Privacy Policy

Last updated: March 2026

CRITICAL DISCLAIMER: Fattourah is an independent third-party SaaS tool. It is NOT affiliated with, endorsed by, or certified by ZATCA (Zakat, Tax and Customs Authority).

Table of Contents

1. Overview

Fattourah ("we," "us," "our," or "Company") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services, including during your 14-day free trial and paid subscription plans (Starter $19/month, Pro $39/month).

Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our services.

2. Data We Collect

2.1 Business Information

When you create an account, we collect:

2.2 Invoice Data

Your invoices and related financial records uploaded to or generated within Fattourah, including:

2.3 ZATCA Integration Credentials

For invoice submission to ZATCA, we collect and securely store:

2.4 Usage Data

We automatically collect:

2.5 Payment Information

Payment processing is handled by Moyasar (Saudi payment gateway). We do not store full credit card details; Moyasar securely handles all payment information.

3. How We Use Your Data

4. Third-Party Services

4.1 Moyasar (Payment Processing)

We use Moyasar for all payment processing. Moyasar is PCI-DSS Level 1 certified and handles all credit card and payment data securely. Moyasar may store tokenized payment methods for subscription renewals. Note: Mada cards have limitations with auto-renewal subscriptions and may require manual intervention for monthly billing.

Moyasar Privacy Policy

4.2 ZATCA API

To submit invoices, we transmit invoice data to the Saudi ZATCA API in compliance with Phase 3 Wave 24 requirements. This data is transmitted via encrypted connections and includes your business TIN and invoice details.

ZATCA Official Website

4.3 Plausible Analytics

We use Plausible for privacy-respecting website analytics. Plausible does not use cookies, does not track across websites, and does not collect personal data. It only collects aggregated, anonymized usage patterns.

Plausible Privacy Policy

4.4 Cloudflare CDN

Our website is delivered via Cloudflare's content delivery network for performance and security. Cloudflare may log IP addresses and request metadata.

Cloudflare Privacy Policy

4.5 Supabase (Database & Hosting)

We use Supabase for secure database hosting, backup, and infrastructure. Your data is encrypted at rest on Supabase servers.

Supabase Privacy Policy

5. Data Security & Storage

While we implement industry-standard security measures, no system is completely immune to security breaches. We cannot guarantee absolute security of your data.

6. Data Retention

7. Financial Data & PCI-DSS Compliance

We take the security of payment information extremely seriously:

8. Your Rights

You have the right to:

To exercise any of these rights, contact us at support@fattourh.com with your request. We will respond within 30 days.

9. Cookie Policy

Most browsers allow you to control cookies through settings. Disabling essential cookies may affect your ability to use Fattourah.

10. Saudi Arabia Compliance

Fattourah operates in accordance with Saudi Arabia's regulatory frameworks:

11. Contact Us

If you have questions about this Privacy Policy or our privacy practices:

Fattourah

Company: TrustDraft

Location: Dammam, Saudi Arabia

Email: support@fattourh.com

Website: https://fattourh.com

This Privacy Policy is effective as of March 2026 and may be updated periodically. We will notify you of material changes by updating this page and sending an email notification.