Staffru
中文

隐私政策

最后更新:2026 年 9 月

中文译本即将提供。本页显示英文译本,仅供参考;具有法律约束力的是阿拉伯语版本。 阅读阿拉伯语版本

1. Introduction

This Privacy policy explains how Staffru collects, uses, shares, and protects personal data when you visit our website at staffru.com and when you use the Staffru platform. It is intended to align with the Kingdom of Saudi Arabia's Personal Data Protection Law (PDPL).

Staffru operates a marketplace connecting client and supplier companies. This policy covers data about visitors to our website, about the companies and users who use the platform, and about the workers whose details suppliers record on it.

Staffru ("we") is the controller responsible for the processing of the personal data described in this policy under the PDPL.

This policy is issued in Arabic, and the Arabic version is the legally binding version. Any version in another language is a translation provided for convenience.

2. Visiting our website

Our website at staffru.com has no forms. If you contact us, you write to [email protected] from your own email account. We keep that correspondence for as long as needed to reply to you and follow up.

We may use Cloudflare Web Analytics to understand how the website is used. It is a cookieless service that gives us aggregated visit statistics. It sets no cookie and stores no device identifier.

When you choose a language on the website, your browser remembers that choice in its local storage, not in a cookie. The choice stays on your device, and you can clear it at any time in your browser's settings.

The website is hosted on Cloudflare.

3. Data we collect

Company and account data: company identity such as name, legal name, commercial registration (CR) number, VAT number, address, and contact email and phone; and, for each user, name, email, phone, role, a hashed password, and last-login time.

Worker personal data (entered by supplier companies): worker name, Iqama/residency ID number, Iqama expiry, a scanned copy of the Iqama document, nationality, date of birth, phone number, and a link to a worker photo, where the supplier adds one.

Financial data: supplier bank details (bank name, account-holder name, IBAN, SWIFT); and uploaded financial documents including client settlement sheets, supplier tax invoices, bank-transfer payment proofs, and Staffru platform-fee invoices and their payment proofs.

Authentication and technical data: a login token stored in a secure, http-only cookie (Staffru does not use server-side sessions); a locale-preference cookie; and IP address and browser user-agent, which are recorded in Staffru's audit log for security-relevant actions such as email verification and contract signing.

Communications data: the content of messages exchanged between client and supplier users in a service order's chat, together with the identity of the sender, the time each message was sent, and read and delivery status.

Uploaded documents: files you upload for verification (e.g. CR copy, VAT certificate, activity license) and bulk-import spreadsheets, which may transiently contain worker personal data.

4. How we use your data

We use personal data to operate the marketplace (matching clients and suppliers), to create and record service orders and their signed contracts, to facilitate the monthly settlement and direct payment between a client and its supplier, to bill and collect Staffru's platform fee from suppliers, to secure the platform, and to comply with legal obligations.

Staffru does not calculate or process the amounts payable between a client and a supplier; it records the settlement and the resulting invoices.

5. Communications on the platform

Each service order includes a chat so that the client and the supplier working on that engagement can coordinate it. Staffru stores these messages as part of the record of the service order; they remain associated with that order after the engagement ends.

Staffru may access and review messages sent through the platform. We do this for purposes including operating and securing the platform, resolving disputes raised by either party, enforcing our Terms of service and platform policies, preventing fraud and circumvention of the platform, and protecting the safety and integrity of the platform and the people who use it.

The service-order chat is a business communication tool provided within a B2B platform. It is not a private or personal messaging service, and you should not expect communications you send through it to be inaccessible to Staffru as the operator of the platform. If a matter is genuinely private, or unrelated to the engagement, it does not belong in a service-order chat.

6. Monitoring for circumvention

Staffru may use automated and manual means to detect attempts to move a transaction, or contact between the parties, off the platform — for example the sharing of personal contact details, or a solicitation to deal outside Staffru. Where something is detected, it may be reviewed by our team, recorded, and acted on under our Terms of service.

This monitoring is limited to communications and activity on the platform, and is carried out for the purposes set out in the section above. We do not publish the specific methods used.

7. Contract signing, IP address, and signing evidence

When you sign a service-order contract, Staffru records the signer's identity, the signing date and time, and the IP address at signing. The contract PDF itself shows the signer's name, the company they signed for, and the date and time of signing, and is made available to both the client and the supplier on that service order.

Staffru also generates a signing-evidence certificate for each fully signed contract. That certificate records, for each signer, their identity and the email address on their account, the date and time of signing, the IP address and browser used, the consent statement they accepted, a log of the signing events, and an integrity hash of the signed document. The IP address and browser are recorded here rather than on the contract itself. Like the contract, this certificate is available to both parties on the service order. This is standard proof-of-signing evidence and is what makes a signature on the platform defensible.

Sign only if you are comfortable with all of the above being recorded and shared with the other party to the contract.

8. How we share data

Between matched parties: worker and service-order data is shared between the client and the supplier matched on a given engagement, for the purpose of that engagement. The client sees the details of the workers assigned to it that it needs to receive and manage them: name, nationality, date of birth, phone number, Iqama number and expiry date, and the worker photo link. When the client pays the supplier, it also sees the supplier's bank details (bank name, account-holder name, IBAN and SWIFT code) so that it can pay the supplier directly.

Service providers: we use third-party providers to run the website and the platform. Cloudflare hosts the website, provides the website analytics described in section 2, and stores uploaded files through Cloudflare R2. Resend delivers our transactional emails. Google Maps provides the work-site maps described below. These providers process data on our behalf.

Maps: where a page shows a map of a work site, the map image is requested from Google Maps. That request discloses the site's coordinates and your browser's IP address to Google. Maps are shown only on pages that display a site location.

Legal: we may disclose data where required by law or to protect the rights, safety, and security of Staffru, our users, or the public. Staffru does not sell personal data.

9. Where your data is stored

Our service providers may store or process personal data outside the Kingdom of Saudi Arabia. We choose providers that protect data appropriately, and we handle any transfer of personal data outside the Kingdom in line with the PDPL and its implementing regulations. If this changes, we will update this policy.

10. Cookies and browser storage

Staffru uses only functional cookies on this platform: a secure, http-only authentication cookie that keeps you signed in, and a cookie that remembers your language preference. This platform uses no advertising or third-party tracking cookies, and runs no analytics, product-tracking or session-replay SDKs. Our public marketing website at staffru.com uses a cookieless visitor-analytics service, which sets no cookie and stores no device identifier.

The platform also uses your browser's local storage and session storage for functional settings only, for example to remember a collapsed sidebar, your chat sound preference, or an upload in progress. Nothing stored there is used for tracking. On the website, local storage holds only your chosen language, as described in section 2.

Location: the platform never collects your location in the background. Where you add a work site, you may choose to use your device's location to position it; your browser asks your permission first, and declining does not prevent you from entering the address yourself.

11. Data retention

We keep personal data only for as long as it is needed for the purposes described in this policy:

Account and company data: we keep it while the account is active.

Contracts, signing evidence, settlements, invoices and fee records: we keep them for the period required by Saudi tax and commercial regulations, and as needed to protect the rights of the parties. These records are not deleted on request.

Security and audit records: we keep them to protect the platform and to meet our legal obligations.

Website correspondence: we keep emails sent to us for as long as needed to handle the enquiry.

12. Security

We use technical and organizational measures to protect personal data, including hashing of passwords, secure http-only authentication cookies, access controls scoped to your company, and encrypted-in-transit uploads to cloud storage. No system is perfectly secure, but we work to protect your data.

13. Your rights under the PDPL

Subject to the PDPL, you have the right to be informed of how we collect and use your personal data, to request access to it and a copy of it in a clear format, to request that it be corrected, completed or updated, and to request its destruction once it is no longer needed.

To exercise these rights, email [email protected]. We may verify your identity before acting on a request, and we respond within the period required by the PDPL.

Deletion is handled on request; there is no self-service deletion option. Contracts, signing evidence, settlements, invoices and fee records are kept even after a deletion request, for the reasons given in section 11, and we will explain this when we respond.

Because much of the worker data on the platform is controlled by supplier companies, we may direct certain requests to the relevant company.

You also have the right to lodge a complaint with the competent authority responsible for overseeing the PDPL.

14. Children

The website and the platform are intended for businesses. They are not intended for anyone under the age of 18.

15. Changes to this policy

We may update this Privacy policy from time to time. We will notify users of material changes through the platform or by email before those changes take effect, and the date at the top of this page shows when the latest version was published.

16. Contact

For privacy questions or to make a data request, contact Staffru's privacy team at [email protected].