Privacy Policy
Last updated: 3 October 2026
This policy explains what personal data Kite collects when you use the kite.sa website and the Kite iOS app, why we collect it, who we share it with, how long we keep it, and the rights you have under Saudi Arabia's Personal Data Protection Law (PDPL).
In short
- You can search and browse listings without an account.
- If you sign in, we keep your email address, what you save, and your alert settings, so they sync between the website and the app.
- We don't sell your personal data. The iOS app contains no analytics or advertising SDKs and doesn't track you.
- You can delete your account in the app or on the website at any time, and it takes effect immediately.
Who we are
Kite is a service operated by Founderproof, Inc., a Delaware corporation ("Kite", "we", "us"). We decide how and why your personal data is processed, which makes us the controller of that data. Our address is 2810 N Church St STE 90880, Wilmington, DE 19802, USA, and our phone number is +1 839 222 5418. You can also reach us at any time at the email address at the end of this policy.
What we collect
We collect only what we need to run Kite. Nothing is required to browse. To create an account you must give an email address or sign in with Google or Apple; everything else is optional, or is created as you use Kite:
- Account details. Your email address. If you continue with Google, we also receive your name and profile picture from Google. If you sign in with Apple, we receive your name if you choose to share it, and either your email address or an Apple private relay address if you choose to hide it. We keep the sign-in tokens Google or Apple issue so your account stays linked to them.
- Sign-in sessions. When you sign in we create a session and record the IP address and browser or device type it came from, to keep you signed in and protect your account. On the website the session is a cookie; in the app it is a token stored in the iOS Keychain.
- Saved listings and recently viewed. Listings you save and the last 20 listings you viewed while signed in, so you can find them again on any device. When you're signed out, the website keeps these only in your browser's local storage.
- Saved searches and alerts. The filters, name, language and frequency of each saved search, your choices for each alert type by channel (email or push), and a record of the alerts we've sent you so we don't send the same one twice.
- Push notifications (app). If you allow notifications, the push token Apple assigns to your device, plus the app version, language and whether the token is for testing or production. We use them to send the alerts you turned on and, unless you turn off “News and picks” in the app, occasional news and picks from Kite. This applies whether or not you're signed in.
- Location (app). The app asks for your location only when you tap "My location", and uses it on your device to center the map. Your coordinates are never sent to us. As with any map search, we do receive the map area you're looking at so we can load the listings in it. The website does not access your location.
- Website usage. On the website we use PostHog to record how the site is used: pages viewed, searches and filters, listings opened, and the referring site or campaign. When you're signed in, these events are linked to your account ID, email address and name. Vercel Web Analytics and Speed Insights measure visits and page performance without cookies.
- App usage. The app has no analytics SDK. Our servers record a few service events, such as a saved search being created, which are linked to your account ID.
- Advertising measurement (website only). We use the Reddit Ads pixel on the website to measure our Reddit ad campaigns. It tells Reddit when someone visits a page, searches, views a listing (with the listing ID, property type and neighborhood) or creates an account. We don't send your email address or name to Reddit. The pixel does not run in the iOS app. It runs only if you choose Allow in the cookie banner; until then nothing is sent to Reddit.
- Feedback. If you answer the website's feedback prompt, your rating and any comment you write.
- Email. Messages you send us, and delivery information about emails we send you (such as bounces and spam complaints), so we stop emailing addresses that bounce or complain.
- Technical logs. Like any online service, our hosting and network providers process your IP address, browser or device type and the pages or data you request, to deliver the service and protect it from abuse.
How we use it
- To provide Kite: your account, syncing what you save, and showing listings and market data.
- To send the emails and push notifications you ask for, such as sign-in links and new-listing or price-drop alerts.
- To understand how Kite is used and fix problems.
- To measure whether our ads on Reddit bring people to the website, only if you allow advertising cookies.
- To keep Kite secure, prevent abuse, and meet our legal obligations.
We process your data to provide the service you ask for, with your consent where it's required (for example push notifications, location permission and optional product news), or where it's necessary for our legitimate interests in keeping Kite secure and working, as the PDPL allows.
What we don't do
We don't sell your personal data or rent it out. The iOS app doesn't track you across other companies' apps or websites, doesn't use Apple's advertising identifier (IDFA), and contains no advertising SDKs. We don't send marketing email unless you choose to receive product news, and every marketing email has an unsubscribe link.
Listing data from other platforms
Kite collects property ads that were posted publicly on other Saudi real-estate platforms and shows them with a link to the original ad. Some ads include the advertiser's name and phone number. We show an advertiser's contact details only when the advertiser is a broker or advertiser licensed by the Real Estate General Authority (REGA); for other ads, contact the advertiser through the original platform.
If an ad is about you or shows your details, tap "Report / request removal" on the listing, on the website or in the app, or email us. We can remove just your contact details or the whole ad. A removal also covers future ads with the same phone number, so your details don't come back when the source is checked again. We aim to act on removal requests within 3 business days.
Where your data is stored
Our servers and most of our providers are in the United States, so your data is transferred outside Saudi Arabia. These transfers are necessary to provide the service you ask for, and we make them as the PDPL and its regulations permit, with safeguards that include encryption in transit and at rest and contractual obligations on each provider.
How long we keep it
- Your account, saved listings, saved searches, alert settings and alert history: until you delete them or your account.
- Recently viewed: only your last 20 listings.
- Sign-in sessions expire after 7 days without use. Sign-in links expire after 5 minutes.
- Push tokens: kept while notifications are allowed, signed in or not. Signing out detaches the token from your account, deleting your account deletes the record linked to it, and a token is marked inactive once Apple reports the app was removed.
- Do-not-email list and email send log: we keep a record of addresses that bounced, complained or unsubscribed so we never email them again, and a log of when alert emails were sent, which we use to limit how many you get. The send log is deleted with your account.
- Analytics events: kept by PostHog under our account settings. When you delete your account, your PostHog profile and its events are deleted too.
- Technical logs: kept by our hosting providers for a short period for security and troubleshooting.
Deleting your account
You can delete your account yourself at any time: in the iOS app under Profile → Delete account, or on the website by signing in and choosing Account → Delete account from the account menu (kite.sa/settings/account).
Deletion is immediate and permanent. It removes your account, its sign-in links to Google or Apple, your sessions, saved listings, recently viewed, saved searches, alert settings, alert history and push tokens. If you signed in with Apple, we also revoke Kite's access to your Apple ID. It also deletes the log of emails we've sent to your address, your analytics profile and its events in PostHog, and your contact in our mailing list at Resend.
If you can't sign in, email us from the address on your account and we'll delete it within 30 days, usually much sooner.
We keep only a do-not-email entry for your address if it bounced, complained or unsubscribed, so we never email it again. Copies in our database provider's backups expire on their normal backup cycle.
Your rights
Under the PDPL you have the right to:
- Know what data we collect and why (this policy).
- Get access to your personal data and a copy of it in a readable format.
- Have inaccurate or incomplete data corrected.
- Have your data deleted when we no longer need it, or when you ask.
- Withdraw your consent at any time.
You can also act directly: turn alerts off on the Alerts settings page on the website or under Profile → Alerts in the app, turn off push notifications in the app or in iOS Settings, use the unsubscribe link in any alert or marketing email, and turn off location access in iOS Settings. For anything else, email us. We'll reply within 30 days. If you're not satisfied with our response, you can complain to the Saudi Data & AI Authority (SDAIA).
Security
Data is encrypted in transit (TLS) and at rest. We don't use passwords: you sign in with a one-time email link, Google or Apple. Access to production systems is limited to the people who run Kite. If a breach affects your data, we'll notify you and the authorities as the law requires.
Children
Kite is for people looking to rent or buy property. It isn't directed at children, and we don't knowingly collect personal data from anyone under 18. If you think a child has given us their data, email us and we'll delete it.
Developer platform and API
If you use the Kite API, the developer platform at platform.kite.sa, or connect an AI assistant to Kite, your organization's data and request logs are covered by the API Terms of Use, the Security page and the subprocessor list on platform.kite.sa.
Changes to this policy
We'll update this page when our practices change and revise the date at the top. If a change is significant, we'll tell you by email or in the app before it takes effect. This policy is published in Arabic and English; if the two differ, the Arabic text applies. Versions in other languages are automated translations provided for convenience only.
Contact us
For questions about this policy, or to exercise any of your rights, email us at: [email protected]