This summary is for convenience only; the full Policy below governs.
PART A — PRIVACY POLICY
1.1 Controller. The Coffex service (the “Service”) is operated by Orikka Limited, a company registered in the Masdar City Free Zone, Abu Dhabi, United Arab Emirates, license no. MC 13554, registered address: Smart Station - First Floor, Incubator Building, Masdar City, Abu Dhabi, or by an affiliated group company (including a company under common holding ownership) or successor entity to which operation of the Service is transferred (see Section 15.3). The company operating the Service from time to time (“Coffex”, “we”, “us”) is the controller of your personal data. Our designated privacy contact can be reached at support@coffex.club (subject line “Privacy”).
1.2 Scope. This Policy applies to personal data we process when you use the Coffex mobile application, our web portal at https://www.coffex.club and https://www.coffex.ae (together, the “App”), and when you communicate with us. It applies to registered members, visitors, and (as described in Section 7.5) representatives of Participating Outlets.
1.3 Definitions. Capitalized terms not defined here (“Plan”, “Cup”, “Participating Outlet”, “Participating Product”) have the meanings given in our Terms of Service, available at https://www.coffex.club/terms.
1.4 Legal basis of this Policy. We process personal data in accordance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (“PDPL”) and other applicable UAE law. If the Service is transferred to a successor operating company (see Section 15.3), the data protection law applicable to that company (for example, the DIFC Data Protection Law No. 5 of 2020, if the company is incorporated in the DIFC) will apply, and we will update this Policy accordingly.
1.5 Acceptance; relationship with the Terms of Service. By registering for the Service — including by entering your mobile number and completing verification — you accept both the Terms of Service and this Policy. This Policy forms part of your agreement with us and should be read together with the Terms of Service. Where you have questions about the Service itself (Plans, redemptions, cancellation, refunds), the Terms of Service govern.
1.6 Age. The Service is available only to persons aged 18 or over. We do not knowingly collect personal data from anyone under 18. If we learn that we hold such data, we will delete it. If you believe a person under 18 has provided data to us, contact us at support@coffex.club.
Depending on how you use the Service, we collect:
| Category | Examples |
|---|---|
| Identity & account data | First and last name; verified mobile number (the unique identifier of your account — one account per person); email address; account settings; profile details you choose to add. |
| UAE Pass data (only if offered and you choose it) | If we offer sign-in or identity verification through UAE Pass and you use it, we receive the identity attributes you authorize UAE Pass to share with us (for example, verified name, mobile number, email and, where applicable, Emirates ID details). UAE Pass is operated by the UAE government’s digital identity infrastructure under its own terms and privacy policy. |
| Transaction data | Plans purchased, upgrades/downgrades, prices paid, payment method type, payment history, VAT invoices, refunds and chargebacks. Card payments are processed by our payment processor Stripe: your card details are entered directly with Stripe and are not stored on our systems — we receive only limited payment information (such as card brand, last four digits and payment status) together with transaction confirmations (see Section 6.1). |
| Redemption data | Redemption codes generated and used, date and time, Participating Outlet, discount applied, Cups consumed and remaining balance. |
| Referral data | Your referral code and link; the contact details of a friend you invite (only if you enter them for us to send the invitation); whether an invitation you sent is pending or has become active; rewards credited under the referral program. |
| Technical & device data | IP address, device type and model, operating system and version, app version, device identifiers (including advertising identifiers, subject to your permissions), language, time zone, mobile network, crash logs. |
| Usage data | How you use the App — screens viewed, searches, features used, session data. |
| Location data | Approximate location, and precise location only if you grant the App permission (used to show nearby Participating Outlets). You can disable this in your device settings at any time. |
| Support & interaction data | Your correspondence with us across any channel (in-app chat, email, phone, WhatsApp, Telegram or other messaging services), complaints, feedback and survey responses; any additional information or documents you provide during support (see Section 5.3); recordings and transcripts of support calls and chats. |
| Marketing & communications data | Your marketing preferences, consents and opt-outs. |
| Fraud-prevention data | Records used to detect and prevent misuse of the Service, including free-trial usage flags, device identifiers and hashed identifiers linked to your mobile number and email (see Sections 5.1(e) and 9). |
We may also create aggregated or anonymized data (for example, redemption statistics by area). Such data can no longer identify you and is not personal data; we may use it for any purpose, indefinitely.
We do not intentionally collect sensitive personal data (such as health data, biometric data or beliefs) and ask that you do not submit it to us.
If you do not provide required data. The verified mobile number and payment details are necessary to create an account and purchase a Plan. Without them, we cannot provide the Service.
We process personal data only where the PDPL permits. Most processing is based on: performance of our contract with you; compliance with a legal obligation; your consent (which you may withdraw at any time); or our legitimate interests, where these are not overridden by your rights.
5.1 We use personal data to:
| Purpose | Main data used | Legal basis | |
|---|---|---|---|
| (a) | Create and administer your account; verify your identity and mobile number (including via UAE Pass, if you choose it); enforce one-account-per-person | Identity & account, UAE Pass | Contract |
| (b) | Provide the Service — generate and validate redemption codes, apply discounts, maintain Cup balances | Identity, redemption | Contract |
| (c) | Process payments, renewals, upgrades/downgrades; issue tax invoices | Transaction | Contract; legal obligation |
| (d) | Provide customer support and handle complaints across all support channels | Identity, support & interaction, transaction | Contract; legitimate interests |
| (e) | Prevent, detect and investigate fraud and misuse — including enforcing the one-free-trial-per-person rule, detecting multiple-account abuse, chargebacks and unauthorized use, and maintaining records needed to identify repeat misuse | Fraud-prevention, identity, technical, transaction | Legitimate interests (protecting the Service and other members); establishment of legal claims; contract (Terms of Service §9.4, §13) |
| (f) | Operate, maintain, secure and improve the App; analytics; fix errors; develop new features | Technical, usage | Legitimate interests |
| (g) | Send service communications (verification codes, receipts, renewal and balance notices, changes to terms or this Policy) via the channels in Section 12 | Identity & account | Contract; legal obligation |
| (h) | Send marketing about Coffex offers via the channels in Section 12 | Identity, marketing, usage | Consent (opt-out at any time) |
| (i) | Build audience segments and profiles — analyze usage, transaction and redemption patterns (including through a data management platform, if we deploy one) to group members into segments for personalization, offers and advertising | Usage, transaction, redemption, technical, marketing | Legitimate interests; consent where required (see Section 11 for your right to object) |
| (j) | Select and display advertising in the App, including third-party offers personalized by us (see Section 6.5) | Usage, profile segments, technical | Legitimate interests; device-level permissions where required |
| (k) | Measure advertising and attribute installs | Technical, usage | Consent (device-level permissions where required); legitimate interests |
| (l) | Record, store and transcribe support interactions for quality, training and analytics (see Section 5.3) | Support & interaction | Legitimate interests; consent where required |
| (m) | Share data as described in Sections 6 and 7 | As described there | As described there |
| (n) | Comply with law, regulations and lawful requests; establish, exercise or defend legal claims | As relevant | Legal obligation; legal claims |
| (o) | Operate the referral program — deliver invitations, attribute sign-ups to referrers, show you the status of your referrals, grant rewards under the offer applicable at the time, and prevent referral abuse | Referral, identity, transaction | Contract (Terms of Service); legitimate interests |
5.2 We will use personal data only for the purposes for which we collected it, unless we reasonably consider a new purpose compatible with the original one. If we need to use your data for an unrelated purpose, we will update this Policy and, where required, seek your consent.
5.3 Support interactions, recordings and storage. When you contact support, we may ask for additional information or documents needed to resolve your issue (for example, screenshots, receipts or details of a redemption). Anything you provide during support will be used and stored for handling your request, quality assurance, training, analytics and the establishment or defense of claims. Customer support may be provided by our own team or by specialist support providers acting on our behalf under written agreements (see Section 6.1); they may collect and store support-related personal data solely on our instructions. Support calls may be recorded and transcribed — including using AI-assisted transcription tools — and support chats (in-app, WhatsApp, Telegram or other messaging services you use to reach us) may be stored and reviewed for the same purposes. You will be informed at the start of any recorded call. Support interactions and account history are stored in our CRM systems, which run on our own infrastructure. Messaging platforms (such as WhatsApp or Telegram) process your communications under their own terms and privacy policies.
5.4 No solely automated decisions with legal effect. We do not make decisions based solely on automated processing that produce legal or similarly significant effects for you. If that changes, we will tell you and you will have the rights described in Section 11.
5.5 Referral program. You can invite friends using your referral code or link. If you share the link yourself (for example, via a messaging app), we receive no data about your friend unless and until they use it. If you enter a friend’s contact details for us to send the invitation, you confirm that you know them and that they agree to us receiving their details for this purpose; we use those details only to deliver the invitation and attribute the referral — not for marketing to your friend — and we delete them if the invitation is not accepted within 90 days. Visibility is deliberately limited in both directions: you see only the status of each referral (pending, or active once your friend starts a paid Plan) and none of your friend’s other data; your friend does not see your account data beyond the invitation you chose to send. Referral rewards are credited under the terms of the referral offer in force at the time, as described in the Terms of Service and the App. Referral misuse (including self-referral) is handled under Section 5.1(e) and the Terms of Service.
6.1 We share personal data with the categories of recipients below. This list describes our current sharing; we may add categories of recipients where we have a lawful basis to do so, and will update this Policy before any materially new category of sharing begins (see Section 16).
| Recipient category | What is shared and why |
|---|---|
| Participating Outlets | See the data-sharing schedule in Section 7. |
| Payment processors | We use Stripe for payments and related business services. Your card details are entered directly with Stripe; we do not receive or store full card numbers. Stripe may collect personal data, including via cookies and similar technologies; the personal data Stripe collects may include transactional data and identifying information about devices that connect to its services. See Stripe’s Privacy Policy. |
| Customer-support providers | Specialist providers who handle member inquiries and complaints on our behalf. Under written agreements meeting Section 6.2, they may collect and store support-related personal data (your correspondence and the account details needed to resolve your issue) solely on our instructions. |
| IT, hosting and communications providers | Cloud hosting, databases, content delivery, website hosting, messaging gateways (SMS/OTP, WhatsApp, email, push) and AI-assisted transcription providers — under contracts limiting use to our instructions. |
| Analytics, attribution and advertising partners (such as Google/Firebase, Meta, TikTok, AppsFlyer or similar) | Technical, usage and advertising-identifier data to measure App performance, attribute installs, and run and measure advertising, subject to your device permissions and cookie choices (Part B). |
| Outlet partners for their own marketing | Only as described in Section 7.3 and only with your consent. |
| Professional advisers | Lawyers, auditors, accountants and insurers, under confidentiality duties. |
| Authorities and regulators | Where disclosure is required by law, court order or a lawful request of a competent UAE authority. |
| Group and successor companies | Any parent, subsidiary or successor company that operates the Service (see Section 15.3), on the terms of this Policy. |
| Business-transfer parties | If we sell, transfer or merge parts of our business or assets, or acquire another business, data may be disclosed to the counterparty; any new owner may use it only as set out in this Policy (as updated). |
6.2 Protection of your data by recipients. We require all service providers processing personal data on our behalf to protect it to a standard equivalent to this Policy, to use it only for the specified purposes and on our instructions, and to keep it confidential and secure.
6.3 No sale of your identity. We do not disclose your personal data to third parties except as described in this Policy. Sharing for a third party’s own marketing happens only with your consent (Sections 6.4 and 7.3), which you can withdraw at any time.
6.4 Marketing consent. By creating an account and confirming your marketing choices during registration (or later in the App’s settings), you consent to the marketing uses and marketing sharing described in this Policy. You can withdraw any marketing consent at any time — see Section 12.5. Withdrawal is as easy as consenting; it does not affect the lawfulness of anything done before withdrawal, and it does not affect the Service itself. Section 7.4 explains what withdrawal means for data already shared.
6.5 Advertising in the App. We may display offers and advertisements of third parties in the App and on the web portal. Where such advertising is personalized, the selection is made by us, using your usage, transaction and segment data — the advertiser does not receive your personal data. Personal data is disclosed to a third party for its own marketing only under Section 7.3.
7.1 Standard redemption data (all Outlets). When you redeem, the Participating Outlet sees, through its outlet portal, only: the date and time, the redemption code used, the discount applied, and the number of Cups redeemed. This does not include your name, mobile number, email, photo, Plan details or any other personal data.
7.2 No database access by default. Participating Outlets do not have access to our systems, member database or your account by default. Limited access may be granted in specific cases, and only under a written agreement imposing the safeguards described in Section 7.3(2)–(3). Anything you disclose to an Outlet yourself (for example, joining that outlet’s own loyalty scheme) is collected by the Outlet as an independent controller under its own privacy policy, and we are not responsible for it.
7.3 Enhanced sharing with selected Outlet partners (consent-based). With selected Outlet partners (typically larger chains), we may agree in writing to share limited personal data — for example, the contact details (name, mobile number and/or email) of members who have redeemed at that partner’s outlets — so that the partner can send those members its own offers. Such sharing happens only where all of the following are met:
7.4 Effect of withdrawing consent. Withdrawal operates prospectively — it does not undo sharing that lawfully took place before it. If you withdraw marketing-sharing consent (in the App’s privacy settings or via support@coffex.club): we stop sharing your data under Section 7.3 from that point; we notify partners who received your data under Section 7.3 that you have opted out, and our agreements require them to stop using your data for marketing; and you may additionally unsubscribe directly with the partner at any time.
7.5 Outlet representatives. If you use the outlet portal on behalf of a Participating Outlet, we process your name, business contact details, role, login credentials and portal activity to operate the partnership, provide support and settle accounts. Sections 8–13 of this Policy apply to this data. Retention follows the commercial-records periods in Section 9.2. The commercial terms of data handling between Coffex and each Outlet are set out in the outlet agreement.
8.1 Some of our service providers (for example, payment, customer-support, analytics, attribution, advertising and AI-transcription partners) store or process data outside the UAE.
8.2 Where personal data is transferred outside the UAE, we do so in accordance with the PDPL: to jurisdictions recognized as providing an adequate level of protection, or otherwise subject to appropriate safeguards — including contractual commitments requiring an equivalent standard of protection — or where the transfer is necessary to perform our contract with you, or with your consent.
8.3 You may contact us for more information about the safeguards applied to a specific transfer.
9.1 We keep personal data only as long as necessary for the purposes described in this Policy, including satisfying legal, accounting, tax and reporting requirements, resolving disputes and preventing fraud and misuse. When data is no longer needed, we delete or anonymize it.
9.2 Retention schedule.
| Data | Retention period | Reason |
|---|---|---|
| Account and profile data | Life of the account + the 30-day deletion window (Section 10) | Providing the Service |
| Transaction, invoicing and financial records | At least 7 years from the end of the relevant tax period | UAE tax and accounting law (VAT and corporate tax record-keeping) |
| Records relevant to an actual or reasonably anticipated dispute or claim | Until the claim is resolved or the applicable UAE limitation period expires (up to 15 years) | Establishing, exercising or defending legal claims |
| Fraud- and misuse-prevention records (see 9.3) | For as long as the relevant offer (e.g. free trial) or misuse risk exists, reviewed at least annually | Preventing repeated free-trial abuse, multiple-account abuse and other misuse |
| Support correspondence, complaints, call recordings and transcripts | 3 years from closure of the matter | Service quality; handling follow-up and disputes |
| Technical logs and usage data | Up to 24 months | Security, diagnostics, analytics |
| Marketing preferences and consents | Until you withdraw consent or delete your account | Marketing |
| Referral invitation contact details (entered by a member) | Until the invitation is accepted or 90 days from sending, whichever is first | Delivering the invitation; attributing the referral |
| Opt-out / suppression records | Indefinitely (minimal record only) | To ensure we and our partners continue to honor your opt-out |
| Outlet-representative records | Duration of the outlet relationship + commercial-records periods above | Operating the partnership |
| Aggregated / anonymized data | Indefinitely | No longer identifies you |
9.3 What we keep after account deletion — fraud and misuse prevention. The Service includes offers (such as the one-per-person free trial) that are open to abuse through repeated account creation. To protect the Service and other members, when your account is deleted we retain a limited fraud-prevention record: your mobile number and email address (in hashed form where practicable), device identifiers, and flags recording free-trial use, misuse findings or unpaid amounts. We use this record solely to recognize a returning individual for the purposes of applying the one-free-trial-per-person rule and the misuse provisions of the Terms of Service (§9.4, §13), and to meet the legal obligations above. It is not used for marketing, is kept under restricted access, and is reviewed at least annually against necessity. We also retain post-deletion any records required under rows 2 and 3 of the table in Section 9.2 (tax, financial and dispute records).
10.1 How to delete. You may request deletion of your account at any time:
10.2 What happens next. Your account is deactivated promptly after the request, and deletion is completed within 30 days. During those 30 days you can cancel the deletion request by logging back into your account and confirming restoration on the screen shown to you; after the period ends, deletion is permanent and your account, balances and history cannot be restored.
10.3 What deletion covers. On completion, we delete or anonymize your personal data, except the limited data described in Section 9.3 (fraud and misuse prevention) and records we must keep by law (Section 9.2). Deleting your account does not by itself entitle you to a refund; the Terms of Service govern cancellation and refunds, and any active Plan lapses in accordance with them.
10.4 Uninstalling ≠ deleting. Removing the App from your device does not delete your account or stop any active Plan. Use the steps in Section 10.1.
11.1 Subject to the conditions and exceptions in the PDPL, you have the right to:
11.2 How to exercise your rights. Contact support@coffex.club (subject “Privacy”) or use the App. We may ask you to verify your identity (for example, via your registered mobile number) before acting — this protects your data from unauthorized requests. We aim to respond within 30 days. We do not charge a fee unless a request is manifestly unfounded, repetitive or excessive, in which case we may charge a reasonable fee or decline, giving reasons.
12.1 Channels. By accepting this Policy you agree that we may contact you through: email (if you have provided it), SMS, WhatsApp and other messaging services, push notifications (in the App and, where supported, via the web portal) and in-app messages.
12.2 Service messages. We send transactional and service communications (verification codes — which may arrive by SMS or WhatsApp — receipts, renewal and balance notices, security and legal notices) regardless of marketing preferences: they are part of the Service.
12.3 Coffex marketing. With your consent, we send offers and news through the channels above. We follow applicable UAE rules on electronic marketing communications. WhatsApp marketing is sent only where you have specifically opted in to receive Coffex messages on WhatsApp; every WhatsApp marketing message includes an opt-out option, and we honor stop requests immediately.
12.4 Third-party marketing. We share personal data for third parties’ own marketing only as described in Section 7.3 (consent-based enhanced sharing with Outlet partners).
12.5 Opting out. You can opt out of each marketing channel at any time: in the App (Settings → Notifications / Privacy), via the unsubscribe link in any marketing email, by replying as instructed in any SMS or WhatsApp message, through your device’s push-notification settings, or by contacting support@coffex.club. Opting out of marketing does not affect service messages.
We apply appropriate technical and organizational measures to protect personal data against accidental or unlawful loss, access, alteration and disclosure — including encryption in transit, access controls, and limiting access to personnel and providers who need it and are bound by confidentiality. No system is completely secure; please keep your device and verification codes safe and notify us immediately of any suspected unauthorized use of your account. If a personal data breach occurs that risks your privacy or security, we will notify the competent authority and, where the risk is high, you, in accordance with the PDPL.
The App and our communications may contain links to third-party websites and services (including Outlets’ own sites and booking or ordering tools). We do not control them and are not responsible for their privacy practices. Participating Outlets process data they collect from you directly (e.g. at the till) as independent controllers. We also maintain accounts on social media platforms; if you interact with us there, the platform processes your data under its own policy — we do not share your Coffex account data with social platforms except as described in Part B (advertising tools).
15.1 Accuracy. Please keep your account details accurate and up to date in the App.
15.2 Language. This Policy is made available in English and in Arabic within this single document. In case of any conflict between the two versions, the English version prevails, except where mandatory UAE law provides otherwise.
15.3 Successor operator. If the Service is assigned or transferred to an affiliated group company or successor operating company (including a newly incorporated company within our holding structure) in accordance with the Terms of Service, that company becomes the controller under this Policy and will honor it (as it may be updated under Section 16), and we will reflect the change in this Policy’s controller details.
15.4 Governing law and disputes. This Policy and any dispute arising out of or in connection with it are governed by the laws of the United Arab Emirates as applied under the Terms of Service, and are subject to the dispute-resolution provisions of the Terms of Service — including the parties’ specific, clear and express agreement that the Courts of the Dubai International Financial Centre (DIFC Courts) have exclusive jurisdiction, as set out there. Nothing in this Section deprives you of any protection or complaint channel granted by mandatory UAE law, including your right to approach the competent consumer-protection authorities or to complain to the UAE Data Office (Section 11.1).
We may amend this Policy from time to time — for example, to reflect new features, new categories of recipients, or changes in law. The current version is always available in the App and at https://www.coffex.club/privacy. For material changes we will give you advance notice in the App and/or by email, SMS or WhatsApp, and where the change concerns processing that requires consent, we will seek it. The “Effective date” above shows when this Policy was last revised; earlier versions are available on request.
Orikka Limited (license no. MC 13554)
Smart Station - First Floor, Incubator Building, Masdar City, Abu Dhabi, United Arab Emirates
Privacy contact: support@coffex.club (subject line “Privacy”) — or via the App.
PART B — COOKIE POLICY
Cookies are small files placed on your browser or device. We and our partners also use similar technologies: SDKs embedded in the App, pixels/web beacons, local storage, and mobile device and advertising identifiers. In this Part B, “cookies” covers all of these.
| Category | What it does | Legal basis / your control |
|---|---|---|
| Strictly necessary | Sign-in, security, verification, fraud prevention (including cookies set by our payment processor Stripe), load balancing, remembering your session and cookie choices. The Service cannot function without these. | Not consent-based; cannot be switched off. |
| Performance / analytics | Measures how the App and website are used so we can fix and improve them. We use Google Analytics / Firebase (including crash reporting); Google explains its processing at “How Google uses information from sites or apps that use our services”. | Consent via the cookie banner (web) and device settings (App); can be withdrawn at any time. |
| Functionality | Remembers your choices (language, preferred outlets) to personalize your experience. | Consent; can be withdrawn at any time. |
| Targeting / advertising & attribution | Set by us and advertising partners (e.g. Google Ads, Meta, TikTok) and attribution SDKs (e.g. AppsFlyer, which measures which campaign led to your install) to measure campaigns, attribute installs, and show you relevant Coffex advertising on other platforms; may involve sharing device identifiers with those partners. | Consent via the cookie banner, and on iOS via the App Tracking Transparency prompt; can be withdrawn at any time. AppsFlyer also offers a direct opt-out. |
A current list of the specific cookies and SDKs in use is available on request and, for the website, in the cookie banner’s settings panel.
Refusing non-essential cookies does not prevent you from using the Service; analytics, personalization and advertising measurement simply will not apply to you. Strictly necessary cookies remain active because the Service cannot operate without them.
© Orikka Limited. All rights reserved.