ArkhasArkhas

Privacy Policy

Last updated: 27 August 2026

Arkhas is committed to protecting your privacy in accordance with the Communication and Information Technology Regulatory Authority (CITRA) Resolution No. 42/2021 concerning the Data Privacy Protection Regulation, its applicable updates, and related Kuwaiti legislation. In case of any discrepancy, the Arabic version prevails.

1. Data We Collect

Technical data — collected: IP address (stored hashed/encrypted, never in its original form), device and browser type, country, pages visited, visit time, referral source. Purpose: operating the platform, performance analysis, protection against abusive use. Preference data — collected: language, dark/light mode, and search queries (statistically, to improve search results). Purpose: improving your experience. We never collect or ask you for: payment card data, bank account numbers, civil ID, or passwords. All payments happen at the retailer, not on our platform.

2. Processing Basis and Consent

We obtain your explicit consent before collecting any personal data not necessary for operating the platform. If you are under eighteen, guardian consent is required.

3. Your Rights

— Access: request a copy of the data we hold about you. — Correction: request correction of any inaccurate data. — Deletion: request deletion of your data. — Withdrawal of consent: at any time, by a simple step — contacting us. — Objection: to any processing of your data. To exercise any of these rights, contact [email protected]. We commit to responding within 30 days.

4. Cookies and measurement

We use essential cookies to operate the platform and save your preferences, and measurement cookies to understand how the platform is used and improve it. You can control them from your browser settings; disabling essential cookies may affect some features. Our own measurement uses two first-party cookies. Neither contains your name, email, IP address or any other personal detail, and neither can be read by any other website: — A session cookie holding a random identifier, which expires after 30 minutes of inactivity. — A cookie kept for up to 180 days holding a random visitor identifier and the source that first brought you here, so we can tell returning visitors from new ones. We record the page you arrived on, the website that referred you, and campaign tags in the link you followed. We deliberately do NOT store the rest of the web address you arrived with, and we never place anything you type into our search box into these records. We do not store your IP address; where we need to tell visits apart we use an irreversible code derived from it. We also use Google Analytics and Google Ads, which set their own cookies and may be used for advertising measurement and audiences. Any web address we send to Google has your search terms removed first. Measurement records are kept for up to 90 days and then deleted or reduced to daily totals.

5. Data Sharing

We do not sell your personal data to anyone. We may share it only in the following cases: — With technical service providers working on our behalf (hosting, content delivery network, analytics), and only to the extent necessary. — Where there is a legal obligation or an official request from a competent authority in the State of Kuwait. Any data used for statistical or analytical purposes is processed in aggregated, anonymised form from which no individual can be identified.

6. Retention

Technical visit logs: 90 days, after which they are deleted or converted into aggregated statistics that identify no individual.

7. Data Transfer Outside Kuwait

The platform's servers are hosted with a hosting provider in the Federal Republic of Germany (European Union), and site traffic passes through Cloudflare's global network for protection and faster browsing. Data in this environment is subject to strict data-protection frameworks — including the EU General Data Protection Regulation (GDPR) — providing an adequate level of personal data protection consistent with CITRA regulation requirements. As a reminder, what is stored is limited to begin with: IP addresses are only kept hashed, and we collect no payment or identity data.

8. Data Security

We apply reasonable technical and organisational measures to protect your data, including encryption in transit (HTTPS), IP address hashing, and restricted internal access. In the event of a breach affecting personal data, we commit to notifying the competent regulatory authority within 72 hours in accordance with applicable requirements, and to notifying affected individuals where appropriate.

9. Policy Changes

We may update this policy; the date of the last update is published at the top of this page. For material changes we will endeavour to notify you in advance.

10. Privacy Contact

For any inquiry or complaint regarding your data privacy: [email protected]