Skip to content
VVoM Flow
عربيEN
Sign in

Privacy Notice

Last updated 11 October 2026

Contents

  1. 1Who is responsible for your data
  2. 2The data that is handled
  3. 3Why it is handled
  4. 4Who receives it
  5. 5How long it is kept
  6. 6How it is protected
  7. 7Your choices and requests
  8. 8Changes to this notice

How personal data is handled on the VoM Flow website and platform, operated by شركة اعملها بنفسك لتقنية نظم المعلومات.

About this notice

VoM Flow is a platform that businesses use to take bookings and payments and to issue tax invoices. This notice explains what personal data passes through the website and the platform, why, who is responsible for it, and what you can ask for. It is read together with the terms and conditions.

1Who is responsible for your data

1.1

Who is responsible depends on how you meet the platform:

1.1.1

If you are the customer of a business that uses the platform, that business is the Controller of your personal data. It decides why your data is collected and what is done with it, and its own privacy notice applies to you. VoM Flow handles that data as a Processor, on the business’s behalf and on its lawful instructions.

1.1.2

If you visit this website, send us an enquiry, or hold an account that runs a business on the platform, VoM Flow is the Controller of the personal data described in this notice for those purposes.

1.2

These roles are the ones set out in article (8) of the terms and conditions, under the Personal Data Protection Law issued by Royal Decree No. (M/19), its amendments and its Implementing Regulations.

2The data that is handled

2.1

When you book with a business: your name and mobile number, your email address where you give one, the bookings you make, the payments recorded against them and the invoices issued for them, the language you read in, whether you have agreed to receive marketing messages, and anything further the business records about you.

2.2

When you sign in as a customer: a one-time verification code is sent to your mobile number by text message. The code is not kept in a readable form.

2.3

When you run a business on the platform: your name, email address and mobile number, and a password, which is stored only as a hash; or, if you sign in with Google, the name and email address of your Google account. To activate online payments, the business also provides the commercial registration, tax and national address details, the identity of its authorised representative and its bank details.

2.4

When a payment is made online: card details are entered on the payment service provider’s own pages. VoM Flow does not hold card numbers. It keeps the record of the payment: the amount, the method, the status and the provider’s reference.

2.5

When you send us an enquiry: the name, business name, email address, mobile number and message you send, and the internet address (IP) the enquiry was sent from.

2.6

When you browse: cookies that keep you signed in, protect forms from misuse, and remember your language, your light or dark display preference and, on the sign-in page, the address of the business you last signed in to. Where analytics is switched on, Google Analytics records which pages are visited.

3Why it is handled

3.1

Personal data is handled for these purposes and no others:

3.1.1

To provide the service a business has asked for: taking and managing bookings, sending booking confirmations, reminders and verification codes, taking payment, and issuing the invoice.

3.1.2

To meet a legal requirement: tax invoices are issued and reported to the Zakat, Tax and Customs Authority as the law requires.

3.1.3

To answer enquiries and requests for support.

3.1.4

To keep the platform secure and working, including a record of who did what in a business’s account.

3.2

Messages: a business’s marketing messages are sent only to customers who have agreed to receive them. Messages about a booking itself, such as a confirmation, a reminder or a verification code, are sent whatever the marketing choice, because the booking cannot work without them.

3.3

What is not done: VoM Flow does not sell, lease or exploit the identifying personal data of a business’s customers for independent marketing or advertising, or to train general-purpose generative artificial intelligence models, without an express legal basis and the prior written consent of the data subjects and the Controller.

4Who receives it

4.1

The business you book with, whose staff see bookings and customer records according to the permissions the business gives them. Each business’s data is kept apart from every other business’s.

4.2

The service providers without which the service cannot be delivered, each receiving only what its part requires:

4.2.1

The licensed electronic payment service provider, which processes the payment and, for a business, the details needed to activate and pay out to its account.

4.2.2

The licensed telecommunications provider that delivers text messages, which receives the mobile number and the text of the message.

4.2.3

The Zakat, Tax and Customs Authority, which receives the tax invoices the law requires to be reported.

4.2.4

Google, where a business account signs in with Google, where a business shows its location on a map, and where analytics is switched on.

4.3

A competent authority, where a law or a binding order requires it.

5How long it is kept

5.1

A business’s data is kept while its account is open. When the agreement ends, the business has thirty (30) calendar days to export its booking and customer data, after which the account’s data and records may be permanently deleted, as article (14) of the terms and conditions provides.

5.2

A business can set how long the personal data of customers who are no longer active is kept, and can erase a customer’s personal data on request. Bookings and financial records, such as payments and tax invoices, are kept where the law requires them to be.

5.3

An enquiry is kept for as long as it takes to answer it and to follow it up.

6How it is protected

6.1

VoM Flow takes appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, disclosure or unauthorised access. Among them: each business’s data is separated from every other’s, passwords are stored as hashes, the credentials that connect a business to other services are encrypted, access inside a business follows the role each member of staff is given, and changes are recorded.

6.2

Should a significant leak or security breach occur, VoM Flow notifies the business concerned immediately upon becoming aware of it, in accordance with the periods and requirements of the Implementing Regulations of the Personal Data Protection Law.

7Your choices and requests

7.1

If you are a business’s customer, ask that business. As the Controller it answers requests about your data, and the platform lets it give you a copy of the data it holds about you and erase your personal data.

7.2

You can stop a business’s marketing messages at any time, from your own bookings page with that business or by telling the business. Messages about a booking itself will still reach you.

7.3

For data VoM Flow is the Controller of, write to us through the Contact page of this website.

8Changes to this notice

8.1

This notice is updated when the platform or the law changes, and the date at its head is the day its wording last changed. A material change is notified to businesses in the way the terms and conditions provide for amendments.

VVoM Flow

Online booking, payments and ZATCA invoices for anything sold by the hour.

Product

  • Features
  • Pricing
  • ZATCA e-invoicing

Company

  • About
  • Contact
  • Journal

Get started

  • Create your venue
  • Book a demo
  • Sign in

© 2026 VoM Flow. All rights reserved.

عربيEN
Terms and conditionsPrivacy noticeBack to the top
شركة اعملها بنفسك لتقنية نظم المعلومات