Privacy Policy
Last updated: 30 June 2026
This Privacy Policy explains how HAANK for Computer Systems & Communication Equipment Software Trading (“HAANK”, “we”, “us”), of Dubai, United Arab Emirates, collects, uses, and protects personal data when you use MidaOne (the “Service”). For the account and business data of Subscribers, HAANKis the data controller. We process personal data in accordance with applicable law, including UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (“PDPL”). This Policy should be read with our Terms of Service and Data Processing Addendum.
1. Data we collect
Account & business data — your name, email, café name, and contact details when you sign up.
Service content — the data you enter to run your business, such as products, prices, sales, inventory, suppliers, and expenses.
Your customers' data — if you use loyalty or similar features, the customer names and phone numbers you choose to record.
Payment data — handled by our payment processor (Stripe); we do not store full card numbers.
Technical data — log and usage data, device and browser information, and limited diagnostic data used to keep the Service secure and working.
2. How we use data, and our legal basis
We use data to provide and operate the Service (performance of our contract with you); to process subscriptions and meet legal, accounting, and tax obligations (legal obligation); and to keep the Service secure, prevent abuse, and improve it (our legitimate interests). Accepting these Terms and this Policy when you sign up is your acceptance of our contract — it is not a general consent to processing. Where we genuinely rely on consent (for example optional marketing emails), we request it separately and you can withdraw it at any time. We do not sell your data. We may send you service and account emails (for example password resets, receipts, and important notices).
3. Cookies
We use a single essential, secure cookie to keep you signed in. It is required for the Service to function and is not used for advertising or cross-site tracking.
4. Service providers (sub-processors)
We rely on trusted providers to run the Service, who process data on our behalf under their own security and contractual commitments: cloud hosting and our database (Vercel and Neon), image hosting (Vercel Blob), transactional email (Resend), error monitoring (Sentry), and a payment processor (Stripe), where card payments are enabled. Some providers process data on servers located outside the UAE. We keep this list current. Before we add or replace a sub-processor that processes personal data, we will give you at least 30 days' notice (by email or in the app) so that you, as controller of your customers' data, may object; if you reasonably object on data-protection grounds and we cannot resolve it, you may terminate the affected Service.
5. International transfers
The Service is currently hosted on infrastructure located in the United States, and some sub-processors operate in other countries. The United States is not currently the subject of a UAE adequacy decision, so where we transfer personal data outside the UAE we do so under appropriate contractual safeguards with the recipient, pursuant to Article 23 of the PDPL and the transfer terms in our Data Processing Addendum. We do not rely on your consent as the basis for the transfers that are necessary to provide the Service. You can contact us for more information about these transfers.
6. Your customers' personal data
When you record your own customers' details in the Service, you are the controller of that data and we act as your processor — we handle it only on your instructions to provide the Service, keep it confidential, apply appropriate security, and assist you with data requests and breaches as reasonably required, including notifying you without undue delay after we become aware of a personal-data breach affecting that data and giving you the information you need to meet your own notification duties. Your customers should contact you, the café, about their personal data. You are responsible for giving them any required notice and obtaining any required consent. Our processing on your behalf is governed by our Data Processing Addendum.
7. Data retention & account deletion
We keep your data while your account is active. Your account may be active, archived (a reversible deactivation — your data is retained so the account can be restored; we may permanently delete an archived account after 12 months), or deleted. After your account ends, you can export your data for 30 days; we then delete or anonymise it within a further 90 days. These periods are maximums — if you (or a person we verify is authorised) ask us to delete the account, we may delete sooner — except where we must keep certain records to meet a legal, tax, or accounting obligation.
The café owner can delete the account themselves, at any time, from inside MidaOne (Settings → Close account, or midaone.com/delete-account). Deletion takes effect immediately — the account locks and any subscription is cancelled — and becomes permanent after a 30-day grace period during which it can be cancelled via an emailed link. When the grace period ends we erase staff accounts, customer records, menus, images and other personal data. Sales and tax records are retained without personal data(the business name, tax registration number and transaction amounts) only as long as tax law requires — 5 years under UAE VAT law — and are then destroyed. Individual staff accounts are managed and removed by the café owner from the Staff page.
8. Security
We protect data with measures including encryption in transit (HTTPS), hashed passwords, optional two-factor authentication for admin accounts, access controls, and rate limiting. No system is perfectly secure, but we work to protect your data. If a personal-data breach occurs, we will notify the UAE Data Office and affected individuals as and when required by the PDPL and its executive regulations. Where a breach affects personal data we process on behalf of a café (as its processor), we will notify that café without undue delay after becoming aware and provide the information it needs to meet its own obligations.
9. Your rights
For the account and business data for which we are the controller, and subject to applicable law, you may ask to access, correct, or delete your personal data; object to or ask us to restrict certain processing; withdraw consent where processing is based on consent; receive an export of your data; and lodge a complaint with the UAE Data Office. To make a request, contact us at support@midaone.com. We may need to verify your identity, and we will respond within the time required by law.
For personal data about a café's own customers, the café is the controller. If one of those individuals contacts us, we will refer them to the café and assist the café in responding, as set out in Section 6 and our Data Processing Addendum.
10. Automated decisions
We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you. If this changes, we will update this Policy and tell you about the associated rights.
11. Children
The Service is intended for businesses and is not directed at children under 18. We do not knowingly collect personal data from children.
12. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will take reasonable steps to notify you. The “Last updated” date above shows when it last changed.
13. Contact
For privacy questions or requests, contact our data-protection contact at support@midaone.com. If our processing ever requires the appointment of a Data Protection Officer under the PDPL, we will appoint one and update this contact.
This document is not legal advice. HAANK should have it reviewed by a qualified UAE lawyer before relying on it.