y yaalah
Flights Hotels Packages eSIM Manage Booking Terms Help
+234 700 000 9252 Sign In

Privacy policy draft

How Yaalah should protect customer data

This page is a production-readiness draft. It explains the intended privacy posture for the static preview and future backend launch, and must be reviewed by qualified legal counsel before Yaalah is launched publicly.

Legal review required before public launch Supabase RLS and audit posture documented Payment secrets stay server-side only
Policy status Draft for owner and legal review. Not yet a final public release policy.
Data boundary Customer-safe data handling is prepared, but live provider and payment operations still require final operational approval.
Customer channel Support, account, and payment flows should only use approved contact paths and secure systems after launch approval.

Data Yaalah May Collect

Yaalah may collect profile details, contact details, booking requests, passenger details, saved travellers, support tickets, price alerts, payment summaries, and admin workflow records.

Sensitive Travel Data

Passport details, passenger identity data, itinerary records, provider references, payment references, and support messages should be protected with role-based access, Supabase RLS, audit logs, and secure storage rules.

Payments

Yaalah should not store full card details. Payment credentials, webhook secrets, and gateway secret keys must stay server-side. Customer-facing payment information should show only safe summaries and references.

Flight Providers

When GDS, airline, aggregator, or manual fare providers are connected, customer data should only be shared where needed to search, price, book, service, or support a trip.

Customer Rights

Production Yaalah should provide a clear process for customers to request access, correction, export, or deletion of personal data where legally allowed and operationally possible.

Preview Boundary

The current hosted version is a static preview. Live account persistence, live payments, ticketing, provider search, and notification delivery are not active yet.

Support And Safety

Customers should never be asked to share full card details through support channels. Live support, payment, and provider workflows should use secure approved systems after production setup.