Template notice for the site owner: this is a working draft covering UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection and, where relevant, GDPR. Replace every [BRACKETED] field and have it reviewed by a UAE-qualified lawyer before launch. Delete this box when you publish.
1. Who we are
Safr ("we", "us") is operated by [COMPANY NAME], a company registered in [FREE ZONE / EMIRATE], United Arab Emirates, under trade licence [LICENCE NUMBER], with a registered address at [ADDRESS].
We are the data controller for the information described here. For anything about your data, email [PRIVACY EMAIL].
2. What we collect
Information you give us
- Email address — when you join the waitlist, subscribe to alerts, or contact us.
- Alert preferences — which UAE airports you will fly from, which regions or routes you want watched, and your alert frequency settings.
- Name and message content — only if you use the contact form.
- Invite code — if you were referred, we record which code was used so we can credit the member who referred you.
Information collected automatically
- Usage data — pages viewed, deals opened, and which deal links you click. We use this to work out which routes are worth watching more closely.
- Technical data — IP address, browser type, device type, approximate city-level location, and referring page.
- Email engagement — whether an alert was opened and which link was clicked.
What we never collect: we do not take payment card details, passport or Emirates ID numbers, or any booking details. We are not part of your transaction with the airline, so we never see it.
3. Why we collect it, and our legal basis
- To send you deal alerts — on the basis of your consent, given when you subscribe. You can withdraw it at any time.
- To match deals to your preferences — so you only receive alerts for airports and regions you chose. Necessary to provide the service you asked for.
- To operate and improve the service — understanding which deals get opened tells us which routes to prioritise. Our legitimate interest in running a useful product.
- To answer you — when you contact us. Necessary to respond to your request.
- To prevent abuse — detecting bulk signups, fake invite codes and automated scraping. Our legitimate interest in protecting the service.
- To meet legal obligations — where UAE law requires us to retain or disclose information.
4. Who we share it with
We do not sell your personal data. We never have and we will not. We share it only with service providers who help us run Safr, and only to the extent they need:
- Email delivery — [PROVIDER, e.g. Resend / Brevo], to send alerts and replies.
- Hosting and database — [PROVIDER, e.g. Supabase / Vercel], where the site and your preferences are stored.
- Analytics — [PROVIDER], to measure site usage. Only if you accept analytics cookies.
- Messaging — if you join our WhatsApp channel, that relationship is with WhatsApp and is governed by their privacy policy. Broadcast channels do not reveal your number to us.
We may also disclose information where required by UAE law, a court order, or a lawful request from a regulator or authority.
Affiliate links: when you click through to an airline or booking site, that site sets its own cookies and collects its own data under its own policy. We receive only aggregate confirmation that a booking occurred — never your booking details, passenger names or payment information.
5. How long we keep it
- Subscriber data — for as long as you are subscribed, then deleted within 90 days of you unsubscribing.
- Waitlist entries — up to 24 months, then deleted if you have not joined.
- Contact form messages — 24 months, so we can pick up an old thread.
- Analytics data — aggregated after 14 months and no longer linked to you.
6. Your rights
Under UAE Federal Decree-Law No. 45 of 2021 (and GDPR if you are in the EU/UK) you can:
- Ask what we hold about you and get a copy
- Correct anything inaccurate
- Have your data deleted
- Withdraw consent to alerts at any time — one click in any email
- Object to processing, or ask us to restrict it
- Request your data in a portable format
- Complain to the UAE Data Office, or your local supervisory authority
Email [PRIVACY EMAIL] with the subject "Data request". We respond within 30 days and never charge for it.
7. Security
Data is encrypted in transit (HTTPS) and at rest. Access to the subscriber database is limited to team members who need it and protected by multi-factor authentication. No system is perfectly secure — if a breach affects your data, we will notify you and the relevant authority as required by law.
8. International transfers
Some of our providers store data outside the UAE (typically the EU or United States). Where that happens we rely on providers offering an adequate level of protection and appropriate contractual safeguards. You can ask us which providers hold what.
9. Children
Safr is not intended for anyone under 18 and we do not knowingly collect data from children. If you believe a child has given us their information, contact us and we will delete it.
10. Changes and contact
If we change this policy materially we will email subscribers before it takes effect. The date at the top always reflects the current version.
Questions: [PRIVACY EMAIL] · contact form