Privacy Policy

Last updated: 7 August 2026 · Controller: Queenpass (the "Company", "we", "us") · Contact: privacy@queenpass.app


1. Who this applies to

Queenpass is a beauty-deals marketplace connecting customers with salons in the UAE and the wider region. Customers buy prepaid Service Passes in the app and redeem them at the salon by QR code. This policy covers both the customer app and the business (salon) app + dashboard.

2. What we collect

From customers

  • Email address and password — you sign in with email + password (we ask you to verify the address). The password is stored only as a secure hash.
  • Google / Apple sign-in — if you choose them, we receive an account identifier and, where the provider shares them, your name and email. We never see your Google or Apple password.
  • Name and preferred language — provided at sign-up.
  • Phone number — only where your account actually has one (for example, added by you or carried by an older account). Phone-code sign-in is not currently offered.
  • Approximate location — only if you grant location permission, and only to sort deals "near you." You can use the app without it.
  • Passes, visits, reviews, loyalty activity — the passes you buy, appointments scheduled on them, redemptions (QR scans), and star reviews you leave after a scanned visit.
  • Payment confirmation — payments are processed by Stripe; we receive a confirmation and amount, not your full card number (Stripe handles card data). If you scan your card with the camera at checkout, the scan goes to Stripe, not to us.
  • Consent records — which Terms/Privacy versions you accepted, when, and from where.
  • Device push token — if you enable notifications, to deliver pass and visit updates.
  • Support messages — if you contact us.

From salons (business users)

  • Business details, location, opening hours, photos.
  • Trade licence (KYC) and bank/IBAN details — to verify the business and pay out earnings.
  • Owner name, phone, and email.

Automatically

  • Basic technical/diagnostic data (app version, error reports via Sentry) to keep the service reliable. We do not use third-party advertising trackers.

3. Why we use it (legal bases)

  • To provide the service — accounts, discovery, pass purchase and redemption (QR), appointments, reviews, loyalty, payouts (performance of a contract).
  • Payments — to take the pass payment and reconcile it (contract / legal obligation).
  • Notifications — pass, visit, and account updates (consent, which you can withdraw per category in settings).
  • Safety, fraud prevention, and legal/tax compliance (legitimate interests / legal obligation).

4. What the salon sees about you

Salons see you as your first name and last initial only, together with the pass and visit details they need to serve you (the deal, the pass state, the appointment time). Your contact details are not shared through the platform — what you share when you contact a salon directly is up to you.

5. Who we share it with (processors)

We share the minimum necessary with service providers acting on our instructions:

  • Stripe — payment processing.
  • Amazon Web Services — hosting, database, and secure file storage (e.g. trade licences).
  • Expo / Apple (APNs) / Google (FCM) — delivering push notifications.
  • Google — only if you choose "Sign in with Google."
  • Apple — only if you choose "Sign in with Apple."
  • Sentry — error diagnostics.

We do not sell your personal data. We disclose data to authorities only where legally required.

6. International transfers

Our infrastructure currently runs in AWS (Europe, eu-west-3). Where data is processed outside your country, we rely on appropriate safeguards (e.g. standard contractual clauses / adequacy).

7. How long we keep it

  • Passes and financial records — retained as required for tax/accounting and dispute resolution, even after account closure.
  • Short-lived security codes (e.g. verification codes) — they expire within minutes and are not stored.
  • On account deletion — we anonymize your personal identifiers (name, email, phone) and remove your device push tokens, while retaining the non-identifying transaction records the law requires us to keep. Consent records are retained as proof of the consent that existed.

8. Your rights

Subject to local law, you can access, correct, or delete your data, withdraw consent, and object to certain processing. The customer app lets you delete your account from within the app (Profile → account settings); deletion runs a real erasure — your identifiers are anonymized and your devices stop receiving pushes. Salons can request deletion from the dashboard. To exercise other rights, contact privacy@queenpass.app.

9. Notifications & permissions

  • Location is requested only when needed and can be revoked in your device settings. The camera is used only if you choose to scan your payment card at checkout (the scan goes to Stripe); the salon app uses it to scan pass QR codes.
  • You control which push categories you receive; the in-app notification history remains regardless.

10. Children

Queenpass is intended for users who are 18 or older. It is not directed at children, and we do not knowingly collect their data.

11. Security

Traffic is encrypted in transit (HTTPS/TLS). Access to personal data is restricted, sign-in tokens are stored in the device's secure keystore, and sensitive documents (trade licences) are kept in private storage.

12. Changes

We may update this policy; we'll post the new version here and update the "last updated" date. For material changes we ask you to accept the new version in-app.

13. Contact

Questions or requests: privacy@queenpass.app.