Scope of this policy
This policy applies to the platform's public pages, the dashboard, the cashier app, and the online-store and table-ordering pages that subscribed businesses run through Loqma. It complements the terms of use.
Data we collect
- Account and team data: business name and contact details, user names, roles, and login credentials (passwords and PIN codes are stored hashed with modern algorithms).
- Operational data: menus, prices, orders, invoices, inventory, reports, and shift records.
- The business's customer data: what the business enters about its customers such as name, phone, addresses, and loyalty points, and what customers enter themselves when ordering from the business's store or table pages.
- Usage and device data: technical logs such as device type, browser, IP address, usage events, and errors, for security and product improvement.
Purposes of processing
- Operating the service: executing orders, issuing invoices, syncing branches and devices, and printing receipts.
- Regulatory compliance: issuing electronic invoices and submitting them to ZATCA, and retaining records for statutory periods.
- Security: authentication, permission enforcement, audit logging, and detecting unauthorized use.
- Product improvement: aggregate feature-usage analysis and error monitoring.
- Communication: service notices, updates, and technical support.
Processing roles: the business and Loqma
For restaurant and cafe customer data, the subscribed business is the data controller (it decides what is collected and why), and Loqma acts as a processor of that data under the business's instructions and this policy. The business is responsible for obtaining any consents required from its customers.
Analytics and error logs
We use analytics tooling (PostHog) to measure page usage and monitor technical errors so we can improve the product and its stability. We do not record user sessions or capture field contents in the dashboard, and events are linked to the user's identifier within the business for support and service quality.
Sharing data with third parties
We do not sell personal data. We share data only as needed to run the service, with providers contractually bound to protect it, including:
- Hosting and file-storage providers (for example, menu images and logos).
- Licensed payment gateways when electronic payment is activated.
- Delivery platforms when the business connects its channels to them.
- ZATCA's e-invoicing system.
- Any competent government authority where the law requires it.
Payments and card data
Card and digital-wallet payments are processed by the licensed payment gateway; Loqma does not store full card numbers on its systems. We keep only transaction references, statuses, and amounts for invoicing, settlement, and reporting.
Data retention
We retain data for the duration of the subscription and as needed to provide the service. After the subscription ends we allow the business a reasonable period to export its data, then delete or anonymize it, keeping what regulations require us to retain (such as tax records and invoices) for the prescribed statutory periods.
Information security
- Encryption in transit (HTTPS/TLS) and strong hashing for passwords and PIN codes.
- Fine-grained role-based permissions, with each business's data fully isolated from others.
- An audit log for sensitive operations inside the dashboard.
- Periodic backups and recovery plans.
Your rights
Under the PDPL you have the right to access your personal data and request its correction or deletion within legal limits, and to withdraw consent where processing is based on it. If you are a customer of a business that uses Loqma, direct your request to that business as the controller, and we will support it in fulfilling the request.
Cookies
We use essential cookies only: a language-preference cookie and session data for signing in. We do not use advertising cookies or cross-site tracking.
Changes to this policy
We may update this policy from time to time. The updated version will be published on this page with its last-updated date, and subscribers will be notified of material changes.
Contact
For any privacy question or request, email us at [email protected], reach support at [email protected], or contact us from inside the dashboard.