1.Overview
This policy explains how Akara collects, uses, shares, and protects personal data when you visit our website, use the merchant dashboard, or interact with a deposit request. It is written to comply with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, “PDPL”) and to reflect good practice under comparable laws such as the GDPR.
Two roles matter throughout this policy: for data about merchants and website visitors, Akara is the data controller. For data about guests that a merchant submits to send a deposit request, the merchant is the controller and Akara processes the data on the merchant's instructions.
2.Data we collect
- Merchant account data — name, company name, email, phone, website, address, and login credentials (passwords are hashed; we never see them in plain text).
- Guest deposit data — name, email, phone number, deposit amount and status, and communications about the deposit, submitted by the merchant or by the guest during approval.
- Claims evidence — descriptions, itemized costs, and any documents or images submitted in support of, or against, a claim.
- Technical data — IP address, device and browser information, and usage events collected through cookies and similar technologies (see section 9).
- What we never collect — full card numbers. Card details are entered directly into Stripe's secure fields and never pass through or rest on Akara's servers.
3.How we use data
We process personal data to:
- create and manage accounts, and authenticate access (performance of contract);
- send, hold, release, and resolve deposits, including notifications by email and WhatsApp (performance of contract);
- mediate claims and keep audit trails of deposit state changes (legitimate interest in fair, documented outcomes);
- prevent fraud and abuse, and meet anti-money-laundering and sanctions obligations (legal obligation);
- improve the product through aggregated, privacy-respecting analytics (legitimate interest / consent where required);
- respond to support requests and legal process.
We do not sell personal data, and we do not use it for third-party advertising.
4.Payments and card data
Payment processing is handled by Stripe, a PCI-DSS Level 1 certified payment services provider. When a guest approves a deposit, their card details go directly to Stripe, which places and manages the pre-authorization. Akara receives only tokenized references and status events — enough to show that a deposit is held, claimed, or released, but never the card number itself. Stripe's own privacy policy applies to its processing.
5.Sharing and sub-processors
We share personal data only with service providers that help us run Akara, under contracts that restrict their use of the data:
- Stripe — payment authorization, capture, and payouts.
- Supabase — database, authentication, and secure serverless functions.
- Netlify — website and application hosting.
- Resend — transactional email delivery.
- Twilio — WhatsApp deposit notifications.
- Sentry — error monitoring (technical data only).
- PostHog — product analytics (see cookies, section 9).
Beyond service providers, we disclose data only to the parties to a deposit (merchant and guest can each see the deposit's status and claim details), to comply with law or valid legal process, or in connection with a corporate transaction with appropriate safeguards.
6.International transfers
Some of our providers store data outside the UAE (for example in the EU or the US). Where personal data leaves the UAE, we rely on the safeguards permitted by the PDPL, including transfers to jurisdictions with adequate protection and contractual protections such as standard contractual clauses with our providers.
7.Retention
We keep personal data only as long as it is needed:
- Deposit and claim records — up to 7 years after the deposit closes, reflecting UAE commercial record-keeping expectations and the window for legal claims.
- Merchant account data — for the life of the account plus the same record-keeping window for financial records.
- Technical logs and analytics — typically 12 months or less, in aggregated or pseudonymized form where possible.
When retention ends, data is deleted or irreversibly anonymized.
8.Security
All traffic is encrypted in transit with TLS, and data is encrypted at rest by our infrastructure providers. Access to production data is restricted by role, protected by row-level security in our database, and logged in audit trails. Deposit state changes can only occur through controlled server-side functions — never directly from a browser. Webhooks are signed and verified. No system is perfectly secure; if we become aware of a breach affecting your data, we will notify you and the UAE Data Office as required by the PDPL.
9.Cookies and analytics
We use two kinds of cookies and similar technologies:
- Essential — session and security cookies needed to sign you in and protect the Service. These cannot be switched off.
- Analytics — PostHog events that tell us which features are used, and Sentry reports when something breaks. Analytics run only with your consent, which you can give or withdraw at any time in the cookie banner.
10.Your rights
Under the PDPL you may request:
- access to the personal data we hold about you, and a copy in a portable format;
- correction of inaccurate data;
- deletion, where the data is no longer needed for the purposes above;
- restriction of, or objection to, certain processing, including direct marketing;
- withdrawal of consent where processing is based on consent.
Write to contact@akara.ae and we will respond within 30 days. If you are a guest, we may route your request to the merchant that controls your data and assist them in fulfilling it. You also have the right to complain to the UAE Data Office.