LoYalla
VenuesMembershipFAQ
العربية

Privacy Policy

Last updated: 25 July 2026

Loyalla operates the Loyalla loyalty programme across OCCO Business Bay, OCCO Hessa and SanosFit in Dubai, United Arab Emirates. This policy explains what personal data we collect when you use the Loyalla app and website, why we collect it, how long we keep it, and the choices you have.

We have written this policy to be read, not skimmed. If anything is unclear, write to us at privacy@loyalla.ae and we will answer plainly.

1. Who we are

Loyalla is the loyalty membership of a Dubai hospitality group whose participating venues at launch are OCCO Business Bay, OCCO Hessa and SanosFit. The group is the controller of the personal data described in this policy. For any privacy matter, the single point of contact is privacy@loyalla.ae.

2. The data we collect

We collect only what the programme needs to work:

  • Mobile number — your primary identifier, verified by a one-time code when you join.
  • Name — so venues can welcome you properly and staff can confirm they are serving the right member.
  • Birthday — used once a year for your birthday reward, and never shared for any other purpose.
  • Email address and preferred language, if you choose to provide them.
  • Transaction history — the venue, date, eligible amount, the reward you chose (save now or earn points), and the points earned, redeemed, expired or reversed.
  • Receipt images — photographs of receipts taken by venue staff, or submitted by you in the app, used to verify that a transaction is genuine.
  • Device and notification tokens, so the app can deliver the notifications you have consented to.
  • Support correspondence, when you contact us.

3. Why we use your data

  • To operate your membership: one points wallet across all participating venues, including calculating points, applying the 45-day expiry, and honouring redemptions.
  • To verify transactions and prevent fraud, including manager review of receipts and risk checks on unusual activity.
  • To send service communications about your account — points pending, approved, redeemed, or approaching expiry, and booking confirmations.
  • To send marketing communications, only on the channels you have consented to (see section 4).
  • To recognise your birthday with a reward, if your profile includes a birthday.
  • To produce internal settlement reports between venues. These use transaction records; venues settle between themselves, and this does not create any new use of your personal data.
  • To comply with legal, tax and audit obligations in the United Arab Emirates.

4. Marketing consent, channel by channel

Consent for marketing is stored separately for each channel: push notifications, email, SMS and WhatsApp. Consenting to one channel never opts you into another. You may withdraw consent for any channel at any time in the app under Profile → Notifications, and we will respect that choice on every send.

Service messages that are necessary to run your account — such as a code to sign in, or notice that points are about to expire — are not marketing and are sent regardless of marketing preferences.

5. Who we share data with

We do not sell personal data. We share it only with:

  • Participating venues within the group, so staff can serve your membership at the venue you are visiting. Staff access is limited by role and by venue.
  • Service providers who process data on our instructions — hosting, messaging delivery, and analytics strictly for operating the programme.
  • SevenRooms, our reservations partner, when you choose to book a table; only the details needed for the booking are involved.
  • Public authorities, where the law of the United Arab Emirates requires it.

6. How long we keep data

We keep your profile and points ledger while your membership is active. Receipt images are kept for the period needed for verification, fraud review and audit, and are then deleted.

When your account is deleted, personal data is erased or irreversibly anonymised, except for records we are legally required to retain — such as financial and audit records — which are kept only for the statutory period and only for that purpose.

7. Security

Data is encrypted in transit. Access by staff is restricted by both role and assigned venue, there are no shared staff accounts, and access to evidence such as receipt images is logged and auditable.

8. Your rights

Under UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, you have the right to access the personal data we hold about you, to correct it, to ask for it to be deleted, and to withdraw any consent you have given. To exercise any of these rights, use the app or write to privacy@loyalla.ae. We respond to every request.

9. Deleting your account

You can delete your account yourself, in the app, at any time: Profile → Delete account. Deletion is permanent and any remaining points are forfeited, as points have no cash value. You do not need to call anyone or give a reason.

10. Age

Loyalla membership is intended for adults aged 18 and over. We do not knowingly collect personal data from anyone younger.

11. Changes to this policy

If we change this policy in a way that matters, we will tell you in the app before the change takes effect. The date at the top always shows the current version.

12. Contact

For anything relating to your personal data: privacy@loyalla.ae.

This policy has been prepared for the Loyalla programme and is subject to review by qualified UAE legal counsel prior to publication. The English and Arabic versions are intended to be identical in meaning.

LoYalla
VenuesPrivacy PolicyProgramme TermsDownload the app

© 2026 Loyalla — All rights reserved.