Privacy policy

Last updated: July 2026

Slashia is a restaurant-discovery service for Dubai. This policy explains what we collect on our website and mobile app, why, who we share it with, and the choices you have. Browsing the website and the free areas of the app requires no account — the data below under "Account data" only applies once you sign in.

1. Information we collect

Account data — if you sign in on the mobile app: your mobile number (used only for one-time-passcode sign-in), and, if you choose to add them, your name, date of birth, gender, and profile photo. Date of birth is used solely to avoid recommending alcohol-serving venues to under-21 users; it is never shown to other people.

Saved restaurants and preferences — the venues you save, and any vibe/notification preferences you set.

Usage data — pages and restaurants you view, searches you make, vibe filters you apply, and whether you tap through to WhatsApp or Directions for a restaurant. On the mobile app, this is linked to your account once you're signed in. On the website, it's linked to an anonymous browser session, not your identity. We use this to rank restaurants, to understand what's popular, and — as the service grows — to make our own advertising more relevant and to report engagement to investors and partners.

Location — with your permission, we use your device's GPS (mobile) or an approximate location derived from your IP address (website) to show nearby restaurants and sort by distance. This is not stored against your identity beyond what's needed for that session.

Push notification token — a device identifier used to deliver push notifications, linked to your account if you're signed in.

Device and log data — standard technical data such as IP address, browser/app version, and crash logs, collected automatically by our hosting and infrastructure providers.

2. How we use it

To sign you in and keep your saved restaurants and preferences in sync; to show you nearby and relevant venues; to send notifications you've opted into; to understand usage and improve Slashia; and, as noted above, to inform our own advertising and to report aggregate engagement metrics internally and to investors. We do not sell your personal data to third parties.

3. Advertising and analytics partners

Our website may use Google Analytics and the Meta (Facebook) Pixel to measure traffic and ad performance. These tools receive standard web analytics signals (such as pages viewed and actions taken, e.g. tapping "Book on WhatsApp") directly from your browser when these integrations are active.

Our mobile app uses the Meta (Facebook) SDK to measure how well our app-install ad campaigns perform — it reports standard app events (such as app opens and completing sign-up) to Meta so we can tell which ads led to real installs. On iOS, this requires your permission via Apple's App Tracking Transparency prompt, which you can change any time in your device Settings; the app still works fully if you decline, you'll just be measured in an anonymised, aggregated way rather than individually. Meta may use this information in line with its own privacy policy. You can also limit web tracking using your browser's tracking/cookie controls or an ad blocker.

4. Service providers

We use trusted providers to run the service, each of whom processes data on our behalf under their own security and privacy terms:

  • Supabase — database, authentication, file storage.
  • Twilio — delivers the SMS one-time passcode; receives your phone number for that purpose only.
  • Google Places / Google Maps — restaurant details, ratings, photos, and location lookups.
  • Expo / EAS — delivers push notifications and app updates.
  • Vercel — hosts our website and processes standard request logs.

5. Data retention

We keep account data for as long as your account is active. Usage/analytics data is generally kept for up to 24 months to support the reporting described above, then aggregated or deleted. If you delete your account, we delete your profile, saved restaurants, and push token, and disassociate your past usage data from your identity.

6. Your choices and rights

You can log out at any time, and can request access to, correction of, or deletion of your account and associated data by contacting us. We'll act on deletion requests within 30 days. Depending on where you live, you may have additional rights under local data protection law (for example the UAE's data protection law, or the EU/UK GDPR) — contact us and we'll help.

7. Children

Slashia is not directed at children and is not intended for use by anyone under 16. We do not knowingly collect data from children under 16; if you believe a child has provided us data, contact us and we'll delete it.

8. Security

We use industry-standard measures (encryption in transit, access controls, and a service-provider model built on Supabase's security practices) to protect your data, but no system is 100% secure. Contact us if you believe your account has been compromised.

9. Changes to this policy

We may update this policy as Slashia evolves. Material changes will be reflected by updating the date above; continued use after an update means you accept the revised policy.

10. Contact

Questions, or a request to access/delete your data? Contact us.

This policy describes our current data practices as accurately as we can. It is not a substitute for legal advice — if you need certainty for a specific regulatory requirement, have it reviewed by a qualified professional.