Privacy Policy
Version 2026-09-29
Draft for legal review. This text has not yet been reviewed by a UAE lawyer and may change.
This policy explains what personal data MERSY collects, why, how long we keep it, who we share it with, and your rights. We process personal data in line with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and, where it applies to you, the EU GDPR.
Who is responsible
[LEGAL ENTITY NAME — e.g. MERSY Perfumes Trading L.L.C.], [BUILDING / OFFICE NUMBER], [STREET, AREA], [CITY], United Arab Emirates, is the controller of your personal data. Contact us about privacy at [privacy@yourdomain.ae].
What we collect
- Account: your name, email address, a securely hashed password (we never store the password itself), your UAE mobile number once verified, your language and communication preferences, and whether two-step verification is on.
- Orders: products, prices, delivery name, address and phone number, and order history.
- Payments: handled by our payment provider. We receive a payment reference and a card "fingerprint" (a code that identifies a card without revealing its number). We never receive or store card numbers.
- Referral offer: which account’s code was used on an order, the status of referrals and rewards, and fraud-prevention signals (see below).
- Security: IP address, browser type, a random device identifier stored in a cookie, sign-in history, and records of failed sign-in attempts.
- Consents: what you agreed to (terms, marketing, cookies), when, and the policy version.
- Messages you send us and reviews you write.
We do not collect your date of birth, gender, or any special categories of data, and we do not buy data about you from others.
Why we use it (and our legal basis)
- To create your account, take payment, deliver orders and handle returns — to perform our contract with you.
- To keep records required by UAE tax and commercial law — legal obligation.
- To protect accounts and the site (rate limits, lockouts, two-step verification, security logs) — our legitimate interest in keeping the service secure.
- To run the referral offer and prevent referral fraud — performance of the offer’s terms and our legitimate interest in preventing abuse.
- To send marketing emails or texts — only with your consent, which you can withdraw at any time.
Referral offer and fraud prevention
Your referral code is your verified mobile number. Anyone you give it to can enter it at checkout. We never confirm to them whose number it is or whether it belongs to a customer. We never tell you who your referred friends are.
To stop people referring themselves, we compare keyed, irreversible codes ("hashes") derived from phone numbers, email addresses, payment-card fingerprints, delivery addresses, device identifiers and network ranges between the referrer and referred customers. Some checks automatically disqualify a referral (for example, the same card on both orders); others send it to a person on our team for review. You can ask for a human review of any decision at [support@yourdomain.ae].
If you delete your account, we keep only these hashes — never the underlying details — for 24 months, so that the offer cannot be abused by deleting and re-registering.
How long we keep it
- Account data: while your account is open. When you delete it, we remove your personal details straight away (or within 30 days if an order is still in progress).
- Order and invoice records: 5 years, as required by UAE VAT law. After account deletion, these records no longer contain your name, address or phone number.
- Security logs: 90 days.
- Fraud-prevention hashes after deletion: 24 months.
- Consent records: for as long as needed to prove consent, up to 5 years.
Your rights
You can ask to access, correct, delete or receive a copy of your data, to restrict or object to certain uses, and to withdraw consent at any time. Most of this you can do yourself in your account: download your data, change your preferences, or delete your account. Otherwise, email [privacy@yourdomain.ae]; we reply within 30 days. You also have the right to complain to the UAE Data Office.
How we protect it
Data is encrypted in transit (HTTPS) and personal details such as your name, email, phone and addresses are encrypted in our database. Passwords are hashed with Argon2id. Access is limited to the staff who need it, and administrator accounts require two-step verification. Every administrative action is logged.
Children
Our site is for adults. We do not knowingly collect data from anyone under 18. If you believe a child has created an account, contact [privacy@yourdomain.ae] and we will delete it.
Changes
If we change this policy in a way that matters, we will tell you by email or on the site before the change takes effect.