Bunkr privacy policy

Status · draft for legal review · pending UAE counsel sign-off Version · 0.1 · 2026-06-11 Framework · UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL)

This policy describes what personal data Bunkr collects, why, where it lives, who sees it, and what rights you hold over it. It is written for the companies and people who use the Bunkr platform · buyers, traders, their staff, and their drivers.

1 · Who we are

Bunkr operates a B2B fuel procurement marketplace for the UAE. Buyers post RFQs, verified traders quote, deals are awarded, deliveries are signed off, and payment confirmations are recorded on the platform. Money settles directly between buyer and trader · Bunkr does not hold or move funds.

For this policy, Bunkr is the data controller for platform account and operational data.

Contact · shadidf@gmail.com

2 · What we collect

We collect only what the marketplace needs to run. By category:

CategoryDataSource
AccountFull name · work email · mobile number · roleYou, at signup
CompanyLegal name · trade license number · license document · email domainYour company admin, at KYC
Trader profileProducts carried · coverage areas · banking details for settlement · company descriptionTrader admins
FleetTruck plates · driver names · driver mobile numbers · license referencesTrader admins
OperationalRFQs · quotes · deals · drop plans · delivery notes · invoices · payment confirmations · ratings · disputesGenerated by your use of the platform
Signature artifactsDriver phone number · hashed one-time code · document hash · server-keyed HMACGenerated at delivery sign-off
ComplianceSanctions and PEP screening results for your companyBunkr ops, at verification
NotificationsDelivery preferences · notification historyYou and the platform
UsageProduct analytics events · error reportsYour browser, with consent where required

We do not collect payment card data. We do not process payments.

3 · Why we process it

PDPL Article 4 requires consent unless an exception applies. We rely on:

  • Contract performance · running your account, matching RFQs to traders, forming deals, recording deliveries and payment confirmations.
  • Legal obligation · company verification, sanctions screening, retention of commercial records.
  • Legitimate platform operation · fraud prevention, dispute resolution, service-level measurement, security logging.
  • Consent · product analytics and any processing not covered above. You can withdraw consent without affecting the rest of the service.

4 · Who sees your data

  • Your counterparties · when you trade, the other side of the deal sees what the deal needs · company name, RFQ and quote terms, delivery records, dispute filings. Traders see buyer bank-facing invoice details only where the deal requires it.
  • Bunkr ops · KYC review, sanctions screening, dispute adjudication, support.
  • Sub-processors · listed below. Each is bound by contract to process only on our instructions.

We do not sell personal data. We do not share it with advertisers.

Sub-processors

ProviderFunctionRegion
Supabase (AWS)Database · authentication · file storageap-south-1 · Mumbai, India
VercelApplication hostingGlobal edge · compute co-located with users
SentryError trackingEU/US
PostHogProduct analyticsUS · United States
ResendTransactional emailUS/EU
UnifonicDelivery-code SMS (when activated)UAE/KSA
ComplyAdvantageSanctions screening (when activated)EU/UK

5 · Where your data lives · cross-border transfer

During the closed beta, the primary database, authentication records, and uploaded documents are hosted on Supabase infrastructure in AWS ap-south-1 (Mumbai, India). Product analytics events and error reports are processed in the United States (PostHog · Sentry) · page addresses are stripped of query parameters before they leave your browser, and analytics identifiers are opaque account ids, not names or email addresses. These are transfers of personal data outside the UAE under PDPL Articles 22 and 23. We rely on contractual safeguards with our sub-processors and on your informed notice through this policy.

A migration path to in-region hosting (AWS Bahrain me-south-1, with an in-UAE alternative) is documented and maintained as a runbook in the platform repository. The schema is portable by design. No migration date is committed · execution is triggered by customer residency requirements, regulatory findings, or the availability of managed in-region hosting. This policy will be updated before any such move.

6 · How long we keep it

The full retention posture is documented in docs/ops/data-retention.md. The short version:

  • Commercial records · deals, delivery notes, signature artifacts, invoices, and payment confirmations are retained for 5 years after deal closure, in line with UAE commercial record-keeping obligations.
  • Audit artifacts · delivery signature events and sanctions screening records are append-only by database design. They cannot be edited or deleted, by anyone, including us. This is what makes a signed delivery note worth something.
  • Account data · retained while your account is active. On a deletion request, personal account data enters a 30-day retention countdown, after which it is archived and minimised. See section 7.
  • Deletion is soft-delete · records are archived and excluded from active use, never physically destroyed where they anchor a commercial or audit trail.

7 · Your rights

Under PDPL Articles 13 to 18 you can:

  • Access and portability · download a machine-readable export of your account and company data at any time from /settings/data-export. The export is JSON, scoped to exactly what your account is permitted to see.
  • Rectification · correct your account and company details in settings, or ask us.
  • Deletion · request deletion of your account. Personal data not anchored to a commercial or audit record is archived after a 30-day countdown. Data inside signed delivery notes, signature artifacts, and screening records is retained per section 6 · we will tell you exactly what is retained and why.
  • Restriction and objection · ask us to stop a specific processing activity. Where the activity is consent-based, withdrawal stops it.
  • No automated decisions · company verification and dispute outcomes are decided by people. Sanctions screening produces a record for human review · it does not auto-reject.

Send requests to shadidf@gmail.com. We confirm receipt and respond within the periods the PDPL prescribes.

8 · Security

  • Every database table is protected by row-level security. Your account reads only what its role and company membership permit.
  • Delivery sign-off codes are stored as hashes, never in clear text. Each signed delivery note carries a SHA-256 document hash and a server-keyed HMAC.
  • All traffic is TLS. Service credentials are never exposed to the browser.
  • Access to production data is limited to Bunkr ops accounts with audited admin roles.

9 · Breach notification

If a personal data breach creates risk to your privacy or rights, we notify the UAE Data Office and affected users as PDPL Article 9 requires, with the facts, the likely consequences, and the measures taken.

10 · Changes

We will post material changes here and notify active accounts in-app before they take effect. Continued use after the effective date is acceptance.


This document is a working draft prepared for legal review. It does not constitute legal advice and has not yet been reviewed by UAE counsel.