Legal › Privacy Policy
Version 1.2.0 · In force 2026-06-20
Privacy Policy
How Lebsloop handles your personal data
This Privacy Policy explains what personal data Lebsloop collects, why we collect it, how long we keep it, and the choices you have. It is written to comply with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, "PDPL") and the executive regulations issued under it. If anything here conflicts with the [Terms of Service](terms-of-service), this Privacy Policy controls for matters of personal data.
1. Who is the controller
Lebsloop is the data controller for the personal data described here. "Lebsloop", "we", "us", and "our" mean the company that owns and operates the Lebsloop mobile application and the lebsloop.com website, based in the United Arab Emirates. Its full registered particulars (registered company name, trade-licence number, and registered office) are available on request at legal@lebsloop.com. "You" means the person whose data we are processing.
For any privacy question, request, or complaint, write to privacy@lebsloop.com. We aim to respond within 30 days, as required by PDPL Article 14.
2. What data we collect
2.1 Account data
When you create an account we collect your first name, last name, mobile number, email address, country of residence, and language preference. Sign-in uses one-time codes sent by SMS or email — we do not collect or store a password. You may add a profile photo, a short bio, and your size and brand preferences.
2.2 Identity verification (KYC) data
To list items or receive payouts you must verify your identity; buying does not require verification. Where possible, verification is performed by UAE Pass — the UAE government identity service — at assurance level SOP2 (Emirates ID, verified mobile, and verified email). For users without UAE Pass, an Emirates ID image and a selfie are processed by our licensed KYC vendor (Didit).
2.3 Payment data
All payments are processed by our licensed UAE payment partner. The payment partner collects and stores your card details under PCI-DSS. Lebsloop only sees a tokenised reference, the last four digits of the card, the card brand, and the transaction status. For seller payouts we store the IBAN you register so we can pay you by bank transfer.
2.4 Listing, sale, and delivery data
When you list an item, buy an item, or a delivery is carried out we collect: the photos you upload to a listing, the photos a buyer attaches when filing a claim, the descriptions and condition notes you write, the pickup and delivery addresses, reviews you leave, and any defect or not-as-described claims you raise — see the Trust & Safety Policy.
2.5 Messages
In-app messages between you and other users are stored on our servers so we can deliver them and so they are available as evidence if a dispute is raised. Message bodies are not end-to-end encrypted. We do not read messages routinely; access is limited to dispute resolution and safety investigations.
2.6 Device and usage data
Each event the app sends carries a per-device envelope: a device identifier we generate, the app version, platform (iOS or Android), locale, device brand and model, OS version, and network type (cellular or wi-fi). On the server we attach the country and region derived from the request IP using an offline geo database.
For Android, we read the Play Install Referrer at first launch to record where the install came from (campaign, ad group, referrer). For iOS this field is currently "unknown" — when we adopt Apple's AdServices framework in a future build we will update this policy and prompt you for the App Tracking Transparency permission.
2.7 Behavioural and transactional events
Lebsloop records two kinds of events. Behavioural events — taps, screen views, scrolls, search queries, performance traces — are written to a ClickHouse analytics store and used in aggregate for product improvement. Transactional events — sign-up, KYC outcomes, sale-order lifecycle, money movements, dispute milestones — are written to our PostgreSQL database and are joined to your account because they form the audit trail for regulated activity.
3. Why we process your data (legal basis)
PDPL Article 5 requires a lawful basis for each processing activity. We rely on the following:
- Performance of a contract
- Running your account, taking sale orders, processing payments, paying sellers, arranging delivery, and operating disputes. Without this data we cannot deliver the service you signed up for.
- Consent
- Direct marketing (Lebsloop updates and promotions by email and push notification), optional profile fields, and the use of behavioural analytics where consent is required. Marketing is strictly opt-in — off by default until you choose it — and you can withdraw at any time (see “Direct marketing” below and section 7).
- Legitimate interest
- Fraud prevention, security monitoring, dispute investigation, abuse detection, debugging, aggregate product analytics, and protecting the rights of other users. We balance these interests against your rights and use the minimum data needed.
- Legal obligation
- Keeping transaction and tax records (UAE Federal Tax Authority requires retention of accounting records for 7 years), anti-money-laundering monitoring, responding to lawful requests from UAE authorities, and complying with PDPL itself.
Direct marketing. With your consent we send “Lebsloop updates and promotions” — news, offers, and product updates — by email and push notification. This is separate from the transactional messages about your orders, payouts, disputes, and account, which we always send and which are not marketing. Marketing consent is off by default; you opt in only if you choose to, and you can withdraw just as easily at any time from Settings → Notifications → Promotions (turn off email, push, or both) or via the one-click unsubscribe link in any marketing email. Withdrawing takes effect immediately and does not affect the transactional messages above. This first-party marketing is separate from the ad-measurement sharing described in section 5 (Meta, TikTok, Google Ads) — each has its own, independent control.
4. How long we keep your data
We keep personal data only for as long as we need it for the purpose it was collected, or for as long as we are required to by UAE law.
- Active account — kept for the lifetime of your account.
- Deleted account — there is a 30-day grace period during which you can restore the account by signing back in. After day 30 the account is anonymized as described in the Account Deletion Policy.
- Financial and tax records — retained for 7 years from the end of the relevant tax period, as required by UAE Federal Decree-Law No. 28 of 2022 on tax procedures. After anonymization the records are linked to a hash, not to you personally.
- Anti-money-laundering audit trail (payments, payouts, verification outcomes) — retained for 5 years per UAE Central Bank guidance, as described in the Account Deletion Policy.
- KYC documents (Emirates ID images, selfie, biometric templates) — not stored on Lebsloop servers; held by UAE Pass or the KYC vendor under their own retention windows. Lebsloop only retains the verification result and the minimal identity attributes released to us.
- In-app messages — retained while your account is active and for 6 months after the related sale order ends. Messages tied to an open dispute are retained until the dispute closes plus the legal retention window for the dispute itself.
- Behavioural analytics events — retained in ClickHouse for 24 months in identifiable form, then aggregated.
- Server logs and security telemetry — 90 days.
5. Who we share data with
We share personal data only with processors who help us run the service, and only the minimum each one needs. Every processor is bound by a written contract that requires PDPL-equivalent protection.
- UAE Pass — government identity service; receives the assertion request and returns identity attributes.
- Our licensed payment partner (Mamo, a DFSA-regulated payment provider) — payment processor; receives card and transaction data needed to take payment, hold funds, and issue refunds and payouts.
- Our appointed courier partner — collects items from sellers and delivers them to buyers; receives the names, addresses, and contact details needed to collect and deliver.
- Our licensed KYC vendor (Didit) — identity verification for users who do not use UAE Pass; processes the Emirates ID image and selfie to confirm identity, under its own retention policy.
- Twilio — SMS provider; receives your mobile number and the OTP body when we send a verification SMS.
- AWS (Frankfurt, eu-central-1) — hosting; runs the database, application servers, and supporting infrastructure.
- MinIO / Amazon S3 — object storage; holds listing photos, dispute-claim photos, and other uploads.
- Amazon SES / Postmark — email delivery; receives the recipient address and the email body.
- Expo (Expo Notifications) — push delivery; receives your device push token to deliver notifications through Apple (APNs) and Google (FCM).
- Sentry — crash and error monitoring; receives stack traces and a redacted device context.
- PostHog — product analytics (when enabled); receives the device envelope and behavioural events.
- Meta, TikTok, Google Ads — for measurement of ad effectiveness, we share a hashed email and phone number (SHA-256 with NFKD normalization, lowercase, trimmed) along with the country as a single hashed string. To opt out of ad measurement, write to privacy@lebsloop.com from your registered email.
We will also share data when we are required to by UAE law, a court order, or a request from a UAE authority acting within its mandate, and when sharing is necessary to investigate fraud or to protect the safety of users.
6. Where your data is stored
Lebsloop's primary infrastructure runs in AWS Frankfurt (eu-central-1). We chose Frankfurt after evaluating regional availability, including the recovery status of AWS me-central-1 (UAE) since the drone-strike incident of March 2026. Storing in Frankfurt is a cross-border transfer of personal data out of the UAE.
Under PDPL Article 22, cross-border transfer is permitted to jurisdictions that provide an adequate level of protection. The European Economic Area, where Germany sits, is widely recognized as providing such protection through the EU General Data Protection Regulation (GDPR). In addition, our contract with AWS includes the EU Standard Contractual Clauses and supplementary security measures (encryption at rest, encryption in transit, key management under AWS KMS, and least-privilege access controls).
When the recovery of AWS me-central-1 is complete and the region meets our reliability bar, we plan to migrate the primary region back to the UAE. We will update this policy at that point.
7. Your rights under PDPL
You have the following rights over your personal data:
- Access — ask for a copy of the personal data we hold about you.
- Rectification — ask us to correct data that is inaccurate or incomplete.
- Deletion — ask us to delete your account and the data tied to it, subject to the retention rules in section 4.
- Portability — ask for your data in a structured, machine-readable format you can take elsewhere.
- Restriction — ask us to pause processing while a dispute or correction is being handled.
- Objection — object to processing we base on legitimate interest, including direct marketing.
- Withdraw consent — withdraw a consent you gave us, with no effect on processing already carried out under it.
- Complain — lodge a complaint with the UAE Data Office under PDPL.
- Human review — where an important decision (such as a suspension or a dispute outcome) was assisted by our automated systems, ask for a person to review it.
To exercise any of these rights, write to privacy@lebsloop.com from the email registered on your account. We will respond within 30 days. We may ask for additional verification before acting on a request so we do not disclose data to the wrong person.
Automated decisions and AI. We use AI to power recommendations and smart search, and to help flag suspicious activity, counterfeits, and policy breaches. We do not make decisions that significantly affect you — such as suspending your account or deciding a dispute — by automated means alone; a member of our team reviews the situation before we act, and you can ask for that human review (see the right above). To opt out of personalised recommendations, write to privacy@lebsloop.com from your registered email.
8. Security and breach handling
We protect data with HTTPS everywhere, encryption at rest, passwordless one-time-code sign-in, short-lived access tokens with refresh-token rotation, isolated environments for production and staging, least-privilege role-based access, audit logging, and continuous vulnerability scanning.
If we detect a personal data breach that is likely to result in a risk to your rights, we will notify the UAE Data Office within the timeframes required by PDPL and notify affected users directly via email and in-app banner. The notification will describe what happened, what data was affected, what we have done to contain it, and what you can do to protect yourself.
9. Children
Lebsloop is for adults. You must be 18 or older to use the service. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, write to safety@lebsloop.com and we will close the account and delete the data.
10. Cookies and similar technologies
The Lebsloop mobile app does not use cookies. Sessions on the app are managed with native secure storage.
The marketing website lebsloop.com uses cookies for the bare minimum needed to operate the site (a session cookie, a language preference) and, with your consent, for analytics and advertising measurement. The consent banner on first visit lets you choose. You can change your choice at any time from the footer of the marketing site. See the Cookie Policy for the full detail.
11. Changes to this policy
We may update this Privacy Policy. Material changes will be notified in the app and by email at least 14 days before they take effect. The current version is shown at the top of this document.
12. Contact
For privacy questions or to exercise your rights, write to privacy@lebsloop.com. For safety reports including suspected misuse of personal data, write to safety@lebsloop.com.