Last updated: July 2026
1. Introduction
Credit Line Company ("Credit Line", "we", "us") provides Shariah-compliant consumer micro-financing through the Credit Line app and website (creditline.finance), under the supervision of the Saudi Central Bank (SAMA). We serve adults in the Kingdom of Saudi Arabia; our services are not directed to or available to anyone under 18, and we do not knowingly collect their data. This Policy explains what personal data we collect, why, how we protect it, and the rights you have under the Saudi Personal Data Protection Law (PDPL).
We are the data controller for your personal data. Our registered address is 3283, Anas bin Malik Road, Al-Narjis District, Riyadh, Saudi Arabia (Commercial Registration 7042944996).
This Policy is based on the following laws and regulations:
- The Personal Data Protection Law (PDPL) and its Implementing Regulation.
- The SDAIA Privacy Policy Developing and Elaboration Guideline.
- The SAMA Finance Companies Control Law and applicable SAMA instructions.
- The Credit Information Law and its Implementing Regulation (SIMAH).
- The Anti-Money Laundering Law and the Law of Combating Crimes of Terrorism and its Financing.
Key terms used in this Policy:
- Personal data: any data that identifies you directly or indirectly.
- Processing: any operation performed on personal data, such as collection, use, storage, disclosure or destruction.
- Controller: the party that determines the purposes and means of processing (Credit Line).
- Credit data: data about your creditworthiness, obligations and payment behaviour, obtained from or reported to SIMAH.
- Competent authority: the Saudi Data and AI Authority (SDAIA).
2. Contact details and updates to this Policy
You can reach us through the Credit Line app or using the details below.
- Privacy and your rights: data.privacy@creditline.finance
- Website: creditline.finance
- Postal address: 3283, Anas bin Malik Road, Al-Narjis District, Riyadh, Saudi Arabia
- Last updated: July 2026; this version becomes effective on approval.
We review this Policy periodically and whenever our processing changes, record each change in our internal update record, and notify you of material changes through the app, by email or on our website.
3. What personal data we collect
Identity, income and credit data are necessary to assess and provide financing; other data, such as marketing preferences, is optional.
4. How we collect your personal data, and why
We collect personal data in two ways:
- Directly from you: when you apply for financing and use the app, through in-app forms and uploaded documents.
- Indirectly: from SIMAH (credit bureau), government services (GOSI/Mudad for income, the National Information Center and Nafath for identity), and automatically from your device.
Where we obtain your personal data indirectly rather than from you, we inform you within 30 days, unless you already have this information.
On our website and app we use cookies and similar technologies, such as pixels, web beacons and SDKs, to keep the service working, remember your preferences, and collect anonymous usage statistics; you can control or disable cookies through your browser or device settings. Our website does not currently respond to browser "Do Not Track" signals.
5. How we use your personal data
We use your personal data for the following purposes:
- Assess your creditworthiness and affordability, and originate and service your financing.
- Verify your identity and income, and enquire from and report to SIMAH.
- Disburse funds and collect instalments and repayments.
- Recover overdue amounts and, where necessary, pursue debt collection and legal claims.
- Meet anti-money-laundering, sanctions-screening and other regulatory obligations.
- Protect against fraud and secure our systems; send marketing where you have opted in.
We collect only the personal data necessary for each purpose. Where a financing decision is based solely on automated processing and has a significant effect on you, you may request a human review.
6. How we disclose your personal data
- SIMAH: credit enquiry and reporting under the Credit Information Law.
- Government services: GOSI/Mudad for income verification; Nafath/NIC for identity.
- Banks and payment providers: to disburse funds and collect repayments.
- Service providers: e-signature and promissory-note providers (Sadq, Nafith) under agreements.
- Regulators and authorities: SAMA, SDAIA or law enforcement, only where the law requires.
We do not sell your personal data, and we share only the minimum necessary for each purpose.
We may share some of your personal data with sister companies within the group, inside the Kingdom of Saudi Arabia, on the basis of legitimate interest, for the following purposes:
- Verifying your identity and the accuracy of your data.
- Improving the quality of the services provided to you and the speed of completing transactions.
- Preventing fraud and detecting unlawful activities.
We do not share your credit data or anti-money-laundering data with our sister companies.
Where any party requests disclosure of your credit data, we notify you as required by the Credit Information Law.
Where you have opted in to marketing, you can withdraw your consent and unsubscribe at any time through the app or the unsubscribe link in every marketing message, without affecting your financing.
7. Legal basis for collecting and processing your personal data
We obtain your explicit consent for credit-data processing (SIMAH enquiry and reporting), which we handle in accordance with the Credit Information Law. You can withdraw consent at any time, without affecting processing required by law (such as credit reporting or AML).
8. Where we store your data, retention and destruction
Your personal data is stored and processed within Saudi Arabia, on in-Kingdom cloud infrastructure, and our backups stay in the Kingdom. Where a transfer of personal data outside the Kingdom becomes necessary, we carry it out only where the PDPL and the Personal Data Transfer Regulation permit it, limited to the minimum necessary, under an approved transfer mechanism with equivalent safeguards, and following a transfer risk assessment.
When a retention period ends, we securely destroy personal data so it cannot be viewed or recovered. Certain records under a legal hold (for example AML or credit-reporting obligations) are restricted rather than erased while the obligation applies.
We protect your data with encryption in transit and at rest, anonymization or pseudonymization where possible, strict need-to-know access controls, logging and monitoring, aligned with the SAMA Cyber Security Framework. If a personal data breach occurs that is likely to cause serious harm to your data, rights or interests, we will notify the competent authority and inform you, as required by the PDPL.
9. Your rights regarding your personal data
Under the PDPL you have the following rights:
- The right to be informed: You have the right to know how we collect your personal data, the lawful basis for collecting and processing it, and how it is processed, stored, destroyed and to whom it is disclosed. You can find the full details in this Privacy Policy or by contacting us using the details below.
- The right to access your personal data: You have the right to ask us to view your personal data.
- The right to obtain your personal data: You have the right to request your personal data held by the controller in a readable and clear format, provided in a commonly used electronic format or as a printed copy where practicable.
- The right to correct your personal data: You have the right to ask us to correct, complete or update your personal data.
- The right to destroy your personal data: You have the right to ask us to destroy your personal data in certain circumstances, without prejudice to the legal justifications and the limitations on the right to erasure.
- The right to withdraw your consent: You have the right to withdraw your consent to the processing of your personal data at any time, unless a legal justification requires otherwise.
Beyond these statutory rights, we also honour requests to object to or restrict certain processing where this is feasible and permitted by law.
You will not be required to pay any fee to exercise these rights, and we respond within 30 days. Some processing (such as credit reporting and AML) is required by law and cannot be stopped on request.
10. Data Protection Officer
Our Data Protection Officer oversees privacy at Credit Line and is your point of contact for any question about how we process your personal data or to exercise your rights. Please email data.privacy@creditline.finance.
11. Complaint or objection filing method
If you believe we have not complied with the PDPL, or we have not allowed you to exercise your rights within the time stated above, you can complain to our Data Protection Officer at data.privacy@creditline.finance. We handle complaints within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Saudi Data and AI Authority (SDAIA), the Competent Authority, within 90 days of the incident or of becoming aware of it (Implementing Regulation Art 37).
Compliance Mapping Index
This index maps each section of the Privacy Policy to the PDPL Law and Implementing Regulation articles it addresses. The section order follows the SDAIA Privacy Policy Guideline's Detailed Model and covers its ten key elements.
