Bustan بستان
Legal

Bustan — Privacy Policy

What Bustan collects, why, who it goes to, and how to delete it. We never ask for card numbers or bank logins.

Effective 23 August 2026 Last updated 4 September 2026 Version 1.3 Jasmine Entertainment FZE Sharjah, UAE

1. Who is responsible for your data

Jasmine Entertainment FZE is the Controller of the personal data described in this policy.

ControllerJasmine Entertainment FZE
Trade licence4422193.01 (Sharjah Publishing City Free Zone)
Registered addressSharjah Publishing City, Business Centre, Sharjah, United Arab Emirates
Privacy contactsupport@getbustan.com
Phone / WhatsApp+971 50 749 3651

support@getbustan.com is the only email address we operate, and it is the address to use for every privacy request, question, or complaint. It reaches the person responsible for privacy at Jasmine Entertainment FZE.

This policy is written to meet Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL") and its implementing regulations as in force from time to time.

2. What this policy covers

This policy covers:

It does not cover the practices of Apple, your bank, or any benefit provider. Those are governed by their own policies, which we do not control.


3. What we collect

Everything below is either something you type in, something your device tells us in the ordinary course of connecting to us, or something a payment or analytics provider tells us. Nothing is inferred from your bank.

3.1 Identity

DataWhy we have itDo we need it?
Per-install identifier — a random UUID generated before the Apple sign-in sheetSecurely proves and merges a new installation; after sign-in it is attached to the canonical Bustan accountRequired
Apple identifier (sub) — an opaque, Apple-generated account identifierEstablishes the Bustan account and lets us restore and sync data across supported Apple devicesRequired
Canonical Bustan identifier — a random UUID generated by our serverThe identifier used for your wallet, settings, audits, usage state, and purchase entitlementRequired
Email address — only if you write to support or join the website waitlistSupport replies; waitlist announcementsOptional

Bustan asks Apple for neither your name nor your email address. Sign in with Apple provides us only the opaque account identifier described above. We therefore do not receive your real Apple ID email or an Apple private-relay email through the App.

3.2 Your wallet — the important one

DataDetail
Card products you holdThe product, chosen from our list — for example "Emirates NBD Skywards Infinite". Not a card number. Not the last four digits. Not an image of your card.
NicknameOptional free text you choose for a card, e.g. "the travel one"
Annual fee anniversaryA date you optionally enter, or defer, so we can remind you before the fee falls due
When you added or removed a cardTimestamps

We cannot tell your specific card from anyone else's card of the same product. We know you hold "a Card X", the same way a forum post would.

3.3 How you use your benefits

DataDetail
Marked as usedWhich benefits you tap "used" on, and when
Usage windowsA count of uses per benefit cycle, so we know whether a monthly or quarterly allowance is spent
Muted benefitsWhich benefits you have told us to stop reminding you about

This is self-reported by you. We have no way to observe whether you actually used a benefit, and we do not try.

3.4 Notification settings

Push token (an Expo/Apple identifier for your device's notification channel), timezone (default Asia/Dubai), quiet hours start and end, your home emirate if you tell us, and your per-category notification preferences (expiry, fee anniversary, monthly recap, database updates, win-back). We also keep a push ledger — a record of which notifications were sent to you and when — so that we do not send you the same reminder twice.

3.5 Purchases and entitlements

DataDetail
Entitlement statusWhether you hold the wallet_audit or pro entitlement, whether it is active, and when it expires
Purchase event identifiersOpaque IDs from our purchases provider, used to apply each event exactly once

We never receive your payment card details, billing address, or Apple ID password. Apple takes your payment. Apple tells our purchases provider that a valid purchase happened. Our provider tells our server that you are entitled. That is the whole chain, and no payment instrument crosses it.

3.6 Your Wallet Audit dossiers

When you generate a dossier we store it: the catalog version it was built from, which of your cards were included, the generated content, and the total value and estimated waste figures. This is so you can open it again, and so a re-audit can show you what changed.

3.7 Reports you send us

If you tell us a benefit is wrong, we store the benefit concerned, a reason chosen from a fixed list (not offered, different terms, couldn't redeem, location wrong, other), an optional note of up to 280 characters, and the time.

Please do not put personal or financial information in the note field. It is a free-text box about a data error, and we do not need anything about you in it.

3.8 Technical data

When your device contacts our servers we necessarily receive, and our infrastructure logs for a short period: IP address, approximate country or region derived from it, the request made, the app version and operating system version, and timestamps. This is ordinary internet plumbing, used for security, abuse prevention, debugging, and rate limiting.

3.9 Analytics

We run a closed allowlist: an event is either on a short, pre-approved list or it is never sent. Anything not on the list cannot be sent, by design.

What the events contain:

What the events never contain:

Analytics exist to answer one question — is the product working — and are configured to answer it with the least data that will do.

3.10 Support correspondence

If you email, call, or WhatsApp us, we keep what you send and our replies, so we can help you and keep a record. Please do not send card numbers, PINs, passwords, one-time passcodes, or photographs of identity documents. If you do, we will delete them and ask you not to do it again.

3.11 The website

The getbustan.com website currently serves a marketing page, a waitlist sign-up, this policy, the Terms, the Cookie Policy, and a page describing our crawler. If you join the waitlist we store your email address (lowercased and trimmed), the source, and the time. Nothing else. See the Cookie Policy.

3.12 Your location, only if you turn on Nearby

The Home screen has a Nearby rail that shows perks at partner venues around you. It is off until you tap to enable it. When you do, iOS asks whether Bustan may use your location while you are using the App.

If you allow it, the App takes a single, low-accuracy position fix while it is in the foreground and compares it, on your device, with the venue coordinates in our catalog. That is the whole use. Your position:

If you decline, or would rather not, you can pick an emirate by hand instead. That choice is a preference you typed; it is stored on your device only and never leaves it.

You can withdraw location access at any time in iOS Settings → Bustan → Location. The App never asks for motion, fitness, or background location access.

3.13 Measuring our own adverts — the Meta SDK

We advertise Bustan on Meta's platforms (Facebook and Instagram). To know whether those adverts actually bring people to the App, the App includes the Meta (Facebook) SDK. This is the one third-party marketing component in Bustan, and here is exactly what it does.

What Meta receives from the App, regardless of any prompt: Meta's standard app events — that the App was installed, that it was launched, and that an in-app purchase completed (the product and price, as Apple reports it) — together with ordinary device technical data: device model, iOS version, App version, IP address, locale and timezone, and an anonymous identifier the SDK generates for the installation.

What Meta receives only with your permission: your device's advertising identifier (IDFA). After you sign in, iOS shows the App Tracking Transparency prompt once. If you tap "Ask App Not to Track", the SDK is placed in its limited-data mode, no advertising identifier is read, and campaign measurement falls back to Apple's SKAdNetwork, which reports only aggregate, non-identifying conversion counts. If you tap "Allow", the advertising identifier is shared so that Meta can attribute your install to a specific advert.

What Meta never receives: the cards you hold, anything you mark as used, your Wallet Audit or any AED figure in it, your Bustan identifier, Apple's sub, your location, or anything you typed.

Meta uses these events to measure and optimise our campaigns, which can include deciding whether to show a Bustan advert to you, or to people whose behaviour resembles yours. If you have a Meta account, Meta may combine this data with what it already holds about you, under its own Privacy Policy and Business Tools terms; for those purposes Meta acts as an independent controller.

You can change your mind at any time in iOS Settings → Privacy & Security → Tracking → Bustan, or iOS Settings → Bustan → Allow Tracking. Withdrawing stops any further sharing of the advertising identifier immediately.


4. What we deliberately do not collect

This list is part of the product, not an afterthought.

Financial credentials and data Card numbers (full or partial), CVV/CVC, PINs, expiry dates, bank usernames or passwords, one-time passcodes, bank statements, transaction or spending history, account numbers, IBANs, credit reports, credit scores, income, or salary.

Identity documents Emirates ID number or copy, passport, visa, driving licence, or any photograph of an identity document.

Location history We do not track where you are. The only time the App touches your location is when you turn on Nearby, and then it is a single while-in-use fix that is processed on your device and never stored or transmitted (Section 3.12). No background location, no location history, no location in analytics. Where the App shows that a benefit applies in a particular emirate or venue, that is static information about the benefit, held in our catalog — it is not information about you. Your "home emirate", if you set it, is a preference you typed, not a measurement.

Your device's contents Contacts, calendar, photos (the App can write a share image to your photo library when you tap Save, and cannot read your library), microphone, camera, health data, SMS messages, other apps' notifications, or your clipboard.

Advertising and tracking No adverts inside the App. No data brokers, no fingerprinting, no re-targeting pixels or advertising tags on our website, no selling or renting of any list. The single exception is the Meta SDK described in Section 3.13, which exists to measure our own advertising and reads the advertising identifier only if you allow it at the iOS tracking prompt.

Bank connections No open banking, no account aggregation, no screen-scraping of bank portals, no statement upload, no email or SMS parsing.


Under Article 4 of the PDPL, we rely on the bases below. Where we rely on consent, you can withdraw it at any time, and withdrawal does not affect processing that already happened.

PurposeData usedLegal basis
Give you the App at all — hold your cards, settings, and benefit state§3.1, §3.2, §3.3Performance of a contract with you (the Terms)
Generate and store your Wallet Audit dossier§3.2, §3.6Performance of a contract
Check and honour what you have paid for§3.5Performance of a contract
Send you push notifications§3.4Consent — you grant it at the iOS permission prompt and can revoke it at any time
Send you service messages about your purchase, security, or a change to the Terms§3.1, §3.5Legal obligation and legitimate interests in operating the service properly
Keep the service secure, prevent abuse and fraud, enforce our Terms§3.8Legitimate interests in protecting the service and our users
Fix data errors in the catalog§3.7Legitimate interests in accuracy, which benefits every user
Understand whether the product works, in aggregate§3.9Legitimate interests in improving the service, using banded and minimised data
Respond to you when you contact us§3.10Performance of a contract and legitimate interests
Waitlist announcements before launch§3.11Consent, given when you submit the form
Show perks near you (Nearby)§3.12Consent — the iOS location prompt; processed on-device only; revoke at any time
Measure whether our own adverts bring people to the App§3.13Consent for the advertising identifier, given at the iOS tracking prompt; legitimate interests in measuring our own marketing for the non-identifying install and purchase events
Comply with law, respond to lawful requests, defend claimsas requiredLegal obligation and establishing or defending legal claims

We have assessed each legitimate-interest basis against your rights and interests, and use the minimum data that achieves the purpose. You can object to legitimate-interest processing — see Section 10.

We do not process any "sensitive personal data" as defined by the PDPL: no data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, criminal records, biometric data, genetic data, or health data. The presence of an Islamic card product in your wallet is a fact about a financial product, chosen for many reasons, and we do not treat it as, use it as, or infer from it any indicator of religious belief.


6. What we never do with your data


7. Who we share it with

We share personal data only with the processors below, only for the purpose stated, and only under contracts that require them to protect it and use it for nothing else.

7.1 Our processors

ProcessorWhat it doesWhat it receivesWhere it processes
Apple Inc.App distribution, in-app purchases, Sign in with Apple, push delivery (APNs)Your purchase transaction and Apple ID relationship, which Apple holds as its own controller; the opaque sub if you sign in; push payload for deliveryUnited States and globally
RevenueCat, Inc.Purchase validation and entitlement managementYour app user ID, purchase receipts and events, entitlement status. No payment card data.United States
Cloudflare, Inc.Hosting our API and website, security, DDoS protection, CDNRequest metadata including IP address, in transit and short-term logsGlobal edge network
Neon, Inc.Managed PostgreSQL databaseThe application data in Sections 3.1–3.7Cloud region we select
Expo (650 Industries, Inc.)Push notification deliveryPush token and notification contentUnited States
PostHog, Inc. (EU Cloud)Product analyticsThe allowlisted, banded events in §3.9European Union
Meta Platforms, Inc.Measuring and attributing our own advertising, via the Meta SDK in the AppApp install, launch, and purchase events, device technical data, and — only if you allow tracking — the advertising identifier (§3.13). For its own purposes Meta is an independent controllerUnited States and globally
Email and messaging providersSupport correspondence; WhatsApp if you message that numberThe content of your correspondenceVaries by provider

We may add or change processors. When we do, we update this table. If a change is significant, we will say so in the App.

7.2 Other disclosures

We may also disclose personal data:

7.3 A note about the AI in our pipeline

We use an AI service (the Anthropic API) as part of the pipeline that keeps our benefit catalog current.

It only ever processes publicly available bank web pages and public terms and conditions documents. No user data of any kind is sent to it — not your cards, not your settings, not your dossier, not your reports. The AI reads what a bank published on its own website and helps us extract and compare it; a person reviews the result before anything is published. Your data is not part of that pipeline and is not used to train any model.


8. Transfers outside the UAE

Bustan is operated from the UAE, but several of our processors store or process data outside it — principally in the United States and the European Union (see the table in Section 7.1). Our analytics provider is deliberately on its EU infrastructure.

Under Articles 22 and 23 of the PDPL, we transfer personal data outside the UAE only where:

We keep the transferred data minimal, and no financial credentials are ever transferred because we never hold any.


9. How long we keep it

DataRetention
Your account, cards, benefit state, settingsWhile your account is active, then deleted when you delete your data
Inactive accountsDeleted after 24 months with no activity, after we attempt to notify you if we have a way to reach you
Wallet Audit dossiersWhile your account is active, so you can reopen them
Push ledger12 months, then deleted — it exists only to prevent duplicate reminders
Perk reportsRetained after your account is deleted, but detached from you and kept only as an anonymous data-quality signal
Entitlement and purchase recordsUp to 7 years, to meet accounting, tax, and audit obligations, and to defend claims. Records are reduced to the minimum required.
Deletion-prevention markerUp to 7 years as a one-way hash, only to stop later subscription events or a backup restore from recreating a deleted account
Server and security logsTypically 30 days, longer only where a specific security investigation requires it
Analytics events24 months, in banded and non-identifying form
Support correspondence24 months after your matter is closed
Waitlist emailsUntil launch, or until you unsubscribe or ask us to delete, whichever is first
Your location (Nearby)Not retained. Held in the App's memory only while the screen is open; never stored or sent to us
Ad-measurement events (Meta SDK)Held by Meta under its own retention policy; we hold no copy

Where we are required by law to keep something longer, we keep it for that period and no longer, and we stop using it for any other purpose.


10. Your rights

Under the PDPL you have the following rights over your personal data. They are free to exercise, and we will respond within 30 days. If a request is genuinely complex we may extend once, and we will tell you why before the first 30 days are up.

RightWhat it meansHow
AccessGet confirmation of what we hold and a copy of itEmail us
CorrectionFix anything inaccurate or incompleteMost things you can edit yourself in the App; otherwise email us
ErasureHave your personal data deletedIn the App: You → Account → Delete Account, or email us
RestrictionHave us pause processing while a dispute about accuracy or legitimate interests is resolvedEmail us
ObjectionObject to processing based on legitimate interests, or to direct marketing (which we then stop, unconditionally)Email us
PortabilityReceive the data you gave us in a structured, commonly used, machine-readable format, or have it sent to another controller where technically feasibleEmail us
Withdraw consentWithdraw consent at any time, without affecting what happened beforeTurn off notifications, location, or tracking for Bustan in iOS Settings; unsubscribe from the waitlist; or email us
Object to automated decisionsAsk for human review of a decision made solely by automated means that significantly affects youEmail us — though see Section 12; we do not believe we make any
ComplainComplain to us, or directly to the regulatorSee Section 15

How to ask. Email support@getbustan.com and say what you want. Because Bustan is pseudonymous and does not receive your Apple email address, we may need you to make the request from within the App, or to provide the identifier shown in the App's settings, so that we can be sure we are giving your data to you and not to somebody else. We will not ask you for identity documents to verify a privacy request. If we genuinely cannot connect a request to an account, we will tell you rather than guess.

We may decline a request that is manifestly unfounded or excessive, or where the law requires or permits us to keep the data — for example a tax record. If we decline, we will explain why and tell you how to complain.


11. Deleting your data

11.1 How

In the App: You → Account → Delete Account. Or email support@getbustan.com.

11.2 What happens

Deletion cascades across our systems and removes your user record, your cards, your benefit state, your entitlement records, your Wallet Audit dossiers, your reports' link to you, and your push ledger. We also submit a deletion request to our purchases provider for the data it holds about you.

11.3 What does not disappear, and why

11.4 Two things to know before you delete

  1. Deleting your data does not cancel a Bustan Pro subscription. Cancel through Apple: Settings → your name → Subscriptions → Bustan → Cancel Subscription. If you delete your data without cancelling, Apple will keep charging you.
  2. Deletion is permanent and immediate. We cannot get your cards, history, or dossiers back. Restoring Bustan Pro through Apple restores subscription access, not data you asked us to delete.

12. Automated processing

The Wallet Audit dossier, the value and waste estimates, the best-card-for-category answers, and notification scheduling are all produced automatically, by algorithms, without a person looking at your individual case.

These produce information for you to read. They do not decide anything about you: they do not grant or refuse anything, do not affect your credit, your eligibility for any product, your employment, or any legal right. In our view they are therefore not decisions that produce legal effects or similarly significantly affect you.

If you disagree, tell us at support@getbustan.com and a person will review it. And in every case, remember that the numbers are estimates produced from generic assumptions — Section 4 of the Terms explains this in detail.


13. Security

No system is perfectly secure, and we cannot guarantee absolute security. If a personal data breach occurs, we will notify the UAE Data Office and affected individuals as and when the PDPL requires, describing what happened, what data was involved, what we are doing, and what you should do.

Your part: keep your device locked and updated, keep your Apple ID secure, and never give your card number, PIN, password, or one-time passcode to anyone claiming to be us.


14. Children

Bustan is for adults aged 18 and over only. It is not directed at children, is not marketed to them, and has no features designed for them.

We do not knowingly collect personal data from anyone under 18. If we learn that we have, we will delete the account and its data promptly. If you are a parent or guardian and believe a child has provided us with personal data, email support@getbustan.com and we will act quickly.


15. Complaints

Come to us first. Email support@getbustan.com with "Privacy complaint" in the subject line. We will acknowledge it and respond substantively within 30 days. Most issues are resolved this way.

If you are not satisfied, you can complain to the UAE Data Office, the federal authority responsible for personal data protection, established under Federal Decree-Law No. 44 of 2021. Details of how to complain are published on the UAE Government portal at u.ae.

Complaining to us first is not a precondition, and nothing here limits your right to go straight to the regulator or to a court.


16. Changes to this policy

We may update this policy. When we do we will change the "Last updated" date and increment the version number.

For changes that materially affect how we use your personal data, or that introduce a new purpose or a new category of data, we will give you at least 30 days' notice before they take effect — by in-app notice, push notification, or email if we have one for you — and, where the law requires consent, we will ask for it rather than assume it. We will not apply a new purpose retroactively to data we already hold without a lawful basis for doing so.

Previous versions are available on request.


17. Contact

Emailsupport@getbustan.com
Phone / WhatsApp+971 50 749 3651
PostJasmine Entertainment FZE, Sharjah Publishing City, Business Centre, Sharjah, United Arab Emirates
Trade licence4422193.01

See also: Terms & Conditions · Cookie Policy


Bustan is a product of Jasmine Entertainment FZE. We never ask for card numbers or bank logins.