Privacy Policy
Last updated: 22 August 2026
This Privacy Policy explains how Yellow Polar SPC ("Radeet", "we", "us") collects, uses, and protects personal data in connection with Radeet (radeet.com), a digital loyalty-program platform for businesses in the GCC.
Radeet serves two kinds of people, and our role is different for each — read Section 2 first, as it explains which part of this policy applies to you.
1. Who We Are
Radeet is operated by Yellow Polar SPC, registered in the Sultanate of Oman with its principal place of business in Muscat. For any question about this policy or your personal data, contact privacy@radeet.app.
2. Two Roles: Business Data vs. Cardholder Data
Radeet is a business-to-business service used by shops, cafés, salons, and similar businesses (each a "Business") to run loyalty programs for their own customers (each a "Cardholder").
For data about the Business itself — the account owner's contact details, staff records, billing information, and how the Business's owner or staff use our dashboard — Radeet is the data controller. We decide how and why that data is processed, and this policy describes that processing directly.
For data about a Business's Cardholders — a Cardholder's name, phone number, email, loyalty balance, and similar — Radeet acts as a data processor, or service provider, on behalf of the Business. The Business decides what Cardholder data to collect and why; Radeet stores and processes it only to operate the loyalty program the Business has configured. If you are a Cardholder and have a question about your own data, please contact the Business you enrolled with in the first instance — they hold the primary relationship and responsibility for your data. Radeet will still support and act on legitimate requests it receives directly, as described in Section 8.
3. Information We Collect From Businesses
- Business name, contact email, contact phone number, and country, provided at signup.
- Login credentials, handled by our authentication provider (Supabase Auth) — Radeet's own database never stores your raw password.
- If you sign up or log in using Google or Facebook, the email address associated with that account.
- Staff member names and 4-digit PINs, which are cryptographically hashed before storage — we cannot recover a Staff PIN once set, only reset it.
- Optional details you choose to add: a Google Business review link, and branch/location details including an optional GPS coordinate (used to make your Cardholders' Wallet Passes appear on their lock screen when near your location).
- Billing records: your subscription plan, billing status, and payment references. We never receive or store your card number, expiry date, or CVV — these are handled entirely by our payment provider, Amwalpay, on a page it hosts directly.
4. Information Processed on Behalf of Businesses (Cardholder Data)
When a Cardholder enrolls in a Business's loyalty program (typically by scanning a QR code and filling in a short form), we process:
- Name — required.
- Phone number — required. This is used as the unique identifier for that Cardholder within the Business (so re-enrolling with the same number reuses the same loyalty card rather than creating a duplicate).
- Email address — optional.
- Preferred language (Arabic or English).
- Loyalty activity: stamps, points, or cashback balance and history, and (if the Cardholder adds their card to a wallet) an Apple or Google Wallet device identifier used solely to push balance updates to that Wallet Pass.
- Date of birth — only if a Business's staff member chooses to record it (for example, to send a birthday reward). This field is not part of the standard enrollment form a Cardholder fills in themselves; where it is collected, it is the Business's own staff entering it, and the Business is responsible for having the Cardholder's consent to do so.
What we do not collect from Cardholders
We do not collect a Cardholder's payment or card details — Cardholders never pay Radeet directly. We do not track a Cardholder's location — the only location data Radeet holds is the Business's own branch address/coordinates, entered by the Business, used solely to make a Wallet Pass locally relevant on a lock screen. We do not use any third-party advertising or analytics trackers anywhere on Radeet.
5. How We Use This Information
- To create and operate loyalty program accounts and Wallet Passes.
- To process subscription payments and manage billing.
- To send transactional communications — for example, a reward-earned notice to a Cardholder, or a billing/renewal reminder to a Business owner.
- To operate and secure the service, including preventing fraud and misuse.
- To comply with legal obligations we are subject to.
6. Who We Share Information With
We do not sell personal data. We share information only with the service providers who help us operate Radeet (our "subprocessors"), each of which is contractually restricted to using data only to provide its service to us:
- Supabase — our database, authentication, and file storage provider. Hosted on Amazon Web Services in the Asia Pacific (Sydney, Australia) region. Holds the great majority of the data described in Sections 3 and 4.
- Vercel — our application hosting provider, running our web application and scheduled background jobs, primarily from United States (Virginia) infrastructure.
- Amwalpay — our payment gateway, licensed to process card payments in the GCC. Handles your card details directly on its own hosted payment page; we only receive a payment reference and status.
- Apple Inc. — to issue and update Apple Wallet passes, including sending update notifications through Apple's Push Notification service.
- Google LLC — to issue and update Google Wallet passes, and to offer Google as an optional sign-in method for Business owners.
- Resend — our transactional email provider, used to deliver reward and billing notification emails.
7. International Data Transfers
Radeet operates across the GCC, but the infrastructure providers listed in Section 6 are based outside the GCC — principally in Australia and the United States. This means personal data we hold is stored and processed outside the country where you or your Cardholders are located.
Where this transfer requires your consent or another lawful basis under applicable data protection law, we rely on your consent, given by using Radeet or enrolling in a Business's program, together with contractual protections we put in place with our subprocessors. If you have questions about a specific transfer, contact privacy@radeet.app.
8. Data Retention, Access, Correction, and Deletion
We retain personal data for as long as the relevant Business account remains active, and for a reasonable period afterward as needed for legal, accounting, or dispute-resolution purposes.
You have the right to request access to, correction of, or deletion of your personal data, subject to any legal exceptions that may apply (for example, records we must keep for accounting or legal-compliance purposes).
To make a request, email privacy@radeet.app. Business owners can also correct most of their own information directly from the dashboard's Settings page, and can permanently delete a Cardholder's record — their contact details, cards, and stamp/reward history — directly from that Cardholder's profile in the dashboard. We aim to respond to and act on requests within 45 days. If you are a Cardholder, we encourage you to also reach out to the Business you enrolled with, since they hold the primary relationship and can act on a deletion request immediately — but you do not have to, and we will act on a request we receive directly from you.
Please note: deleting a Business's account permanently deletes that Business's data, including all of its Cardholders' loyalty history — this cannot be undone or recovered afterward.
9. Cookies
Radeet uses only first-party, functional cookies — no third-party advertising or analytics cookies. Specifically:
- An authentication session cookie, needed to keep a Business owner logged in.
- A language-preference cookie, remembering whether you prefer Arabic or English (retained for up to 1 year).
- A dashboard display-preference cookie, remembering interface settings such as whether the sidebar is expanded (retained for up to 7 days).
10. Security
We use industry-standard measures to protect personal data, including encrypted connections (HTTPS) for all traffic, row-level database access controls that keep each Business's data isolated from every other Business, and cryptographic hashing of staff PINs and account passwords. No system is completely secure, and we cannot guarantee absolute security.
11. Children's Data
Radeet's loyalty programs are intended for adult customers of our Business subscribers. We do not knowingly collect personal data from children. Where a date of birth is recorded for a Cardholder (see Section 4), this is used solely for age-appropriate loyalty perks such as a birthday reward, and does not indicate that Radeet is directed at children.
12. Data Breach Notification
If we become aware of a security incident affecting your personal data, we will notify the relevant authorities and affected individuals as required by applicable law.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page with a new "last updated" date, and for material changes, notify Business owners by email or in-dashboard notice.
14. Contact
For any question about this Privacy Policy or your personal data, contact privacy@radeet.app, or write to Yellow Polar SPC, Muscat, Sultanate of Oman.
Other legal documents