PRIVACY
ALLINDUBAI LEGAL
PRIVACY POLICY
Website, Booking & Concierge Data Master
|
Legal entity |
All In Concierge Services FZE LLC |
|
Legal status |
Free Zone Entity - FZE LLC |
|
Licence No. |
2621219432888 |
|
Registered address |
CWS-1V-228138, 26th Floor, Amber Gem Tower, Ajman, UAE |
|
Website |
https://allindubai.net/ |
|
Effective date |
September 2026 |
IMPORTANT
This master draft is designed to provide strong privacy, operational and evidentiary protection while preserving non-excludable rights under applicable UAE law. It should be reviewed by UAE-qualified counsel before publication and updated once the final payment processor, analytics tools, CRM, hosting, marketing platforms and supplier data flows are confirmed.
PLEASE READ THIS PRIVACY POLICY CAREFULLY. It explains how AllInDubai collects, uses, discloses, stores and protects personal data when you browse our Website, contact us, request concierge assistance, make or receive a booking, pay through our authorized channels, or otherwise interact with us.
1. Who We Are and Scope
AllInDubai is a brand operated by All In Concierge Services FZE LLC, a Free Zone Entity registered in the United Arab Emirates ("AllInDubai", "we", "us" or "our"). This Privacy Policy applies to personal data processed in connection with https://allindubai.net/, authorized payment links, booking and concierge operations, customer support, WhatsApp, telephone, email and other authorized communication channels.
For particular services, an independent Service Provider may separately determine how it processes personal data required to deliver the service. In that case, the provider may act as an independent data controller under its own privacy obligations. This Policy describes AllInDubai's processing and does not replace a provider's own privacy notice where one applies.
2. Personal Data We May Collect
We collect only data that is reasonably relevant to operating the Website, responding to requests, arranging and administering Services, receiving payment, complying with legal obligations, protecting our business and improving customer experience.
• Identity and profile data: name, title, date of birth or age where relevant, nationality where required for a Service, and account/profile details.
• Contact data: telephone number, WhatsApp number, email address, country of residence and communication preferences.
• Booking and travel data: dates, party size, hotel or pickup location, itinerary, requested experiences, preferences, special occasions and booking history.
• Identification and eligibility data where genuinely required: passport or Emirates ID details/copies, driving-licence details, vehicle-rental eligibility information and other documents required by a licensed provider or authority.
• Payment and transaction data: amounts, currency, payment status, refund information, transaction references and limited payment metadata. Full card credentials should ordinarily be handled by the authorized payment processor rather than stored by AllInDubai.
• Communications: messages, emails, WhatsApp correspondence, call notes, requests, complaints, reviews and customer-support records.
• Technical and Website data: IP address, device/browser information, pages viewed, referring source, timestamps, cookie identifiers and security logs, subject to applicable consent requirements.
• Marketing data: campaign interactions, consent status, opt-out records and interests inferred from interactions where lawful.
• Sensitive or special-category information only where necessary for a requested Service, such as health, allergy, accessibility or childcare-related information supplied for a medical, wellness, activity or childcare booking.
3. How We Collect Personal Data
• directly from you when you use the Website, submit a form, make a Booking, contact us or provide documents;
• from a person booking on your behalf, who is responsible for having authority to provide the information;
• from Service Providers where necessary to administer a Booking, refund, complaint, incident or customer request;
• from payment processors, fraud-prevention providers and banks in relation to transactions;
• automatically through Website technologies such as cookies, logs and analytics tools, where lawfully configured; and
• from public or business sources where lawful and reasonably necessary for legitimate business operations.
4. Purposes for Which We Use Personal Data
• to respond to enquiries and provide concierge assistance;
• to create, confirm, administer, amend and cancel Bookings;
• to communicate necessary information to Service Providers and receive booking confirmations;
• to process payments, refunds, invoices, deposits and payment disputes;
• to verify identity or eligibility where necessary for fraud prevention, high-value transactions or provider requirements;
• to provide customer support, investigate complaints and resolve service issues;
• to maintain transaction records, defend legal claims and respond to chargebacks;
• to comply with legal, regulatory, tax, accounting, licensing and law-enforcement obligations;
• to secure the Website, detect abuse, fraud and unauthorized activity;
• to understand Website performance and improve services, subject to cookie/consent requirements; and
• to send marketing communications where permitted and where any required consent has been obtained.
5. Legal Basis and Consent
AllInDubai will process personal data only where a lawful basis is available under applicable UAE data-protection law. Depending on the circumstances, processing may be necessary to perform or prepare a contract requested by you, comply with law, protect rights or legitimate interests where permitted, respond to emergencies or legal claims, or rely on valid consent.
Where processing relies on consent, consent must be freely given where required and may be withdrawn through the applicable contact or preference mechanism. Withdrawal does not invalidate processing that was lawful before withdrawal and may not require deletion of data that must be retained for another lawful reason.
Marketing consent, where required, should be separate from acceptance of booking terms. Refusing optional marketing should not prevent a customer from making a Booking.
6. Sharing Personal Data with Service Providers
To fulfil a Booking, AllInDubai may share the minimum reasonably necessary personal data with the relevant Service Provider. For example, a yacht operator may need passenger identification, a vehicle provider may need driver and licence information, a hotel may need guest details, and a medical or childcare provider may need information relevant to safe delivery of the requested Service.
Service Providers may be independent businesses with their own legal and privacy obligations. AllInDubai does not authorize a provider to use data received from us for unrelated purposes merely because the provider receives a booking referral or fulfilment instruction.
Customers should not send sensitive documents or medical information unless requested through an authorized AllInDubai or provider channel and reasonably necessary for the Service.
7. Other Recipients
Where reasonably necessary and lawful, personal data may also be disclosed to payment processors, banks, hosting and cloud providers, CRM and customer-support vendors, communications providers, analytics/security vendors, professional advisers, insurers, auditors, regulators, courts, law-enforcement bodies, tax authorities, competent government authorities, and a purchaser or successor in a lawful corporate transaction.
We do not sell personal data as a standalone commercial product. We do not authorize third parties to use customer data for their own unrelated marketing merely because they provide technical services to AllInDubai.
8. International and Cross-Border Transfers
Some Service Providers or technology vendors may process data outside the UAE. Where personal data is transferred across borders, AllInDubai will seek to use a transfer mechanism, contractual protection, consent or other legal basis required by applicable law and will take reasonable steps to ensure an appropriate level of protection.
The Internet and international travel industry necessarily involve communications across jurisdictions. Customers should be aware that a booking involving an overseas supplier may require relevant booking data to be transferred to the country where that supplier operates.
9. Payment Security
AllInDubai may use third-party payment service providers to process card and electronic payments. Customers may be redirected to or interact with a secure payment interface operated by such provider. AllInDubai should not intentionally store full card numbers, CVV/CVC security codes or equivalent authentication credentials unless a compliant payment architecture expressly requires and lawfully permits it.
We may retain transaction references, payment status, masked card information where supplied by the processor, refund records and other information necessary for accounting, fraud prevention and dispute management.
10. Cookies, Analytics and Similar Technologies
The Website may use strictly necessary cookies and, where enabled, analytics, preference, advertising or remarketing technologies. Non-essential technologies should be activated only in accordance with applicable consent requirements.
Further details should be provided in the AllInDubai Cookie Policy and cookie preference interface. A customer should be able to revisit relevant cookie choices where required.
11. Marketing, WhatsApp, Email and SMS
AllInDubai may send transactional messages necessary for a Booking regardless of optional marketing preferences. Transactional communications may include confirmations, payment notices, provider instructions, changes, reminders and customer-support messages.
Promotional messages by email, SMS, WhatsApp or similar channels will be sent only where permitted by applicable law. Where consent is required, it will be recorded. Customers may opt out of promotional communications using the available unsubscribe, STOP, preference or customer-support mechanism. Opting out of marketing does not opt a customer out of essential booking communications.
12. Children and Minors
The Website is not intended to invite children to independently purchase concierge Services. Where information about a minor is required for a family, childcare, activity, accommodation or medical Booking, it should be supplied by or with the authority of a parent, guardian or other person legally entitled to provide it.
AllInDubai will seek to limit collection of children's information to what is reasonably necessary for the requested Service and applicable legal or provider requirements.
13. Sensitive and Health-Related Data
Certain requested Services may require sensitive information, including health, allergy, disability, emergency-contact or childcare information. AllInDubai will seek to process such information only where necessary and where a lawful basis exists, and to disclose it only to persons who reasonably need it to arrange or safely provide the Service.
Medical records created by an independent licensed healthcare provider are controlled and retained by that provider in accordance with applicable healthcare and privacy law; AllInDubai should not request or retain complete clinical records unless genuinely necessary and lawfully justified.
14. Data Retention
AllInDubai retains personal data only for as long as reasonably necessary for the purposes for which it was collected and for applicable legal, tax, accounting, regulatory, fraud-prevention, dispute and evidentiary requirements. Different categories of data may have different retention periods.
Data may be retained for longer where a complaint, chargeback, legal claim, investigation or regulatory requirement is pending. When data is no longer required, AllInDubai will seek to delete, anonymize or securely dispose of it in accordance with applicable requirements.
The developer and operations team should implement a documented retention schedule rather than retaining all customer data indefinitely.
15. Data Security
AllInDubai will use reasonable technical and organizational safeguards appropriate to the nature of the personal data and risks involved. Measures may include access controls, strong authentication, least-privilege permissions, secure transmission, logging, backups, vendor controls and staff confidentiality.
No online system can be guaranteed to be completely secure. Customers are responsible for protecting their own devices, accounts and authentication credentials and should promptly report suspected unauthorized access.
16. Personal Data Breaches
Where AllInDubai becomes aware of a personal-data breach, it will assess the incident, take reasonable containment and remediation steps, preserve relevant evidence, and make notifications to competent authorities and affected individuals where required by applicable law.
Employees and contractors must promptly escalate suspected loss, unauthorized disclosure, account compromise, phishing, malware or other security incidents involving customer data.
17. Your Data Protection Rights
Subject to applicable UAE law, conditions and exemptions, individuals may have rights relating to their personal data, including rights to obtain information about processing, request access, request correction of inaccurate data, request deletion in applicable circumstances, restrict or object to certain processing, request transfer where applicable, withdraw consent, and object to certain automated decisions.
A request may require reasonable identity verification before AllInDubai releases, changes or deletes personal data. Rights are not absolute; for example, AllInDubai may need to retain transaction information required by law or necessary for the establishment, exercise or defence of legal claims.
Privacy requests should be submitted through the current privacy/customer-support contact channel published on the Website. AllInDubai will handle verified requests in accordance with applicable legal timeframes.
18. Automated Decision-Making and Profiling
AllInDubai does not intend to make solely automated decisions that produce significant legal effects on customers unless the use is lawful and appropriate safeguards are provided. Recommendations, personalization or fraud indicators may use automated tools, but material booking decisions may also involve human review where appropriate.
19. Third-Party Websites and Social Platforms
The Website may link to maps, social networks, payment pages, supplier websites and other external services. Their privacy practices are controlled by the relevant third party. Customers should review the applicable privacy notice before providing data directly to an external service.
20. Accuracy of Customer Information
Customers should provide accurate and current information and promptly notify AllInDubai if booking-critical information changes. AllInDubai is not responsible for service problems caused by materially inaccurate information supplied by the Customer, subject to applicable law.
21. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in law, technology, vendors, Website functionality or business operations. The current version and effective date will be published on the Website. Where law requires additional notice or consent for a material change, AllInDubai will provide it.
22. Company and Privacy Contact
AllInDubai is operated by All In Concierge Services FZE LLC, Licence / Registration No. 2621219432888, registered at CWS-1V-228138, 26th Floor, Amber Gem Tower, Ajman, United Arab Emirates.
Website: https://allindubai.net/. Privacy and data-rights requests may be submitted through the current email address, telephone/WhatsApp number or privacy/customer-support channel published on the Website. Before publication, a dedicated privacy email address should preferably be designated and inserted here.
Last updated: September 2026.
INTERNAL - DEVELOPER IMPLEMENTATION INSTRUCTIONS
NOT FOR PUBLICATION ON THE CUSTOMER-FACING PRIVACY POLICY PAGE
A. Mandatory Website Placement
• Add a permanent 'Privacy Policy' link in the global footer and make it accessible before account creation, form submission and checkout.
• Add links to Terms & Conditions, Cancellation & Refund Policy and Cookie Policy beside the Privacy Policy in the footer.
• Display the legal entity name, licence/registration number, registered address and active support/privacy contact details in the Contact/Legal area.
• Do not publish this internal appendix on the public Website.
B. Forms and Data Minimization
• Every form field must have a defined purpose. Do not collect passport, Emirates ID, driving licence, health or child information at the first enquiry stage unless it is actually required.
• Use progressive collection: collect basic contact/booking data first; request sensitive documents only after the relevant Service requires them.
• Do not place sensitive information in URL query strings, analytics events, page titles or unsecured notes.
• For file uploads containing ID/health data, use authenticated or expiring upload access where practical and restrict staff access.
C. Checkout and Consent Logging
• Terms acceptance must use an unticked checkbox. Store booking ID, customer identifier, timestamp, Terms version, Cancellation Policy version and the service-specific cancellation terms displayed.
• Privacy Policy acknowledgement may be linked to the booking flow; do not bundle optional marketing consent into mandatory booking acceptance.
• Marketing consent must be a separate unticked checkbox where consent is relied upon. Store consent source, channel, wording/version, timestamp and withdrawal/opt-out history.
• Payment links sent by WhatsApp/email must point to the same current legal notices or clearly provide access to them before payment.
D. Cookies and Tracking
• Before enabling non-essential analytics, Meta Pixel, Google advertising/remarketing or similar trackers, implement a cookie consent/preferences interface appropriate to applicable law.
• Strictly necessary cookies may operate as required for security, checkout and core functionality; categorize all other cookies.
• Do not fire non-essential tags before the required consent state is obtained. Persist and honor the user's cookie choices.
• Provide a visible 'Cookie Settings' control so a user can revisit choices. Keep a record of consent configuration/version.
E. Payments
• Use a PCI-compliant hosted/approved payment flow where possible. Do not store full card number, CVV/CVC or raw payment credentials in AllInDubai databases, CRM, logs, WhatsApp or email.
• Store only necessary payment references/status, masked details supplied by the processor, invoice/refund records and dispute evidence.
• Ensure payment pages use HTTPS and verify webhook signatures or equivalent payment-provider security controls.
F. Supplier Data Sharing
• Build supplier workflows so staff share only data necessary for fulfilment. Avoid sending an entire customer profile when a provider only needs name, date and contact number.
• Where practical, maintain a record of which supplier received customer data and for which booking.
• Do not automatically add suppliers to marketing lists or expose one supplier's customer data to another supplier.
• Supplier agreements should contain appropriate confidentiality/data-protection obligations and define permitted use of customer data.
G. Access Control and Security
• Use individual staff accounts; do not share one administrator password.
• Require MFA for Website admin, CRM, email, payment dashboards and cloud storage where available.
• Apply role-based/least-privilege access. Staff who do not need passport, health or payment-dispute data should not be able to access it.
• Keep security/audit logs for important admin actions, booking changes, refunds and exports where feasible.
• Use encrypted HTTPS/TLS across the Website and secure backups. Keep CMS, plugins and dependencies patched.
H. Retention and Deletion
• Create a written data-retention matrix by category: enquiries, confirmed bookings, invoices/accounting, identity documents, support communications, chargeback evidence, marketing consent and analytics.
• Do not keep passport/ID/health document copies indefinitely. Configure deletion or review dates after the operational/legal need ends.
• Deletion must include primary systems and reasonable downstream copies, subject to backup cycles and legal retention obligations.
• Maintain a legal-hold mechanism so records relevant to an active dispute, chargeback, investigation or claim are not automatically deleted.
I. Data Rights Workflow
• Create an internal process for access, correction, deletion, objection, consent withdrawal and other privacy requests.
• Verify identity before disclosing or deleting customer information. Do not send account data merely because someone knows a booking number.
• Log request date, identity verification, action taken, response date and any lawful reason for refusing or limiting a request.
• Add a dedicated privacy email before launch if possible (for example a role-based address on the AllInDubai domain), but do not invent or publish one until it actually exists.
J. Incident Response
• Create an internal security-incident contact and escalation procedure.
• If customer data is exposed, preserve logs, identify affected systems/data/people, contain access, document the timeline and obtain legal/privacy advice on notification obligations.
• Do not silently delete logs or evidence after a suspected breach.
K. Launch Checklist
• Confirm actual hosting provider, CRM, payment processor, email/SMS/WhatsApp provider, analytics tools, advertising pixels and cloud-storage services, then update this Policy if necessary.
• Confirm whether any customer data is hosted or accessed outside the UAE and document the transfer basis/contractual protections.
• Confirm VAT/accounting retention requirements with the company's UAE accountant and legal adviser before setting automated deletion periods.
• Have the final English Privacy Policy reviewed by UAE-qualified counsel and professionally translated/reviewed in Arabic where required.
• Run a privacy test before launch: submit enquiry -> booking -> payment -> supplier fulfilment -> cancellation/refund -> marketing opt-out -> data-rights request, and confirm each system behaves as documented.
L. Legal Framework Considered in Drafting
This draft was prepared with reference to the UAE federal data-protection and digital-law framework available in September 2026, including Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data, together with other applicable UAE laws governing electronic transactions, consumer protection, regulated services, payments, healthcare and business records. This is a commercial drafting document and not a substitute for UAE-qualified legal advice tailored to AllInDubai's final technology stack and processing activities.
