LEGAL · LAST UPDATED 4 AUGUST 2026
Privacy Policy
What personal data this site collects, which is almost none; the one cookie it sets, which readers never receive; who else touches it; and how to exercise your rights under the Saudi PDPL, the UAE PDPL and the GDPR.
Data controller
RiyadhCargo.com
Reader data collected
An email address, only if you subscribe
Analytics & trackers
None — no scripts on public pages
Cookies set for readers
None (one admin-only session cookie)
Sold or shared for marketing
Never
Last updated
4 August 2026
Who this policy covers, and who is responsible
This policy explains how RiyadhCargo.com (“we”, “us”, “this service”) handles personal data when you read this website, follow a link from it, or subscribe to the Morning Manifest. For that processing, RiyadhCargo.com is the data controller — the party that decides why personal data is processed and how.
RiyadhCargo.com is an independent news monitoring service for the cargo, freight and logistics industry, with a Saudi-first focus. It is not a cargo company, carrier, freight forwarder, customs broker or logistics provider, and it is not affiliated with any airline, port authority or operator it reports on. That matters here for one practical reason: we have no shipments, no consignees and no commercial counterparties, so there is no operational personal data for this site to hold. See About and Terms of Service.
For any privacy matter, write to info@riyadhcargo.com with “Privacy” in the subject line. It reaches the same newsdesk inbox as everything else, which is a one-person operation, not a ticketing system — which is also why a clear subject line gets you a faster answer.
The short version
We run no analytics. We run no advertising trackers. We set no cookie on a reader’s browser. We do not sell, rent, trade or share personal data for anyone else’s marketing. The only personal data we ever hold about a reader is an email address — and only if you asked us to send you the Morning Manifest, confirmed it by clicking a link, and have not since unsubscribed.
Everything below is the detail behind those five sentences. None of it is aspirational: every public page on this site ships zero client-side JavaScript, which means there is nothing on the page capable of reading your device, fingerprinting your browser or following you to another site. The privacy position is a property of how the site is built, not a promise about how it is operated.
What we collect
Information you give us directly
- Email address
- Collected only when you submit the Morning Manifest signup form. Nothing else on this site asks for one.
- Subscription record
- Your address, the list, whether the subscription is pending, active or unsubscribed, a random confirmation token, and the dates you signed up, confirmed and (if applicable) unsubscribed.
- Correspondence
- Whatever you choose to put in an email to the newsdesk — a story tip, a correction, a complaint, a commercial enquiry — and the address it came from.
The signup form carries one hidden field that no human can see or fill. If it arrives filled, the submission is treated as automated and discarded without being stored. That is an anti-spam measure, not a tracking measure, and it records nothing about you.
Information collected automatically
Like every website, this one is delivered over HTTP, and the request that fetched this page reached our infrastructure provider carrying your IP address, the URL you asked for, the time, your browser’s user-agent string and, where your browser chooses to send one, a referring page. That is a technical necessity of the protocol, not a decision we made.
Cloudflare processes that request data as our hosting, CDN and security provider, for delivery, caching and attack mitigation, under its own retention policy. We do not extract it, we do not keep copies of it, we operate no analytics product on this site, and we do not join it to any other record. There is no reader profile here because there is nothing from which to build one.
One narrow exception, stated in full: failed sign-in attempts to the private administrator panel are counted against the IP address they came from, for fifteen minutes, purely to defeat password guessing. The counter is a number, it expires automatically, and no member of the public ever reaches the page that increments it.
What we do not collect
- Your name, postal address or telephone number.
- Payment card or bank details — nothing on this site is for sale to readers, and there is no checkout.
- Precise location, device identifiers or a browser fingerprint.
- A behavioural, interest or reading-history profile of any kind.
- Any special-category or sensitive personal data — health, biometrics, religion, political opinion, trade union membership, sexual orientation, criminal record or national ID number. We have no purpose for any of it and no field in which to put it.
Why we process personal data, and on what legal basis
| Purpose | Data used | Legal basis |
|---|---|---|
| Sending the Morning Manifest | Email address; subscription status | Consent — opt-in, confirmed by link. Withdrawable at any time. |
| Confirming a signup, so nobody can subscribe an address they do not own | Email address; one-time token | Consent; and our legitimate interest in not emailing people who never asked. |
| Answering your email | Your address and whatever you wrote | Legitimate interest in responding to correspondence addressed to us. |
| Serving pages, caching them and defending the site from attack | Technical request data at the CDN | Legitimate interest in operating and securing the service. |
| Protecting the administrator account from password guessing | IP address of failed sign-ins, for 15 minutes | Legitimate interest in the security of the service. |
| Meeting a legal obligation, or answering lawful process | Whatever is legally required | Legal obligation. |
“Legal basis” is the language of the EU and UK GDPR and of Saudi Arabia’s Personal Data Protection Law as amended in 2023, which recognises legitimate interest alongside consent. Where you are in a jurisdiction that requires consent for a purpose listed above as legitimate interest, we treat consent as the basis for that purpose and you may withdraw it.
We do not process personal data for any purpose that is not on this table. If a new purpose ever arises, this table changes before the processing starts, not after.
International transfers
This site runs on a global edge network. A page is served from whichever data centre is nearest you rather than from one fixed location; subscriber records sit in distributed key-value storage; email is delivered through a provider that operates internationally. Personal data may therefore be processed outside the country you are reading from, including in the European Union and the United States.
Where a transfer is subject to Saudi Arabia’s Personal Data Protection Law and its Transfer Regulations, the UAE’s Federal Decree-Law No. 45 of 2021, the EU GDPR or the UK GDPR, we rely on our providers’ contractual safeguards — Standard Contractual Clauses and equivalent data processing terms — together with the technical measures described below.
It is worth being blunt about the scale of this: the only reader data that ever crosses a border is an email address you gave us so that we could send you an email to it.
How long we keep it
- Confirmed subscriber
- For as long as the subscription is live — until you unsubscribe, or until the Morning Manifest is discontinued.
- Unconfirmed signup
- Held only so that the confirmation link works. An address that is never confirmed is never sent an edition, and is cleared on request.
- Unsubscribed record
- We keep a minimal suppression record — the address and the fact that it opted out — so that an unsubscribe cannot be silently undone by a later import or mistake. Ask us and we will delete it outright, on the understanding that the suppression goes with it.
- Email correspondence
- For as long as needed to deal with the matter, and thereafter where it forms part of the record of a published correction.
- Failed sign-in counters
- Fifteen minutes, then automatic expiry. Nothing survives it.
- CDN and server logs
- Under our infrastructure provider’s own retention policy. We neither extract nor retain copies.
Your rights, and how to use them
Depending on where you are, you have some or all of the following rights. We apply them to everyone, wherever they are, because drawing a line through our readership on the basis of geography would cost more effort than simply honouring the request.
- Access — to be told whether we hold personal data about you, and to get a copy of it.
- Rectification — to have inaccurate data corrected and incomplete data completed.
- Erasure — to have your data deleted where we no longer have a basis to hold it.
- Restriction — to have processing paused while a dispute about accuracy or basis is resolved.
- Objection — to object to processing carried out on the basis of legitimate interest.
- Portability — to receive the data you gave us in a structured, machine-readable form.
- Withdrawal of consent — at any time, without giving a reason and without affecting the lawfulness of what was done before.
- Not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We make no such decisions — see section 15.
- Complaint — to a supervisory authority, at any time.
How to exercise them. Email info@riyadhcargo.com from the address concerned, or tell us plainly which address it is. We will answer within 30 days — the deadline set by the Saudi PDPL Implementing Regulations, and shorter than the one month plus extension the GDPR allows. If a request needs genuinely unusual effort we may extend once, and we will tell you before the first 30 days are up rather than after.
We may need to satisfy ourselves that a request comes from you. Ordinarily, sending it from the subscribed address is enough. We will not demand identity documents from someone whose entire relationship with this service is a free newsletter: that would collect far more personal data than the request itself concerns, which is the opposite of the point.
If you think we have got it wrong, tell us first — it is faster, and we would rather fix it than defend it. But you do not have to. You may complain directly to the Saudi Data & Artificial Intelligence Authority (SDAIA) in the Kingdom, the UAE Data Office in the Emirates, the Information Commissioner’s Office in the United Kingdom, or your own supervisory authority in the EU or EEA.
Email, marketing and unsubscribing
The Morning Manifest is opt-in and double opt-in: you ask for it, we email a confirmation link, and nothing is sent until you click it. An address that is entered by somebody else therefore never receives anything but a single confirmation email it can ignore.
Every edition carries a working unsubscribe link, and we support one-click unsubscribe to RFC 8058, so the unsubscribe button built into Gmail and Yahoo works directly. Unsubscribing takes effect immediately and needs no reason, no login and no reply from us.
We do not send third-party marketing. We do not mail on anyone else’s behalf. We do not add subscribers to any other list, and there is no other list. Where a future edition carries a sponsored placement it will be labelled inside the email, and it will still be our email — not a rented send.
Security
- The whole site is served over HTTPS, with the www and trailing-slash forms canonicalised in a single redirect so nothing lands on an unexpected host.
- Administrator passwords are stored as PBKDF2-SHA-256 derivations, 100,000 iterations, with a per-account salt. The password itself is never stored, logged or recoverable — a reset issues a new one, it does not reveal the old one.
- Session cookies are HttpOnly, Secure and SameSite=Lax; sign-in is rate-limited per IP address; changing the password revokes every existing session.
- Password comparison is constant-time, so a wrong guess reveals nothing about how wrong it was.
- Public pages ship no client-side JavaScript and load no third-party script, which removes an entire class of injection, supply-chain and third-party tracking risk rather than mitigating it.
No system is perfectly secure and we will not claim otherwise. Transmission over the internet carries risk that no operator can eliminate. If we become aware of a personal data breach affecting you, we will notify the competent regulator within 72 hours where the law requires it — as both the Saudi PDPL and the GDPR do — and tell the people affected without undue delay, in plain language, whether or not we are obliged to.
Children
This is a trade publication for logistics professionals. It is not directed at children, it is not designed to appeal to them, it carries nothing of interest to them, and we have no use whatsoever for their personal data.
We do not knowingly collect personal data from anyone under 13, or under the higher age of digital consent set by local law where one applies — 16 in a number of jurisdictions. The only route by which a child could give us anything is by typing an email address into the newsletter form, and we have no way of knowing an age from an address.
If you believe a child has given us personal data, write to info@riyadhcargo.com and we will delete it. We will not ask you to prove anything first.
Other sites we link to
Every headline on this site links out to the publisher who reported it — that is the entire premise of a monitoring service. The moment you follow one, you are on someone else’s website, governed by their privacy policy, their cookies and their trackers, not ours.
We have no control over what they collect and take no responsibility for it. The same applies to official sources, data authorities, social profiles and any sponsored placement. If a publisher’s practices concern you, their policy is the document to read, and it is one click from the headline.
Do Not Track and Global Privacy Control
There has never been an agreed standard for how a publisher should answer a Do Not Track header, and Global Privacy Control is a signal to stop something we do not start. We do not track readers, so there is nothing for either signal to switch off.
We honour both by construction rather than by promise, which is the only version of that promise worth making.
Automated decision-making and profiling
There is none. Nothing on this site makes a decision about you, automated or otherwise, and nothing here produces a legal or similarly significant effect on anybody.
Story selection is applied to stories, not to readers: the wire is filtered by subject — region, mode, desk — and every reader sees the same one. There is no personalisation layer, no recommendation engine and no per-reader ranking. It would need data we do not have.
Changes to this policy
We may update this policy, because the law changes or because the service does. The current version always lives at this URL, and the “last updated” date at the top of the page is the authoritative one.
A change that materially affects subscribers will be flagged in the Morning Manifest before it takes effect. We will not apply a material change retrospectively to data already collected under an earlier version without a fresh legal basis for doing so.
How to contact us
Every privacy question, request, objection or complaint goes to the same place: info@riyadhcargo.com. Put “Privacy” in the subject line. The contact page has the other newsdesk routes — tips, corrections and commercial enquiries — if your question is not about personal data.
RiyadhCargo.com · independent cargo and freight news monitoring for the Middle East · publishing under this name since 2024 · last updated 4 August 2026.