1. Who is responsible for your data
Jasmine Entertainment FZE is the Controller of the personal data described in this policy.
| Controller | Jasmine Entertainment FZE |
| Trade licence | 4422193.01 (Sharjah Publishing City Free Zone) |
| Registered address | Sharjah Publishing City, Business Centre, Sharjah, United Arab Emirates |
| Privacy contact | support@getbustan.com |
| Phone / WhatsApp | +971 50 749 3651 |
support@getbustan.com is the only email address we operate, and it is the address to use for every privacy request, question, or complaint. It reaches the person responsible for privacy at Jasmine Entertainment FZE.
This policy is written to meet Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL") and its implementing regulations as in force from time to time.
2. What this policy covers
This policy covers:
- the Bustan mobile app on iOS and any other platform we later release it on;
- the getbustan.com website, including the pre-launch waitlist;
- push notifications we send you;
- support correspondence by email, phone, or WhatsApp on the number above.
It does not cover the practices of Apple, your bank, or any benefit provider. Those are governed by their own policies, which we do not control.
3. What we collect
Everything below is either something you type in, something your device tells us in the ordinary course of connecting to us, or something a payment or analytics provider tells us. Nothing is inferred from your bank.
3.1 Identity
| Data | Why we have it | Do we need it? |
|---|---|---|
| Per-install identifier — a random UUID generated before the Apple sign-in sheet | Securely proves and merges a new installation; after sign-in it is attached to the canonical Bustan account | Required |
Apple identifier (sub) — an opaque, Apple-generated account identifier | Establishes the Bustan account and lets us restore and sync data across supported Apple devices | Required |
| Canonical Bustan identifier — a random UUID generated by our server | The identifier used for your wallet, settings, audits, usage state, and purchase entitlement | Required |
| Email address — only if you write to support or join the website waitlist | Support replies; waitlist announcements | Optional |
Bustan asks Apple for neither your name nor your email address. Sign in with Apple provides us only the opaque account identifier described above. We therefore do not receive your real Apple ID email or an Apple private-relay email through the App.
3.2 Your wallet — the important one
| Data | Detail |
|---|---|
| Card products you hold | The product, chosen from our list — for example "Emirates NBD Skywards Infinite". Not a card number. Not the last four digits. Not an image of your card. |
| Nickname | Optional free text you choose for a card, e.g. "the travel one" |
| Annual fee anniversary | A date you optionally enter, or defer, so we can remind you before the fee falls due |
| When you added or removed a card | Timestamps |
We cannot tell your specific card from anyone else's card of the same product. We know you hold "a Card X", the same way a forum post would.
3.3 How you use your benefits
| Data | Detail |
|---|---|
| Marked as used | Which benefits you tap "used" on, and when |
| Usage windows | A count of uses per benefit cycle, so we know whether a monthly or quarterly allowance is spent |
| Muted benefits | Which benefits you have told us to stop reminding you about |
This is self-reported by you. We have no way to observe whether you actually used a benefit, and we do not try.
3.4 Notification settings
Push token (an Expo/Apple identifier for your device's notification channel), timezone (default Asia/Dubai), quiet hours start and end, your home emirate if you tell us, and your per-category notification preferences (expiry, fee anniversary, monthly recap, database updates, win-back). We also keep a push ledger — a record of which notifications were sent to you and when — so that we do not send you the same reminder twice.
3.5 Purchases and entitlements
| Data | Detail |
|---|---|
| Entitlement status | Whether you hold the wallet_audit or pro entitlement, whether it is active, and when it expires |
| Purchase event identifiers | Opaque IDs from our purchases provider, used to apply each event exactly once |
We never receive your payment card details, billing address, or Apple ID password. Apple takes your payment. Apple tells our purchases provider that a valid purchase happened. Our provider tells our server that you are entitled. That is the whole chain, and no payment instrument crosses it.
3.6 Your Wallet Audit dossiers
When you generate a dossier we store it: the catalog version it was built from, which of your cards were included, the generated content, and the total value and estimated waste figures. This is so you can open it again, and so a re-audit can show you what changed.
3.7 Reports you send us
If you tell us a benefit is wrong, we store the benefit concerned, a reason chosen from a fixed list (not offered, different terms, couldn't redeem, location wrong, other), an optional note of up to 280 characters, and the time.
Please do not put personal or financial information in the note field. It is a free-text box about a data error, and we do not need anything about you in it.
3.8 Technical data
When your device contacts our servers we necessarily receive, and our infrastructure logs for a short period: IP address, approximate country or region derived from it, the request made, the app version and operating system version, and timestamps. This is ordinary internet plumbing, used for security, abuse prevention, debugging, and rate limiting.
3.9 Analytics
We run a closed allowlist: an event is either on a short, pre-approved list or it is never sent. Anything not on the list cannot be sent, by design.
What the events contain:
- counts (how many cards, how many benefits);
- value bands, never exact amounts — "AED 1,000–2,500", never "AED 1,847";
- a category name, or a card identifier only for the specific "card added" event;
- the length of a search query, never the text you typed;
- durations and scroll percentages.
What the events never contain:
- your name, email, or any direct identifier;
- your full list of cards;
- exact AED figures;
- the text of anything you typed;
- your precise location;
- any device fingerprint.
Analytics exist to answer one question — is the product working — and are configured to answer it with the least data that will do.
3.10 Support correspondence
If you email, call, or WhatsApp us, we keep what you send and our replies, so we can help you and keep a record. Please do not send card numbers, PINs, passwords, one-time passcodes, or photographs of identity documents. If you do, we will delete them and ask you not to do it again.
3.11 The website
The getbustan.com website currently serves a marketing page, a waitlist sign-up, this policy, the Terms, the Cookie Policy, and a page describing our crawler. If you join the waitlist we store your email address (lowercased and trimmed), the source, and the time. Nothing else. See the Cookie Policy.
3.12 Your location, only if you turn on Nearby
The Home screen has a Nearby rail that shows perks at partner venues around you. It is off until you tap to enable it. When you do, iOS asks whether Bustan may use your location while you are using the App.
If you allow it, the App takes a single, low-accuracy position fix while it is in the foreground and compares it, on your device, with the venue coordinates in our catalog. That is the whole use. Your position:
- is held in the App's memory only while the screen is open;
- is never written to the device's storage, never sent to our servers, never included in analytics, and never shared with anyone;
- is never collected in the background, and we keep no history of where you have been.
If you decline, or would rather not, you can pick an emirate by hand instead. That choice is a preference you typed; it is stored on your device only and never leaves it.
You can withdraw location access at any time in iOS Settings → Bustan → Location. The App never asks for motion, fitness, or background location access.
3.13 Measuring our own adverts — the Meta SDK
We advertise Bustan on Meta's platforms (Facebook and Instagram). To know whether those adverts actually bring people to the App, the App includes the Meta (Facebook) SDK. This is the one third-party marketing component in Bustan, and here is exactly what it does.
What Meta receives from the App, regardless of any prompt: Meta's standard app events — that the App was installed, that it was launched, and that an in-app purchase completed (the product and price, as Apple reports it) — together with ordinary device technical data: device model, iOS version, App version, IP address, locale and timezone, and an anonymous identifier the SDK generates for the installation.
What Meta receives only with your permission: your device's advertising identifier (IDFA). After you sign in, iOS shows the App Tracking Transparency prompt once. If you tap "Ask App Not to Track", the SDK is placed in its limited-data mode, no advertising identifier is read, and campaign measurement falls back to Apple's SKAdNetwork, which reports only aggregate, non-identifying conversion counts. If you tap "Allow", the advertising identifier is shared so that Meta can attribute your install to a specific advert.
What Meta never receives: the cards you hold, anything you mark as used, your Wallet Audit or any AED figure in it, your Bustan identifier, Apple's sub, your location, or anything you typed.
Meta uses these events to measure and optimise our campaigns, which can include deciding whether to show a Bustan advert to you, or to people whose behaviour resembles yours. If you have a Meta account, Meta may combine this data with what it already holds about you, under its own Privacy Policy and Business Tools terms; for those purposes Meta acts as an independent controller.
You can change your mind at any time in iOS Settings → Privacy & Security → Tracking → Bustan, or iOS Settings → Bustan → Allow Tracking. Withdrawing stops any further sharing of the advertising identifier immediately.
4. What we deliberately do not collect
This list is part of the product, not an afterthought.
Financial credentials and data Card numbers (full or partial), CVV/CVC, PINs, expiry dates, bank usernames or passwords, one-time passcodes, bank statements, transaction or spending history, account numbers, IBANs, credit reports, credit scores, income, or salary.
Identity documents Emirates ID number or copy, passport, visa, driving licence, or any photograph of an identity document.
Location history We do not track where you are. The only time the App touches your location is when you turn on Nearby, and then it is a single while-in-use fix that is processed on your device and never stored or transmitted (Section 3.12). No background location, no location history, no location in analytics. Where the App shows that a benefit applies in a particular emirate or venue, that is static information about the benefit, held in our catalog — it is not information about you. Your "home emirate", if you set it, is a preference you typed, not a measurement.
Your device's contents Contacts, calendar, photos (the App can write a share image to your photo library when you tap Save, and cannot read your library), microphone, camera, health data, SMS messages, other apps' notifications, or your clipboard.
Advertising and tracking No adverts inside the App. No data brokers, no fingerprinting, no re-targeting pixels or advertising tags on our website, no selling or renting of any list. The single exception is the Meta SDK described in Section 3.13, which exists to measure our own advertising and reads the advertising identifier only if you allow it at the iOS tracking prompt.
Bank connections No open banking, no account aggregation, no screen-scraping of bank portals, no statement upload, no email or SMS parsing.
5. Why we process it, and our legal basis
Under Article 4 of the PDPL, we rely on the bases below. Where we rely on consent, you can withdraw it at any time, and withdrawal does not affect processing that already happened.
| Purpose | Data used | Legal basis |
|---|---|---|
| Give you the App at all — hold your cards, settings, and benefit state | §3.1, §3.2, §3.3 | Performance of a contract with you (the Terms) |
| Generate and store your Wallet Audit dossier | §3.2, §3.6 | Performance of a contract |
| Check and honour what you have paid for | §3.5 | Performance of a contract |
| Send you push notifications | §3.4 | Consent — you grant it at the iOS permission prompt and can revoke it at any time |
| Send you service messages about your purchase, security, or a change to the Terms | §3.1, §3.5 | Legal obligation and legitimate interests in operating the service properly |
| Keep the service secure, prevent abuse and fraud, enforce our Terms | §3.8 | Legitimate interests in protecting the service and our users |
| Fix data errors in the catalog | §3.7 | Legitimate interests in accuracy, which benefits every user |
| Understand whether the product works, in aggregate | §3.9 | Legitimate interests in improving the service, using banded and minimised data |
| Respond to you when you contact us | §3.10 | Performance of a contract and legitimate interests |
| Waitlist announcements before launch | §3.11 | Consent, given when you submit the form |
| Show perks near you (Nearby) | §3.12 | Consent — the iOS location prompt; processed on-device only; revoke at any time |
| Measure whether our own adverts bring people to the App | §3.13 | Consent for the advertising identifier, given at the iOS tracking prompt; legitimate interests in measuring our own marketing for the non-identifying install and purchase events |
| Comply with law, respond to lawful requests, defend claims | as required | Legal obligation and establishing or defending legal claims |
We have assessed each legitimate-interest basis against your rights and interests, and use the minimum data that achieves the purpose. You can object to legitimate-interest processing — see Section 10.
We do not process any "sensitive personal data" as defined by the PDPL: no data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, criminal records, biometric data, genetic data, or health data. The presence of an Islamic card product in your wallet is a fact about a financial product, chosen for many reasons, and we do not treat it as, use it as, or infer from it any indicator of religious belief.
6. What we never do with your data
- We do not sell your personal data. Not to data brokers, not to banks, not to anyone, for anything.
- We do not share it for advertising or marketing by anyone else. The Meta SDK (Section 3.13) measures our adverts for Bustan; it receives install and purchase events and, only with your permission, the advertising identifier — never your wallet, and never anything for a third party's benefit.
- We do not tell banks or card issuers what you hold, what you use, or what our data says about you. They are not our customers and they receive nothing from us.
- We do not use your data to make automated decisions that produce legal effects for you or similarly significantly affect you. The Wallet Audit is generated by an algorithm, but it only produces an informational document. It does not decide anything about you, does not affect your credit, and is not a decision within the meaning of Article 16 of the PDPL. See Section 12.
- We do not use your personal data to train general-purpose AI models, ours or anyone else's. See Section 7.3.
7. Who we share it with
We share personal data only with the processors below, only for the purpose stated, and only under contracts that require them to protect it and use it for nothing else.
7.1 Our processors
| Processor | What it does | What it receives | Where it processes |
|---|---|---|---|
| Apple Inc. | App distribution, in-app purchases, Sign in with Apple, push delivery (APNs) | Your purchase transaction and Apple ID relationship, which Apple holds as its own controller; the opaque sub if you sign in; push payload for delivery | United States and globally |
| RevenueCat, Inc. | Purchase validation and entitlement management | Your app user ID, purchase receipts and events, entitlement status. No payment card data. | United States |
| Cloudflare, Inc. | Hosting our API and website, security, DDoS protection, CDN | Request metadata including IP address, in transit and short-term logs | Global edge network |
| Neon, Inc. | Managed PostgreSQL database | The application data in Sections 3.1–3.7 | Cloud region we select |
| Expo (650 Industries, Inc.) | Push notification delivery | Push token and notification content | United States |
| PostHog, Inc. (EU Cloud) | Product analytics | The allowlisted, banded events in §3.9 | European Union |
| Meta Platforms, Inc. | Measuring and attributing our own advertising, via the Meta SDK in the App | App install, launch, and purchase events, device technical data, and — only if you allow tracking — the advertising identifier (§3.13). For its own purposes Meta is an independent controller | United States and globally |
| Email and messaging providers | Support correspondence; WhatsApp if you message that number | The content of your correspondence | Varies by provider |
We may add or change processors. When we do, we update this table. If a change is significant, we will say so in the App.
7.2 Other disclosures
We may also disclose personal data:
- When the law requires it — to a court, regulator, or law enforcement body acting under valid legal authority. We check that requests are lawful and properly scoped, disclose the minimum required, and will tell you unless we are legally barred from doing so.
- To establish, exercise, or defend legal claims.
- To protect life or prevent serious harm.
- On a business transfer — if Jasmine Entertainment FZE is merged, acquired, or sells the Bustan business, your data may transfer to the buyer, who will be bound by this policy or a policy no less protective. We will notify you before your data becomes subject to a different policy, and you will be able to delete your data first.
7.3 A note about the AI in our pipeline
We use an AI service (the Anthropic API) as part of the pipeline that keeps our benefit catalog current.
It only ever processes publicly available bank web pages and public terms and conditions documents. No user data of any kind is sent to it — not your cards, not your settings, not your dossier, not your reports. The AI reads what a bank published on its own website and helps us extract and compare it; a person reviews the result before anything is published. Your data is not part of that pipeline and is not used to train any model.
8. Transfers outside the UAE
Bustan is operated from the UAE, but several of our processors store or process data outside it — principally in the United States and the European Union (see the table in Section 7.1). Our analytics provider is deliberately on its EU infrastructure.
Under Articles 22 and 23 of the PDPL, we transfer personal data outside the UAE only where:
- the destination has been recognised as providing an adequate level of protection; or
- the transfer is covered by appropriate contractual safeguards obliging the recipient to protect the data to the PDPL's standard, which is the basis we rely on for our processors; or
- the transfer is necessary to perform our contract with you — which is the case when Apple processes your purchase or delivers a push notification to your device; or
- you have given explicit consent, having been told of the risks.
We keep the transferred data minimal, and no financial credentials are ever transferred because we never hold any.
9. How long we keep it
| Data | Retention |
|---|---|
| Your account, cards, benefit state, settings | While your account is active, then deleted when you delete your data |
| Inactive accounts | Deleted after 24 months with no activity, after we attempt to notify you if we have a way to reach you |
| Wallet Audit dossiers | While your account is active, so you can reopen them |
| Push ledger | 12 months, then deleted — it exists only to prevent duplicate reminders |
| Perk reports | Retained after your account is deleted, but detached from you and kept only as an anonymous data-quality signal |
| Entitlement and purchase records | Up to 7 years, to meet accounting, tax, and audit obligations, and to defend claims. Records are reduced to the minimum required. |
| Deletion-prevention marker | Up to 7 years as a one-way hash, only to stop later subscription events or a backup restore from recreating a deleted account |
| Server and security logs | Typically 30 days, longer only where a specific security investigation requires it |
| Analytics events | 24 months, in banded and non-identifying form |
| Support correspondence | 24 months after your matter is closed |
| Waitlist emails | Until launch, or until you unsubscribe or ask us to delete, whichever is first |
| Your location (Nearby) | Not retained. Held in the App's memory only while the screen is open; never stored or sent to us |
| Ad-measurement events (Meta SDK) | Held by Meta under its own retention policy; we hold no copy |
Where we are required by law to keep something longer, we keep it for that period and no longer, and we stop using it for any other purpose.
10. Your rights
Under the PDPL you have the following rights over your personal data. They are free to exercise, and we will respond within 30 days. If a request is genuinely complex we may extend once, and we will tell you why before the first 30 days are up.
| Right | What it means | How |
|---|---|---|
| Access | Get confirmation of what we hold and a copy of it | Email us |
| Correction | Fix anything inaccurate or incomplete | Most things you can edit yourself in the App; otherwise email us |
| Erasure | Have your personal data deleted | In the App: You → Account → Delete Account, or email us |
| Restriction | Have us pause processing while a dispute about accuracy or legitimate interests is resolved | Email us |
| Objection | Object to processing based on legitimate interests, or to direct marketing (which we then stop, unconditionally) | Email us |
| Portability | Receive the data you gave us in a structured, commonly used, machine-readable format, or have it sent to another controller where technically feasible | Email us |
| Withdraw consent | Withdraw consent at any time, without affecting what happened before | Turn off notifications, location, or tracking for Bustan in iOS Settings; unsubscribe from the waitlist; or email us |
| Object to automated decisions | Ask for human review of a decision made solely by automated means that significantly affects you | Email us — though see Section 12; we do not believe we make any |
| Complain | Complain to us, or directly to the regulator | See Section 15 |
How to ask. Email support@getbustan.com and say what you want. Because Bustan is pseudonymous and does not receive your Apple email address, we may need you to make the request from within the App, or to provide the identifier shown in the App's settings, so that we can be sure we are giving your data to you and not to somebody else. We will not ask you for identity documents to verify a privacy request. If we genuinely cannot connect a request to an account, we will tell you rather than guess.
We may decline a request that is manifestly unfounded or excessive, or where the law requires or permits us to keep the data — for example a tax record. If we decline, we will explain why and tell you how to complain.
11. Deleting your data
11.1 How
In the App: You → Account → Delete Account. Or email support@getbustan.com.
11.2 What happens
Deletion cascades across our systems and removes your user record, your cards, your benefit state, your entitlement records, your Wallet Audit dossiers, your reports' link to you, and your push ledger. We also submit a deletion request to our purchases provider for the data it holds about you.
11.3 What does not disappear, and why
- Anonymous perk reports stay, detached from you, because they are a data-quality signal about a benefit, not about a person.
- Aggregated analytics already recorded in banded, non-identifying form cannot be traced back to you and cannot be removed.
- Financial records of purchases are kept for the statutory period in Section 9.
- A one-way deletion marker is kept for up to 7 years. It contains no raw account identifier and is used only to stop later subscription events or a backup restore from recreating an account you deleted.
- Backups are retained on a rolling cycle and are overwritten in the ordinary course, normally within 35 days. Restoring a backup does not resurrect a deleted account: deletions are re-applied after any restore.
- Apple's records of your purchase are Apple's, held under Apple's policy. We cannot delete them; you deal with Apple directly.
- Ad-measurement events already sent to Meta (Section 3.13) are held by Meta under its own policy. They are not linked to your Bustan account, and Meta's Privacy Policy explains how to exercise your rights with Meta directly.
11.4 Two things to know before you delete
- Deleting your data does not cancel a Bustan Pro subscription. Cancel through Apple: Settings → your name → Subscriptions → Bustan → Cancel Subscription. If you delete your data without cancelling, Apple will keep charging you.
- Deletion is permanent and immediate. We cannot get your cards, history, or dossiers back. Restoring Bustan Pro through Apple restores subscription access, not data you asked us to delete.
12. Automated processing
The Wallet Audit dossier, the value and waste estimates, the best-card-for-category answers, and notification scheduling are all produced automatically, by algorithms, without a person looking at your individual case.
These produce information for you to read. They do not decide anything about you: they do not grant or refuse anything, do not affect your credit, your eligibility for any product, your employment, or any legal right. In our view they are therefore not decisions that produce legal effects or similarly significantly affect you.
If you disagree, tell us at support@getbustan.com and a person will review it. And in every case, remember that the numbers are estimates produced from generic assumptions — Section 4 of the Terms explains this in detail.
13. Security
- Everything is encrypted in transit using TLS, and encrypted at rest by our database and hosting providers.
- The best security control we have is not collecting the data. There is no card number, PIN, or bank credential in our systems to steal, and an automated check in our build pipeline fails the build if any such field is introduced.
- Our API validates every request at the edge, and the App never talks to our database directly.
- Catalog bundles delivered to your device are integrity-signed.
- Access to production data is limited to those who need it, and protected by strong authentication. Our administrative surface sits behind additional access control.
- We keep dependencies patched and monitor for anomalies and abuse.
No system is perfectly secure, and we cannot guarantee absolute security. If a personal data breach occurs, we will notify the UAE Data Office and affected individuals as and when the PDPL requires, describing what happened, what data was involved, what we are doing, and what you should do.
Your part: keep your device locked and updated, keep your Apple ID secure, and never give your card number, PIN, password, or one-time passcode to anyone claiming to be us.
14. Children
Bustan is for adults aged 18 and over only. It is not directed at children, is not marketed to them, and has no features designed for them.
We do not knowingly collect personal data from anyone under 18. If we learn that we have, we will delete the account and its data promptly. If you are a parent or guardian and believe a child has provided us with personal data, email support@getbustan.com and we will act quickly.
15. Complaints
Come to us first. Email support@getbustan.com with "Privacy complaint" in the subject line. We will acknowledge it and respond substantively within 30 days. Most issues are resolved this way.
If you are not satisfied, you can complain to the UAE Data Office, the federal authority responsible for personal data protection, established under Federal Decree-Law No. 44 of 2021. Details of how to complain are published on the UAE Government portal at u.ae.
Complaining to us first is not a precondition, and nothing here limits your right to go straight to the regulator or to a court.
16. Changes to this policy
We may update this policy. When we do we will change the "Last updated" date and increment the version number.
For changes that materially affect how we use your personal data, or that introduce a new purpose or a new category of data, we will give you at least 30 days' notice before they take effect — by in-app notice, push notification, or email if we have one for you — and, where the law requires consent, we will ask for it rather than assume it. We will not apply a new purpose retroactively to data we already hold without a lawful basis for doing so.
Previous versions are available on request.
17. Contact
| support@getbustan.com | |
| Phone / WhatsApp | +971 50 749 3651 |
| Post | Jasmine Entertainment FZE, Sharjah Publishing City, Business Centre, Sharjah, United Arab Emirates |
| Trade licence | 4422193.01 |
See also: Terms & Conditions · Cookie Policy
Bustan is a product of Jasmine Entertainment FZE. We never ask for card numbers or bank logins.