✨ We’re Hiring. Apply now ✨

Privacy Policy

Introduction

webook.com (“webook”, “Halayalla”, “we”, “us”, or “our”, referred to as “webook”) operates a digital super app designed for sports, entertainment, culture, communities, and related experiences. Through one integrated platform, webook enables users to discover activities around them, connect with others, and access a wide range of entertainment and lifestyle services.

We respect your privacy and maintaining your trust is our priority. We are committed to protecting your personal data in line with applicable data protection laws, including (as relevant):

  • European Union General Data Protection Regulation (EU) 2016/679 (GDPR)

  • UK GDPR and Data Protection Act 2018

  • Kingdom of Saudi Arabia’s Personal Data Protection Law (PDPL) 

  • UAE’s Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) 

  • Law No. 09-08 of Morocco on the Protection of Individuals with Regard to the Processing of Personal Data

  • Personal Data Protection Law No. 24 of 2023 of Jordan

  • Bahrain's Personal Data Protection Law (PDPL)

  • Law No. 13 of 2016 concerning Personal Data Privacy and Protection of Qatar

This Privacy Notice explains how we collect, use, disclose, store, and safeguard your personal data when you visit our website, create an account, purchase tickets, book events, or otherwise interact with our services.

Where local data protection laws impose additional or different requirements, the Jurisdiction-Specific Addendum applicable to your location supplements this Notice and prevails in the event of conflict.

Identity of Controller

Hala Yalla for Information Technology Co. (Saudi Arabia), a company incorporated in the Kingdom of Saudi Arabia with its registered address at “Floor 1, Building No. 4162, Abi Alasbat Street, Al Olaya District, Riyadh, Kingdom of Saudi Arabia, 12311”, is the parent company of the group (“Group”, “we”, “us”, “our”), and includes webook and other affiliated entities.

Depending on your location and the services you use, the relevant Group entity that provides services to you and determines the purposes and means of processing your personal data acts as the data controller.

The controller is typically the entity with which you contract, create an account, or purchase services.

Where two or more Group entities jointly determine the purposes and means of processing, they act as joint controllers in accordance with applicable law.

Further information about the relevant Group entities and their roles may be made available to you at the point of data collection or upon request.

When We Act as a Processor

In certain circumstances, such as when we provide ticketing, technology, or event management services to event organizers, corporate customers, or business partners, we may process personal data strictly on their behalf.

In such cases, we act as a data processor and the relevant customer or partner acts as the data controller. The privacy notice of that controller governs the processing of your personal data. We encourage you to review their privacy notice for further information.

Information we collect

We may collect and process the following categories of personal data, depending on how you interact with us:

Personal Identification Information

Name, email address, phone number, billing address, and other contact details. In limited cases and where strictly necessary, we may collect additional details such as date of birth, gender, nationality, or identification information (e.g., passport or ID details).

Payment Information

Payment method, billing address, and transaction history. Payments are processed securely by third-party payment service providers. We do not store full credit or debit card numbers.

Account and Booking Information

Account credentials, booking history, ticket details, preferences, and special requests.

Technical Data

IP address, browser type and version, time zone setting, operating system, device identifiers, and related technical data.

Usage Data

Information about how you use our website and services, including pages viewed and interaction data. Information collected through cookies is governed by our Cookie Notice.

Marketing and Communications Data

Preferences in receiving marketing communications, responses to surveys, and engagement with promotional activities.

Location Data

Approximate geographic location derived from your device or IP address.

Social Media Data

Information you choose to share when interacting with us via social media platforms, subject to those platforms’ privacy settings.

Interaction Data

Records of communications with us, including customer support interactions.

User Generated Data

Reviews, feedback, ratings, comments, and other content voluntarily submitted.

Legal and Compliance Data

Information required to comply with legal obligations, detect fraud, resolve disputes, or enforce our terms.

Certain data may qualify as sensitive or special category data under applicable laws, such as government issued identification information (e.g., passport or national ID details) or other data required for regulatory or legal compliance purposes. 

We process such data only where strictly necessary and where permitted under applicable laws. This includes, where required, obtaining your explicit consent or relying on other lawful bases permitted under applicable regulations. For example, under the Saudi Personal Data Protection Law (PDPL), processing of sensitive data is carried out on your explicit consent in accordance with Article 6 and other applicable provisions. 

Such data is subject to enhanced safeguards, including restricted role-based access controls, encryption in transit and at rest, data minimization, segregation of sensitive datasets, enhanced monitoring and logging of access, and restricted retention periods.  

Children’s Data

Our services may be accessed by individuals of different age groups, including children, subject to applicable legal requirements. The age at which a child may provide valid consent for the processing of their personal data varies by jurisdiction.

In the European Economic Area and the United Kingdom, parental or guardian consent is required for children below the applicable digital age of consent (which is 16 years, or lower where permitted by Member State law, but not below 13). 

In jurisdictions such as the Kingdom of Saudi Arabia, United Arab Emirates, Qatar, Bahrain, Jordan, and Morocco, parental or guardian consent is typically required for the collection and processing of personal data relating to minors, typically individuals under the age of 18 years, subject to applicable laws.

Where required under applicable law, we rely on parental or guardian consent for the collection and processing of personal data relating to children. 

If we become aware that personal data has been collected from a child without the required consent, we will take necessary steps to delete such data as soon as reasonably practicable.

If you believe that a child has provided personal data without appropriate authorization, please contact us so that we can take appropriate action.

How We Collect Your Information

We collect data through various methods, depending on how you interact with our website and services:

  • Direct Interactions: When you provide your personal data directly to us, such as creating an account, filling in forms, booking services, submitting reviews or feedback, participating in surveys or promotions, or communicating with us through customer support or other channels.

  • Automated Technologies: When you access and use our website, we may automatically collect certain technical and usage data through server logs and similar technologies. Information collected through cookies, or similar technologies is subject to your preferences and applicable consent requirements and is detailed in our Cookie Notice.

  • Third Parties or Publicly Available Data Sources: We may receive personal data from third parties, where permitted by applicable law, such as analytics providers, advertising or marketing partners, payment service provider, search information providers, social media platforms (including when you choose to log in or interact with us through such platforms), and publicly available sources.

Third-Party Links and Embedded Content: Our website may contain links to third-party websites or embedded content (such as videos, images or social media features). These third-parties may collect personal data independently of us and in accordance with their own privacy notices. We are not responsible for the privacy practices or content of such third-party websites or services.

How We Use Your Information and Legal Basis for Processing

We use your personal data only for specified, explicit and legitimate purposes for which it was originally collected, and in a manner compatible with applicable data protection laws. Where required by law, we rely on your consent or other legal basis. If we intend to use your personal data for a new that is incompatible with the original purpose, we will notify you and, where required, obtain your consent or identify an appropriate legal basis that authorizes such use.

Where required, we rely on:

Performance of a Contract

Account creation and management

Booking processing and ticket issuance

Payment processing and refunds

Transactional communications

Legal Obligations

Financial and tax compliance

Regulatory reporting

Responding to lawful authority requests

Legitimate Interests (Where Permitted)

Customer support and service improvement

Fraud prevention and system security

Business analytics and operational improvement

Non-intrusive personalization

Establishing or defending legal claims

Where legitimate interests apply, we conduct appropriate assessments to ensure our interests do not override your rights.

In jurisdictions where legitimate interests are not recognized as an independent lawful basis (such as the Kingdom of Saudi Arabia), processing is carried out based on consent or another lawful ground permitted under applicable law.

Consent (Where Required)

Marketing communications

Optional surveys

Analytics or marketing cookies

You may withdraw consent at any time.

We do not carry out automated decision-making that produces legal or similarly significant effects.

How We Share Your Information

We may share your personal data with the following categories of recipients, where necessary and in accordance with applicable data protection laws. All sharing is subject to contractual safeguards and confidentiality obligations.

  • Service Providers (Processors): Third-party service providers who perform services on our behalf,such as but not limited to IT, payment processing, analytics, marketing, security services and customer service support. These providers are authorized to process personal data only in accordance with our instructions and are subject to appropriate contractual and confidentiality obligations.

  • Business Partners: Partners involved in delivery of our services, such as event organizers, cinema operators, and fulfillment agencies or logistics providers. Depending on the context, these partners may act as independent data controllers, as they determine how and why your personal data is processed for the purpose of delivering their services and complying with their legal obligations. For example, event organizers or venue operators may use attendee information to manage access, safety, and compliance at their venues and therefore act as independent controllers.

  • Law Enforcement, Legal and Regulatory Authorities: Government bodies, regulatory authorities, courts or law enforcement agencies where disclosure is required by applicable law, regulation, legal process, or to protect our legal interests, or to establish, exercise or defend legal claims.

  • Corporate Transactions: In the event of a merger, acquisition, reorganization, or sale of assets, or similar corporate transaction, your personal data may be shared with prospective or actual counterparties and their advisors, subject to appropriate confidentiality and date protection safeguards.

  • Third-Party Links and Embedded Content: Our website may include links to third-party websites or embedded content (such as videos or social media features). These third parties may collect personal data independently of us and in accordance with their own privacy notices. We are not responsible for their privacy practices.

International Data Transfer

Your personal data may be transferred to, stored, and processed in countries outside your country of residence, including jurisdictions that may not provide the same level of data protection as your home country. Where such transfers occur, we ensure that they are carried out in accordance with applicable data protection laws and are subject to appropriate safeguards.

These safeguards include:

  • Adequacy decisions, i.e. transfers to countries that are recognized as providing an adequate level of data protection under applicable laws;

  • Standard Contractual Clauses or Contractual safeguards designed to protect personal data;

  • Intra-group data transfer agreements;

  • Regulatory approvals where required or notifications, where required under applicable law; and

  • Other lawful transfer mechanisms permitted under applicable data protection regulations.

For transfers originating from the Kingdom of Saudi Arabia, personal data is transferred only in accordance with Article 29 of the PDPL and its Implementing Regulations.

You may request further details regarding safeguards.

How We Protect Your Information

We implement appropriate technical and organizational measures designed to protect your personal data against unauthorized access, alteration, disclosure, loss, or destruction. These measures are implemented taking into account the nature of personal data, the purposes of processing, and the risks involved. These may include, as appropriate, encryption, secure servers, firewall protections, access controls, and regular security monitoring and reviews. We also limit access to personal data to authorized personnel and service providers who require such access for legitimate business purposes and who are subject to confidentiality obligations. Where sensitive or special category data is processed, we apply additional safeguards such as enhanced access restrictions, stronger encryption standards, data segregation, increased monitoring of access and processing activities, and stricter retention and deletion controls, in line with applicable legal and regulatory requirements.

While we are committed to protecting your personal data and take reasonable and appropriate measures to do so, no method of transmission over the internet or electronic storage is completely secure.

Data Retention

We retain your personal data only for as long as is necessary to fulfill the purposes for which it was collected, including to meet legal, regulatory, accounting, reporting, or business requirements. The retention period may vary depending on the nature of data, purpose of processing and the applicable legal obligations.

Where possible, we apply the following standard retention periods:

Category of Personal Data

Purpose of Processing

Retention Period

User account data (e.g., first name, last name, email)

Account management and authentication

Duration of the account; deleted after 24 months of inactivity or upon account deletion (based on last login)

Ticket orders and booking records

Legal, accounting and transactional management

Up to 10 years from the end of the relevant fiscal year; thereafter anonymized

Payment transaction metadata

Payment reconciliation, audits and financial compliance

Up to 10 years from the end of the relevant fiscal year; thereafter anonymized

Marketing contact details (email, phone number, preferences)

Marketing communications and preference management

Until you unsubscribe or withdraw consent; thereafter retained on a suppression list

Analytics data

Product analytics and service improvement

Up to 24 months from the date of collection

Security logs

Security monitoring and incident response

Up to 12 months from log creation

Marketing consent records

Demonstrate compliance with consent management

Up to 5 years after withdrawal of consent

Customer support communications

Handling enquiries, disputes, and service quality improvement

Up to 3 years from closure of the request

Event operations data (e.g., attendance, ticket scans)

For event management and operations

Up to 90 days after the relevant event

We retain personal data for these periods for legitimate business purposes, including responding to enquiries or complaints, maintaining appropriate records, and verifying your identity when you contact us.

In certain circumstances, personal data may need to be retained for longer periods where required or permitted by applicable law. This may include, for example, retaining contact details, correspondence, complaints, or related records to comply with regulatory requirements, demonstrate compliance with data protection laws (such as handling data subject rights requests), or to establish, exercise, or defend legal claims within applicable statutory limitation periods.

When personal data is no longer required for the purposes for which it was collected, and there is no legal or regulatory requirement to retain it, we will securely delete, anonymize, or otherwise dispose of it in accordance with our data retention policies.

Data Storage

Your personal data may be stored and processed in secure data centers located in one or more jurisdictions where we or our service providers operate.

Where personal data is transferred or accessed across borders, we ensure that appropriate safeguards are implemented in accordance with applicable data protection laws and regulatory requirements.

Your Rights

Applicable data protection laws across jurisdictions of our operations, including but not limited to the EU GDPR, UK GDPR, KSA PDPL, UAE Federal PDPL, Jordan PDPL No. 24/2023, Morocco Law 09-08 and Bahrain PDPL, grant individuals ("Data Subjects") certain rights in relation to their personal data. 

Requests to exercise these rights are commonly referred to as Data Subject Requests (DSRs).

Not all rights are absolute. Their applicability depends on factors such as the legal basis for processing, statutory obligations, public interest considerations, or exemptions under applicable local laws.

The rights available to you may include the following, subject to jurisdictional applicability as set out in the Jurisdiction-Specific Addendum:

Right of Access

You have the right to request confirmation as to whether we process your personal data and, where applicable, to obtain access to such personal data together with supplementary information regarding its processing.

Right to Be Informed

You have the right to be informed about how your personal data is collected and used, including the purposes of processing, retention periods, and categories of recipients. This Privacy Notice is intended to satisfy that obligation.

Right to Rectification

You have the right to request correction of inaccurate personal data and completion of incomplete personal data.

Right to Erasure or Deletion

You have the right to request deletion of your personal data in certain circumstances, for example where the data is no longer necessary for the purposes for which it was collected. This right is subject to statutory exceptions, including legal retention obligations and legitimate legal claims.

Right to Restriction of Processing

In certain jurisdictions, you may have the right to request restriction or suspension of processing of your personal data under specific conditions, such as where you contest its accuracy or the lawfulness of processing.

Right to Data Portability

Where provided under applicable law and where processing is based on consent or contract and carried out by automated means, you may have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format and to request transmission to another controller, where technically feasible.

Right to Object

You may have the right to object to certain types of processing, including processing based on legitimate interests. You have an absolute right to object to the processing of your personal data for direct marketing purposes.

Rights Related to Automated Decision-Making

Where applicable law provides, you may have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal or similarly significant effects, and to request human intervention.

Marketing & Profiling Controls

You may opt out of marketing communications at any time by using the unsubscribe mechanism included in communications or by contacting us directly.

Right to Lodge a Complaint

You have the right to raise concerns regarding our data handling practices.

You may:

Visit our Help Center

Contact our Data Protection Officer (DPO) at [email protected] 

Lodge a complaint with the competent data protection supervisory authority in your jurisdiction, as identified in the Jurisdiction-Specific Addendum.

Where provided by applicable law, you may also pursue legal remedies in respect of violations of your data protection rights.

To exercise your rights, please visit our Help Center.

We aim to respond to all valid requests within one month, in line with widely applicable data protection standards.

In certain jurisdictions, shorter response timeframes may apply (for example, 30 days under the laws of the Kingdom of Saudi Arabia). Where such requirements apply, we will comply with the applicable timeframe.

Where permitted by law, this period may be extended in complex cases, in which case we will notify you accordingly.

Personal Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within the timeframes required by applicable law (typically within 72 hours).

Where the breach is likely to result in a high risk to you, we will also notify you directly, unless an exemption applies under applicable law.

We maintain internal incident response procedures to ensure timely detection, investigation, and remediation of such incidents.

Data Protection Officer (DPO)

We have appointed a Data Protection Officer (DPO) responsible for overseeing compliance with applicable data protection laws and this Privacy Notice across the jurisdictions in which we operate.

The DPO is responsible for informing and advising the organization on its data protection obligations, monitoring compliance with applicable data protection laws and internal policies, and providing guidance on data protection impact assessments where required. The DPO also cooperates with relevant supervisory or regulatory authorities and acts as a point of contact for data subjects and regulators on matters relating to the processing of personal data.

The DPO operates independently and is supported by appropriate resources to carry out these responsibilities.

You may contact our DPO for any questions, concerns, or requests relating to this Privacy Notice or the processing of your personal data at: [email protected].

Cookies

We use cookies and similar technologies. Please refer to our Cookie Notice for further information.

Changes to this Notice

We may update this Notice periodically. Updates will be published on our website with a revised “Last Updated” date.

Contact Us

For any queries, complaints or information regarding this Notice, you may contact us at [email protected].

Jurisdiction-Specific Annexure

Jurisdiction

Applicable Law

Additional/Specific Rights and Clarifications

Supervisory Authority

European Economic Area (EEA)

General Data Protection Regulation (EU) 2016/679

Right to lodge a complaint in the EU Member State of habitual residence, place of work, or place of alleged infringement.

Relevant Supervisory Authority in your EU Member State, available at link.

United Kingdom (UK)

UK GDPR & Data Protection Act 2018

Right to lodge a complaint with the UK supervisory authority.

Information Commissioner's Office (ICO)

Kingdom of Saudi Arabia (KSA)

Personal Data Protection Law (PDPL)

Rights include access, correction, and deletion, subject to regulatory exemptions.

Saudi Data & Artificial Intelligence Authority (SDAIA)

United Arab Emirates (UAE)

Federal Decree-Law No. 45 of 2021

Rights include access, rectification, erasure, restriction, portability, and objection.

UAE Data Office

Qatar

Law No. 13 of 2016

Rights include access, correction, objection, and deletion, subject to legal limitations.

National Cyber Security Agency (NCSA)

Bahrain

Personal Data Protection Law

Rights include access, rectification, erasure, objection, and portability.

Personal Data Protection Authority (PDPA)

Morocco

Law No. 09-08

Rights include access, rectification, and objection.

Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP)

Jordan

Personal Data Protection Law No. 24 of 2023

Rights include access, rectification, erasure, withdrawal of consent, and objection in specified circumstances.

Ministry of Digital Economy and Entrepreneurship

Cookie Notice

This Cookies Notice (“Notice”) should be read alongside, and in addition to, our Global Privacy Notice.

webook's Cookies Notice describes how we use cookies and similar technologies and explains why we use them. We may also use similar technologies such as pixels, tags, SDKs, and local storage, which operate in a similar way to cookies and are used for similar purposes, including analytics and advertising.

It also explains how cookies enable the Website to function properly and why you may not be able to experience the full functionality of the Website if you disable their use.

For the purposes of this Notice, “Website” refers to any website, platform, application, or digital service operated or made available by webook ("webook.com", "HalaYalla for Information Technology Co.", "Company", "we", "us", "our", hereby referred to as "webook") or our affiliated entities, including any localized or country-specific versions, through which this Cookies Notice is made available or referenced.

What are Cookies?

Cookies are small text files that help websites work better, for example, remembering your preferences or showing content that’s relevant to you.

Types of Cookies

Cookies may be stored on your device for different periods of time. Some cookies are session cookies, which are deleted when you close your browser, while others are persistent cookies, which remain on your device until they expire or are deleted.

First-Party and Third-Party Cookies

Cookies may be set either by us (first-party cookies) or by third parties whose services we use (third-party cookies), such as analytics or advertising providers. Third-party cookies are subject to the respective third parties’ privacy policies.

We use different categories of cookies on our Website:

Essential Cookies

These cookies are required for the Website's basic functions and are always active.

Name

Provider

Purpose

Expiry

lang

First-Party

Keeping user language

1 month

token

First-Party

Stores user authentication JWT for API requests

Based on JWT expiry

refresh_token

First-Party

Refreshes authentication session without re-login

180 days

token_expires_in

First-Party

Stores token expiration timestamp

180 days (stores token expiry time)

__cf_bm

Third-Party (Cloudflare)

Bot protection & security

30 minutes

Analytics Cookies (optional)

We use cookies that help us understand how users interact with our Website to count visits and see which pages are popular. These may include cookies set by third-party analytics providers.

Name

Provider

Purpose

Expiry

_ga

Third-Party (Google)

Distinguishes users

2 years

ga* (all variants)

Third-Party  (Google)

Stores session state

2 years

AMP_*

Third-Party  (Amplitude)

Tracks user behavior and sessions

1 year

AMP_MKTG_*

Third-Party (Amplitude)

Marketing attribution tracking

1 year

prism_*

Third-Party (Amplitude)

Identifies returning users

1 year

cfz_amplitude

Third-Party (Amplitude via proxy)

Stores device & event tracking data

1 year

hjSessionUser*

Third-Party (Hotjar)

Identifies unique users

1 year

hjSession*

Third-Party  (Hotjar)

Stores session data

30 min

_clck

Third-Party (Microsoft)

Persists user ID

1 year

_clsk

Third-Party (Microsoft)

Session tracking

1 day

_dd_s

Third-Party (Datadog)

Session tracking & performance monitoring

Few minutes (very short-lived)

_ScCbts

Third-Party (Snapchat analytics)

Tracks user behavior

1 day

Advertisement Cookies (optional)

These cookies are used to show you advertisements that are relevant to your interests and may be used to track your browsing activity across different Websites. These may be set by us or by third-party advertising partners.

Name

Provider

Purpose

Expiry

_fbp

Third-Party (Meta)

Tracks visitors for ad targeting

3 months

_ttp

Third-Party (TikTok)

Tracks user behavior for ads

1 year

_tt_enable_cookie

Third-Party (TikTok)

Enables tracking via TikTok pixel

1 year

ttcsid* (all variants)

Third-Party (TikTok)

Tracks sessions & attribution

1 year

_scid

Third-Party (Snapchat)

Identifies users for ads

1 year

_scid_r

Third-Party (Snapchat)

Retargeting tracking

1 year

_gcl_au

Third-Party (Google Ads)

Measures ad conversions

3 months

__gads

Third-Party (Google)

Ad personalization

1 year

__gpi

Third-Party (Google)

Ad targeting & profiling

1 year

__eoi

Third-Party (Google)

Ad delivery optimization

6 months

_pin_unauth

Third-Party  (Pinterest)

Tracks anonymous users for ads

1 year

_twpid

Third-Party  (Twitter/X)

Tracks ad attribution

1 year

How You Can Manage Cookies

When you first visit our Website, you will be presented with a cookie banner that allows you to accept or reject non-essential cookies. Non-essential cookies are only placed on your device after you provide your consent, where required by applicable law. Where permitted, essential cookies are processed based on our legitimate interests in ensuring the proper functioning and security of the Website.

You can update or withdraw your consent at any time through our cookie settings tool available on the Website.

Essential cookies are necessary for the functioning of the Website and cannot be disabled through our cookie settings tool.

Additional Information on Device and Browser Privacy Controls

You can manage or disable cookies through your browser settings. Most browsers allow you to block or delete cookies and to configure preferences for certain Websites.

In addition, you can manage your preferences for certain third-party cookies through the following industry opt-out tools:

We use third party analytics services, such as Google Analytics, to help us understand how users interact with our Website. For information on how Google processes and collects information using Google Analytics, please see https://policies.google.com/technologies/partner-sites, and for how to opt out, please see https://tools.google.com/dlpage/gaoptout.

Please note that these tools are provided by third parties and we do not control or operate them.

Do Not Track

Some web browsers may allow you to enable a do-not-track feature that alerts the Websites you visit that you do not want your online activities to be tracked. Our Websites may not recognize or respond to Do Not Track signals. At present, no generally accepted standards exist on how companies must respond to Do Not Track signals. In the event a final standard is established, we will assess and provide an appropriate response to these signals.

Help/Contact Us

For more information on how we process personal data collected through cookies or in case of any questions about our use of cookies, please refer to our Privacy Notice or contact us using the details provided in our Privacy Notice.

Changes to this Notice

We may update this Cookies Notice from time to time. Any changes will be posted on this page with an updated “Last Updated” date.