Privacy Policy — United Arab Emirates
This policy informs you how personal data is processed on the Emaride platform in the United Arab Emirates (www.emaride.ae and the Emaride app for the UAE market). It is information under Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("PDPL"). It is not a consent and does not require your acceptance.
1. Controller
EMARIDE L.L.C-FZ Limited liability company (Free Zone), Meydan Free Zone Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba Dubai, United Arab Emirates Licence number: 2535707.01 Represented by its manager Ramez Mohamad Alkhalaf E-mail: info@emaride.ae
Data protection requests: privacy@emaride.ae
2. Scope
This policy applies to passengers, drivers and contact persons of fleet partners and business customers who use the Emaride platform in the UAE (together the "Platform"). Users in the European Union are covered by the privacy policies of Emaride EU on www.emaride.lu; their data is stored separately in the EU.
3. Categories of Data Processed
| Category | Examples |
|---|---|
| Master / account data | name, e-mail, phone number, language setting |
| Profile and address data | saved addresses (max. 3), preferred settings |
| Location data | pickup and destination, GPS position during an active ride |
| Ride data | bookings, route, timestamps, status, OTP/QR verification, no-show events |
| Payment data | payment method (token), transaction and invoice data, tips |
| Ratings | ratings given by you and given about you |
| Driver data | licence and permit documents, vehicle data, date of birth |
| Support / communication data | tickets, chat logs with (possibly AI-assisted) support |
| Device and usage data | device and app version, push token, log and error data |
Full payment card data is not stored by us but processed exclusively by the payment provider (Section 5).
4. Purposes and Legal Grounds
We process personal data only for specified purposes and to the extent necessary:
| Purpose | Ground under the PDPL |
|---|---|
| Provision of the Platform, arranging and handling rides | performance of a contract with you |
| Location processing to carry out the ride (pickup, routing) | performance of a contract with you |
| Payment processing, invoicing, retention of records | contract; compliance with legal obligations |
| Verification of drivers (documents, age, permits) | compliance with legal and regulatory obligations; contract |
| Fraud prevention, abuse and penalty checks, safety | protection of our legitimate interests and of other users |
| Support and communication | performance of a contract with you |
| Transactional notifications (ride status, payments) | performance of a contract with you |
| Anything beyond the above (e.g. optional features) | your consent, which you may withdraw at any time |
We do not send advertising or marketing messages and do not use advertising cookies on www.emaride.ae.
5. Recipients and Service Providers
- Fleet partners and drivers — to carry out the booked ride. Before acceptance the driver receives your first name, the verification status and the pickup and destination address; after acceptance additionally your phone number and rating average. E-mail address, surname and card details are never transmitted.
- Authorities — where required by law, in particular the Roads and Transport Authority (RTA) of Dubai for regulatory reporting once the service is authorised.
- Service providers acting on our instructions:
| Service | Purpose | Location |
|---|---|---|
| Supabase | Hosting, database, storage, sign-in | India (Mumbai) |
| Stripe | Payment processing | USA / Ireland |
| Google Maps Platform | Maps, geocoding, routing | USA |
| Mapbox | Map rendering (web) | USA |
| Resend | Transactional e-mail, ride OTP | USA |
| OpenAI | AI-assisted support triage (content is not retained) | USA |
| Expo | Push notifications | USA |
| Vercel | Hosting of the website and web dashboard | global (edge), USA |
Avoiding duplicate accounts across regions. When you register, request a password reset or are invited, we check whether an account with your e-mail address already exists in our European database. For these three operations only a pseudonymous code derived from your e-mail address (a keyed hash) is transmitted; your address itself does not leave the region. If an account exists there, we inform you by e-mail how to sign in. This does not apply to signing in, see the next paragraph.
Signing in across regions. When you sign in with your e-mail address and password, we do not always know in advance in which region your account is held (for example on a new device or while travelling). If sign-in fails in the region asked first, we transmit your e-mail address and password in encrypted form (TLS) to the sign-in service of the other region (our European database, Supabase, Frankfurt data centre, or our UAE database in Mumbai, India). Unlike the check above, these are the credentials themselves, not a pseudonymous code. The sign-in service there uses them only to check the sign-in and does not store the password. Every failed attempt is recorded to protect against attacks in the region where it fails, even if sign-in then succeeds in the other region: in the protective log against repeated failed attempts, with a hash of your identifier and the IP address (deleted after 15 minutes), and in the audit log (retention as for log data, Section 7). The purpose is to let you sign in with one account in every region.
Check against known passwords. When you register, we check whether your password appears in known data breaches and reject it if so. For this we send only the first five characters of a SHA-1 hash of your password to the "Pwned Passwords" service of Have I Been Pwned; neither your password nor your e-mail address is transmitted, and the service cannot infer you or your password from these five characters.
6. Cross-Border Transfers
Our database for the UAE market is operated in India (Mumbai); further service providers are located in the USA and the EU (Section 5). Transfers outside the UAE take place only under the conditions of Articles 22 and 23 PDPL, in particular on the basis of contractual safeguards with the respective provider or where the transfer is necessary for the performance of the contract with you.
7. Retention Periods
| Data | Period |
|---|---|
| Account and profile data | for the duration of the usage relationship; deletion on request |
| GPS coordinates of a ride | 24 months, then irreversibly removed |
| Pickup and destination address of a ride | 10 years (description of the invoiced service) |
| Invoice and transaction data | 10 years (commercial and tax retention) |
| Support tickets and chat content | 24 months after the matter is closed |
| OTP code for ride verification | deleted after verification (at the latest after 1 day) |
| Notifications (push/in-app) | 90 days |
| Log data | 24 months |
8. Cookies
On www.emaride.ae we only use strictly necessary cookies: emaride_lang (display
language, 1 year), emaride_country (market, 1 year), the session cookie of our sign-in
(sb-…-auth-token, until you sign out or the session expires), emaride_remember (your
"stay signed in" choice) and emaride_region (the region in which your account is kept, so
that we connect you to the right database; 1 year). We do not use tracking or advertising
cookies.
9. Automated Decisions
The penalty check for cancellations and no-shows, the automatic suspension when mandatory documents expire and the blocklist are prepared automatically. Measures with a significant effect on you — in particular the restriction or suspension of your account — are reviewed by a person at Emaride. You may object to a decision based solely on automated processing and request a human review via privacy@emaride.ae.
10. Your Rights
Under the PDPL you have the right to:
- obtain information about the processing of your data and a copy of it,
- request the transfer of your data,
- request correction of inaccurate data and erasure of data no longer required,
- request restriction of processing,
- request that processing stops, and
- object to decisions based solely on automated processing.
You can trigger a data export and the deletion of your account directly in the app. For everything else, contact privacy@emaride.ae. We respond within the periods set by law.
11. Complaints
You may lodge a complaint with the UAE Data Office if you believe that the processing of your personal data violates the PDPL.
12. Data Security
We use appropriate technical and organisational measures (including encryption in transit, role- and country-based access controls and separate storage of UAE and EU data) to protect your data.
13. Changes and Status of This Version
This version applies to the test phase of the Platform in the UAE and will be updated before rides can be booked. The current version is available on the website and in the app; it carries a version number and an effective date.