Privacy Policy
Last updated 12 August 2026
This page explains what information Vouchnexus collects about you, why we need it, who else sees it, and how to get it removed. It is written to be read, not to be survived.
Our operating company is not yet finalised
Everything below describes exactly how Vouchnexus handles your information today, and you can rely on it. What is still being confirmed is the registered company, its address, the law that governs these terms, and the regulator you can complain to. We publish this page now rather than a placeholder because you are entitled to know what happens to your data before you decide to use the service. This notice will be replaced by those details, and the “last updated” date above will change when it is.
Who this is about
Vouchnexus is a marketplace where restaurants and cafés sell vouchers to customers. This policy covers three kinds of people: customers who buy vouchers, merchants and their staff who sell and redeem them, and visitors who only browse.
The controller of your information is the company operating Vouchnexus (to be confirmed, see the notice above).
What we collect, and why
If you only browse, we do not ask for anything. Your language and currency preference are stored in cookies on your device so the site remembers them, and the offers you have recently viewed are stored in a cookie so we can show them again. None of that is tied to an identity.
If you buy a voucher, we collect your email address, because a voucher has to be delivered somewhere and you need a way to open it later. You may optionally add a display name, a phone number, a WhatsApp number, or link a Telegram account, but only if you want vouchers delivered through those channels. We record the vouchers you hold, when they were issued, when they expire, and where and when they were redeemed.
Customers do not have passwords. You prove an email address is yours by clicking a one-time link we send to it. That is the whole account. We keep a short-lived record of the verification request, including the IP address it came from, so the link cannot be abused to send mail to strangers.
If you are a merchant or staff member, we collect your email address, your display name and your role, because those decide what you are allowed to see and do. Merchants also provide business details: trading name, branches, and the offers themselves, which are business information rather than personal information, though a sole trader’s business details may be both.
Payments. Card details never reach us. Payment is handled by Stripe on their own systems; we receive a payment reference, an amount, and whether it succeeded. We could not see your card number if we wanted to.
What we do not do
We do not sell your information. We do not share it with advertising networks. We do not build profiles of you for anyone else’s benefit.
A merchant can see the vouchers sold and redeemed for their own business, and aggregate patterns such as which hours are busiest. Merchants cannot see your activity at other merchants, and this is enforced by the database itself rather than by application code alone. Every table carries row-level isolation, and we run a test suite whose entire job is to try to break it.
Our AI features never see customer data.Vouchnexus uses AI to help merchants write offer descriptions and translate them into Arabic. What is sent is the merchant’s own marketing copy. No customer email, voucher, or purchase is ever sent to an AI provider.
Who else processes your information
We use a small number of providers. Each one only receives what it needs to do its job.
- Stripe: takes payments. Receives your payment details directly; we never hold them.
- Resend: sends email for voucher delivery, sign-in links and receipts. Receives your email address and the message.
- Telegram: only if you choose to link it, and only then receives the messages we send you.
- Cloudflare: serves the site and protects it from attack. Sees the network traffic any website host would see.
- Our own servers: the database, the application and error monitoring all run on infrastructure we operate ourselves rather than a third-party analytics platform.
Some of these providers operate outside the UAE, which means your information may be processed abroad. We choose providers that commit to appropriate safeguards.
Marketing email
Messages about vouchers you have bought, such as delivery, expiry reminders and receipts, are part of the service and are not marketing. You cannot turn those off while you hold a valid voucher, because turning them off would mean you stop being told about something you paid for.
Promotional email is separate, is off by default, and every promotional message carries a one-click unsubscribe. Unsubscribing takes effect immediately and applies across the whole platform, not just the merchant whose message you clicked.
How long we keep things
- Sign-in links expire one hour after they are requested, and can be used once.
- Vouchers and their redemption records are kept while the voucher is valid and afterwards as a record of the transaction, because a merchant is paid out on the strength of it.
- Records we are required to keep for tax and accounting are kept for as long as the law requires, even if you close your account.
- Cookies for language, currency and recently-viewed offers expire within 30 days.
Your choices
You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it.
Deleting your account takes seven days. When you request deletion we mark the account and then wait a week before removing anything. That is deliberate: account deletion is the one action nobody can undo for you, and a week means a mistake, or somebody else acting on your account, can still be reversed. You can cancel during that week from your profile, and we will tell you it happened.
To make any of these requests, use your profile or write to [email protected].
Security
Vouchers are cryptographically signed, so a voucher presented at a till can be proven genuine rather than merely looked up. Access between merchants is isolated at the database level. Traffic to the site is encrypted. We monitor errors on our own systems rather than shipping them to a third party.
No system is perfect. If you believe you have found a security problem, please tell us at [email protected] and we will look at it properly.
Children
Vouchnexus is not intended for children. We do not knowingly collect information from anyone under 18. If you believe a child has given us information, tell us and we will remove it.
Changes
If we change how we handle your information, we will change this page and update the date at the top. If the change is significant and we have your email address, we will tell you directly rather than relying on you to notice.