Privacy policy

Last Updated: September 2026

Taif Al Emarat Perfumes (“Taif Al Emarat”, “we”, “us”, or “our”) respects the privacy of our customers and is committed to protecting Personal Data in accordance with the laws and regulations applicable in the Kingdom of Saudi Arabia.

This Privacy Policy explains how we collect, use, process, disclose, store, transfer, retain, and protect Personal Data when you visit or purchase through our Saudi Arabia online store, create an account, communicate with us, participate in a promotion, visit our stores, or otherwise interact with our services.

Personal Data will be processed in accordance with the Saudi Personal Data Protection Law (“PDPL”), its Implementing Regulations, the Regulation on Personal Data Transfer Outside the Kingdom, and other applicable Saudi laws and regulations.

1. Who Is Responsible for Your Personal Data?

The entity operating the Taif Al Emarat Saudi Arabia online store is responsible for determining the purposes and methods of processing Personal Data in connection with the Saudi online store.

The Website should display the exact registered Saudi legal entity name, Commercial Registration number, registered address, and applicable contact details of the entity acting as the Data Controller.

2. Personal Data We Collect

Depending on how you interact with us, we may collect Personal Data including:

·         full name;

·         mobile number;

·         email address;

·         billing and delivery addresses;

·         National Address information where required for delivery;

·         customer-account information;

·         order and purchase history;

·         payment and transaction information;

·         refund information;

·         customer-service communications;

·         marketing preferences and consent records;

·         product reviews and feedback;

·         IP address;

·         browser and device information;

·         Website activity and interaction information;

·         cookie and similar technology identifiers;

·         fraud and security information; and

·         other information you voluntarily provide to us.

We seek to limit the Personal Data collected to what is appropriate and necessary for the relevant processing purpose.

3. How We Collect Personal Data

Personal Data may be collected:

·         directly from you when you place an order;

·         when you create or manage an account;

·         when you contact Customer Support;

·         when you subscribe to marketing communications;

·         when you participate in promotions, surveys, or campaigns;

·         when you submit a product review;

·         automatically when you interact with our Website, subject to applicable requirements;

·         through cookies and similar technologies;

·         from payment and delivery providers;

·         from technology, security, analytics, and marketing providers where lawfully permitted; and

·         from other lawful sources.

We will use appropriate and transparent methods of collection.

4. Why We Process Personal Data

We may process Personal Data for purposes including:

Order & Contract Management

To:

·         process orders;

·         verify transactions;

·         arrange payment;

·         arrange delivery;

·         provide order tracking;

·         process returns, exchanges, cancellations, and refunds; and

·         provide customer support.

Website & Account Management

To:

·         create and maintain customer accounts;

·         maintain Website functionality;

·         remember customer preferences;

·         improve Website performance and customer experience; and

·         troubleshoot technical problems.

Security & Fraud Prevention

To:

·         authenticate transactions;

·         identify suspicious activity;

·         prevent fraud;

·         protect customer accounts;

·         maintain cybersecurity; and

·         protect Taif Al Emarat’s legitimate legal rights.

Legal & Regulatory Compliance

To comply with applicable:

·         legal obligations;

·         regulatory requirements;

·         tax and accounting requirements;

·         lawful requests from competent authorities; and

·         dispute-resolution requirements.

Marketing

Where permitted under Saudi law and the required consent has been obtained, Personal Data may be used to provide information concerning:

·         new products;

·         promotions;

·         discounts;

·         campaigns;

·         events;

·         product recommendations; and

·         other Taif Al Emarat marketing communications.

5. Legal Basis for Processing

We process Personal Data only where an appropriate legal basis exists under applicable Saudi law.

Depending on the processing activity, this may include:

·         the Data Subject’s consent;

·         processing necessary to perform an agreement to which the Data Subject is a party;

·         processing required to comply with a legal obligation;

·         processing necessary to protect legitimate interests where permitted under the PDPL and where the applicable conditions are satisfied; or

·         another legal basis permitted under Saudi law.

Where processing relies on consent, customers may withdraw that consent in accordance with applicable law.

Withdrawal of consent does not affect processing lawfully carried out before withdrawal.

6. Marketing Communications

Taif Al Emarat will obtain the required consent before processing Personal Data for direct-marketing purposes where required by Saudi law.

Providing an email address or mobile number for the purpose of:

·         placing an order;

·         receiving an OTP;

·         processing payment;

·         arranging delivery; or

·         receiving customer service

does not automatically constitute consent to receive direct marketing communications.

Where consent has been provided, customers may receive marketing through channels such as:

·         email;

·         SMS;

·         WhatsApp; or

·         other permitted communication channels.

Every applicable direct-marketing process should provide an appropriate and easy method for withdrawing consent or opting out.

Withdrawal from marketing communications will not prevent necessary transactional communications concerning an order, payment, delivery, refund, security matter, or customer-service request.

7. Cookies & Similar Technologies

Our Website may use cookies and similar technologies for purposes including:

·         essential Website functionality;

·         maintaining shopping-cart functionality;

·         account authentication;

·         security;

·         remembering preferences;

·         analytics;

·         Website performance measurement;

·         advertising measurement; and

·         personalized advertising where lawfully permitted.

Where consent is required for a particular cookie or tracking technology, the applicable technology should not be activated until the required consent has been obtained.

Customers should be provided with appropriate controls to manage applicable cookie preferences.

8. Disclosure of Personal Data

Where necessary and legally permitted, we may disclose Personal Data to:

·         Taif Al Emarat group entities;

·         payment processors;

·         banks and financial institutions;

·         delivery and logistics providers;

·         Website and e-commerce technology providers;

·         cloud and hosting providers;

·         customer-support providers;

·         analytics providers;

·         marketing and advertising providers;

·         cybersecurity and fraud-prevention providers;

·         professional advisers, auditors, and insurers;

·         competent Saudi government, judicial, regulatory, or law-enforcement authorities where legally required; and

·         an acquiring or successor entity in connection with a lawful corporate transaction.

We do not disclose Personal Data for unrelated purposes without an appropriate legal basis.

Processors acting on our behalf should be subject to appropriate contractual and data-protection obligations.

9. International Transfers of Personal Data

Some Taif Al Emarat group entities, technology platforms, service providers, or other authorized recipients may operate outside the Kingdom of Saudi Arabia.

Where Personal Data is transferred or disclosed outside Saudi Arabia, Taif Al Emarat will comply with the PDPL and the Regulation on Personal Data Transfer Outside the Kingdom.

Where applicable, this may require:

·         confirming an appropriate level of protection;

·         limiting transferred Personal Data to what is necessary;

·         implementing appropriate safeguards;

·         using approved Standard Contractual Clauses or other legally recognized safeguards where required;

·         carrying out an applicable transfer risk assessment; and

·         satisfying any other requirements imposed by the competent Saudi authority.

Personal Data will not be transferred internationally merely on the basis of a general statement that use of the Website constitutes unrestricted consent to international transfer.

10. Data Security

We implement appropriate organizational, administrative, and technical measures designed to protect Personal Data against:

·         unauthorized access;

·         unauthorized disclosure;

·         alteration;

·         misuse;

·         unlawful processing;

·         accidental loss; and

·         destruction.

Measures may include, where appropriate:

·         access controls;

·         authentication;

·         encryption;

·         security monitoring;

·         system controls;

·         staff-access restrictions; and

·         appropriate contractual controls with service providers.

No electronic system can be guaranteed to be completely secure.

11. Personal Data Breaches

Where a Personal Data breach occurs, Taif Al Emarat will assess and respond to the incident in accordance with applicable Saudi PDPL requirements.

Where notification to the competent authority and/or affected Data Subjects is legally required, the applicable notification procedures will be followed.

12. Data Retention

Personal Data will be retained only for as long as necessary to fulfil the purposes for which it was collected and to satisfy applicable legal, contractual, accounting, tax, security, fraud-prevention, and dispute-resolution requirements.

Once Personal Data is no longer required and no lawful retention requirement applies, it will be securely destroyed, deleted, or otherwise handled in accordance with applicable Saudi requirements.

13. Your Rights

Subject to the conditions and exceptions provided by the Saudi PDPL, Data Subjects have rights relating to their Personal Data.

These may include the right to:

·         be informed about the processing of Personal Data;

·         access Personal Data;

·         obtain Personal Data in a readable and clear format where applicable;

·         request correction, completion, or updating of Personal Data;

·         request destruction of Personal Data where applicable;

·         withdraw consent where processing is based on consent; and

·         exercise other rights provided under applicable Saudi law.

Requests may be subject to applicable legal conditions, restrictions, or exceptions.

14. Exercising Your Rights

To submit a Personal Data request, please contact us using the contact details provided below.

We may request reasonable information necessary to verify the identity of the person making the request and to protect Personal Data against unauthorized disclosure.

Requests will be handled within the periods and according to the procedures required by applicable Saudi law.

15. Children’s Personal Data

Our online store is intended for customers legally capable of completing the relevant transaction or persons acting with appropriate parent or guardian involvement where required.

Where Personal Data relating to a child or another person lacking full legal capacity is processed, applicable Saudi legal requirements will be followed.

16. Customer Service Communications

Customer-service communications may be retained where necessary for:

·         handling customer requests;

·         dispute resolution;

·         service quality;

·         security;

·         fraud prevention;

·         staff training; and

·         legal or regulatory compliance.

Where communications are recorded, applicable notification and legal requirements will be followed.

17. Product Reviews & User Content

Where customers voluntarily submit reviews, ratings, questions, photographs, or other content for public display, some information may become publicly visible.

Customers should avoid including unnecessary Personal Data or sensitive information in publicly accessible reviews.

18. Third-Party Services

Our Website may integrate third-party services such as payment providers, delivery services, social-media platforms, analytics services, or other technology providers.

Where a customer interacts directly with an independent third-party service, that provider may process Personal Data under its own privacy policy and legal obligations.

19. Complaints

If you believe that your Personal Data has been processed in violation of applicable Saudi data-protection requirements, please contact us first so that we can review the matter.

You also retain any right available under applicable Saudi law to submit a complaint to the competent authority.

20. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our:

·         processing activities;

·         services;

·         technologies;

·         business operations; or

·         applicable laws and regulations.

The updated version will be published on the Website together with the revised “Last Updated” date.

Where additional notification or consent is legally required, the applicable requirements will be followed.

21. Contact Us

For privacy-related questions, requests, or complaints:

Taif Al Emarat – Saudi Arabia

WhatsApp: +966 55 165 1605
Customer Support Hotline: +971 800 8243

The Website should also identify the exact Saudi legal entity acting as the Data Controller, together with the applicable registered contact details.