This Privacy Policy explains how Abdulla Alhashmi Marketing Management — a sole establishment licensed in Dubai, UAE (trade licence no. 1371998, issued by the Department of Economy and Tourism), which operates the shalwa app and brand (“shalwa”, “we”, “us”) — collects, uses, shares and protects your personal data when you use the shalwa app, our website at shalwa.io, and related services (together, the “Service”). shalwa is the data controller for this personal data. This Policy is written for the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, the “PDPL”).
Contact / Data Protection: support@shalwa.io · Villa 15, Al Safa Second, Bur Dubai, Dubai, UAE.
1. A note on location
shalwa works by knowing when and where you park. To do this, the app requests “Always” (background) location and motion access so it can detect that you have stopped in a paid zone and start/stop a parking session for you — even when the app is not open. We use this data only to provide the Service as described below. You can change these permissions at any time in your device settings, but the Service cannot run sessions without them (it will show “shalwa is off”).
2. Personal data we collect
You provide
- Account: your first name and mobile phone number; OTP verification (via WhatsApp).
- Vehicle: licence plate number(s), emirate and plate type.
- Support: messages and information you send us.
- On our website (shalwa.io): if you sign up to hear when shalwa comes to Android, or joined our earlier waitlist, your email address, mobile phone number, country and city. If you write to us through our support page, your name, email address, the topic you choose and your message.
Collected automatically when you use the Service
- Precise & background location (to detect zones and run sessions).
- Motion & activity data (to detect when you stop/start driving).
- Car connection: connect/disconnect events for CarPlay, Android Auto, your car’s Bluetooth and your car’s Wi-Fi, plus internet status.
- Car connection identifiers: when you link a car to a vehicle in the app, we store that connection’s identifier against that vehicle — the Bluetooth or CarPlay hardware identifier of your car’s system (derived from its MAC address) and/or the Wi-Fi network name (SSID) of your car’s hotspot. We use these only to recognise that you have connected to, or disconnected from, your car. To make that comparison the app reads the Wi-Fi network name your device is currently on; only the network you link to a vehicle is stored by us.
- Wallet & transactions: balance, top-ups, session times, zones, tariffs, Platform Fees, receipts.
- Device & technical: device model, OS version, app version, app/device identifiers, language, IP address, diagnostics, and push-notification tokens.
- Product analytics: in-app events, screens viewed and feature usage, collected via Mixpanel to understand and improve how the Service is used. Mixpanel receives your device’s IP address with each event and uses it to derive an approximate location — the city and country the event came from. This is separate from the precise location above, and we use it only to understand where the Service is being used. During the TestFlight beta, Apple also collects crash logs, usage data and any feedback you submit as a tester.
From third parties
- Payment data: when you top up using Apple Pay, Google Pay or a debit or credit card (processed through our payment gateway, MyFatoorah), the processor handles your card details and shares with us limited information such as a payment token, card type/last digits, and transaction status. We do not collect or store full card numbers.
- Parking data from operators: the operators of the paid zones and car parks you use tell us about parking sessions and Pay later charges linked to your registered plate — the plate, the location, the times, the amount and, for Pay later charges, the payment deadline.
We do not intentionally collect special-category data, and we do not collect data from children under 18 (see Section 9).
We use analytics only to run and improve shalwa. We do not track you across other companies’ apps or websites for advertising, we do not use advertising SDKs, and we do not sell your data.
3. How we use your data, and our legal basis
Under the PDPL we process your data on the following bases:
| Purpose | Examples | Legal basis (PDPL) |
|---|---|---|
| Provide the Service | detect parking, start/stop sessions, charge tariffs from your Wallet | Performance of a contract |
| Location, motion & car-connection processing | run sessions automatically; recognise your car by its saved connection; show “shalwa is off” states | Your consent (device permissions) + contract |
| Payments & Wallet | process top-ups, charge sessions and Platform Fees, issue receipts | Performance of a contract |
| Account & security | verify your number, secure your account, prevent fraud/misuse | Contract + legitimate interests + legal obligation |
| Notifications | session, low-balance and service alerts | Consent / contract |
| Support & service improvement | respond to you; fix bugs; improve reliability (aggregated/diagnostic) | Legitimate interests |
| Website sign-ups | tell you when shalwa is available on Android, or that it has launched where you are | Your consent |
| Website support enquiries | receive and answer messages sent from our support page | Legitimate interests / contract |
| Product analytics | understand feature usage via Mixpanel; diagnose crashes via TestFlight (beta) | Consent / legitimate interests |
| Legal & compliance | comply with law, respond to lawful requests, enforce our Terms | Legal obligation / legitimate interests |
We do not sell your personal data.
4. Who we share data with
- Parking operators: the authority or operator of the paid zone or car park you use, which receives your licence plate and session times so that your parking can be started, run and paid for, and which tells us about Pay later charges linked to your plate.
- Payment providers: Apple Pay, Google Pay and MyFatoorah (our payment gateway), to process top-ups.
- Messaging provider: WhatsApp (Meta Platforms), to send your one-time passcode and service messages.
- Push notifications: Firebase Cloud Messaging (Google), which delivers the session, confirmation and low-balance notifications we send to your device. We share your device’s push token with it for that purpose.
- Hosting & infrastructure: Amazon Web Services (AWS) and Google Cloud Platform (GCP), who host the Service and process data on our behalf.
- Analytics / crash reporting: Mixpanel (product-usage analytics) and Apple TestFlight (beta testing, crash logs and tester feedback during the beta period).
- Website form handling: Formspree (Formspree, Inc., United States), which receives, stores and forwards to us the submissions you make through our Android sign-up, earlier waitlist and support forms on shalwa.io, so that we can reply to you and tell you when shalwa is available. Formspree processes this data on our behalf and under our instructions; it does not use it for its own purposes.
- Professional advisers, authorities and successors: where required by law, to protect rights/safety, or in connection with a merger, acquisition or asset transfer.
We require our processors to protect your data and use it only on our instructions.
5. International transfers
Your data may be processed outside the UAE where our providers operate — including in the European Union and the United States, where Amazon Web Services, Google (Google Cloud Platform and Firebase Cloud Messaging), Mixpanel, Meta Platforms (WhatsApp), Apple and Formspree operate the infrastructure and services we use. Where we transfer personal data internationally, we do so in accordance with the PDPL transfer conditions — to jurisdictions with adequate protection, or under appropriate safeguards and contractual terms with each provider, or with your consent where required.
6. How long we keep data
We keep personal data only as long as needed for the purposes above, then delete or anonymise it:
- Account & vehicle data: while your account is active, and for 90 days after you close it.
- Transaction/Wallet records: 5 years, as required by UAE tax and accounting law.
- Location & motion data: 6 months, which is what we need to run and audit sessions and resolve any dispute raised within the periods in our Terms; we aggregate or anonymise it thereafter.
- Diagnostics & logs: 12 months.
- Website form submissions: support enquiries for 12 months after your question is resolved; website sign-ups (the Android list and the earlier waitlist) until we have told you shalwa is available, or until you ask us to remove you — whichever is first.
7. How we protect your data
We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls, and tokenised payments (we don’t store full card numbers). No system is perfectly secure; we will notify you and the relevant authority of a personal-data breach as required by the PDPL.
8. Your rights
Subject to the PDPL and applicable conditions, you may:
- access the personal data we hold about you;
- correct inaccurate or incomplete data;
- request deletion of your data;
- restrict or object to certain processing;
- request portability of data you provided;
- withdraw consent (e.g. by disabling location, motion, notification or Bluetooth permissions — note the Service then cannot run sessions); and
- lodge a complaint with the UAE Data Office.
To exercise your rights, contact support@shalwa.io. We will respond within the period required by law. We may need to verify your identity.
Deleting your account. You can delete your account and associated personal data at any time directly in the app (Settings → Delete account). We will delete or anonymise your data, except records we are required to keep to meet legal, tax or accounting obligations (see Section 6).
9. Children
The Service is for users 18 and over. We do not knowingly collect data from anyone under 18. If you believe a minor has used the Service, contact support@shalwa.io and we will take appropriate action.
10. Permissions you control
You can manage the permissions shalwa uses in your device settings at any time: location, motion & fitness, notifications and Bluetooth, where your device asks for it — Bluetooth is what lets shalwa see which device your phone is connected to. Reading your car’s Wi-Fi network name relies on the location permission you have already granted; there is no separate permission for it. Disabling any of these puts shalwa into an “off” state and stops automatic sessions. You can also manage notification preferences in the app.
11. Changes to this Policy
We may update this Policy. We will post the updated version with a new “Last updated” date and, for material changes, notify you in-app or by message. Please review it periodically.
12. Contact
Abdulla Alhashmi Marketing Management (trading as shalwa) — Villa 15, Al Safa Second, Bur Dubai, Dubai, UAE
Privacy / data requests: support@shalwa.io · Support: support@shalwa.io
This Policy should be read together with the shalwa Terms of Service.