Privacy Policy
Version: 2026-09-29
Operator: Souhib Trabelsi FZEFree Zone Establishment · Trade licence 4429733.01
Sharjah Publishing City Free Zone Authority
Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates
support@latabdhir.ae
1. Controller and scope
Souhib Trabelsi FZE operates La Tabdhir and determines how platform personal data is used. This notice covers the website, app, waiting list, customer and guest orders, store accounts and support. Stores also process the customer information they receive to fulfil orders and meet their own legal duties.
2. Information processed
Accounts and guests: name, email, phone, language, verification records, hashed passwords where applicable and security settings. Orders: food, store, quantity, price, collection details, fulfilment status and contact information; for delivery, the address and instructions provided. We record which version of the terms and of this notice was shown when you order or register.
Stores: business identity, contact details, location, trade licence records and uploaded licence documents, review status and subscription billing references. A separate payout-preparation form for identity and bank details exists but is not open to stores; if it is opened, its content is stored encrypted and this notice will be updated first.
Other data includes support messages, chats with a store about an order, reviews, favourites, achievements, notification preferences, push tokens and technical records such as request logs, browser/device details, timestamps and errors. Location you enter or permit us to access helps find nearby stores; saved delivery addresses are more precise than a city.
3. Purposes and choices
We use information to provide requested accounts and reservations, verify access, coordinate fulfilment, manage subscriptions, answer support requests and protect the service against misuse. Processing necessary to perform your contract and processing required by applicable law are assessed separately from optional consent-based activities.
Joining the waiting list requests launch updates; unsubscribe through the email link or contact support. Account deletion and waiting-list withdrawal are separate choices. We retain minimal suppression information to respect an email opt-out. Transactional order or security notices are separate from marketing.
Optional device permissions can be changed in device settings. A location or notification permission does not authorize unrelated uses of your data. Accepting the terms or reading this notice does not give unlimited permission for marketing or unrelated processing.
4. Recipients and payment services
Order information needed for fulfilment is shared with the relevant store. Service providers act on our instructions: Amazon Web Services (hosting, database, storage and content delivery), Oracle Cloud (a server hosting our encrypted database backups and our self-hosted monitoring tools), Resend (email), Google Firebase (mobile push notifications) and Stripe (store subscription payments; we keep billing identifiers and status, not card numbers or security codes).
We measure website use with a self-hosted Umami instance that sets no cookie and does not store IP addresses. When a page is viewed, it uses the network address and browser details only to derive an approximate location (country, region, city) and a pseudonymous visitor identifier that changes every month. Errors are reported to a self-hosted Sentry-compatible service. Our error-reporting libraries are configured not to send IP addresses, cookies, email addresses or authentication headers, and we do not record browsing sessions; the monitoring server itself still records the network address from which each report is received, and we are removing that. Google Maps, Google Sign-In and Apple Sign-In receive information when you use the corresponding feature. When you sign in or use guest checkout on the website, Google reCAPTCHA Enterprise, through Firebase App Check, receives technical information about your browser and device (including its network address) so that we can check that the request comes from our website rather than an automated script; Google processes that information under its own terms.
Customer online payments through Tap are currently disabled and there is no Tap-hosted onboarding form. If online payments or store payout onboarding are enabled, the data needed for the payment or the onboarding will be sent to Tap and this notice will be updated before that happens. We may disclose records to competent authorities when lawfully required and do not sell personal data. A list of recipients with their purpose and location is available from support.
5. Hosting and international processing
The current production infrastructure is configured in AWS Mumbai, India. Encrypted backups and monitoring tools run on a server operated by Oracle Cloud, and other service providers may process information in other countries. Data is therefore not represented as stored exclusively in the UAE.
Applicable UAE rules govern international transfers. We must establish the applicable transfer basis and arrangements for each recipient; this notice and your acceptance of general terms are not a substitute for those requirements. Contact support for information about the arrangements applicable to your data.
6. Retention and deletion
We keep account information while needed to provide the service. A deletion request starts a 30-day grace period, after which personal fields are removed or redacted. An email account never verified and never used to order is erased after 90 days. Guest contact details are erased after 180 days without activity. Delivery addresses, instructions and guest contact copies on completed orders are erased after 365 days; amounts, statuses and identifiers are kept as financial records and are not described as fully anonymous.
In-app notifications are deleted after 30 days (re-engagement offers after 45 days), and chats after 365 days without a new message. Data linked to an order is not erased while that order is still active or its refund is unsettled, nor while an administrative hold preserves data for a dispute; the erasure then happens once the matter is resolved. Encrypted backups are kept for up to 30 days, and erasures are re-applied if a backup is ever restored. Provider records and documents held by a store follow their own retention. Contact support about a particular record.
7. Rights, security and contact
You may request information about processing, access and a copy of your data, correction, restriction or erasure where applicable, and withdraw consent for activities relying on it. Legal exceptions may apply; we will explain a refusal or limitation. Account tools provide a data export (profile, orders, addresses, reviews, favourites, achievements, notifications, chats, referrals, consents and linked guest orders) and deletion-request functions; guests can contact support. Contact support to exercise a right or challenge a decision; you may also complain to the competent data-protection authority.
We use access controls, encrypted connections and other security measures, but do not claim that any service is risk-free. We assess incidents and make notifications required by applicable law. Essential browser or device storage supports authentication and preferences. Material notice changes will be identified with a new version.