1. Introduction
At Kashy, we value your trust and are committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you use the Kashy app or any of our services.
This Policy applies to all Kashy users — both shoppers and partner merchants. By using the app, you consent to the data practices described in this document.
2. Data We Collect
2.1 Data You Provide Directly
Full name
Mobile phone number
Email address (optional)
General location (governorate / city)
2.2 Data We Collect Automatically
Date, time, and value of confirmed transactions
Partner stores where purchases were made
Cashback amounts earned
Device type and operating system
In-app usage data (pages visited, buttons tapped, session duration)
IP address and device identifier
2.3 Data We Never Collect
Bank card or bank account details
Direct financial transaction data between you and the merchant
Passwords in plain text
Real-time precise GPS location
3. How We Use Your Data
We use your data exclusively for the following purposes:
a) Core Service Operation
Recording your transactions and crediting cashback to your account
Verifying your identity and preventing fraud or duplicate accounts
Sending transaction confirmation notifications
b) Service Development and Improvement
Analysing usage patterns to improve the app experience
Developing new features based on user needs
Diagnosing technical issues and improving performance
c) Communication
Sending important service or policy updates
Responding to your enquiries and support requests
Sending promotional offers, with unsubscribe available at any time
d) Legal Compliance
Meeting regulatory requirements in the Sultanate of Oman
Responding to lawful requests from competent authorities
4. Data Sharing
We do not sell your personal data to any third party. We may share your data only in the following circumstances:
Partner Merchants: We share with the relevant merchant only the transaction data relating to them, such as purchase value, date, and cashback amount, for monthly settlement purposes.
Technical Service Providers: We may engage technical partners, such as cloud services and analytics providers, who are contractually bound to protect your data and use it for no other purpose.
Regulatory and Legal Authorities: When a lawful request is received from a competent governmental or judicial authority in the Sultanate of Oman.
Emergency Situations: Where necessary to protect against fraud or serious security threats.
In all cases, only the minimum necessary data is shared.
5. Data Storage and Security
Your data is stored on secure servers protected by SSL/TLS encryption.
We apply strict access controls — only employees whose roles require it can access your data.
We conduct regular security reviews of our systems and infrastructure.
We retain your data for the duration of your account's activity, and for five (5) years after closure for legal compliance purposes, after which it is securely deleted.
In the event of a security breach affecting your data, we commit to notifying you within 72 hours of discovery.
6. Cookies and Tracking Technologies
The Kashy app uses cookies and similar tracking technologies to:
Maintain your login session
Save your in-app preferences
Analyse usage and improve performance
You may configure your device settings to reject cookies, though this may affect some app functions.
7. Children's Privacy
Kashy's services are intended exclusively for adults aged 18 and above. We do not knowingly collect data from children under 18. If we become aware that a child has registered an account, we will delete their data immediately.
8. Your Rights
Under Oman's Personal Data Protection Law, you have the right to:
Right of Access — Request a copy of your personal data held by us
Right of Rectification — Correct any inaccurate or incomplete data
Right of Erasure — Request deletion of your data, subject to legal retention obligations
Right to Object — Object to processing of your data for marketing purposes
Right to Portability — Receive your data in a machine-readable format
Right to Withdraw Consent — Withdraw your consent to processing at any time
To exercise any of these rights, contact us at support@kashy.om. We will respond to your request within 30 business days.
9. International Data Transfers
Where technical operations require your data to be transferred outside the Sultanate of Oman, for example international cloud services, we ensure that the receiving country provides an equivalent level of protection, or we apply binding contractual safeguards.
10. Changes to This Privacy Policy
We may update this Policy from time to time to reflect changes in our services or legal requirements. We will notify you of any material changes via:
A prominent notice within the app
An email to your registered address
An update to the "Last Updated" date at the top of this document
Your continued use of the app following the publication of changes constitutes implied acceptance of the updated Policy.
11. Contact and Complaints
If you have any enquiry or complaint regarding this Policy or how we handle your personal data, please contact us:
Data Protection Officer — Kashy
Email: support@kashy.om
Phone: +968 94579998
Postal Address: Muscat, Sultanate of Oman
If you are not satisfied with our response, you have the right to lodge a complaint with the competent regulatory authority in the Sultanate of Oman.