Privacy Policy
Effective Date: 01 August 2026
Last Updated: 08 August 2026
1. Introduction
This Privacy Policy explains how Tamrinn Group of Hotels ("we," "us," "our") collects, uses, discloses, and protects personal data when you use the Onasadhya booking website and application (the "Service"). We aim to handle your personal data in line with the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL"), as amended, and other applicable data protection laws.
2. Personal Data We Collect
- Identity and contact data: name, mobile number, email address
- Communication preference: whether your mobile number is registered on WhatsApp
- Delivery data (delivery orders only): building/ street, area, and map-pin location
- Booking data: location, date, fulfilment mode, quantity, and amounts paid
- Payment data: our payment service provider processes your card details directly; we retain only a payment reference and status, never your full card number
- Verification data: mobile number and OTP verification records (OTP codes are short-lived and not retained beyond their validity window)
- Technical data: device/browser information and IP address, collected for security and service operation
- Communications: records of tickets, receipts, and notifications sent to you
We do not knowingly collect more personal data than the Service needs.
3. How We Use Your Personal Data
- Create, process, and confirm your booking
- Verify your identity by OTP and enable password-free login
- Calculate pricing, delivery charges, and VAT
- Generate and deliver your electronic ticket(s) and receipts via WhatsApp and/or email
- Fulfil delivery orders
- Provide customer support
- Detect and prevent fraud, duplicate ticket use, and misuse of the Service
- Maintain records for financial reconciliation, audit, and legal compliance
- With your consent, send updates or promotions about future events (you can opt out anytime)
4. Legal Basis for Processing
We process personal data based on: performance of the contract formed when you book; compliance with legal obligations (including tax and record-keeping); our legitimate interests in operating and securing the Service; and, where applicable, your consent (for example, marketing messages or WhatsApp ticket delivery).
5. Sharing of Personal Data
We share personal data only as needed to run the Service, with:
- Our payment service provider (currently Network International/ N-Genius Online), to process payments
- SMS and messaging providers, to deliver OTPs, tickets, and receipts
- Email service providers, to deliver tickets and receipts
- Mapping/address services (Google Maps/Places), to validate delivery addresses
- Cloud hosting providers (Amazon Web Services), to host the Service
- Our staff and authorised operators at participating locations, to validate tickets and fulfil orders
- Regulators, law enforcement, or courts, where legally required
We do not sell your personal data.
6. International Data Transfers
Where any third party listed above processes personal data outside the United Arab Emirates, we take reasonable steps to ensure the transfer has appropriate safeguards consistent with the PDPL.
7. Data Retention
We retain booking, payment, and audit records for the duration of the event and the following reconciliation period, and afterward only as long as needed for tax, accounting, and legal record-keeping. Booking-history data linked to your mobile number is retained so you can view past bookings, unless you ask us to delete it (Section 9).
8. Data Security
We apply reasonable technical and organisational safeguards, including encrypted transmission (HTTPS/TLS), OTP-based guest authentication instead of stored passwords, hashed credentials for staff accounts, and a PCI-compliant hosted payment page so full card details never reach our servers. No system is completely secure, and we cannot guarantee absolute security.
9. Your Rights
Subject to applicable law, you may have the right to access the personal data we hold about you, request correction of inaccurate data, request deletion, object to or restrict certain processing, and withdraw consent (for example, for marketing) without affecting processing already carried out. Contact us using the details in Section 12 to exercise these rights.
10. Cookies and Similar Technologies
The Service uses essential cookies and browser storage — for example, to keep you logged in after OTP verification. We do not use these for third-party advertising tracking. [Update this section if analytics or marketing cookies are added later.]
11. Children's Privacy
The Service is not directed at, and we do not knowingly collect personal data from, anyone under 18. If you believe a minor has provided us personal data, please contact us so we can act on it.
12. Contact Us
Tamrinn Group of Hotels
Email: support@tamrinn.com
Phone: +971 56 482 8347
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by a new "Last Updated" date. Please review this Policy periodically.