ZUPPRA

Privacy at Zuppra

Privacy Policy

A transparent account of what we collect, why we need it, and the choices that remain yours.

Effective 23 July 2026

Privacy at a glance

We collect the information needed to run a trusted catering marketplace, protect payments, support bookings, and meet legal obligations. We do not sell personal data. Exact event and payment details are shared only where needed for the service, safety, or law.

Necessary data onlyEncrypted sensitive dataRights and control
01

Who this policy covers

This Policy explains how Zuppra, the operator of the Zuppra marketplace in Dubai, UAE, processes personal data when you visit the Platform, create an account, plan or service an event, communicate, pay, submit documents, contact support, or exercise a privacy right.

Zuppra acts as controller for Platform account, marketplace, trust, payment-status, support, and administration data. A caterer may separately act as controller for information it receives to quote for or deliver an event and must use that information lawfully.

02

Information we collect

The information varies by how you use Zuppra. It may include:

  • Identity and account data: name, email, mobile number, avatar, authentication and account role.
  • Event and booking data: date, location, guest count, budget, menu, dietary and allergy information, instructions, quotes, changes, cancellations, reviews, and disputes.
  • Business and compliance data: business profile, licences, certificates, insurance, Foodwatch information, team roles, packages, tax and payout references.
  • Payment data: amount, currency, status, provider references, refunds, and chargeback or dispute records. Full card details are handled by the payment provider and are not stored by Zuppra.
  • Communications and evidence: messages, support requests, uploaded documents, photographs, and other materials you choose to provide.
  • Technical and usage data: IP address, device and browser information, request and security logs, cookie identifiers, and interaction data.
03

Where information comes from

We receive information directly from you; from another booking participant or authorised team member; from payment, communications, identity, hosting, and analytics providers; from Dubai Pulse or Foodwatch and other permitted public or regulatory sources; and from security or fraud-prevention checks.

If you provide another person’s information—for example a venue contact or guest dietary requirement—you must have authority to do so and share only what is necessary.

04

How and why we use information

We process personal data only for specific, lawful purposes, including:

  • Creating accounts, authenticating users, and managing team permissions.
  • Matching event briefs with caterers and enabling quotes, bookings, messages, payments, refunds, payouts, reviews, and notifications.
  • Verifying caterers, documents, and marketplace integrity.
  • Preventing fraud, duplicate payments, abuse, security incidents, and improper chargebacks.
  • Investigating complaints, preserving evidence, resolving disputes, and enforcing agreements.
  • Providing support, improving accessibility and performance, and understanding service use.
  • Complying with accounting, tax, consumer, data-protection, sanctions, court, and regulatory obligations.
  • Sending service communications and, where permitted or consented to, marketing that can be opted out of at any time.
Depending on the activity, processing is necessary to perform a contract, comply with law, protect legal rights or vital interests, pursue a permitted legitimate interest, or act on consent.
05

When information is shared

We do not sell personal data. We share only what is reasonably necessary with:

  • Customers and caterers involved in an event, with sensitive location or contact details revealed only when needed for quoting, a paid lead, a confirmed booking, service delivery, or dispute handling.
  • Payment providers, banks, and fraud-prevention partners to authorise, reconcile, refund, or investigate transactions.
  • Email, messaging, storage, hosting, security, document-processing, and professional service providers acting under appropriate duties.
  • Competent authorities, courts, regulators, insurers, auditors, or advisers where required by law or reasonably necessary to establish, exercise, or defend rights.
  • A buyer, investor, or successor in a genuine corporate transaction, subject to confidentiality and legal safeguards.
06

Public and private information

Caterer names, profiles, packages, service areas, ratings, reviews, verification indicators, and selected imagery may be public. Event briefs may be visible to eligible caterers, but Zuppra is designed to withhold sensitive contact and precise location information until the relevant access condition is met.

Do not place phone numbers, exact private addresses, payment details, identity documents, or confidential information in public titles, descriptions, reviews, or profile fields.

07

How long information is kept

We keep personal data only as long as needed for the purposes described above. Retention depends on account status, booking and payment lifecycle, dispute or chargeback windows, fraud and safety needs, and accounting, tax, consumer, limitation, and regulatory requirements.

An account-deletion request has a 30-day grace period in which it may be cancelled. After that period, account PII is anonymised unless a lawful exception applies. Closing an account does not erase transactional records that must be retained for confirmed bookings, outstanding payments, disputes, legal claims, security, or compliance. When retention is no longer justified, information is deleted, anonymised, or securely isolated.

08

How information is protected

We use technical and organisational safeguards designed for the sensitivity of the information, including encryption of selected personal and compliance data, access controls, role-based permissions, authentication protections, audit records, secure transport, backups, and monitoring.

No service can guarantee absolute security. You must use a strong unique password, protect verification codes, limit team access, and notify us immediately if you suspect compromise. If a breach creates a legally reportable risk, we will take the notification steps required by applicable law.

09

International processing

Some providers or support operations may process data outside the UAE. Where personal data is transferred internationally, we apply the conditions and safeguards required by UAE data-protection law, considering the destination, provider commitments, security, and available legal transfer mechanism.

10

Your privacy rights

Subject to applicable law and valid exceptions, you may ask to:

  • Receive information about processing and access personal data held about you.
  • Correct incomplete or inaccurate information.
  • Delete information that is no longer required or withdraw consent where consent is the basis.
  • Restrict or object to certain processing, including direct marketing.
  • Receive or transfer information in a technically feasible portable format.
  • Raise a concern about automated processing or complain to the competent UAE authority.
Send a request to privacy@zuppra.com. We may verify identity and may retain information where law, fraud prevention, payment reconciliation, a dispute, or a legal claim requires it.
11

Cookies and communications

Zuppra uses essential cookies and similar storage to keep sessions secure, remember necessary preferences, and operate core features. We may use limited measurement tools to understand performance and improve the service. Where law requires consent for a non-essential technology, we will request it before use.

Operational messages about security, bookings, payments, disputes, and account changes are part of the service. Marketing email or WhatsApp choices can be changed in notification settings or through the unsubscribe method in the message.

12

Children

Zuppra is not intended for people under 18 and we do not knowingly create accounts for them. An adult arranging an event involving children should not submit children’s personal data unless necessary, authorised, and handled with appropriate care.

13

Changes and contact

We may update this Policy to reflect law, technology, providers, or service changes. Material updates will be highlighted through the Platform or by email and will show a new effective date.

For privacy questions or rights requests, contact privacy@zuppra.com. For booking or account support, contact support@zuppra.com. Arabic and English versions are intended to have the same meaning; applicable UAE law governs any unresolved difference.

When the details matter, we are here.

Visit the Help Centre for clear next steps before opening a dispute.

Visit Help Centre