Privacy Policy
1. Who is responsible for your data
The controller of your personal data is OWNER-ACTION: legal entity name, registered address and licence number ("Rotspit"). This policy explains how we handle personal data under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021).
2. Data we collect
- Account: email address, password (stored hashed by our authentication provider), sign-in events, your 18+ confirmation and the versions of our terms you accepted. If you sign in with Apple or Google, the name and email address the provider shares with us.
- Profile: name, username, photo, bio, language, birthday or occasion dates you choose to add.
- Addresses, including recipient data: delivery names, phone numbers and addresses, which may belong to the person receiving a gift.
- Payments: card details are collected directly by Stripe. We receive a token, card brand, last four digits, expiry month and year, and payment status. We never see or store your full card number or CVC.
- Contributions and gifts: pledges, amounts, messages, anonymity choice, payment authorisations you accepted (text, time, IP address, browser or app details, device platform), orders, deliveries and returns.
- Social: friends, friend requests, wishlists and what you choose to share. If you share your profile link, anyone with the link can see your public profile and the gifts you marked as shared; a private wishlist is never shown.
- Contact matching (only if you opt in): when you choose to find friends from your contacts, the app turns each phone number and email address into a one-way SHA-256 hash on your device and sends only those hashes. We compare them with the hashes of people who turned on “Let contacts find me” and return the matching public profiles. We never receive or store your contacts’ names, numbers or addresses. If you turn on “Let contacts find me”, we keep hashes of your own email address and phone number for matching until you turn it off or delete your account.
- Product search: the search text and product links you enter to find items.
- Devices and notifications: push notification tokens, device platform, app version, notification preferences.
- Logs and security: request logs, a salted hash of your IP address for rate limiting and fraud prevention, error reports.
- Product analytics (only if you opt in): the screens you visit (by page type, not their content), key actions in the app, a pseudonymous user id, device model, operating system and app version.
- Waitlist: email address and marketing preference if you join the waitlist on our website.
3. Why we use it and our legal bases
| Purpose | Legal basis |
|---|---|
| Provide your account, wishlists, pledges, purchases and deliveries | Performance of our contract with you |
| Place card holds and charge pledges under your payment authorisation | Contract; your explicit consent to the authorisation |
| Share recipient details with retailers and carriers to deliver a gift | Contract; legitimate interest of the recipient in receiving the gift |
| Service and transactional notifications | Contract |
| Marketing emails and waitlist updates | Consent (you can withdraw at any time) |
| Product analytics to improve the app | Consent (off until you opt in; you can switch it off in Settings → Privacy) |
| Fraud prevention, security, rate limiting | Legitimate interests; legal obligations |
| Error monitoring and service reliability | Legitimate interests |
| Accounting, tax and dispute records | Legal obligation |
4. Who we share it with
We share personal data only with service providers that process it for us under contract, and with retailers and carriers to deliver gifts. The current list of subprocessors:
- Supabase (database, authentication, file storage and server functions; holds all account data)
- Stripe (payment processing and card storage; receives the card details you enter in its payment form, your account email as the billing email, payment amounts and our reference ids, and, if you dispute a charge, the evidence of your payment authorisation, including the IP address recorded when you accepted it)
- Resend (email delivery, including sign-in and account emails; receives your email address and the message content; our emails are sent from mail.rotspit.com)
- Expo (push notification delivery and app updates; receives your device's push token and the notification text, and passes notifications to Apple Push Notification service or Google Firebase Cloud Messaging)
- Apple and Google (Sign in with Apple and Google sign-in, only if you choose them where offered; they confirm your identity and share your name and email address with us)
- PostHog (product analytics, only if you opt in; EU cloud; receives a pseudonymous user id and the analytics data described in section 2, not your name or email address)
- Sentry (error monitoring for the app, including app.rotspit.com, our admin tools and servers; receives technical error details and a pseudonymous user id, with email addresses, card numbers and access tokens removed before sending)
- Bright Data (retrieving public retailer search results and product pages; receives the search text and product links you enter, not your account, contact or address details; never used for checkout)
- DigitalOcean (hosts our product lookup and order fulfilment server; processes product links and order references, and recipient delivery details only when automated purchasing is enabled for a retailer)
- Cloudflare (DNS, network delivery and hosting of www.rotspit.com and app.rotspit.com; processes connection data such as IP address and browser details)
- Vercel (hosts our internal admin dashboard; processes the account and order data our team views there)
- Slack (internal alerts for our operations team; receives order numbers and internal reference ids, not names, email addresses or delivery addresses)
- Retailers and delivery carriers (recipient name, phone and address for the order)
Other users see only what you choose to share. Anonymous contributions hide your identity and amount from other users. We do not sell personal data.
5. International transfers and hosting
Some providers store or process data outside the UAE. Product analytics are processed in PostHog's EU cloud. We transfer data only where the destination offers adequate protection or under safeguards such as data processing agreements with standard contractual protections. OWNER-ACTION: confirm the production hosting region and the transfer mechanism for each subprocessor after counsel review.
6. How long we keep it
| Data | Retention |
|---|---|
| Account and profile | Until you delete your account |
| Addresses | Until you delete them or your account; delivered order addresses are redacted after the return window |
| Payment, order and ledger records | As required by UAE commercial and tax law OWNER-ACTION: confirm period (expected 5 years) |
| Consent records | For the legal claims period, kept without your name after account deletion |
| Notifications | 180 days |
| Security and rate-limit logs | Up to 30 days |
| Data exports you request | 7 days |
| Waitlist | Until 12 months after launch, or until you unsubscribe |
7. Your rights
You can:
- Access and export your data: Settings → Privacy → Export my data.
- Correct your profile and addresses in the app.
- Delete your account: Settings → Account → Delete account. Deletion may be delayed while a charged gift, return or dispute is in progress, and some records are kept as described above.
- Object to processing based on legitimate interests, and restrict processing in some cases.
- Withdraw consent for marketing at any time using the unsubscribe link or notification settings.
- Complain to the UAE Data Office.
8. Children
Rotspit is for people aged 18 and over. We do not knowingly collect data from children. If you believe a child has an account, contact us and we will delete it.
9. Security
Data is encrypted in transit and at rest by our providers, access is restricted by role, and card data is handled only by Stripe.
10. Changes
We will notify you in the app about material changes. Each version is numbered and dated.
11. Contact and data protection officer
OWNER-ACTION: privacy contact email, postal address and data protection officer (if appointed)