Legal

Privacy Policy

This policy explains what personal information Burmese.ae collects, why we collect it, who we share it with, and the choices you have. We have written it in plain English on purpose.

Last updated: 22 July 2026

1. Who we are

Burmese.ae is an online platform for the Myanmar community in the United Arab Emirates. Through the site you can buy event tickets, book tours, order merchandise, book pre-wedding photography packages, browse a business directory, and read community blog posts. All prices on the platform are in UAE Dirhams (AED).

When this policy says “we”, “us”, or “Burmese.ae”, it means the operators of this platform. We are based in the UAE and follow the UAE Personal Data Protection Law (PDPL). Because parts of our community live in or travel from other countries, we also keep the principles of the EU GDPR in mind.

2. What information we collect

We only collect information you give us while using a specific service. Here is what each part of the platform collects:

Creating an account

If you sign up with an email and password, we store your name, email address, and a securely hashed version of your password (we never store the password itself). If you sign in with Google, Facebook, or Apple, that provider shares your name, email address, and profile picture with us. You can also add a phone number and a default delivery address to your profile so checkout forms are pre-filled for you.

Buying event tickets

At ticket checkout we collect your name, email address, and phone number, plus an optional address, your ticket selections, and — for tour-style events — your chosen travel date. Your tickets include a unique QR code, and when staff scan it at the venue we keep a check-in log (which ticket, which staff member scanned it, when, and the result) so entry can be verified and disputes resolved.

Please note about guest checkout: if you buy tickets without logging in, we automatically create an account record linked to your email address. This is how we keep your order and tickets retrievable for you later. No password is set on this record until you choose to set one.

Shop orders

For merchandise orders we collect your name and email (required), phone number, shipping address, the items you ordered, and any coupon code you use. Guest checkout is allowed for the shop. If you are logged in, we also save the phone number and shipping address to your profile as your defaults for next time.

Pre-wedding bookings

Pre-wedding photography bookings collect the bride’s and groom’s names, email, phone, WhatsApp number, preferred and alternative dates, shoot location and venue type, the package you chose, and any special requests you write. You do not need an account to make a booking.

Contact form

When you contact us we store your name, email, optional phone number, subject, and message so our team can respond.

Reviews

When you submit a review we collect your name, an optional email address, your rating, and your review text. Reviews are held privately until an admin approves them. Once approved, your name and review are displayed publicly on the site; your email is never shown.

Payment card details

Your card details never touch our servers. They are collected directly by Stripe, our payment processor, in your browser. We only store Stripe’s payment reference IDs and the amounts paid.

3. How we use your information

We use your data to:

  • Process your orders, tickets, and bookings, and take payment for them.
  • Generate your tickets, QR codes, and invoices, and verify tickets at event entry.
  • Pass booking details to the tour operator when you book a vendor-supplied tour (see section 5).
  • Ship merchandise orders to your address.
  • Manage your account, including sending a password-reset email when you request one.
  • Respond to messages you send through the contact form.
  • Moderate and publish reviews you submit.
  • Temporarily hold tickets in your cart for about 10 minutes during checkout so they are not sold to someone else while you pay.
  • Keep records we need for accounting, tax, and dispute resolution.

We do not send marketing emails, and we do not use your data for advertising, profiling, or analytics tracking.

5. Who we share your data with

We never sell your personal data. We share it only with the service providers below, and only what each one needs:

  • Stripe — processes all payments (tickets, shop orders, and pre-wedding deposits) in AED. Your card details go directly to Stripe. We attach your order reference, name, and email to the payment — and for shop orders, your phone number and shipping address — so payments can be matched to orders.
  • TravelDesk (tour operator) — when you book a vendor-supplied tour, we send them the guest name, phone, email, travel date, number of adults, children, and infants, and a booking reference so they can confirm your place. TravelDesk also issues the tour tickets, vouchers, and invoices you download.
  • Email provider — we use an email (SMTP) service to send password-reset emails, which involves processing your email address.
  • Google, Facebook, and Apple — if you sign in with one of these, that provider shares your name, email, and profile picture with us as part of the sign-in.
  • Neon — our managed database host, where the records described in this policy are stored.
  • Vercel — our application hosting provider. Server logs generated while processing your requests may include order details.
  • Redis (cache) — a short-lived cache used to hold tickets for about 10 minutes during checkout, keyed to your account or session.

We do not use any analytics services, advertising networks, or tracking pixels.

6. Cookies

We only use essential cookies — the ones the site cannot work without:

  • A session cookie that keeps you signed in to your account.
  • A security (CSRF) cookie and a sign-in redirect cookie that protect the login process.

We do not set any analytics or advertising cookies. On checkout pages, Stripe’s payment component may set its own cookies or identifiers for fraud prevention — this is part of processing your payment securely.

7. How long we keep your data

We keep order, ticket, booking, and payment records for as long as we need them for legal, accounting, and tax purposes, and to handle any disputes or refund requests. Account details are kept for as long as your account exists.

Some data is naturally short-lived: password-reset links expire after one hour, and checkout ticket holds expire after about 10 minutes.

If you would like data about you removed, contact us using the details in section 13 and we will delete what we are not legally required to keep.

8. Your rights and choices

Under the UAE PDPL (and the GDPR, if it applies to you), you have the right to:

  • Access — ask for a copy of the personal data we hold about you.
  • Correction — ask us to fix inaccurate details. You can also update your name, phone, and default address yourself in your account settings.
  • Deletion — ask us to delete your account and personal data. We will delete everything except records we must keep by law (for example, completed order records needed for accounting).
  • Data portability — ask for your data in a commonly used format.
  • Objection — object to a particular use of your data, or withdraw consent you gave earlier.
  • Review removal — ask us to take down a review you submitted.

To exercise any of these rights, email us at contact@burmese.ae from the email address linked to your account or order. Account deletion and data export are handled by our support team on request — there is currently no self-serve button for them in the app. We may ask you to confirm your identity before acting on a request.

9. Children

Burmese.ae is not directed at children, and you must be old enough to enter into a purchase (or have a parent or guardian do it for you) to use our checkout. We do not knowingly collect personal data from children. Tour bookings may include the number of children or infants travelling, but this is a headcount provided by the adult making the booking. If you believe a child has given us personal data, contact us and we will delete it.

10. How we protect your data

  • All traffic between your browser and our servers is encrypted (HTTPS).
  • Passwords are stored only as strong one-way hashes — we cannot see them.
  • Card details are handled entirely by Stripe and never reach our servers.
  • Admin tools are restricted to authorized staff accounts with specific roles, and ticket scanning is logged.
  • Reviews and business listings are held for moderation before anything appears publicly.

No online service can promise perfect security, but we work to keep your data safe and to fix issues quickly if they arise.

11. Where your data is stored

Our application runs on Vercel and our database is hosted by Neon. These are international cloud providers, so your data may be stored or processed on servers outside the UAE. We choose established providers with strong security practices, and we only share the data described in this policy.

12. Changes to this policy

We may update this policy as the platform grows or the law changes. When we do, we will update the “Last updated” date at the top of this page. If a change significantly affects how we use your data, we will make that clear on the site.

13. Contact us

For any privacy question or request:

We aim to respond to privacy requests within a reasonable time, and to general enquiries within 24 hours.