Privacy Policy
Last updated: Oct 3, 2026
This policy explains how DAWEM (the "platform") handles personal data of customers who join a brand's loyalty program. It is aligned with the UAE/KSA Personal Data Protection Law (PDPL).
1. Data we collect
- Identity & contact: phone number, and optionally name, email, and birthday.
- Loyalty activity: stamps, rewards, and redemptions on your card.
- Consent record: the time you consented at enrollment.
2. How it is protected
Identity fields (phone, name, email, birthday)
are encrypted at rest. Staff look you up via a one-way blind index, never by
reading the stored values. Access is isolated per brand.
3. Purpose & legal basis
We process this data solely to operate your loyalty membership — issuing a card, recording stamps, unlocking and redeeming rewards, and sending you related notifications. Processing is based on the consent you give at enrollment.
4. Notifications
We may notify you in-app, via web push, or via WhatsApp about your card and rewards. WhatsApp messages use approved utility templates only.
5. Retention
We keep your data for as long as your membership is active. Aggregate loyalty history may be retained in anonymized form for reporting after your identity is erased.
6. Your rights
- Access & portability: request a copy of your data.
- Erasure: request deletion. Where loyalty history exists, we anonymize your record (scrub identity, keep unlinked aggregates); otherwise we delete it entirely.
- Withdraw consent: at any time, which ends processing.
To exercise any right, contact the brand you enrolled with, or the platform administrator.
7. Contact
Data protection contact: [email protected]