wallat.
Product Wallat QR Features Pricing Enterprise
Sales professionals Freelancers Founders Real estate Job seekers Corporate professionals
Sign in Get started free
Product Wallat QR Features Pricing Enterprise

For you

Sales professionals Freelancers Founders Real estate Job seekers Corporate professionals Get started free

Privacy Policy

Last updated: June 16, 2026

Plain-English summary. We're Wallat. We collect what we need to run our products, we don't sell your data, and we give you straightforward ways to see, export, or delete what we hold. Everything below explains exactly what, why, for how long, and with whom — written to satisfy the GDPR, UK GDPR, the UAE PDPL, the CCPA/CPRA, and similar laws.

On this page

  1. Who we are
  2. What this policy covers
  3. Information we collect
  4. Why we process it (lawful bases)
  5. Cookies & consent
  6. Who we share with
  7. International transfers
  8. How long we keep data
  9. Your rights
  10. Children
  11. Security
  12. Visitors to a Wallat profile
  13. California & UAE residents
  14. Changes to this policy
  15. Contact

1. Who we are

This policy is published by Wallat Networking Intelligence FZCO ("Wallat", "we", "our", "us"), a free zone company registered at Premise No. DSO-IFZA, IFZA Properties, Dubai Silicon Oasis, Dubai, United Arab Emirates. Wallat is the data controller for the personal data described in this policy.

Privacy questions, requests, and complaints should be sent to [email protected]. We respond within 30 days — the GDPR statutory deadline.

EU residents: Wallat is not established in the EU but offers services to people in the EU. We are in the process of appointing an EU representative under Article 27 GDPR and a separate UK representative under Article 27 UK GDPR. Contact details for both will appear in section 15 once confirmed.

2. What this policy covers

This policy applies to:

  • Our marketing website at wallat.id;
  • The Wallat application at app.wallat.id;
  • Public Wallat profile pages at wallat.id/p/<name> and custom domains pointed at our service;
  • Our wallet passes for Apple Wallet, Google Wallet, and Samsung Wallet.

Three roles to be clear about:

  • If you sign up for Wallat (an "owner"): we are the controller of your account data.
  • If you visit a Wallat profile (a "visitor"): the profile owner is the controller of the contact, lead-form, and engagement data they collect from you; Wallat is the processor that operates the infrastructure on their behalf. We are also the controller for limited operational data (security logs, abuse prevention).
  • If you browse our marketing site: we are the controller of any analytics data we collect — and we only collect it after you give consent (see section 5).

3. Information we collect

From account owners

  • Sign-up details: name, email, password (stored hashed, never in plain text), and the profile data you choose to publish — job title, company, photo, contact links, social handles, calendar URLs, attachments such as brochures or CVs.
  • Wallet pass data: the fields you place on your wallet pass (name, role, contact info, the QR code).
  • Billing data: handled by Stripe. We receive only a limited record (plan, last four digits of card, billing country, invoice history). We never see your full card number.
  • Account activity: sign-in events, IP address at sign-in, device and browser strings, and settings you change.
  • Support communications: emails you send to [email protected] or [email protected].

From visitors to a Wallat profile

  • Scan and view events: when, from which country (derived locally from your IP — your IP is not transmitted to a geolocation vendor and is not stored after location derivation), referrer URL, device type.
  • On-page interactions: clicks, scroll depth, time on page — used to build the engagement score and heatmap the profile owner sees.
  • Session replay: an anonymised, masked replay of the visit. Text inputs and PII fields are masked by default. Disabled on profiles whose owner has turned it off.
  • Lead-capture form submissions: the information you voluntarily enter (typically name, email, optional message). This data flows to the profile owner.
  • Push subscriptions: if you opt in, your browser issues an opaque endpoint (Apple Push, Firebase Cloud Messaging, or Mozilla Autopush) that we send notifications to. We do not see your device identity beyond that endpoint.

Cookies and similar storage

We use a small number of cookies and localStorage entries. The full register, including which are essential and which are optional, is on our Cookies policy. Optional cookies (analytics) are loaded only after you give consent.

What we do not collect

  • We don't buy or rent personal data from data brokers.
  • We don't run ad-targeting cookies, retargeting pixels, or social-media tracking pixels.
  • We don't perform automated decisions with legal effects. The engagement score is a guide for the profile owner — not a credit, immigration, or employment decision.

4. Why we process this data (lawful bases under GDPR Art. 6)

PurposeDataLawful basis
Provide the Service (create your account, render your wallet pass, host your profile, generate your QR code). Sign-up details, profile content, wallet pass data. Contract performance — Art. 6(1)(b).
Bill paid plans. Billing data exchanged with Stripe; plan metadata we retain. Contract performance — Art. 6(1)(b); legal obligation for retention (tax) — Art. 6(1)(c).
Send transactional email (sign-in, password reset, invoice, scan alerts to owners). Account email; event metadata. Contract performance — Art. 6(1)(b).
Secure the service, detect abuse, prevent fraud. IP, device strings, request metadata, audit logs. Legitimate interest — Art. 6(1)(f).
Provide visitor analytics to profile owners (heatmaps, replay, engagement score, CRM timeline). Scan/view events, on-page interactions, masked session replay. Legitimate interest of the owner (their visitor analytics) — Art. 6(1)(f); processed by Wallat on their behalf.
Measure marketing site traffic. Page views, referrer, device class. Consent — Art. 6(1)(a). Off by default; opt-in via banner.
Communicate with you about your account or product changes. Account email. Contract performance — Art. 6(1)(b); legitimate interest for service notices — Art. 6(1)(f).
Comply with law (tax, regulatory, court order). As required. Legal obligation — Art. 6(1)(c).

5. Cookies, analytics, and consent

Our marketing site uses Google Analytics 4 with Google Consent Mode v2: analytics is denied by default and only activates if you click "Accept all" or "Customize → Analytics" in our cookie banner. We do not run ad cookies on the marketing site. IP addresses sent to Google Analytics are anonymised.

You can change your choice any time by clicking "Cookie preferences" in our footer.

The Wallat application (app.wallat.id) and profile pages use only first-party functional storage (session, language preference) — no analytics SDK and no marketing tags.

6. Who we share data with

Wallat is built on third-party infrastructure. Each vendor below is a processor — they handle limited data on our instructions, under a data processing agreement, and they don't use your data for their own purposes. The current list, with location and what each vendor sees, lives at wallat.id/sub-processors. Material changes are notified to paid customers in advance.

Business and Enterprise customers whose visitors include EU or UK data subjects may request our standard Data Processing Agreement (DPA) by emailing [email protected].

Outside our sub-processor list, we share data only in the limited cases below:

  • With the profile owner: visitor data on a profile is shared with that profile's owner — that is the whole product.
  • With your CRM, when you connect it: if you connect HubSpot (or another integration as we add them), we send lead and engagement events into your CRM.
  • To meet legal obligations: when we are legally required to (a binding court order, subpoena, lawful regulatory request). We will challenge overly broad requests where we can.
  • In a corporate transaction: if Wallat is acquired or merges, your data may transfer to the new entity; we'll notify you, and the new entity will be bound by this policy.

We do not sell personal data. We have not done so in the last 12 months and do not intend to.

7. International data transfers

Wallat is registered in the UAE. Some of our sub-processors are in the EU/EEA (Neon eu-central, Sentry Frankfurt, Tinybird EU/UK), and some are in the United States (Stripe, Resend, Google Cloud regions). Where data leaves the EEA or UK, we rely on:

  • The European Commission's Standard Contractual Clauses (2021/914), or the UK International Data Transfer Addendum, where applicable;
  • The EU-US Data Privacy Framework certification of the receiving vendor, where they hold one;
  • Vendor technical safeguards (encryption in transit, encryption at rest).

The transfer mechanism per vendor is in the sub-processors table.

8. How long we keep your data

DataRetention
Account data (name, email, profile content)Until you delete the account. Then permanently deleted within 30 days, except where law requires retention.
Billing records (invoices, plan history)Held by Stripe per its policy. We retain summary records as required by UAE tax/accounting law (approximately 5 years).
CRM timeline & engagement eventsRetained for the life of the account. Owners can delete individual entries from the app at any time.
Lead-capture form submissionsRetained until the profile owner deletes them or their account is deleted, whichever is sooner.
Heatmaps & session replaysApproximately 180 days on a rolling basis, then auto-expired.
Server logs (operational)Up to 30 days.
Support ticketsUp to 24 months from your last interaction with us.
Push subscription endpointsUntil you unsubscribe or the browser revokes the endpoint.
Consent records (your cookie choices)12 months.

9. Your rights

If GDPR or UK GDPR applies to you, you have the following rights, free of charge:

  • Right of access (Art. 15) — ask what we hold about you and get a copy.
  • Right to rectification (Art. 16) — ask us to correct inaccurate data.
  • Right to erasure / "to be forgotten" (Art. 17) — ask us to delete your data. We honour this within 30 days, subject to legal retention obligations (e.g. tax law).
  • Right to restrict processing (Art. 18) — ask us to pause processing.
  • Right to data portability (Art. 20) — get a machine-readable copy of data you provided.
  • Right to object (Art. 21) — object to processing based on legitimate interests, including any direct marketing.
  • Right to withdraw consent — where we rely on consent, you can withdraw it any time. Withdrawal doesn't affect processing carried out before withdrawal.
  • Right to lodge a complaint with the data protection authority in your country of residence.

To exercise any right, email [email protected] from the email address on your Wallat account. Account owners can also self-serve from Settings → Privacy in the Wallat app:

  • Data export — one-click JSON download of your full account.
  • Account deletion — permanently delete within 30 days.

10. Children

Wallat is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, email [email protected] and we will delete it.

11. Security

  • HTTPS / TLS 1.2+ on every endpoint; HSTS preload.
  • Encryption at rest for databases and object storage.
  • Passwords hashed with bcrypt; we never store plaintext credentials.
  • Principle of least privilege for staff access; audit logging on production systems.
  • Annual review of access, vendors, and infrastructure.

12. If you are a visitor to a Wallat profile

If you are visiting someone's Wallat profile (e.g. wallat.id/p/jane), the person who set up that profile (the owner) is the controller of the data collected about your visit. Wallat operates the platform on their behalf. To request access, correction, or deletion of data from a specific profile owner, contact that owner directly. If you cannot reach them or they don't respond, email us at [email protected] and we will help mediate.

13. California & UAE residents

California (CCPA / CPRA): you have substantively equivalent rights — to know, to delete, to correct, to opt out of "sale" or "sharing" (we do neither), and to non-discrimination for exercising your rights. Same channel: [email protected].

UAE residents (PDPL — Federal Decree-Law No. 45 of 2021): the same rights apply, exercisable through the same channel.

14. Changes to this policy

We will update this policy when our practices change. For material changes, we'll give at least 30 days' advance notice by email to account owners and via a banner on the marketing site. Previous versions are available on request via [email protected].

15. Contact

Wallat Networking Intelligence FZCO
Premise No. DSO-IFZA, IFZA Properties
Dubai Silicon Oasis
Dubai, United Arab Emirates

Privacy: [email protected]
General: [email protected]

EU representative (Article 27 GDPR): to be confirmed — full name, address, and contact email will be added here once the appointment is finalised.

UK representative (Article 27 UK GDPR): to be confirmed — full name, address, and contact email will be added here once the appointment is finalised.

See also: Privacy · Cookies · Sub-processors · Terms

© 2026 | Wallat Networking Intelligence Back to homepage