Privacy Policy

Last updated: 17 April 2026  ·  Version 1.0
النسخة العربية (المرجع الأساسي)

This Privacy Policy explains how SmartOrdr collects, uses, shares, and protects personal data in accordance with the Personal Data Protection Law of the Sultanate of Oman (Royal Decree 6/2022) and its Executive Regulation (Ministerial Decision 34/2024). The Arabic version is the authoritative reference in case of any inconsistency.

1. Who we are

SmartOrdr ("SmartOrdr", "we", "us", "our") operates a Software-as-a-Service platform that enables restaurants in the Sultanate of Oman to receive and manage customer orders through WhatsApp using a bilingual AI ordering agent. SmartOrdr is the data controller for personal data collected through smartordr.com and its associated services.

2. Personal Data Protection Officer (DPO)

Data Protection Officer

Email: privacy@smartordr.com

Postal address: Muscat, Sultanate of Oman (full address available on request).

3. Personal data we collect

When you place an order through a restaurant that uses SmartOrdr:

When you visit smartordr.com or the restaurant dashboard:

4. Why we process your data (purposes and legal basis)

5. Who we share your data with

We share your data only to the extent necessary to operate the service:

We do not sell personal data. We do not share personal data with advertisers.

6. Cross-border data transfers

Some of the service providers listed above host data outside the Sultanate of Oman (primarily in the European Union and the United States). Where cross-border transfers occur, they are carried out in accordance with Articles 23–27 of the PDPL and the Executive Regulation, relying on either:

You can contact our DPO for details of the safeguards in place for any specific transfer.

7. How long we keep your data

8. Your rights under the PDPL

You have the right to:

To exercise any of these rights, contact privacy@smartordr.com or send the message "delete my data" on WhatsApp to the restaurant you ordered from. We will respond within 45 days, as required by the Executive Regulation.

9. Security

We apply technical and organisational measures appropriate to the risk, including:

10. Data breach notification

In the event of a personal data breach that is likely to affect the rights of data subjects, we will notify the MTCIT within the timeline set out in the Executive Regulation (generally within 72 hours of becoming aware of the breach) and, where required, notify affected individuals directly.

11. Children

The service is intended for customers aged 18 and over. We do not knowingly collect personal data from children. If you believe a child's data has been collected, please contact the DPO and we will take steps to delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time. The current version number and date appear at the top of this page. Material changes will be communicated through the service.

13. Contact

General privacy enquiries: privacy@smartordr.com

Data Protection Officer: privacy@smartordr.com

Oman regulator (PDPC): PDPC@mtcit.gov.om