Sofred Let’s Support App — Privacy Policy

Last Updated: 4 October 2026

1. Introduction

This Privacy Policy explains how Sofred Mobility (“Sofred”, “we”, “us”, or “our”) collects, uses, stores, discloses, and protects personal data processed through the Sofred Let’s Support App (“Let’s Support App” or “Application”).

The Let’s Support App is an internal business application used by authorized Sofred employees, personnel, contractors, and other authorized representatives to provide customer support and manage communications and operational activities related to Sofred services.

The Let’s Support App is not intended for public registration or general consumer use.

Access to the Let’s Support App is restricted to individuals authorized by Sofred.

Sofred is committed to protecting personal data and processing it responsibly in accordance with applicable laws and regulations of the Sultanate of Oman, including the Personal Data Protection Law issued by Royal Decree 6/2022 and its Executive Regulation issued by Ministerial Decision 34/2024, as applicable.

2. Data Controller

The controller responsible for personal data processed through the Let’s Support App is:
Sofred Mobility
Commercial Registration No.: 1419381
Address: Al-Aqur, Nizwa, Sultanate of Oman
P.O. Box: 1561
Email: admin@sofredmobility.com
Telephone / WhatsApp: +968 7749 8918

For privacy-related questions, requests, complaints, or data-subject requests, please contact: Email: admin@sofredmobility.com

Sofred may designate or appoint a Personal Data Protection Officer or other responsible privacy contact where required by applicable law.

3. Purpose of the Let’s Support App

The Let’s Support App is designed to allow authorized Sofred personnel to manage and respond to customer support requests and operational communications.

The Application may be used for purposes including:

  • Customer support and assistance

  • Customer communications

  • WhatsApp communications

  • Responding to customer inquiries

  • Resolving complaints and service issues

  • Reviewing customer accounts

  • Reviewing ride and trip information

  • Investigating payment and wallet issues

  • Investigating refunds

  • Assisting with subscriptions

  • Investigating vehicle-related incidents

  • Reviewing reported safety or operational issues

  • Managing support tickets

  • Recording internal notes relating to support cases

  • Escalating cases to appropriate Sofred personnel

  • Managing WhatsApp conversations

  • Creating and managing approved WhatsApp message templates

  • Monitoring the status of support communications

  • Maintaining records required for operational, legal, accounting, security, and compliance purposes

  • Preventing fraud, misuse, unauthorized access, and abuse of Sofred services

  • Improving the quality and reliability of Sofred's customer-support operations.

The Let’s Support App is not intended to collect personal data for unrelated purposes.

4. Who May Access the Let’s Support App?

The Let’s Support App is intended for:

  • Authorized Sofred employees

  • Authorized customer-support personnel

  • Authorized operations personnel

  • Authorized managers

  • Authorized administrators

Access is provided based on business requirements and authorization.

Sofred may restrict, suspend, or terminate access where:

  • An individual's role changes;

  • The individual leaves Sofred;

  • Access is no longer required;

  • Unauthorized activity is detected;

  • Security requirements are not satisfied; or

  • The individual violates Sofred policies.

Users of the Let’s Support App are expected to access only the information necessary for their assigned responsibilities.

5. Personal Data We May Process

Depending on the support request and the functionality being used, the Let’s Support App may process different categories of personal data.

This may include:

5.1 Customer identification information

  • Customer name

  • Customer account identifier

  • Customer ID

  • Phone number

  • Email address

  • Account status

  • Registration information

  • Verification information where applicable

5.2 Communication information

When customers contact Sofred through WhatsApp or other support channels, we may process:

  • WhatsApp phone number

  • WhatsApp account information

  • Messages sent to Sofred

  • Messages sent by Sofred to the customer

  • Message timestamps

  • Conversation history

  • Message delivery information

  • Attachments sent as part of a support request

  • Images or documents submitted by customers

  • Internal support notes associated with the conversation

5.3 Sofred service information

Where necessary to resolve a support request, authorized staff may access:

  • Ride history

  • Trip dates and times

  • Ride duration

  • Vehicle information

  • Vehicle identification number

  • Vehicle location or trip-related location information

  • Zone information

  • Ride status

  • Account status

  • Subscription information

  • Wallet balance

  • Wallet transactions

  • Payment status

  • Refund information

  • Promotional information

  • Relevant service activity

5.4 Support information

We may process:

  • Customer complaints

  • Customer requests

  • Support tickets

  • Case status

  • Internal notes

  • Resolution information

  • Escalation records

  • Incident reports

  • Relevant correspondence

5.5 Technical and security information

Depending on the Application's configuration, we may process:

  • User account identifiers

  • Authentication information

  • Login information

  • Access logs

  • Device information

  • Browser or application information

  • IP address

  • Date and time of access

  • Security logs

  • Error logs

  • Audit logs

  • Actions performed within the Support App

Technical information is primarily used for security, troubleshooting, auditing, and maintaining the Application.

6. Information We Do Not Intentionally Collect Through the Let’s Support App

The Let’s Support App is not designed to intentionally collect sensitive personal information unrelated to customer support.

Sofred does not intentionally request or process sensitive categories of personal data through the Let’s Support App unless such processing is legally permitted or required and appropriate safeguards are applied.

Sensitive categories may include, for example:

  • Genetic data

  • Biometric data

  • Health information

  • Racial or ethnic information

  • Religious or political opinions

  • Information concerning sex life

  • Criminal conviction information

  • Security-related information

Where sensitive information is incidentally provided by a customer in connection with a support request, Sofred will handle it in accordance with applicable law and only to the extent reasonably necessary for the relevant purpose.

7. How We Collect Personal Data

Personal data may be obtained from:

7.1 Customers

Customers may provide information when they:

  • Register for Sofred services

  • Use Sofred applications

  • Contact customer support

  • Contact Sofred through WhatsApp

  • Submit a complaint

  • Report an incident

  • Request a refund

  • Ask for assistance

  • Submit documents or images

  • Communicate with Sofred personnel

7.2 Sofred systems

The Let’s Support App may retrieve relevant information from Sofred's internal systems, including:

  • Customer account systems

  • Ride management systems

  • Wallet/payment systems

  • Subscription systems

  • Support systems

  • Administrative systems

  • Vehicle management systems

7.3 Third-party services

Where applicable, personal data may be received through third-party services integrated with Sofred's systems, such as:

  • WhatsApp / Meta services

  • Payment service providers

  • Cloud infrastructure providers

  • Communication providers

  • Authentication services

  • Technical service providers

Such providers may process information according to their own privacy policies and contractual obligations.

8. WhatsApp and Meta

The Let’s Support App may use the WhatsApp Business Platform / WhatsApp Cloud API and services provided by Meta Platforms, Inc. to send and receive customer communications.

When a customer communicates with Sofred through WhatsApp:

  • The customer's WhatsApp phone number may be processed;

  • Messages sent to Sofred may be received by the Let’s Support App;

  • Sofred personnel may respond through the Let’s Support App;

  • Message content and metadata may be processed to provide customer support;

  • Conversation records may be retained where necessary for support, operational, legal, security, or compliance purposes.

WhatsApp and Meta may independently process certain information in accordance with their applicable terms and privacy policies.

Sofred does not sell WhatsApp customer conversations or personal information.

Access to WhatsApp conversations within Sofred systems is restricted to authorized personnel who require access for legitimate business purposes.

9. How We Use Personal Data

Sofred may use personal data for the following purposes:

Customer support

To:

  • Respond to inquiries;

  • Resolve customer complaints;

  • Investigate problems;

  • Provide assistance;

  • Follow up on support requests.

Service administration

To:

  • Review customer accounts;

  • Review ride activity;

  • Resolve wallet or payment issues;

  • Investigate refunds;

  • Assist with subscriptions;

  • Review vehicle-related issues.

Communication

To:

  • Send service-related communications;

  • Respond to WhatsApp conversations;

  • Provide customer assistance;

  • Send approved transactional or service messages.

Security

To:

  • Protect accounts;

  • Prevent unauthorized access;

  • Detect fraud;

  • Investigate abuse;

  • Monitor security events;

  • Maintain audit records.

Legal and regulatory compliance

To:

  • Comply with applicable laws;

  • Respond to lawful requests from authorities;

  • Establish, exercise, or defend legal claims;

  • Maintain records required by law.

Business operations

To:

  • Maintain support records;

  • Measure support performance;

  • Improve internal processes;

  • Train authorized support personnel;

  • Investigate recurring service problems;

  • Improve customer experience.

10. Legal Basis for Processing

Sofred will process personal data in accordance with applicable law.

Depending on the circumstances, processing may be based on:

  • The data subject's explicit consent;

  • Performance of a contract or provision of requested services;

  • Compliance with a legal obligation;

  • Protection of legitimate operational or security interests where permitted by applicable law;

  • Protection of vital interests where applicable;

  • Other lawful grounds recognized by applicable Omani law.

Where consent is required, Sofred will seek consent in a clear and understandable manner.

11. Access Controls

Sofred uses role-based access principles to limit access to personal data.

Authorized personnel should only access information necessary to perform their assigned duties.

Depending on the user's role, access may be restricted to:

  • Customer support;

  • Customer communications;

  • Ride information;

  • Payment/wallet information;

  • Operational information;

  • Administrative functions;

  • WhatsApp functionality.

Sofred may maintain access logs and audit records to identify actions performed within the Let’s Support App.

12. Confidentiality

All authorized users of the Let’s Support App are expected to maintain the confidentiality of information accessed through the Application.

Personnel must not:

  • Share customer information outside authorized business channels;

  • Download or copy customer information unnecessarily;

  • Use customer information for personal purposes;

  • Access customer information without a legitimate business reason;

  • Share screenshots or conversations with unauthorized persons;

  • Use customer information for personal communications;

  • Sell or otherwise commercially exploit customer information.

Unauthorized access or use may result in disciplinary action, suspension of access, termination of employment or contract, and/or legal action where appropriate.

13. Data Sharing and Disclosure

Sofred may disclose personal data only where reasonably necessary and permitted by applicable law.

Potential recipients may include:

Sofred personnel

Authorized employees and personnel who need the information to perform their duties.

Service providers

Third-party providers that support Sofred's operations, such as:

  • Cloud infrastructure providers;

  • Software providers;

  • Communication providers;

  • WhatsApp/Meta services;

  • Payment providers;

  • Technical service providers;

  • Security providers.

These providers may process personal data on Sofred's behalf and are expected to implement appropriate confidentiality and security measures.

Authorities

Sofred may disclose information to government authorities, regulators, law enforcement, courts, or other authorized entities where required or permitted by law.

Professional advisers

Where necessary, Sofred may disclose relevant information to:

  • Lawyers;

  • Auditors;

  • Accountants;

  • Insurers;

  • Professional advisers.

Only information reasonably necessary for the relevant purpose should be disclosed.

Sofred does not sell personal data.

14. International Data Transfers

Some service providers used by Sofred may process or store information outside the Sultanate of Oman.

This may occur where Sofred uses international technology, cloud, communication, payment, or software providers.

Where personal data is transferred outside Oman, Sofred will implement the safeguards and procedures required by applicable Omani law and regulations.

15. Data Security

Sofred takes reasonable technical and organizational measures to protect personal data against:

  • Unauthorized access;

  • Unauthorized disclosure;

  • Accidental loss;

  • Destruction;

  • Alteration;

  • Unauthorized processing;

  • Misuse.

Security measures may include:

  • Authentication;

  • Role-based access controls;

  • Access restrictions;

  • Encryption where appropriate;

  • Secure communications;

  • Audit logs;

  • Monitoring;

  • Administrative controls;

  • Employee confidentiality obligations;

  • Access revocation procedures;

  • Security reviews;

  • Backup and recovery procedures.

No electronic system can be guaranteed to be completely secure. However, Sofred continuously works to reduce security risks and improve its security controls.

16. Data Breaches and Security Incidents

If Sofred becomes aware of a personal data breach that requires notification under applicable law, Sofred will assess the incident and take appropriate action.

Depending on the circumstances, this may include:

  1. Identifying and containing the incident;

  2. Assessing the affected systems and information;

  3. Taking measures to prevent further unauthorized access;

  4. Investigating the cause;

  5. Documenting the incident;

  6. Notifying the relevant authorities where legally required;

  7. Notifying affected data subjects where legally required;

  8. Taking corrective and preventive measures.

17. Data Retention

Sofred retains personal data only for as long as reasonably necessary for the purpose for which it was collected, unless a longer period is required or permitted by law.

Retention periods may depend on:

  • The type of information;

  • The purpose for which it is processed;

  • Customer support requirements;

  • Accounting requirements;

  • Legal obligations;

  • Dispute resolution;

  • Security requirements;

  • Fraud prevention;

  • Regulatory requirements;

  • Contractual requirements.

When information is no longer required, Sofred may:

  • Delete it;

  • Anonymize it;

  • Aggregate it; or

  • Securely archive it where legally required.

Because support cases, financial records, legal claims, and security records may have different retention requirements, not all information will necessarily be deleted at the same time.

18. Data Subject Rights

Subject to applicable law and relevant exceptions, individuals may have the right to:

  • Know whether their personal data is being processed;

  • Request access to their personal data;

  • Obtain a copy of their personal data;

  • Request correction of inaccurate information;

  • Request updating of information;

  • Request blocking or restriction where applicable;

  • Request deletion where legally applicable;

  • Withdraw consent where processing is based on consent;

  • Request transfer of personal data where applicable;

  • Receive information regarding certain processing activities;

  • Lodge a complaint regarding the processing of their personal data.

19. How to Submit a Privacy Request

To exercise a privacy right or ask a privacy-related question, contact:

Email: admin@sofredmobility.com

Subject line:

Privacy Request – Sofred Support App

To protect personal information, Sofred may need to verify the identity of the requester before fulfilling certain requests.

Sofred may decline or limit a request where permitted or required by applicable law, including where retention is necessary for legal, regulatory, security, accounting, fraud-prevention, or dispute-resolution purposes.

20. Employee and Internal Staff Data

Because the Support App is an internal business application, it may process information relating to Sofred employees and authorized personnel.

This may include:

  • Name;

  • Work contact details;

  • Employee or user identifier;

  • Role;

  • Department;

  • Application permissions;

  • Login information;

  • Access records;

  • Audit logs;

  • Actions performed in the Application;

  • Security-related information.

Such information is used to:

  • Provide application access;

  • Manage permissions;

  • Maintain security;

  • Audit system activity;

  • Investigate incidents;

  • Maintain internal operations.

Processing of employee information will be conducted in accordance with applicable Omani law and Sofred's internal policies.

21. Children

The Support App is an internal business application and is not intended for use by children.

Sofred does not knowingly provide Support App accounts to children.

Where Sofred processes personal data relating to a child through customer services, such processing will be handled in accordance with applicable law and appropriate safeguards.

22. Cookies and Similar Technologies

The Support App may use technical mechanisms necessary to:

  • Maintain secure sessions;

  • Authenticate authorized users;

  • Maintain application functionality;

  • Prevent unauthorized access;

  • Monitor technical performance;

  • Detect errors and security events.

The Support App does not use personal data collected through these mechanisms for unrelated advertising purposes.

23. Third-Party Services

The Support App may integrate with third-party services.

These may include, depending on the Application configuration:

  • Meta / WhatsApp Business Platform;

  • Cloud hosting services;

  • Authentication providers;

  • Database services;

  • Payment-related systems;

  • Communication services;

  • Analytics or monitoring tools;

  • Other technology providers required to operate the Application.

Third-party providers may process information according to their own terms and privacy policies.

Sofred seeks to use reputable providers and, where applicable, establish appropriate contractual and security arrangements.

24. No Sale of Personal Data

Sofred does not sell, rent, or commercially trade personal data belonging to customers or employees.

Personal data may be shared with service providers and other recipients only where reasonably necessary for legitimate business, operational, legal, security, or service-related purposes and in accordance with applicable law.

25. Marketing Communications

The Support App is primarily an operational and customer-support tool.

It is not intended to be used as a general-purpose marketing database.

Where Sofred sends commercial or marketing communications, it will do so in accordance with applicable law and required consent mechanisms.

26. Changes to This Privacy Policy

Sofred may update this Privacy Policy from time to time to reflect:

  • Changes to the Support App;

  • Changes to Sofred's services;

  • Changes to technology;

  • Changes to applicable law;

  • Changes to third-party integrations;

  • Changes to data-processing practices.

When the policy is updated, the Last Updated date at the beginning of this document will be changed.

Where required by law, Sofred will provide additional notice or obtain consent for material changes.

27. Governing Law

This Privacy Policy is governed by the applicable laws and regulations of the Sultanate of Oman.

Any dispute relating to the processing of personal data will be handled in accordance with applicable Omani law and the jurisdiction of the competent authorities and courts of Oman, subject to applicable mandatory rights and procedures.

28. Contact Us

If you have any questions regarding this Privacy Policy or the processing of personal data through the Support App, contact:

Sofred Mobility

Legal Entity: Silver Sign for Business SPC
Trade Name: Sofred Mobility
Commercial Registration: 1419381
Address: Al-Aqur, Nizwa, Sultanate of Oman
P.O. Box: 1561
Email: admin@sofredmobility.com
Telephone / WhatsApp: +968 7749 8918

Privacy requests:
admin@sofredmobility.com

Last Updated: 4 October 2026