Compliance and Regulation
Saudi regulatory map for Mahalli — ZATCA e-invoicing and VAT, SAMA and BNPL, PDPL, commercial registration, e-commerce, messaging, advertising, sensitive sectors, and security — plus the decisions that must be made before code.
05 — Compliance and regulation (Saudi Arabia)
Rule: no compliance or data-residency claim is published without verification. Every row below must be verified with the authority or the provider before it is used in marketing.
| Area | Authority | What concerns us | Decision / action |
|---|---|---|---|
| E-invoicing (Fatoora) phase 2 | ZATCA | Every payment issues a simplified invoice: QR TLV, signed XML, integration (Clearance / Reporting) according to the merchant's wave | The core generates the simplified invoice; signing and submission run in a container; a licensed Solution Provider partner is an open decision |
| VAT 15% | ZATCA | Prices are VAT-inclusive; the VAT number appears on the invoice | vatNumber on the organization is mandatory if the merchant is VAT-registered |
| Payments | SAMA | The platform is not a payment service provider; it holds no funds and settles nothing | Licensed PSP + sub-merchant model (ADR-0003) |
| BNPL (Tabby / Tamara) | SAMA | Both are licensed; the merchant contracts with them (directly or via the PSP) | The platform only facilitates onboarding and integration; it offers no financing |
| Personal Data Protection Law (PDPL) | SDAIA | Consent, purposes, data-subject rights, cross-border transfer, processing register | PII classification, encryption, an Arabic privacy notice for every merchant site, database region is an open decision |
| Commercial registration | Ministry of Commerce / Wathq | Verify the CR and the activity | Wathq API at signup |
| E-commerce | Ministry of Commerce | Merchant sites fall under the E-Commerce Law (disclosure data, returns) | A default policy template for every site + optional Maroof verification |
| SMS | CST | Sender-name registration, anti-spam, sending hours | Saudi provider (Unifonic / Msegat via @repo/sms), mandatory opt-in |
| WhatsApp Business API | Meta | Approved templates, 24-hour window | Through an approved BSP |
| Advertising | Ministry of Commerce / GCAM | No misleading ads, discount permits | AI check before publishing + marketing-copy-auditor |
| Advertising on platforms | Google / Snap / TikTok / Meta | API policies, app review, rate limits | Every integration behind packages/integrations/* with per-tenant rate guards |
| Sensitive sectors | SFDA / Ministry of Health | Clinics and pharmacies have content and advertising requirements | Sector Packs carry content restrictions; pharmacies are out of scope for now |
| Security | NCA (guidance) | Essential cybersecurity controls | CSP, WAF, MFA for the owner, audit log |
Critical points that need a decision before code
- PSP partner (Moyasar / HyperPay / Geidea / PayTabs): determines Tabby / Tamara / mada / Apple Pay support, the partner programme, and the referral share.
- ZATCA path: build in-house as a certified Solution Provider, or partner.
- Data region: a Postgres provider with a region inside the Kingdom or the nearest one, and its effect on PDPL and marketing promises.
Business Model
Revenue channels, plans priced in SAR, the revenue model at 1,000 paying merchants, variable costs, and the revenue impact of each module — all figures are modelling assumptions with stated confidence.
Roadmap
Phased roadmap by deliverable, with a measurable exit criterion per phase — from the supastarter foundation through the wedge, presence, ads, marketplace, and scale — and what we will not build.