Privacy Policy
Last updated: 13 August 2026
This policy explains what personal data BeautyPick (“the platform”, “we”) collects, why we collect it, who processes it on our behalf, and the rights you hold under the Saudi Personal Data Protection Law (PDPL).
1. Data we collect
Only what the platform needs to run:
- Account data: email or mobile number, a hashed password (the password itself is never stored), account status and last sign-in time.
- Profile: nickname, username, avatar, bio, and the gender, birth year, country and city you choose to provide.
- Beauty profile: skin type, hair type and interests — used to match you to relevant products and campaigns. Entirely optional.
- Activity: reviews, posts, comments, likes, picks, campaign applications and submitted content.
- Social accounts: the handle and follower count of any account you connect, used to establish eligibility for campaigns.
- Wallet and payments: reward balance, transaction ledger and payout requests. We never store card details — payment data goes directly to the payment provider.
- Technical data: device tokens if you enable notifications, plus IP address and request logs for security and abuse prevention.
2. Why we process it, and on what basis
- Performance of a contract: creating your account, running campaigns and applications, calculating and paying rewards, and operating the community and reviews.
- Legitimate interest: preventing fraud, fake accounts and misleading reviews, protecting platform security, and improving the service through aggregate statistics.
- Consent: marketing notifications, the beauty profile, and connecting social accounts. You can withdraw consent at any time in settings; doing so does not affect processing carried out beforehand.
- Legal obligation: retaining financial and tax records as required by law.
We do not make solely automated decisions with legal effect on you, and we do not sell your personal data to anyone.
3. Third-party processors
These providers process data on our behalf and only on our instructions:
- Database hosting and file storage (images, certificates, submitted content).
- A cache used for sessions and rate limiting.
- An email provider for verification, password reset and invitation messages.
- A push notification provider, where notifications are enabled.
- An SMS provider for one-time codes, where enabled.
- A payment gateway, where payments are enabled — card data is submitted directly to the gateway and never passes through our servers.
4. Transfers outside the Kingdom
Some data may be processed by providers located outside Saudi Arabia. Where that happens we contract for appropriate safeguards, and we are working towards hosting core workloads in regional data centres in line with local data residency expectations.
5. Retention
- Account data: for as long as your account is active.
- After account deletion: sessions are revoked immediately and personal data is deleted or anonymised, except where the law requires us to keep it.
- Financial records: for the period accounting and tax rules require.
- Security and audit logs: for a limited period sufficient to investigate incidents.
6. Your rights
Under the PDPL you have the right to:
- Be informed about how your data is processed — which is what this page is for.
- Access your data and obtain a copy of it.
- Correct anything inaccurate — directly, from your profile page.
- Delete your data — from account settings, unless we are legally required to retain it.
- Withdraw consent, and object to processing based on legitimate interest.
We respond within the statutory period, and you may lodge a complaint with the competent data protection authority in the Kingdom.
7. Cookies and local storage
We use your browser's local storage to keep you signed in and to remember your language. These are necessary for the service to work and are not used for cross-site advertising.
8. Children
The platform is not directed at anyone under 18. If we learn that a minor has registered without guardian consent, we close the account and delete the associated data.
9. Security
Passwords are hashed with a modern algorithm, connections are encrypted, access is restricted by role, request rates are limited, and sensitive administrative actions are written to an audit log. No system is perfectly secure; if an incident affects your personal data we will notify the competent authority and affected individuals as the law requires.
10. Changes to this policy
If we make a material change we will update the date above and notify you in the app before the change takes effect.
11. Contact
For any question, or to exercise your rights, please contact us.