Privacy policy draft
How Yaalah should protect customer data
This page is a production-readiness draft. It explains the intended privacy posture for the static preview and future backend launch, and must be reviewed by qualified legal counsel before Yaalah is launched publicly.
Data Yaalah May Collect
Yaalah may collect profile details, contact details, booking requests, passenger details, saved travellers, support tickets, price alerts, payment summaries, and admin workflow records.
Sensitive Travel Data
Passport details, passenger identity data, itinerary records, provider references, payment references, and support messages should be protected with role-based access, Supabase RLS, audit logs, and secure storage rules.
Payments
Yaalah should not store full card details. Payment credentials, webhook secrets, and gateway secret keys must stay server-side. Customer-facing payment information should show only safe summaries and references.
Flight Providers
When GDS, airline, aggregator, or manual fare providers are connected, customer data should only be shared where needed to search, price, book, service, or support a trip.
Customer Rights
Production Yaalah should provide a clear process for customers to request access, correction, export, or deletion of personal data where legally allowed and operationally possible.
Preview Boundary
The current hosted version is a static preview. Live account persistence, live payments, ticketing, provider search, and notification delivery are not active yet.
Support And Safety
Customers should never be asked to share full card details through support channels. Live support, payment, and provider workflows should use secure approved systems after production setup.