Privacy Policy
We collect your phone number, the content you create, who you send it to, and what you buy. We store it in the UAE. We do not sell it, we do not run ads, and we do not use third-party analytics. Your chats are end-to-end encrypted, which means we cannot read them. The parts worth reading carefully are Section 5 (what happens when you let us see your contacts), Section 6 (data about people who aren't our users) and Section 11 (your rights and how to use them).
1. Who is responsible for your data
LET'S HORARO F-Z-C, registered in Ajman Free Zone, United Arab Emirates under licence 50974, of C1 Building, Ajman Free Zone, Ajman, United Arab Emirates, is the data controller for personal data processed through LetsHoraro.com and the Let's Horaro apps.
Data Protection Officer: dpo@letshoraro.com
Privacy enquiries: privacy@letshoraro.com
Which law applies
We are established in Ajman Free Zone, United Arab Emirates. Ajman Free Zone is not a financial free zone with its own data protection regime, so we process personal data under Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and its executive regulations, together with Cabinet Resolution No. 4 of 2022 where applicable.
Our supervisory authority is the UAE Data Office.
If you are in the EEA or UK: where we offer services to you or monitor your behaviour, the GDPR (and UK GDPR) also applies. See Section 14 for the additional rights and information that gives you.
2. Our privacy commitments
These are the promises this policy is built around. If we ever change one, it will be a material change under our Terms of Service and you will get 30 days' notice.
| We do | We don't |
|---|---|
| ✅ Store your data in the UAE | ❌ Sell your personal data |
| ✅ Encrypt chats end-to-end | ❌ Show you advertising |
| ✅ Collect the minimum we need | ❌ Use third-party advertising or behavioural analytics |
| ✅ Let you export everything | ❌ Read the content of your encrypted chats |
| ✅ Delete your account on request | ❌ Use your content to train AI without your specific action |
3. What we collect
3.1 Information you give us
| Category | Examples | Why |
|---|---|---|
| Account | Mobile number, date of birth, display name, profile photo, "about" status | To create and secure your account, verify age |
| Optional account additions | Email address, Google/Apple ID, PIN, 2FA setup | Recovery and stronger security |
| Tribute content | Message text, photos, videos, voice notes, engraving text, subject, occasion | To store and deliver your Tribute |
| Tribute metadata | Unlock date and time, recipient list, relationship type, anonymity setting, location name and GPS coordinates if you add them | To deliver correctly and show countdowns |
| Recipient details | Recipient name, mobile number, avatar, delivery address, relationship | To notify and deliver to them — see Section 6 |
| Order and delivery | Gift selection, engraving, chain options, shipping address, tracking | To manufacture and deliver goods |
| Payment | Cardholder name, billing address, transaction records, invoices | To take payment and meet tax/accounting law |
| Chat and social | Messages, media, reactions, poll votes, group and Channel membership, contact cards, shared locations | To run messaging features |
| Contacts | Your device address book, if you grant permission | Contact discovery — see Section 5 |
| Identity documents | Passport or Emirates ID copy, only if we need to verify your age or run a required identity check | Age verification; legal compliance on precious metals transactions |
| Support | Complaints, feedback, attachments, support chat history | To help you and improve |
3.2 Information we collect automatically
| Category | Examples |
|---|---|
| Device | Device model, OS version, app version, language, time zone |
| Technical | IP address, connection timestamps, push notification token |
| Usage metadata | When you open the app, which features you used, Credits consumed, storage used |
| Diagnostics | Crash reports, performance traces, error logs |
We do not use third-party advertising SDKs, behavioural analytics or cross-site tracking. Our diagnostics are limited to crash and performance data.
3.3 What we deliberately do not collect
- The content of your end-to-end encrypted chats. Encryption keys live on your device, in the iOS Keychain or Android Keystore. We hold ciphertext we cannot decrypt.
- Precise location tracking. We use GPS coordinates only if you attach a location to a Tribute or use GPS to fill in an address. We do not track your movements.
- Biometric identifiers. We do not run facial recognition on your photos or videos.
4. Why we use your data, and our legal basis
| What we do | Legal basis (PDPL) | Legal basis (GDPR, if applicable) |
|---|---|---|
| Create and run your account | Performance of contract | Art. 6(1)(b) contract |
| Store and deliver Tributes | Performance of contract | Art. 6(1)(b) contract |
| Manufacture, engrave and ship gifts | Performance of contract | Art. 6(1)(b) contract |
| Process payments and issue invoices | Contract; legal obligation | Art. 6(1)(b); Art. 6(1)(c) |
| Notify Tribute recipients by SMS/WhatsApp/email | Legitimate interests of sender and us in delivering a requested message | Art. 6(1)(f) legitimate interests |
| Contact discovery from your address book | Your consent | Art. 6(1)(a) consent |
| Age verification and identity checks | Legal obligation; legitimate interests in child safety | Art. 6(1)(c); Art. 6(1)(f) |
| AML/CDD checks on precious metals orders | Legal obligation | Art. 6(1)(c) |
| Security, fraud prevention, abuse investigation | Legitimate interests | Art. 6(1)(f) |
| Crash and performance diagnostics | Legitimate interests in a working product | Art. 6(1)(f) |
| Aggregated business analytics | Legitimate interests | Art. 6(1)(f) |
| Marketing emails and promotions | Your consent | Art. 6(1)(a) consent |
| Responding to lawful authority requests | Legal obligation | Art. 6(1)(c) |
Where we rely on consent, you can withdraw it at any time in Settings, without affecting anything we did before you withdrew it.
Where we rely on legitimate interests, we have weighed our interest against your rights. You can object — see Section 11.
4.1 A note on our business analytics
We produce internal dashboards on revenue, Tribute volumes, occasions, sender-recipient relationship types, delivery regions and seasonal patterns.
These are built from aggregated, non-identifying metadata only. We do not analyse the content of your messages to do this, and we do not build individual profiles for targeting. Where our dashboards use demographic fields such as age band or nationality, they are aggregated to group level and not used to make decisions about individual users.
5. Contact discovery — please read this one
If you allow it, we access your device address book to show you which of your contacts already use Let's Horaro.
This is optional. The app works without it — you can enter a recipient's number manually. We ask separately, not bundled into signing up, and you can turn it off at any time in your device settings.
How we handle it:
- We match contacts against our user base using irreversible hashes of phone numbers where technically possible, rather than uploading readable numbers.
- Contacts who are not Let's Horaro users are not retained. We discard non-matching entries after the match runs.
- We do not use your address book for marketing, and we do not message your contacts because they are in your address book.
- We do not build a "shadow profile" of non-users from address book data.
Your responsibility: your address book contains other people's personal data. By enabling contact discovery you confirm you may share it with us for this purpose. If a contact objects, ask us at privacy@letshoraro.com and we will remove any trace and add them to a suppression list.
6. Data about people who aren't our users
Let's Horaro is unusual: to work at all, it needs data about people who have not signed up.
6.1 Tribute recipients
When you create a Tribute you give us a recipient's name, mobile number and possibly their address and photo. We use it to send a notification and, where relevant, to deliver a gift.
When we first contact a recipient we tell them: that someone has sent them something on Let's Horaro; where their details came from; how to see this policy; and how to stop further contact.
A recipient who does not want contact can opt out. If they do, we add their number to a suppression list, we stop sending them notifications, and we tell the sender that delivery could not be completed. A suppression request cannot be overridden by a sender.
6.2 People mentioned in Tribute content
A Tribute may include photographs, recordings or descriptions of others, often people who have died. We do not analyse this content — much of it is encrypted and inaccessible to us in any event. If you believe content about you or a family member is being shared inappropriately, contact privacy@letshoraro.com and we will handle it under our Acceptable Use & Community Guidelines.
6.3 Deceased persons and posthumous data
Let's Horaro is expressly designed for messages that may be delivered after a sender has died. Our full position on scheduled delivery after death, and on what a personal representative may and may not request, is set out in Section 9 of the Tribute, Vault & Scheduled Delivery Terms.
In summary: scheduled and paid Tributes are still delivered; a personal representative may request suspension on documented proof; and undelivered Tribute content is not disclosed to the estate.
6.4 Deceased persons appearing in content
Data protection law generally applies to living people. We nevertheless treat material about deceased individuals with care, and we will act on well-founded requests from close family members or a personal representative.
7. Who we share data with
We do not sell personal data. We do not share it for advertising. We share it only with the following categories of recipient, and only what each needs.
| Recipient | What they get | Why |
|---|---|---|
| Payment processors (our certified PCI-DSS payment providers) | Payment and billing details. We do not store your full card number. | To take payment |
| Couriers (our designated high-security logistics partners) | Recipient name, address, phone, parcel details | To deliver |
| Gift manufacturers and QA partners | Engraving text and design assets, order reference | To make your gift |
| SMS / WhatsApp / email gateways | Recipient phone number or email, message template | To send notifications |
| Cloud hosting (our UAE-based cloud infrastructure provider) | Encrypted data at rest | To run the service |
| AI providers | Only the specific prompt or media you submit to an AI feature — see AI Features Terms | To run Auto-Prompt and Memorial Video |
| Professional advisers | As needed | Legal, audit, accounting |
| Authorities | As required — see Section 8 | Legal obligation |
| An acquirer | If our business is sold or merged | Business transfer, with notice to you |
Every processor is bound by a written data processing agreement requiring confidentiality, security, and processing only on our instructions.
A current list of our sub-processors is published at letshoraro.com/legal/sub-processors. We will notify you of material additions.
8. Law enforcement and legal requests
We may disclose data where legally required by a UAE court, regulator or law enforcement authority, or to protect life, prevent serious harm, or defend legal claims.
Our approach: we require requests to be properly authorised and specific; we disclose only what the request actually covers; and we notify affected users unless the law prohibits it or notification would create a risk to someone's safety.
What we can and cannot hand over: we can provide account details, metadata, order and payment records, and Channel content. We cannot provide the content of end-to-end encrypted chats, because we do not have the keys. We will say so rather than imply otherwise.
9. Where your data is stored
Your data is stored in the United Arab Emirates, on our UAE-based cloud infrastructure provider infrastructure in AWS me-central-1. This includes messages, media, metadata and backups.
9.1 Transfers outside the UAE
Some transfers are unavoidable:
- A recipient in another country. If you send a Tribute or gift abroad, the content and address go there. That is what you asked us to do.
- Couriers and payment processors operating internationally.
- AI providers, where you use an AI feature and the provider processes outside the UAE. We tell you in the AI Features Terms.
Where we transfer personal data outside the UAE we rely on: a determination of adequate protection in the destination country; contractual safeguards imposing equivalent protection; or your explicit consent for a specific transfer.
9.2 Federation
Our messaging infrastructure is based on the Matrix protocol, but federation is disabled. Your messages are not exchanged with servers operated by other organisations. All message data remains on our servers in the UAE.
If we ever enable federation, we will treat that as a material change to this policy and give you 30 days' notice before it takes effect.
10. How long we keep things
| Data | Retention |
|---|---|
| Draft Tributes (never sent) | Deleted after 10 days |
| Sent Tributes | Deleted 10 days, unless the sender selects a longer option after unlock, unless you chose "keep forever" |
| Tributes marked "keep forever" | Retained for as long as the account is active and the service operates — see below |
| Chat messages | Deleted after 12 months, and 24 hours after every member has read them |
| Account data | While your account is open, then deleted within 30 days of closure |
| Order and delivery records | 7 years — tax and commercial law |
| Payment and invoice records | 7 years — tax law |
| AML/CDD records, where applicable | 5 years from the transaction, as required by law |
| Identity documents for age checks | Deleted immediately after verification, or within 30 days at the latest |
| Support tickets | 2 years after closure |
| Crash and diagnostic logs | 90 days |
| Security and access logs | 12 months |
| Suppression list (opt-outs) | Indefinitely — we must keep it to honour the opt-out |
| Backups | Overwritten within 90 days |
On "keep forever": we will maintain the Tribute for as long as we reasonably can. We cannot promise a period longer than the life of the company. If we ever wind down, Section 20 of the Terms of Service applies: 90 days' notice, and a way to export or receive your content.
Deletion is not instant. Removing data from live systems is immediate; removing it from rolling backups takes up to 90 days.
11. Your rights
You have the right to:
| Right | What it means | How |
|---|---|---|
| Access | Get a copy of your data | Settings → PDPL Rights → Request My Data. We deliver an encrypted archive within 48 hours. |
| Correction | Fix data that's wrong | Edit in Settings, or ask us |
| Deletion | Have your data erased | Settings → Delete Account, or ask us |
| Restriction | Have us pause processing while a dispute is resolved | privacy@letshoraro.com |
| Object | Object to processing based on legitimate interests | privacy@letshoraro.com |
| Portability | Get your data in a machine-readable format | Included in Request My Data |
| Withdraw consent | For contact discovery, marketing, AI features | Settings |
| Complain | To the supervisory authority | See Section 15 |
Response times: we respond to data requests within 30 days, and to Request My Data exports within 48 hours. We will not charge you, unless a request is manifestly excessive or repetitive.
Limits on deletion. Some things survive an erasure request:
- Tributes already delivered. Once unlocked, the recipient's copy is theirs. Deleting your account does not delete their copy.
- Financial records we must keep for tax and accounting law.
- Suppression list entries, which exist precisely to protect people who asked not to be contacted.
- Records needed to defend legal claims.
We will always tell you what we retained and why.
12. Security
- End-to-end encryption for chats, using the Matrix protocol's Megolm and Olm implementations, with forward secrecy.
- Encryption keys stored on your device only — iOS Keychain or Android Keystore, never on our servers.
- AES-256 encryption for data at rest.
- TLS/HTTPS for all data in transit.
- Access controls limiting staff access to what their role requires, with logging.
- Automated backups with restore testing.
No system is perfectly secure. If a breach affects your personal data and creates a risk to you, we will notify you and the relevant supervisory authority within 72 hours of becoming aware, as required.
What you should do: enable a PIN or two-factor authentication, set up encryption key backup, keep your device updated, and never share a one-time code with anyone. We will never ask you for your OTP.
13. Children
The Platform is not for anyone under 16. We do not knowingly collect data from children under 16. If you believe a child under 16 has an account, tell us at privacy@letshoraro.com and we will investigate and delete it.
Note that children may appear in Tribute content — a parent recording a message for a child, or photographs of a family. That content is under the sender's control and their responsibility under our Terms.
14. If you are in the EEA or UK
Where the GDPR or UK GDPR applies to our processing:
- Additional rights: you may lodge a complaint with your local supervisory authority. In Germany this is your state's Datenschutzbehörde; in the UK, the ICO.
- Automated decision-making: we do not make decisions producing legal or similarly significant effects about you by automated means alone. Automated fraud and abuse screening is always subject to human review before an account is terminated.
- Transfers: transfers from the EEA to the UAE are made under appropriate safeguards, including Standard Contractual Clauses where required. Contact dpo@letshoraro.com for a copy.
- Digital consent age: where a member state sets the age of digital consent above 16 for any processing based on consent, we apply that higher age.
15. Complaints
Talk to us first: privacy@letshoraro.com or dpo@letshoraro.com. We aim to resolve privacy complaints within 30 days.
If you're not satisfied:
- UAE mainland: the UAE Data Office
- DIFC: the DIFC Commissioner of Data Protection
- ADGM: the ADGM Office of Data Protection
- EEA: your national supervisory authority
- UK: the Information Commissioner's Office
You do not need to complain to us first, but we would like the chance to fix it.
16. Changes to this policy
We will notify you of material changes by email and in-app at least 30 days before they take effect. We keep previous versions available at letshoraro.com/legal/archive so you can see what changed.
Questions? privacy@letshoraro.com · Data Protection Officer: dpo@letshoraro.com · LET'S HORARO F-Z-C, C1 Building, Ajman Free Zone, Ajman, United Arab Emirates