Who we are & what this covers
"Livsho" (we, us, our) is the data controller for personal data processed through the Livsho mobile apps, the website at livsho.com, and any related services (the "Platform"). This policy covers buyers, sellers, viewers, and visitors. It does not cover third-party sites, apps, or services we link to.
Data we collect
Account & identity
- Name, username, profile photo, and short bio
- Mobile number (verified by OTP) and email address
- Date of birth — to confirm you are 18 or older
- For sellers: full legal name and a copy of your National ID or Iqama, and where applicable a Commercial Registration (CR) or Maroof verification
- Saudi/GCC shipping address and city
Payment & payout
- Payment method type and a tokenised reference (Mada, Apple Pay, Visa/Mastercard, STC Pay, etc.). We never store your full card PAN or CVV — these stay with the licensed payment provider.
- For sellers: IBAN and bank name for SAR payouts, plus tax/VAT registration number where you are registered
- Transaction history, invoices, and refund records
Content you create
- Live video and audio you broadcast as a seller
- Item photos, descriptions, prices, and shipping rules
- Bids, offers, "Buy Now" purchases, and order history
- Chat messages, comments, and reactions inside live shows
- Ratings and reviews you leave or receive
Device & usage
- IP address, device model, OS version, and app version
- Approximate location (country/city level) derived from IP — used for fraud checks and to show local shows; we do not collect precise GPS location
- Crash logs, performance traces, and feature-usage events
- Push notification tokens (so we can ping you when an auction you're watching is about to close)
Why we use your data
- To run live auctions, the marketplace, and your account
- To process payments in SAR, calculate VAT where applicable, and pay sellers their net earnings
- To verify identity for sellers under Saudi e-commerce and AML rules
- To send transactional notifications: bid won, payment captured, item shipped, refund issued
- To send promotions and recommendations — only if you have opted in. You can switch this off any time in Settings → Notifications.
- To detect and stop fraud, shill bidding, account takeover, and abuse
- To moderate content for compliance with Saudi law, public order, and our Community Guidelines
- To respond to lawful requests from competent authorities (SAMA, ZATCA, Ministry of Commerce, courts, law enforcement)
Lawful basis under PDPL
We process personal data on one or more of the following bases set out in PDPL and its Implementing Regulations:
- Consent — for marketing communications, optional features, and processing of any sensitive data
- Contractual necessity — to deliver the Platform and complete transactions you initiate
- Legitimate interests — to keep the Platform secure, prevent fraud, and improve our services, where this does not override your rights
- Legal obligation — to meet tax, AML/CFT, e-commerce, and consumer-protection rules in the Kingdom
- Public interest — where required to cooperate with competent authorities
Live streams & in-show chat
When a seller goes live, the video and audio they broadcast, the items they show, and any messages or reactions sent in chat are visible to all viewers in that show and may be recorded. Recordings are kept for a limited period to support moderation, dispute resolution, and compliance investigations. Buyers' bids and won-item totals appear publicly during the show.
Viewers should assume that anything they say or send in chat is visible to other participants and may be reviewed by our moderation team. Do not share personal information, payment details, or contact details in public chat.
Payments & payment data
All payments are handled by licensed payment service providers regulated by the Saudi Central Bank (SAMA) and operate over the Mada network for local cards. We support Mada, Apple Pay, Visa, Mastercard, and STC Pay. Card and wallet credentials are tokenised by the payment provider — Livsho only sees the token and the result of the transaction, never the underlying card number or CVV.
We retain transaction records (invoice number, amount, date, parties, item) for at least the period required by ZATCA's e-invoicing rules and Saudi commercial bookkeeping law.
Who we share data with
We do not sell your personal data. We share what is necessary with:
- Payment processors and Mada acquirers — to authorise and settle transactions
- Identity verification providers — to validate IDs/Iqamas for sellers
- Logistics partners (e.g. SMSA, Aramex, Saudi Post / SPL, Naqel) — your name, address, and phone number are shared with the seller and the chosen carrier so the order can be delivered
- Cloud and infrastructure providers — under data-processing agreements that mirror PDPL obligations
- Tax and regulatory authorities — ZATCA, SAMA, the Ministry of Commerce, the Communications, Space & Technology Commission (CST), and courts when legally required
- Counterparties — buyers and sellers see each other's username, ratings, and (after a winning bid) the shipping details needed to deliver the item
Cross-border data transfers
Our preferred infrastructure is hosted within the Kingdom of Saudi Arabia. Some processors (for example, app stores, push notification services, or analytics) may process limited data outside the Kingdom. When this happens we rely on the transfer mechanisms permitted by PDPL — adequacy, contractual safeguards approved by SDAIA, or your explicit consent — and we limit transfers to what is strictly necessary.
Cookies & analytics
The Livsho website uses three categories of cookies and similar technologies. The mobile apps use platform-standard identifiers (the iOS IDFA and the Android Advertising ID) only when you have allowed tracking at the OS level.
Essential
Required for the Platform to function — for example, keeping you signed in, remembering your language and currency preference, protecting against CSRF, and rate-limiting abuse. These run without consent because the Platform cannot work without them.
Statistical
Used to measure how the Platform performs, which features are used, and where users encounter errors. Data is aggregated and pseudonymised, and may be shared with analytics providers such as Google Analytics or Meta in a form that does not identify you. You can switch this category off in the in-app privacy controls or your browser cookie settings.
Marketing & technical storage
Used, with your consent, to personalise recommendations, measure campaign effectiveness, and prevent fraud. May involve tokens or device identifiers stored on your device. You can withdraw consent at any time, after which we stop placing new cookies of this type and existing ones expire on the next session.
How long we keep data
- Account profile — for the life of your account, plus up to 90 days after deletion to clear backups
- Transaction and tax records — at least 10 years, in line with Saudi commercial bookkeeping and ZATCA requirements
- Live stream recordings — typically up to 90 days, longer if a dispute, complaint, or legal hold applies
- Chat logs — up to 12 months for moderation and dispute purposes
- Crash and security logs — up to 12 months
Your rights under PDPL
As a data subject in the Kingdom you have the right to:
- Be informed of how your data is processed (this policy)
- Access a copy of the personal data we hold about you
- Request correction of inaccurate or incomplete data
- Request deletion of your personal data, subject to our legal retention duties
- Withdraw consent at any time, where consent is the basis for processing
- Object to or restrict certain processing, including marketing
To exercise any right, write to privacy@livsho.com from the email registered on your account. We respond within 30 days. If you are not satisfied with our response, you have the right to file a complaint with SDAIA (the Saudi Data & Artificial Intelligence Authority) — the regulator for PDPL.
Minors
Livsho is for users aged 18 or above. We do not knowingly collect data from anyone under 18. If you believe a minor has registered, contact privacy@livsho.com and we will close the account and remove the data without delay.
How we protect your data
We treat your personal information and contact details as confidential in line with PDPL and our internal data-protection policy. Personal data is handled only by authorised personnel under documented purposes, and only to the extent needed for those purposes.
Technical safeguards include TLS 1.2+ for data in transit, AES-256 for data at rest, role-based access controls, MFA for staff, hardened production environments, and routine security audits. Production access is restricted to a small set of trained engineers and is logged. We never ask for your password or OTP by email or chat — Livsho support will never request them; anyone who does is impersonating us and should be reported to security@livsho.com.
Personal data breach notification
If a breach occurs that is likely to harm your rights, we will notify SDAIA within the timelines set by PDPL and inform affected users without undue delay, telling you what happened, what data was involved, and what steps you can take.
Changes to this policy
We may update this policy as the Platform evolves or as Saudi data-protection rules change. Material changes are announced in-app or by email at least 14 days before they take effect. The "Last updated" date at the top of this page shows the most recent revision.
Contact our privacy team
For privacy questions, data requests, or to reach our Data Protection Officer:
- Email: privacy@livsho.com
- General support: info@livsho.com
- Regulator: Saudi Data & Artificial Intelligence Authority (SDAIA), Riyadh — sdaia.gov.sa