Privacy policy
YUNIQ CARDS MANAGEMENT SERVICES L.L.C.
Dubai, United Arab Emirates
Effective Date: 22.02.2026
INTRODUCTION
YUNIQ CARDS MANAGEMENT SERVICES L.L.C. (“YUNIQ”, “we”, “us”, “our”) respects your privacy and is committed to protecting your personal data.
This Privacy Policy (“Policy”) explains how YUNIQ (“YUNIQ,” “we,” “us,” or “our”) collects, uses, processes, protects, stores, and discloses personal data in connection with our bespoke card-customization services, whether:
- in person at a kiosk, service desk, or other physical location;
- through our website or online ordering channels; or
- through remote fulfillment channels, including courier-based workflows where offered.
This Policy is intended to reflect our commitment to privacy, confidentiality, fraud prevention, and secure handling of customer information. It should be read together with our Terms and Conditions and any service-specific authorizations or disclosures presented to you during onboarding or checkout.
1. Scope of this Policy
This Policy applies to personal data processed by YUNIQ in connection with:
- customer inquiries;
- order placement and service onboarding;
- in-person card-customization services;
- remote and courier-based service workflows;
- customer support communications;
- payment administration;
- fraud prevention and operational security;
- intellectual property verification for submitted designs;
- legal, regulatory, and dispute-management obligations;
- website use, cookies, analytics, and related digital interactions.
This Policy does not apply to third-party websites, payment processors, courier platforms, banks, card issuers, card networks, or other external services that may have their own privacy notices or terms.
2. Nature of the Service and Data Sensitivity
YUNIQ provides a bespoke aesthetic card-customization service. In the course of delivering that service, YUNIQ may process sensitive customer-related information associated with a customer-provided payment card or card assembly.
Because the service may involve handling regulated payment instruments and sensitive personal or financial information, YUNIQ applies a heightened privacy and security approach.
YUNIQ does not treat card-related information as ordinary commercial data.
3. Categories of Personal Data We May Collect
Depending on how you interact with us and what service you request, we may collect and process the following categories of personal data.
A. Identification and Contact Data
We may collect:
- full name;
- email address;
- telephone number;
- billing address;
- shipping or delivery address;
- customer account or order identifier;
- customer communication history.
B. Identity Verification and Authorization Data
Where necessary for fraud prevention, lawful service delivery, or compliance, we may collect:
- proof of identity;
- cardholder name consistency checks;
- proof that the customer is the lawful and authorized cardholder;
- service authorizations, declarations, and acknowledgments;
- evidence of authority where the request is submitted through an intermediary;
- additional verification records required to assess a suspicious, unusual, or high-risk request.
C. Service-Related Card Information
Where strictly necessary for the requested service, YUNIQ may temporarily process limited service-related card information, including:
- cardholder name;
- limited visual card features relevant to the requested aesthetic customization;
- card presentation details necessary to complete the customized design or assembly;
- records of the requested customization options;
- limited component-handling records relevant to production control and security.
YUNIQ does not permanently retain sensitive payment data beyond what is strictly necessary and lawfully permitted.
D. Design Submission Data
Where you submit custom designs, we may process:
- names, initials, or text selected for engraving;
- uploaded design files;
- logos, insignia, graphics, or artwork;
- supporting documents showing authorization to use third-party intellectual property;
- communications regarding approval, rejection, or modification of submitted designs.
E. Payment and Transaction Data
We may process:
- transaction confirmation details;
- payment status;
- limited billing information;
- refund or dispute-related records;
- payment processor references.
YUNIQ uses third-party payment providers and does not store payment card details beyond what is strictly necessary and lawfully permitted.
F. Shipping and Courier Data
For remote services, we may process:
- sender and recipient details;
- courier tracking details;
- shipment records;
- chain-of-custody records;
- packaging integrity checks;
- pickup, dispatch, receipt, and delivery timestamps;
- identity verification associated with delivery or collection.
G. CCTV, Security, and Fraud Prevention Data
We may process:
- CCTV footage from service areas;
- time and location records of service interactions;
- workstation or service logs;
- fraud alerts, suspicious activity indicators, and internal review outcomes;
- records of compliance and security incidents.
H. Website and Device Data
When you visit our website or use our digital interfaces, we may process:
- IP address;
- browser type;
- device type;
- operating system information;
- cookies and analytics data;
- website interaction information;
- security logs and abuse-prevention information.
4. Data We Do Not Intend to Retain as a Matter of Policy
As a general rule, YUNIQ does not intend to permanently retain sensitive payment data beyond what is strictly necessary and lawfully permitted.
Subject to legal obligations, fraud prevention needs, or lawful evidentiary requirements, YUNIQ follows a zero-retention-oriented approach for highly sensitive cardholder information, including immediate or prompt deletion once the relevant processing step is complete and continued retention is no longer necessary.
Nothing in this Policy should be interpreted as a promise that all service-related information is deleted instantly in every case; some records may need to be retained for legal compliance, fraud prevention, dispute defense, accounting, security, or evidentiary reasons. However, sensitive payment data will not be retained as a general business asset or marketing resource.
5. How We Process Service-Related Information
During the service workflow, relevant information may be processed on secured systems, service devices, controlled workstations, or limited internal tools used to evaluate, perform, secure, and document the requested service.
YUNIQ does not:
- issue payment cards;
- create new payment credentials;
- program or encode new payment functionality;
- maintain a permanent database of sensitive payment credentials as part of ordinary service operations.
Where existing card components must be physically handled as part of an approved customization workflow, such handling is performed under controlled conditions and does not authorize unauthorized extraction, copying, dissemination, or retention of sensitive payment data.
6. Purposes of Processing
We process personal data only for legitimate, specific, and proportionate purposes, including:
- evaluating and onboarding your service request;
- verifying identity, authorization, and cardholder status;
- performing the requested aesthetic customization service;
- handling customer-provided design instructions;
- fraud prevention and operational security;
- secure processing, shipping, return logistics, and customer communication;
- maintaining service logs and internal quality controls;
- complying with legal, regulatory, accounting, tax, anti-fraud, and dispute-resolution obligations;
- establishing, exercising, or defending legal claims;
- monitoring service integrity and enforcing our Terms;
- obtaining or verifying documentary proof relating to design rights or permissions.
We do not sell or rent personal data.
7. Legal Bases for Processing
Where required by applicable law, we rely on one or more of the following legal bases:
- performance of a contract or steps taken at your request before entering into a contract;
- your explicit consent where consent is the appropriate basis;
- compliance with legal and regulatory obligations;
- legitimate interests in fraud prevention, service security, operational integrity, rights protection, dispute defense, and lawful business administration, where such interests are not overridden by applicable legal rights.
Where consent is relied upon:
- it will be documented;
- it may be requested through service forms, checkout steps, or other auditable onboarding mechanisms;
- it may be withdrawn subject to applicable law and any processing already necessary to complete, secure, or document the service.
8. Kiosk Privacy, Controlled Visibility, and Public-Facing Processing
Because some services may be delivered in a public or semi-public environment, YUNIQ takes measures designed to prevent exposure of sensitive information to bystanders, unauthorized customers, or third parties.
Depending on the service environment, we may implement:
- physical shielding of sensitive processing areas;
- restricted viewing angles;
- controlled workstation positioning;
- screen-protection measures;
- limits on what steps customers may directly observe;
- staff protocols designed to conceal sensitive information during handling;
- privacy signage, access restrictions, or barriers where appropriate.
9. Remote Orders, Courier Handling, and Logistics Security
Where YUNIQ offers remote or courier-based services, personal data may be processed for shipping, identity verification, fraud prevention, chain-of-custody management, and secure return delivery.
To protect customer data and physical card security, YUNIQ may implement:
- tamper-evident or sealed packaging requirements;
- documented receipt and dispatch records;
- identity verification at pickup or delivery where available;
- restricted handling by authorized personnel;
- internal logging of package condition and movement;
- courier coordination and incident documentation.
YUNIQ does not represent that courier-based processing is approved by any bank or regulator. Data collected in connection with courier-based services will be limited to what is necessary for secure operational handling, compliance, and legal protection.
10. Data Retention
YUNIQ retains personal data only for as long as reasonably necessary for the purposes described in this Policy, including:
- service fulfillment;
- operational security;
- accounting and regulatory compliance;
- fraud prevention;
- chargeback and dispute defense;
- legal defense and evidentiary preservation;
- enforcement of contractual rights.
Retention periods may vary depending on the category of data, the sensitivity of the data, the legal basis for processing, and whether the information is needed for compliance, fraud prevention, or dispute defense.
Sensitive payment-related data will not be retained longer than strictly necessary and lawfully permitted.
11. Data Security
YUNIQ applies technical and organizational safeguards appropriate to the sensitivity of the data processed.
Such measures may include:
- need-to-know access restrictions;
- role-based access control;
- secured service devices and workstations;
- internal handling protocols;
- controlled processing environments;
- encrypted storage or transmission where appropriate;
- secure deletion practices;
- device-level and environment-level security controls;
- restrictions on external storage and unauthorized exports;
- fraud monitoring and internal compliance procedures;
- incident response measures;
- periodic internal reviews and audits.
Employees are strictly prohibited from:
- photographing sensitive card details;
- recording sensitive payment information without authorization;
- copying or exporting data to external devices or unapproved systems;
- using customer information for personal, unauthorized, or unlawful purposes.
12. Data Sharing and Disclosure
We may share personal data only where necessary and lawful, including with:
- payment processors for transaction handling;
- shipping or courier providers for remote order fulfillment;
- IT, hosting, communications, or infrastructure providers acting on our behalf;
- legal, regulatory, judicial, or law-enforcement authorities where required or justified by law;
- insurers, professional advisers, auditors, or compliance advisers where reasonably necessary;
- rights holders or their representatives where necessary to investigate or verify submitted intellectual property rights;
- other parties where disclosure is necessary to establish, exercise, or defend legal claims.
We do not share sensitive payment-related information with third parties except where strictly necessary for lawful service operation, payment processing, fraud prevention, compliance, legal obligations, or dispute defense.
We do not sell personal data.
13. International Transfers
Where personal data is transferred outside the United Arab Emirates, including through cloud hosting, external email providers, or service infrastructure, YUNIQ will take steps designed to ensure that appropriate safeguards are in place in accordance with applicable law.
14. CCTV Monitoring and Security Recording
For security, fraud prevention, service integrity, and dispute resolution, our kiosk, service area, or other controlled environments may be monitored by CCTV or other security systems where lawful.
Recordings may be used for:
- operational security;
- fraud prevention;
- investigating incidents;
- dispute resolution;
- chargeback defense;
- legal compliance and evidentiary purposes.
Footage will be retained only for as long as reasonably necessary for the relevant purpose, unless a longer period is required for legal proceedings, fraud investigation, regulatory compliance, or evidentiary preservation.
15. Intellectual Property Verification Data
Where you submit logos, trademarks, insignia, or other potentially protected material, YUNIQ may process supporting evidence necessary to evaluate your right to use that material.
This may include:
- licenses;
- permissions;
- ownership confirmations;
- written rights-holder authorizations;
- correspondence about design legality or rejection.
16. Automated Tools, AI, DPIA, and Oversight
If YUNIQ uses modern technologies, automated tools, or AI-based systems in connection with design handling, service workflow support, or customer interaction, YUNIQ may conduct additional privacy and risk assessments where required by law or where YUNIQ considers such assessments prudent.
Where required by applicable law, risk level, or the nature of the processing, YUNIQ may:
- conduct a DPIA;
- appoint a Data Protection Officer or responsible privacy lead;
- enhance governance, monitoring, and review procedures.
17. Customer Rights
Subject to applicable law, you may have the right to:
- request access to personal data held about you;
- request correction of inaccurate or incomplete data;
- request deletion where legally permissible;
- object to or request restriction of certain processing;
- withdraw consent where processing is based on consent;
- request information about the categories or purposes of processing.
These rights are not absolute. YUNIQ may decline or limit a request where retention or continued processing is necessary for:
- legal obligations;
- fraud prevention;
- security;
- dispute defense;
- evidentiary preservation;
- contractual enforcement;
- other lawful grounds.
18. Marketing Communications
We may use your contact details for marketing only where:
- you have explicitly consented; or
- such communication is otherwise permitted under applicable law.
You may withdraw marketing consent at any time.
We will not use sensitive card-related information or back-side card details for marketing purposes.
19. Children’s Data
Our services are not directed to individuals under 18 years of age, and we do not knowingly collect personal data from minors in connection with our services.
20. Limitation Regarding Absolute Security
YUNIQ implements security measures designed to reduce risk, but no system, environment, transmission method, or storage arrangement can be guaranteed to be completely secure.
Nothing in this clause excludes liability where exclusion is prohibited by mandatory law.
21. Changes to this Policy
We may update this Policy from time to time to reflect changes in our services, technology, operational safeguards, legal requirements, or risk-management practices.
The latest version will be made available through our website or other appropriate customer-facing channels.
22. Contact
If you wish to exercise your privacy rights, make an inquiry, or submit a complaint regarding this Policy or our data-handling practices, you may contact us at the contact details provided in the relevant customer-facing materials.
17. CONTACT INFORMATION
YUNIQ CARDS MANAGEMENT SERVICES L.L.C.
Dubai, United Arab Emirates
Email: service@yuniq.ae