Version 2026-07-18-v1
Privacy Policy
This policy explains how Bubble It Cars Washing LLC collects, uses, protects, retains, and deletes personal data when you use BubbleIt.
Effective date: 2026-07-18
1. Who controls your data
Bubble It Cars Washing LLC, Commercial Registration 182268, at Building No. 24, Zone 60, Street 950, Qatar, is responsible for the personal data described in this policy. Contact privacy@bubbleit.qa for privacy requests or questions.
2. Data we collect
We collect only information needed to operate, secure, and support BubbleIt and to meet legal and financial obligations.
- Identity and account data: name, Qatar mobile number, email if supplied, preferred language, OTP records, and session records.
- Service data: saved addresses, map coordinates, building/zone/street details, vehicles, bookings, selected services, add-ons, notes, cancellations, rescheduling, and service history.
- Commerce data: memberships and usage, store orders, prices, payment attempts, transaction references, refunds, currency, and reconciliation records. BubbleIt does not intentionally store full payment-card credentials.
- Communication data: notification preferences, device notification tokens, delivery results, reviews, and support communications.
- Security data: IP address, request identifiers, access history, device/session details, and fraud or security events.
3. Why we use data
We process data to authenticate customers; calculate availability, duration and price; create and fulfil bookings and orders; administer memberships; allocate operational resources; process and reconcile payments and refunds; send transactional messages; provide support; prevent misuse; comply with law; and improve services using aggregated or irreversibly anonymous information.
4. Location information
A precise service location is required to validate that an address is on Qatar land territory, calculate availability, and allow the service team to reach the vehicle. You may enter coordinates and address details manually instead of granting browser location permission.
6. Notifications and marketing
We may send necessary booking, payment, cancellation, refund, order, membership, and service reminders. Browser or app push is optional. Critical transactional messages may use an approved WhatsApp or SMS channel. Marketing requires separate consent and can be disabled without disabling required transactional messages.
7. How long we retain data
Retention is limited by data type and purpose. A legal hold or active dispute may extend the relevant period until final resolution.
- Sessions and device tokens: revoked immediately when the account is deleted.
- OTP and notification-delivery logs: 90 days.
- Security and access logs: 12 months.
- Support records: 2 years after closure.
- Bookings and service history: 5 years and pseudonymized after account deletion.
- Payments, refunds, invoices, orders, and membership ledgers: 10 years and pseudonymized after account deletion.
- Irreversibly anonymous statistics: may be retained indefinitely.
8. Your privacy rights
Subject to applicable Qatar law, you may request access, a portable copy, correction, deletion, objection, or withdrawal of optional consent, and may ask how your data is processed and disclosed. Withdrawal does not invalidate processing already lawfully completed and does not remove records that must be retained for legal, financial, security, fraud-prevention, or dispute purposes.
9. Data export and account deletion
An authenticated customer may create a portable JSON export. Its download credential expires after 15 minutes and works once. Account deletion requires a fresh OTP and explicit irreversible confirmation. We immediately revoke sessions and notification devices, disable the account, and erase or irreversibly anonymize non-retained profile, address, vehicle, preference, notification, review, and location information. Pseudonymous records retained under section 7 remain unavailable for account use.
10. Processing locations
Some approved technology providers may process data outside Qatar. BubbleIt will use appropriate contractual, organizational, and technical safeguards and will limit transfers to what is necessary for the stated service.
11. Security
We use access controls, encryption in transit, restricted credentials, bounded sessions, audit records, monitoring, and data minimization. No internet service can guarantee absolute security; report suspected misuse promptly to privacy@bubbleit.qa.
12. Age requirement
BubbleIt is intended for customers aged 18 or older. A person under 18 may use the service only with permission and supervision from a parent or legal guardian.
13. Changes and contact
Material changes are versioned and communicated before they apply when required. This English and Arabic policy is one policy version with the same legal meaning; neither language is maintained as an independent policy. Contact privacy@bubbleit.qa or write to the registered address above.
