This Privacy Policy explains how RetailDirect ("RetailDirect", "we", "us", "our") collects, uses, discloses, transfers and protects personal data in connection with the RetailDirect platform at retaildirect.me, app.retaildirect.me, our mobile and point-of-sale applications, our rider and van applications, our APIs and all related services (together, the "Platform").
It should be read together with our Terms of Use and, where applicable, our Data Processing Addendum (available on request).
We process personal data in accordance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and any executive regulations, cabinet decisions and guidance issued under it (the "PDPL"), together with other applicable UAE laws including Federal Decree-Law No. 46 of 2021 on Electronic Transactions and Trust Services and Federal Decree-Law No. 34 of 2021 on Combatting Rumours and Cybercrimes.
1. Who this policy applies to
The Platform is a business-to-business service. This policy applies to personal data relating to:
- Shop personnel — owners, managers, cashiers, storekeepers and staff of retail shops using the Marketplace and/or the POS Add-On;
- Supplier and Manufacturer personnel — administrators, sales representatives, finance and warehouse staff, drivers, riders and van salespeople;
- Prospective customers and leads — including shop contacts captured by field personnel;
- Shoppers and end customers of a shop, where their data is captured through the POS Add-On (for example loyalty details or a customer name on an invoice);
- Website visitors and anyone who contacts us.
2. Our role: controller and processor
Our role depends on the data.
2.1 We act as a CONTROLLER where we decide why and how personal data is processed. This includes:
- account registration, verification and business onboarding data;
- data about the individuals who administer, use or contact us about the Platform;
- billing, invoicing and collections data;
- security, fraud-prevention, audit-log and abuse-detection data;
- platform usage, telemetry and analytics data;
- marketing and communications data.
2.2 We act as a PROCESSOR, on the documented instructions of our business customer (who is the controller), where we process personal data that the customer enters into or generates through the Platform for its own purposes. This includes:
- a shop's own customers' data captured through the POS Add-On (loyalty records, customer names on invoices, contact details, purchase history);
- a business's own employees' data entered by that business (staff records, cashier profiles, rider profiles, performance and monitoring data);
- lead and prospect data captured by a supplier's or manufacturer's field personnel.
Where we act as processor, the business customer is responsible for having a lawful basis, giving notices, obtaining any required consent, and responding to the rights requests of the individuals concerned. We act only on that customer's instructions and as set out in the Data Processing Addendum. If you are a shopper at a shop that uses RetailDirect, please contact that shop directly about your data.
3. Personal data we collect
3.1 Data you provide
| Category | Examples |
|---|---|
| Identity and business | Name, job title, role, trade name, trade licence, establishment card, memorandum of association, Emirates ID and passport copies of signatories and beneficial owners, signature, photograph, VAT certificate and Tax Registration Number |
| Contact | Email address, mobile and landline numbers, business address, shop address, emergency contact |
| Account | Username, password (stored only in hashed form), role and permission settings, security settings, preferences, language |
| Financial | Bank account details, IBAN, cheque details, payment method tokens held by our payment providers, credit terms, credit limits, outstanding balances, payment and collection history |
| Commercial | Orders, invoices, credit and debit notes, product listings, pricing, promotions, statements, disputes, claims |
| Support | Correspondence, support tickets, call and chat records, feedback, survey responses, complaints |
3.2 Data generated by your use of the Platform
| Category | Examples |
|---|---|
| Transaction and operational | Orders, deliveries, returns, POS sales and refunds, till sessions, cash-drawer events, discounts and overrides, stock movements, batch and expiry records, ledger entries |
| Barcode and catalogue | Scan events, product-matching decisions, new-item submissions and approvals |
| Voice | Where you use voice ordering or voice search, an audio recording of the spoken instruction and its transcription |
| Location | GPS coordinates, route history, geofence entry and exit events and timestamps captured by rider, van and field applications while those applications are in use; location of shops captured during lead creation |
| Images | Photographs of shops, premises, deliveries, proof of delivery, damaged goods and documents you upload |
| Device and technical | IP address, device identifiers, device and browser type, operating system, app version, language, screen resolution, network information, crash and diagnostic logs |
| Usage | Pages and screens viewed, features used, searches, clicks, session duration, timestamps, referring pages, error events |
| Communications | Emails sent through the Platform, broadcast messages, in-app notifications, delivery and open events |
3.3 Data from other sources
We may receive personal data from: your employer or the business whose account you use; other Platform users transacting with you; payment service providers, banks and acquirers; credit bureaux and credit-reference agencies; identity verification, sanctions-screening and anti-fraud providers; publicly available sources such as commercial registries and licence databases; delivery, logistics and mapping partners; our resellers, agents and referral partners; and marketing and analytics providers.
3.4 Sensitive personal data
We do not seek to collect sensitive personal data as defined in the PDPL (such as data revealing health, biometric identifiers, racial or ethnic origin, religious or political beliefs, or criminal records). Please do not upload such data to the Platform. Where an identity document you submit incidentally reveals such information, we process only what is necessary for verification and legal compliance.
3.5 Children
The Platform is not directed at, and must not be used by, anyone under 18 years of age. We do not knowingly collect data from children. If we learn that we have, we will delete it. Business customers must not enter children's data into the Platform, including through POS loyalty records.
4. Why we process personal data, and our lawful basis
We process personal data on one or more of the lawful bases in Article 4 of the PDPL: performance of a contract, compliance with a legal obligation, protection of a legitimate interest that does not prejudice the rights of the individual, protection of the public interest, protection of vital interests, or consent.
| Purpose | Examples | Lawful basis |
|---|---|---|
| Provide the Platform | Create and administer accounts, authenticate users, process orders, generate invoices, run the POS, sync stock, provide reports | Contract |
| Verification and onboarding (KYB) | Verify identity, licences, ownership and authority; screen against sanctions and adverse media | Legal obligation; legitimate interest |
| Billing and collections | Charge fees, issue invoices, chase overdue amounts, manage disputes | Contract; legitimate interest |
| Security and fraud prevention | Detect and prevent unauthorised access, fraud, abuse, circumvention and financial crime; maintain audit logs | Legitimate interest; legal obligation |
| Support | Respond to queries, troubleshoot, train our staff | Contract; legitimate interest |
| Operational features | Route planning, live tracking, geofencing, proof of delivery, cash-collection records, voice ordering | Contract; legitimate interest of the operating business |
| Improve and develop | Analyse usage, fix defects, test features, build and tune models and algorithms, product research | Legitimate interest |
| Analytics and insights | Produce reporting, benchmarks, category and market insights in aggregated or de-identified form | Legitimate interest |
| Communications | Service messages, security alerts, billing notices, changes to terms | Contract; legal obligation |
| Marketing | Send information about products, features, offers and events | Consent, where required; otherwise legitimate interest, with an opt-out in every message |
| Legal and regulatory | Tax and accounting records, responding to authorities, establishing or defending legal claims, corporate transactions | Legal obligation; legitimate interest |
Where we rely on consent, you may withdraw it at any time (see section 9). Withdrawal does not affect processing carried out before withdrawal, and may mean we can no longer provide the relevant feature.
5. Automated processing, profiling and AI
5.1 The Platform includes features that use automated processing, machine learning and artificial intelligence, including demand forecasting, reorder suggestions, stock and promotion recommendations, product matching and catalogue enrichment, fraud and anomaly detection, speech recognition and translation.
5.2 Some features may generate indicators relating to a business, such as credit-limit suggestions, payment-risk indicators, order-pattern anomalies or performance scores. These are decision-support tools used together with human review; we do not make decisions producing legal effects on an individual based solely on automated processing without a lawful basis and appropriate safeguards.
5.3 We use personal data and Platform data to train, tune, test and evaluate our models. Where practicable we use aggregated, pseudonymised or de-identified data for this purpose.
5.4 You have the right to object to automated processing where it produces legal effects concerning you or significantly affects you, and to request human review. Contact us using the details in section 13.
6. Who we share personal data with
We do not sell personal data. We share it only as described below.
6.1 Other Platform users. To enable transactions, we share necessary data between counterparties — for example, a shop's business name, address, contact person and order details are visible to the supplier fulfilling the order; a supplier's contact and product data is visible to shops. Each recipient is an independent controller of the data it receives and is responsible for its own compliance.
6.2 Service providers (processors). Including: cloud hosting and infrastructure providers; database, backup and storage providers; email and notification delivery providers; speech recognition, transcription and translation providers; mapping and geolocation providers; analytics, monitoring and error-reporting providers; customer support and ticketing platforms; identity verification, screening and anti-fraud providers; and IT security and penetration-testing providers. These providers act on our instructions under written contracts containing confidentiality and security obligations.
6.3 Payment and financial partners. Licensed payment service providers, acquirers, banks, card schemes and financing partners, to process payments, settle funds, manage chargebacks and provide credit facilities. These parties are generally independent controllers under their own privacy notices.
6.4 Tax and e-invoicing. Where you use e-invoicing features, invoice and counterparty data may be shared with accredited service providers, the Peppol network and the UAE Federal Tax Authority as required by the applicable e-invoicing framework.
6.5 Professional advisers. Lawyers, auditors, accountants, insurers and consultants under duties of confidence.
6.6 Authorities. Regulators, tax and customs authorities, law enforcement, courts and government bodies where required by Applicable Law, where necessary to comply with a lawful request, or where necessary to establish, exercise or defend legal claims or to prevent harm or crime.
6.7 Corporate transactions. In connection with any merger, acquisition, investment, financing, restructuring, insolvency or sale of all or part of our business, we may disclose personal data to prospective and actual counterparties and their advisers, subject to confidentiality.
6.8 Affiliates. Members of our corporate group, for the purposes described in this policy.
7. International transfers
7.1 We use cloud infrastructure and service providers that may store or process personal data outside the United Arab Emirates, including in AWS Asia Pacific – Mumbai.
7.2 Under Articles 22 and 23 of the PDPL, we transfer personal data outside the UAE only where: (a) the destination has an adequate level of protection recognised by the UAE; (b) appropriate contractual safeguards are in place with the recipient, imposing standards equivalent to the PDPL; (c) the transfer is necessary to perform a contract with you or in your interest; (d) the transfer is necessary to establish, exercise or defend legal claims; or (e) you have consented, where consent is the applicable basis.
7.3 Where a specific law requires certain records to be stored within the UAE — including any UAE-residency requirement applicable to electronic invoices — we maintain those records in accordance with that requirement.
7.4 You may request further information about the safeguards we apply by contacting us using the details in section 13.
8. Retention
8.1 We keep personal data only for as long as necessary for the purposes for which it was collected, and then delete or anonymise it. In determining retention periods we consider the nature of the data, the purpose, our legal and regulatory obligations, and any limitation period applicable to potential claims.
8.2 Indicative retention periods:
| Data | Retention |
|---|---|
| Account and profile data | Duration of the account, then up to 2 years |
| Transaction, order, invoice and accounting records | At least 5 years from the end of the relevant tax period, in line with UAE VAT record-keeping requirements, and longer where a specific law requires |
| Electronic invoices | For the period required by the applicable UAE e-invoicing framework |
| KYB, verification and screening records | At least 5 years after the end of the relationship, in line with UAE anti-money-laundering requirements |
| Security, audit and access logs | Typically 12–24 months |
| Location and route data | Typically 12 months |
| Voice recordings from voice ordering | Typically 90 days; transcriptions may be retained longer where linked to an order |
| Support correspondence | Up to 3 years after closure |
| Marketing data | Until you opt out, then a suppression record indefinitely |
| Data processed as processor | As instructed by the controlling customer, and per the Data Processing Addendum |
8.3 We may retain data for longer where necessary to establish, exercise or defend legal claims, to comply with a legal or regulatory obligation, or where it has been irreversibly anonymised.
9. Your rights
Subject to the conditions and exemptions in the PDPL, you have the right to:
- Access — obtain confirmation of whether we process your personal data and receive a copy, together with information about the processing;
- Rectification — have inaccurate or incomplete data corrected;
- Erasure — request deletion where the data is no longer necessary, where processing was unlawful, or where you withdraw consent and no other basis applies;
- Restriction — request that we limit processing in defined circumstances;
- Portability — receive certain data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
- Object — object to processing based on legitimate interests, to direct marketing, and to automated decision-making that significantly affects you;
- Withdraw consent — at any time, where processing is based on consent;
- Complain — lodge a complaint with the UAE Data Office.
How to exercise your rights. Email privacy@retaildirect.me with the subject line "Data Subject Request". We will verify your identity before acting, and will respond within the period required by Applicable Law (and in any event without undue delay). We may refuse or charge a reasonable fee for requests that are manifestly unfounded, excessive or repetitive, and we may decline where an exemption applies — for example where compliance would prejudice an investigation, breach another person's rights, or conflict with a legal obligation. We will explain our reasons.
Note on B2B accounts. If your data is held in an account belonging to your employer or another business, we may need to direct your request to that business as the controller.
Complaints. If you are not satisfied with our response, you may complain to the UAE Data Office at www.uaedataoffice.gov.ae. We ask that you contact us first so we can try to resolve the matter.
10. Security
10.1 We maintain technical and organisational measures appropriate to the risk, including: encryption of data in transit (TLS) and at rest; hashing of passwords; role-based access control and least-privilege access; multi-factor authentication for administrative access; network segmentation and firewalling; audit logging and monitoring; regular patching; secure development practices; backup and recovery procedures; vendor due diligence; and staff confidentiality obligations and training.
10.2 No system is completely secure. While we work to protect personal data, we cannot guarantee absolute security, and any transmission is at your own risk. You are responsible for keeping your credentials confidential, configuring user permissions appropriately, promptly removing access for departing staff, and securing your own devices and networks.
10.3 Breach notification. If a personal data breach occurs that poses a risk to the privacy, confidentiality or security of personal data, we will notify the UAE Data Office and, where required, affected individuals and our controlling customers, without undue delay and in accordance with the PDPL.
11. Employee and workforce monitoring
Certain Platform features record information about individuals at work, including location and route tracking, geofence alerts, delivery and collection timestamps, till sessions, discount and void events, login records and performance metrics.
Where the individual is your employee or contractor, you are the controller of that data. You are responsible for: informing your personnel clearly about what is recorded, why, and for how long; having a valid lawful basis; limiting monitoring to what is necessary and proportionate; and handling their rights requests. We provide the tooling; we do not determine your monitoring practices, and we are not responsible for them.
12. Cookies and similar technologies
12.1 We use cookies and similar technologies (local storage, SDKs, pixels) to keep you signed in, remember preferences, secure the Platform, measure performance and understand usage.
12.2 Categories we use:
- Strictly necessary — authentication, session management, load balancing, security and fraud prevention. These cannot be disabled.
- Functional — language, layout and preference settings.
- Analytics and performance — usage measurement, error diagnostics and feature adoption.
- Marketing — only where you have consented.
12.3 You can manage non-essential cookies through our cookie banner or preference centre, and control cookies through your browser settings. Blocking strictly necessary cookies will prevent the Platform from working.
13. Contact us and Data Protection Officer
Controller: RetailDirect Registered address: Majan, Dubai Commercial licence number: [INSERT LICENCE NUMBER] Privacy contact / Data Protection Officer: The Data Protection Officer Email: privacy@retaildirect.me Telephone: +971581146440
14. Changes to this policy
We may update this Privacy Policy from time to time. We will publish the updated version with a new effective date and, where the change is material, notify you by email and/or in-Platform notice before it takes effect. Your continued use of the Platform after the effective date constitutes acceptance of the updated policy, except where consent is required by Applicable Law, in which case we will obtain it.
This Privacy Policy is available in English and Arabic. In the event of any inconsistency, the English version prevails for the purposes of interpretation between the parties, save where Applicable Law or a competent UAE court requires the Arabic version to prevail.