١. من نحن
تطبيق KF Pay (حزمة com.kfpay.app) تُشغّله شركة بالم باي ومقرها الرياض، المملكة العربية السعودية، وهي المتحكّم في البيانات الشخصية الموضّحة في هذه السياسة.
توضّح هذه السياسة ما نجمعه، ولماذا، ومع من نشاركه، وكم نحتفظ به، وما هي حقوقك.
للتواصل بشأن الخصوصية: support@kfpaysa.com
٢. حقيقة مهمة عن بصمة الكف
تطبيق KF Pay لا يصوّر كفّك ولا يمسحه.
التطبيق لا يطلب إذن الكاميرا ولا يحتوي على أي شاشة لالتقاط الكف. يتم مسح الكف وتسجيله حصريًا على جهاز الدفع لدى التاجر.
ما يفعله التطبيق تجاه الكف هو أمران فقط:
- يعرض حالة تسجيل كفّك (مسجَّل / غير مسجَّل) — قيمة نعم أو لا.
- يستقبل إشعارًا بنتيجة عملية تمّت على جهاز التاجر.
ولا يُخزَّن أي صورة للكف إطلاقًا — لا على جهازك، ولا على خوادمنا، ولا في أي مكان. جهاز التاجر يحوّل الكف إلى متجه رقمي من ٥١٢ رقمًا لا يمكن عكسه لإعادة بناء صورة، وهذا المتجه وحده هو ما يُرسَل ويُخزَّن.
٣. البيانات التي نجمعها
| النوع | البيانات | الغرض |
| الحساب | رقم الجوال (المعرّف الأساسي)، كلمة المرور (مخزّنة كبصمة مشفّرة لا كنص)، الاسم الأول والأخير (اختياري)، البريد الإلكتروني (اختياري) | إنشاء الحساب وتسجيل الدخول |
| القياسات الحيوية | قالب رقمي للكف (٥١٢ رقمًا)، نوع اليد، الرقم التسلسلي للجهاز الذي سجّل، درجة الجودة | التعرّف عليك عند الدفع |
| المالية | الرصيد، المعاملات، الطلبات وتفاصيلها، عمليات الشحن، التحويلات | تشغيل المحفظة وسجل العمليات |
| سجل العمليات | وقت كل مسح، الجهاز والتاجر، درجة المطابقة، هل نجحت | الأمان، كشف الاحتيال، حلّ النزاعات |
| التقني | رمز الإشعارات (FCM)، نظام التشغيل (أندرويد/iOS)، إصدار التطبيق، عنوان IP في سجلات الأخطاء | الإشعارات، التوافق، الأمان |
| رموز التحقق | رمز OTP مؤقت (صلاحيته ٥ دقائق) | التحقق من رقمك |
ما لا نجمعه إطلاقًا: الموقع الجغرافي، جهات الاتصال، الصور، الملفات، معرّف الإعلانات، IMEI، أو أي معرّف تتبّع. ولا نستخدم أي أدوات تتبّع أو تحليلات أو إعلانات — لا Google Analytics ولا Crashlytics ولا أي منها.
٤. الأساس النظامي للمعالجة
- تنفيذ العقد — تشغيل محفظتك ومعالجة مدفوعاتك.
- موافقتك الصريحة — تسجيل قالب الكف. تُعطى عند التسجيل على جهاز التاجر، ويمكنك سحبها بحذف حسابك.
- المصلحة المشروعة — منع الاحتيال وحماية الحسابات.
- الالتزام النظامي — حفظ السجلات المالية وفق الأنظمة السارية في المملكة.
٥. مع من نشارك بياناتك
لا نبيع بياناتك ولا نؤجّرها لأي جهة. نشاركها فقط مع ثلاث جهات، ولكلٍّ غرض محدّد:
| الجهة | ما يصلها | الغرض |
4jawaly (مزوّد رسائل — السعودية) | رقم جوالك ونص الرسالة. رسالة تأكيد التحويل تتضمّن اسم المستفيد والمبلغ. | إرسال رموز التحقق ورسائل التحويل |
Google Firebase (الإشعارات — FCM) | رمز الإشعار الخاص بجهازك، ومحتوى الإشعار (المبلغ، الرصيد الجديد، مرجع العملية، اسم التاجر). رقم جوالك لا يُرسَل إلى Google. | إيصال الإشعارات الفورية |
مصرف الراجحي (بوابة الدفع) | المبلغ ومرجع العملية وعنوان IP الخاص بك. لا يُرسَل اسمك ولا جوالك ولا بريدك. | شحن الرصيد بالبطاقة |
بيانات بطاقتك لا تمرّ علينا أبدًا.
عند الشحن بالبطاقة تُدخل رقمها ورمزها في صفحة المصرف نفسه. نحن لا نرى رقم البطاقة ولا نخزّنه.
وقد نُفصح عن البيانات إذا طلبتها جهة مختصّة وفق الأنظمة السارية في المملكة.
ملاحظة تقنية: يجلب التطبيق خطوط العرض من خدمة Google Fonts عند أول تشغيل، ما قد يكشف عنوان IP لجهازك لـGoogle.
٦. حماية بياناتك
- قالب الكف مشفّر بمعيار AES-256-GCM أثناء التخزين — وهو تشفير مُصادَق عليه. كل القوالب المخزّنة لدينا مشفّرة دون استثناء.
- الاتصال مشفّر — يتصل التطبيق بخوادمنا عبر HTTPS/TLS حصريًا، مع تثبيت الشهادات (Certificate Pinning) الذي يمنع اعتراض الاتصال. الاتصال غير المشفّر معطّل في التطبيق بالكامل.
- كلمات المرور تُخزّن كبصمات مشفّرة (hash) — لا نعرف كلمة مرورك ولا نستطيع استرجاعها.
- على جهازك تُحفظ بياناتك في المخزن المشفّر للنظام (EncryptedSharedPreferences في أندرويد، Keychain في iOS). كلمة مرورك لا تُحفظ على الجهاز إطلاقًا.
- وصول محدود — الوصول للبيانات مقصور على من يحتاجه لتشغيل الخدمة.
وبشفافية: التشفير على مستوى الحقل مطبَّق على قالب الكف. أمّا بيانات الحساب الأخرى (الجوال، الاسم، المعاملات) فتُخزَّن في قاعدة بيانات محمية بضوابط وصول وعزل الشبكة، دون تشفير على مستوى الحقل. ونعمل على توسيع نطاقه.
ولا يوجد نظام آمن بالمطلق؛ نبذل جهدًا معقولًا لكن لا نستطيع ضمان أمان مطلق.
٧. مدة الاحتفاظ
- قالب الكف — يُحفظ ما دام حسابك نشطًا، ويُحذف نهائيًا فور حذف الحساب.
- بيانات الحساب والمعاملات — تُحفظ طوال نشاط الحساب، ثم للمدة التي تقتضيها الأنظمة المالية السارية في المملكة.
- سجلات المسح والعمليات — تُحفظ لأغراض الأمان وحل النزاعات.
- رموز التحقق (OTP) — تُحذف خلال ٥ دقائق أو فور استخدامها.
- سجلات التشغيل — تتضمّن أرقام الجوال لأغراض التشخيص، وتُستبدل دوريًا عند بلوغ حدّ الحجم.
٨. حذف حسابك وبياناتك
يمكنك طلب الحذف بطريقتين:
ما يُحذف نهائيًا وفورًا:
- ✅ قالب بصمة الكف — يُمحى محوًا تامًّا من قاعدة البيانات.
- ✅ اسمك الأول والأخير وبريدك الإلكتروني.
- ✅ تعطيل سجل تسجيل الكف.
وما نحتفظ به بعد الحذف، وبصراحة تامّة:
- رقم جوالك — لمنع إعادة استخدام الرقم لحساب جديد ولحماية سجلّك.
- سجل معاملاتك المالية وسجلات العمليات — التزامًا بحفظ السجلات المالية.
- واقعة الحذف وتاريخها وسببها إن ذكرته.
وبعد الحذف لا يمكن إعادة تفعيل الحساب ولا التسجيل بالرقم نفسه مجددًا.
قبل الحذف: إن كان في محفظتك رصيد، تواصل معنا لاستردادها أولًا — فالحذف يُصفّر الرصيد.
٩. حقوقك
- الاطّلاع على بياناتك لدينا.
- التصحيح إن كانت غير دقيقة.
- الحذف وفق ما ورد في البند الثامن.
- سحب الموافقة على استخدام بصمة الكف.
- الاعتراض على معالجة معيّنة.
- تقديم شكوى للجهة الرقابية المختصّة في المملكة.
لممارسة أيٍّ منها: support@kfpaysa.com — ونستجيب خلال ٣٠ يومًا.
١٠. الأطفال
KF Pay خدمة مالية غير موجّهة لمن هم دون ١٨ عامًا، ولا نجمع بياناتهم عن قصد. ولا نجمع تاريخ الميلاد ولا نُجري تحققًا آليًا من العمر؛ لذا فالأهلية شرط تلتزم به عند التسجيل. وإن علمنا بحساب لقاصر، حذفناه وبياناته.
١١. نطاق الخدمة ونقل البيانات
تُقدَّم الخدمة في المملكة العربية السعودية وتُخزَّن البيانات على خوادم تُشغَّل لصالحنا. وقد تُعالَج بعض البيانات المحدودة خارج المملكة عبر مزوّدي الخدمة المذكورين في البند الخامس (مثل خدمة الإشعارات من Google)، وفق ضمانات تعاقدية مناسبة.
١٢. تحديث السياسة
قد نحدّث هذه السياسة، وسننشر النسخة المحدّثة على هذه الصفحة مع تغيير تاريخ السريان. والتغييرات الجوهرية نُشعرك بها داخل التطبيق.
تاريخ السريان: ٣٠ أغسطس ٢٠٢٦ · آخر تحديث: ٣٠ أغسطس ٢٠٢٦
1. Who We Are
KF Pay (package com.kfpay.app) is operated by Palm Pay Company, based in Riyadh, Saudi Arabia, which is the controller of the personal data described in this policy.
This policy explains what we collect, why, who we share it with, how long we keep it, and what your rights are.
Privacy contact: support@kfpaysa.com
2. An Important Fact About Palm Biometrics
The KF Pay app does not photograph or scan your palm.
The app requests no camera permission and contains no palm-capture screen. Palm scanning and enrolment happen exclusively on the merchant's payment terminal.
Regarding your palm, the app does only two things:
- Displays the status of your palm enrolment (registered / not registered) — a yes-or-no value.
- Receives a notification of the result of a transaction that occurred on the merchant terminal.
No palm image is ever stored — not on your device, not on our servers, nowhere. The merchant terminal converts your palm into a 512-number mathematical vector that cannot be reversed to reconstruct an image. That vector alone is what is transmitted and stored.
3. Data We Collect
| Category | Data | Purpose |
| Account | Mobile number (primary identifier), password (stored as a cryptographic hash, never as text), first and last name (optional), email (optional) | Account creation and sign-in |
| Biometric | Palm template (512 numbers), hand type, serial number of the enrolling terminal, quality score | Recognising you at payment |
| Financial | Balance, transactions, orders and their details, top-ups, transfers | Operating the wallet and transaction history |
| Activity logs | Time of each scan, terminal and merchant, match score, success or failure | Security, fraud detection, dispute resolution |
| Technical | Push notification token (FCM), platform (Android/iOS), app version, IP address in error logs | Notifications, compatibility, security |
| Verification codes | Temporary OTP (valid 5 minutes) | Verifying your number |
What we never collect: location, contacts, photos, files, advertising ID, IMEI, or any tracking identifier. We use no tracking, analytics or advertising tools whatsoever — no Google Analytics, no Crashlytics, none.
4. Legal Basis for Processing
- Performance of a contract — operating your wallet and processing payments.
- Your explicit consent — enrolment of your palm template. Given at the merchant terminal; withdrawable by deleting your account.
- Legitimate interest — fraud prevention and account protection.
- Legal obligation — retention of financial records under applicable Saudi regulations.
5. Who We Share Data With
We do not sell or rent your data to anyone. We share it with exactly three parties, each for a defined purpose:
| Recipient | What they receive | Purpose |
4jawaly (SMS provider — Saudi Arabia) | Your mobile number and the message text. Transfer confirmation messages include the beneficiary's name and the amount. | Sending verification codes and transfer messages |
Google Firebase (Cloud Messaging — FCM) | Your device's push token and the notification content (amount, new balance, transaction reference, merchant name). Your mobile number is not sent to Google. | Delivering instant notifications |
Al Rajhi Bank (payment gateway) | The amount, the transaction reference, and your IP address. Your name, phone and email are not sent. | Card top-ups |
Your card details never pass through us.
When topping up by card, you enter the card number and CVV on the bank's own page. We never see or store your card number.
We may also disclose data where required by a competent authority under applicable Saudi law.
Technical note: the app fetches display fonts from Google Fonts on first launch, which may expose your device's IP address to Google.
6. How We Protect Your Data
- Your palm template is encrypted at rest with AES-256-GCM authenticated encryption. Every stored template is encrypted, without exception.
- Transport is encrypted — the app connects to our servers exclusively over HTTPS/TLS with certificate pinning, which blocks interception. Cleartext traffic is disabled app-wide.
- Passwords are stored as cryptographic hashes — we do not know and cannot recover your password.
- On your device, data is held in the platform's encrypted store (EncryptedSharedPreferences on Android, Keychain on iOS). Your password is never persisted on the device.
- Restricted access — data access is limited to those who need it to run the service.
In the interest of transparency: field-level encryption is applied to the palm template. Other account data (phone, name, transactions) is stored in a database protected by access controls and network isolation, without field-level encryption. We are working to extend its coverage.
No system is absolutely secure; we apply reasonable safeguards but cannot guarantee absolute security.
7. Retention
- Palm template — kept while your account is active; permanently erased the moment the account is deleted.
- Account and transaction data — kept while the account is active, then for the period required by applicable Saudi financial regulations.
- Scan and activity logs — kept for security and dispute resolution.
- Verification codes (OTP) — deleted within 5 minutes or immediately upon use.
- Operational logs — contain mobile numbers for diagnostics and are rotated on reaching a size limit.
8. Deleting Your Account and Data
You can request deletion in two ways:
Permanently and immediately erased:
- ✅ Your palm biometric template — fully wiped from the database.
- ✅ Your first name, last name and email address.
- ✅ Your palm enrolment record is deactivated.
What we retain after deletion, stated plainly:
- Your mobile number — to prevent the number being reused for a new account and to protect your record.
- Your financial transaction and activity history — to comply with financial record-keeping obligations.
- The fact, date and stated reason of the deletion.
After deletion the account cannot be reactivated, and the same number cannot be registered again.
Before deleting: if your wallet holds a balance, contact us to recover it first — deletion zeroes the balance.
9. Your Rights
- Access the data we hold about you.
- Correction of inaccurate data.
- Deletion as described in section 8.
- Withdrawal of consent for palm biometric use.
- Objection to specific processing.
- Complaint to the competent supervisory authority in Saudi Arabia.
To exercise any of these: support@kfpaysa.com — we respond within 30 days.
10. Children
KF Pay is a financial service not directed to anyone under 18, and we do not knowingly collect their data. We do not collect date of birth and perform no automated age verification; eligibility is therefore a condition you accept on registration. If we learn of an account belonging to a minor, we delete it and its data.
11. Service Scope and Data Transfers
The service is provided in Saudi Arabia and data is stored on servers operated on our behalf. Limited data may be processed outside the Kingdom by the service providers named in section 5 (for example Google's notification service), under appropriate contractual safeguards.
12. Changes to This Policy
We may update this policy. The updated version will be published on this page with a revised effective date. We will notify you in the app of material changes.
Effective date: 30 August 2026 · Last updated: 30 August 2026