Privacy Policy

Last updated: 16 September 2026

This policy explains how Caffeine Kick (VAT number 311232653500003) collects, uses and protects your personal data when you use our branches, website or apps.

What we collect

  • Your mobile number, your name if you give it, and your email and address if you enter them when ordering on the website.
  • Your orders: items, amounts, branch, time, status and notes, plus your car make and plate number if you choose drive-thru pickup.
  • Your rewards points, tier and points history, and your subscriptions and how you use them.
  • Notification tokens for your device or browser, including tokens for order updates on your Lock Screen, your language and app version, and a record of the notifications we send you.
  • What you send through the complaints form or when you contact us: name, mobile number, email, order number and the details you share.
  • Technical data such as IP address and device and browser type, to protect the service from abuse and keep it running.

We never collect your card details: they go directly to our payment gateway, and we keep only the payment reference and status.

How we use it

  • To prepare your order and keep you updated on it, including when it is ready.
  • To sign you in with a code sent to you on WhatsApp.
  • To add up your points and activate your subscriptions.
  • To issue electronic tax invoices and report them to the Zakat, Tax and Customs Authority (ZATCA), as the law requires.
  • To answer your questions and complaints.
  • To send offers and news, as described under "Notifications and offers".
  • To protect the service and prevent fraud and abuse.

We don't sell your data, use it for targeted advertising, or track you across other companies' apps and websites. Our website and app contain no third-party analytics or advertising tools.

Who we share it with

Each receives only what it needs to provide the service:

  • Our payment gateway, to process online payments.
  • Our WhatsApp Business messaging provider, to send sign-in codes, notifications and offers.
  • The notification services of your device or browser, to deliver notifications to you.
  • A cloud service provider, which may carry the mobile number you type on the in-store customer screen to the till.
  • The hosting providers our systems run on.
  • ZATCA and other authorities, when the law requires it.

Notifications and offers

  • Order updates reach you on WhatsApp, in your browser or in our app, depending on what you have allowed.
  • Offers only appear in app or browser notifications after you agree. Turn them on or off in our app: Account → Offers and news.
  • We may send offers to your number on WhatsApp. Ask us to stop and we will.
  • You can turn off all notifications in your device's or browser's settings.

How long we keep it

  • Account details: while your account exists, until you delete it.
  • Orders and invoices: as long as Saudi VAT law requires. They stay after an account is deleted, without your personal details.
  • Sign-in codes: expire after 10 minutes.
  • Sign-in sessions: end after 7 days without use on the website, or 90 days in the app.
  • Records of notifications we send: deleted after 30 days, or 90 days for notifications that could not be delivered.
  • Following an order without an account: its notifications stop once the order is finished.

Deleting your account

  • In our app: Account → Delete account.
  • Or message us from the mobile number on your account, and we will delete it.

Deleting your account erases your name, mobile number, email and address, stops notifications, signs you out on all your devices, and forfeits your points and active subscriptions. Orders and invoices are kept without your personal details, as the law requires. You can sign up again later with the same number as a new account.

Your rights

Under the Saudi Personal Data Protection Law, you can:

  • Find out what data we hold about you, and get a copy of it.
  • Have your data corrected or updated.
  • Ask us to delete your data.
  • Withdraw your consent to offers at any time.

To make a request, contact us using the details below.

How we protect it

  • The website and app talk to our servers over encrypted connections (HTTPS).
  • Sign-in session tokens are stored hashed, so they cannot be read back, and only authorised staff can access customer data.
  • We don't store card details.

Changes to this policy

We publish any change to this policy on this page and update the date at the top.

Contact us