account has been accessed without authorisation.
12 International transfers
Our infrastructure and service providers may process personal data outside the Kingdom of Saudi Arabia, including in regions operated by our cloud hosting provider and by Google. Where personal data is transferred outside the Kingdom, we transfer it only for the purposes described in this policy and rely on the conditions and safeguards permitted under the Personal Data Protection Law and its implementing regulations, including contractual protections with the receiving party.
13 Contact us
For any question about this policy, or to exercise a privacy right, use the details below.
- Entity
- Twsila
- Privacy email
- info@twsila.tech
- Phone
- +966 53 735 0413
- Location
- Kingdom of Saudi Arabia
For account deletion, please follow the process in section 9 so that we can verify and action the request without delay.