Skip to content
lebsloopلِبْس لُوبالعربية

LegalPrivacy Policy

Version 1.2.0 · In force 2026-06-20

Privacy Policy

How Lebsloop handles your personal data

This Privacy Policy explains what personal data Lebsloop collects, why we collect it, how long we keep it, and the choices you have. It is written to comply with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, "PDPL") and the executive regulations issued under it. If anything here conflicts with the [Terms of Service](terms-of-service), this Privacy Policy controls for matters of personal data.

1. Who is the controller

Lebsloop is the data controller for the personal data described here. "Lebsloop", "we", "us", and "our" mean the company that owns and operates the Lebsloop mobile application and the lebsloop.com website, based in the United Arab Emirates. Its full registered particulars (registered company name, trade-licence number, and registered office) are available on request at legal@lebsloop.com. "You" means the person whose data we are processing.

For any privacy question, request, or complaint, write to privacy@lebsloop.com. We aim to respond within 30 days, as required by PDPL Article 14.

2. What data we collect

2.1 Account data

When you create an account we collect your first name, last name, mobile number, email address, country of residence, and language preference. Sign-in uses one-time codes sent by SMS or email — we do not collect or store a password. You may add a profile photo, a short bio, and your size and brand preferences.

2.2 Identity verification (KYC) data

To list items or receive payouts you must verify your identity; buying does not require verification. Where possible, verification is performed by UAE Pass — the UAE government identity service — at assurance level SOP2 (Emirates ID, verified mobile, and verified email). For users without UAE Pass, an Emirates ID image and a selfie are processed by our licensed KYC vendor (Didit).

Lebsloop does not store the original Emirates ID image, the selfie capture, or any biometric template on our servers. That data is processed by UAE Pass or the KYC vendor under their own retention policies. Lebsloop only stores the result of the check (pass/fail) and a small set of fields released by UAE Pass or the KYC vendor (subject identifier, name, nationality, date of birth, and the assurance level).

2.3 Payment data

All payments are processed by our licensed UAE payment partner. The payment partner collects and stores your card details under PCI-DSS. Lebsloop only sees a tokenised reference, the last four digits of the card, the card brand, and the transaction status. For seller payouts we store the IBAN you register so we can pay you by bank transfer.

2.4 Listing, sale, and delivery data

When you list an item, buy an item, or a delivery is carried out we collect: the photos you upload to a listing, the photos a buyer attaches when filing a claim, the descriptions and condition notes you write, the pickup and delivery addresses, reviews you leave, and any defect or not-as-described claims you raise — see the Trust & Safety Policy.

2.5 Messages

In-app messages between you and other users are stored on our servers so we can deliver them and so they are available as evidence if a dispute is raised. Message bodies are not end-to-end encrypted. We do not read messages routinely; access is limited to dispute resolution and safety investigations.

2.6 Device and usage data

Each event the app sends carries a per-device envelope: a device identifier we generate, the app version, platform (iOS or Android), locale, device brand and model, OS version, and network type (cellular or wi-fi). On the server we attach the country and region derived from the request IP using an offline geo database.

For Android, we read the Play Install Referrer at first launch to record where the install came from (campaign, ad group, referrer). For iOS this field is currently "unknown" — when we adopt Apple's AdServices framework in a future build we will update this policy and prompt you for the App Tracking Transparency permission.

2.7 Behavioural and transactional events

Lebsloop records two kinds of events. Behavioural events — taps, screen views, scrolls, search queries, performance traces — are written to a ClickHouse analytics store and used in aggregate for product improvement. Transactional events — sign-up, KYC outcomes, sale-order lifecycle, money movements, dispute milestones — are written to our PostgreSQL database and are joined to your account because they form the audit trail for regulated activity.

3. Why we process your data (legal basis)

PDPL Article 5 requires a lawful basis for each processing activity. We rely on the following:

Performance of a contract
Running your account, taking sale orders, processing payments, paying sellers, arranging delivery, and operating disputes. Without this data we cannot deliver the service you signed up for.
Consent
Direct marketing (Lebsloop updates and promotions by email and push notification), optional profile fields, and the use of behavioural analytics where consent is required. Marketing is strictly opt-in — off by default until you choose it — and you can withdraw at any time (see “Direct marketing” below and section 7).
Legitimate interest
Fraud prevention, security monitoring, dispute investigation, abuse detection, debugging, aggregate product analytics, and protecting the rights of other users. We balance these interests against your rights and use the minimum data needed.
Legal obligation
Keeping transaction and tax records (UAE Federal Tax Authority requires retention of accounting records for 7 years), anti-money-laundering monitoring, responding to lawful requests from UAE authorities, and complying with PDPL itself.

Direct marketing. With your consent we send “Lebsloop updates and promotions” — news, offers, and product updates — by email and push notification. This is separate from the transactional messages about your orders, payouts, disputes, and account, which we always send and which are not marketing. Marketing consent is off by default; you opt in only if you choose to, and you can withdraw just as easily at any time from Settings → Notifications → Promotions (turn off email, push, or both) or via the one-click unsubscribe link in any marketing email. Withdrawing takes effect immediately and does not affect the transactional messages above. This first-party marketing is separate from the ad-measurement sharing described in section 5 (Meta, TikTok, Google Ads) — each has its own, independent control.

4. How long we keep your data

We keep personal data only for as long as we need it for the purpose it was collected, or for as long as we are required to by UAE law.

5. Who we share data with

We share personal data only with processors who help us run the service, and only the minimum each one needs. Every processor is bound by a written contract that requires PDPL-equivalent protection.

We will also share data when we are required to by UAE law, a court order, or a request from a UAE authority acting within its mandate, and when sharing is necessary to investigate fraud or to protect the safety of users.

6. Where your data is stored

Lebsloop's primary infrastructure runs in AWS Frankfurt (eu-central-1). We chose Frankfurt after evaluating regional availability, including the recovery status of AWS me-central-1 (UAE) since the drone-strike incident of March 2026. Storing in Frankfurt is a cross-border transfer of personal data out of the UAE.

Under PDPL Article 22, cross-border transfer is permitted to jurisdictions that provide an adequate level of protection. The European Economic Area, where Germany sits, is widely recognized as providing such protection through the EU General Data Protection Regulation (GDPR). In addition, our contract with AWS includes the EU Standard Contractual Clauses and supplementary security measures (encryption at rest, encryption in transit, key management under AWS KMS, and least-privilege access controls).

When the recovery of AWS me-central-1 is complete and the region meets our reliability bar, we plan to migrate the primary region back to the UAE. We will update this policy at that point.

7. Your rights under PDPL

You have the following rights over your personal data:

To exercise any of these rights, write to privacy@lebsloop.com from the email registered on your account. We will respond within 30 days. We may ask for additional verification before acting on a request so we do not disclose data to the wrong person.

Automated decisions and AI. We use AI to power recommendations and smart search, and to help flag suspicious activity, counterfeits, and policy breaches. We do not make decisions that significantly affect you — such as suspending your account or deciding a dispute — by automated means alone; a member of our team reviews the situation before we act, and you can ask for that human review (see the right above). To opt out of personalised recommendations, write to privacy@lebsloop.com from your registered email.

8. Security and breach handling

We protect data with HTTPS everywhere, encryption at rest, passwordless one-time-code sign-in, short-lived access tokens with refresh-token rotation, isolated environments for production and staging, least-privilege role-based access, audit logging, and continuous vulnerability scanning.

If we detect a personal data breach that is likely to result in a risk to your rights, we will notify the UAE Data Office within the timeframes required by PDPL and notify affected users directly via email and in-app banner. The notification will describe what happened, what data was affected, what we have done to contain it, and what you can do to protect yourself.

9. Children

Lebsloop is for adults. You must be 18 or older to use the service. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, write to safety@lebsloop.com and we will close the account and delete the data.

10. Cookies and similar technologies

The Lebsloop mobile app does not use cookies. Sessions on the app are managed with native secure storage.

The marketing website lebsloop.com uses cookies for the bare minimum needed to operate the site (a session cookie, a language preference) and, with your consent, for analytics and advertising measurement. The consent banner on first visit lets you choose. You can change your choice at any time from the footer of the marketing site. See the Cookie Policy for the full detail.

11. Changes to this policy

We may update this Privacy Policy. Material changes will be notified in the app and by email at least 14 days before they take effect. The current version is shown at the top of this document.

12. Contact

For privacy questions or to exercise your rights, write to privacy@lebsloop.com. For safety reports including suspected misuse of personal data, write to safety@lebsloop.com.