Last Updated: 02 June 2025

1. Introduction

Welcome to our Privacy Policy. Aftal Group FZC, a limited liability company operating under the laws of Sharjah, United Arab Emirates (UAE) with trade license number 4413163, and its affiliates (referred to as “us,” “we,” or “our”) are dedicated to safeguarding the personal data of our users. This policy outlines how we collect, use, and protect your information when you interact with www.samaalfan.com, our affiliated websites, and associated mobile applications (collectively, the “Platforms”), or utilize any of our services, including newsletters and social media features (collectively, the “Services”).  

We recognize the significance of your personal data and are committed to upholding your privacy. Please review this Privacy Policy thoroughly to understand our data handling practices. Your use of the Platforms and Services signifies your consent to the collection and processing of your personal data as described herein. “Personal Data,” for the purpose of this policy, refers to the categories of information detailed in Clause 2. The terms “user,” “you,” or “your” pertain to you as an individual or legal entity.  

Our Platforms may contain links to third-party websites, plugins, and applications. Activating these links may permit third parties to gather or share your data. We do not have authority over these external sites and are not accountable for their privacy policies. We advise you to read the privacy statements of any website you visit after leaving our Platforms.  

2. Children’s Data

Our Platforms are not designed for individuals who have not reached the age of majority according to the relevant laws governing them. While we endeavor to prevent underage access, it’s not always possible to stop users, including children, from misrepresenting their age to use the Platforms. If you are a parent or guardian and suspect that we have inadvertently collected data from your child, please contact us immediately using the details in Clause 12.  

3. Personal Data We Collect

To provide and enhance our Platforms and Services, we gather your Personal Data. Personal Data is any information that can identify you as an individual. This excludes anonymized data, where personal identifiers have been removed.  

We collect, use, store, and transfer the following categories of your Personal Data:  

We also gather, utilize, and share Aggregated Data, which is statistical or demographic information. While derived from your Personal Data, Aggregated Data is anonymized and does not directly or indirectly reveal your identity. For instance, we might aggregate browser data to understand the percentage of users utilizing a specific website feature.  

4. How We Collect Your Personal Data

We employ various methods to collect your Personal Data:

Choosing not to provide certain Personal Data may limit your ability to fully utilize many of our Services.  

Directly from You: We obtain your Personal Data when you:

Register on our Platforms or through co-registration methods (like social media logins), subscribe to our Services, or post material on the Platforms.  

Process payments, request refunds, or provide payment method details.  

Engage in contests, promotional offers, or opt into special schemes.  

Provide reviews, testimonials, or feedback.  

Contact us for support, such as raising a complaint ticket for refunds, fraudulent transactions, or replacements.  

Communicate with us via phone, email, or other channels (we may keep a record of such correspondence).  

Browse and engage in other activities on our Platforms.  

Indirectly: We may receive your Personal Data from your acquaintances making purchases for you, or from our vendors and third-party service providers who facilitate our Services. These vendors include:

Logistics and fulfillment service providers and partners.  

Marketing service providers.  

Platforms like Facebook and Google, based on your interactions with us on those platforms.  

Payment service providers.  

If you share a third party’s Personal Data (e.g., friends, relatives, colleagues) with us while using our Services, you confirm that you have obtained their consent to share their information with us under this Privacy Policy.  

Automatically: Certain Personal Data is collected automatically as you use our Services, through log files, cookies, and other unique identifiers.

Log Files: We use log files to gather specific Personal Data. This log information includes details about your Service usage, such as IP address, browser type, referring/exit pages, operating system, date/time stamps, and related data, all stored in log files.  

Cookies: We utilize a limited number of cookies. A cookie is a small data file sent to your device when you access our Services. Cookies serve various functions, including enabling Service features, remembering your preferences, equipment, Browse actions, and patterns. They help us understand your interaction with our Services, deliver targeted advertising, and monitor visitor usage and online traffic. You can typically instruct your browser, by adjusting its settings, to stop accepting cookies or to alert you before accepting a cookie from online services, to the extent your browser permits. We use cookies to enhance your experience by remembering your online behavior on our Platforms and to improve the effectiveness of our ads and Services. If you do not agree to our use of cookies, please discontinue using the Platforms immediately.  

5. Purposes for Collecting Your Personal Data

We collect and use your Personal Data for the following reasons:  

To prevent and detect fraud and abuse, thereby protecting the security of our customers, ourselves, and others.  

To furnish you with information, products, or Services you request or that we believe may interest you (where you have consented to such contact).  

To offer location-based services, such as targeted advertising, search results, and other personalized content.  

To fulfill our obligations arising from any contracts between you and another entity using the Platforms, or between you and us.  

To enhance our Services and provide a more tailored experience, including communicating with you about Services through various channels (e.g., phone, messages, email, instant messaging).  

To ensure Platform content is presented most effectively for you and your device.  

To inform you about modifications to our Services.  

For any other purposes we deem necessary to improve your Platform experience.  

To manage our incentive programs, fulfill your requests for incentives, and enable your participation in sweepstakes, including notifying you if you win.  

To provide functionality, analyze performance, resolve errors, and enhance the usability and effectiveness of our Services.  

To adhere to local laws (e.g., using your nationality and/or identification for cross-border shipments, or seller information like place of establishment and bank account details for identity verification).  

6. How We Utilize Your Personal Data

We will use your Personal Data only under the following circumstances:

Marketing and Communications Data: We may use your Personal Data to provide you with information about goods and services that might interest you and to enhance your Platform experience through service messages, new features, special offers, and events. We may contact you through various channels, including emails, push notifications, web notifications, post, telephone, in-app messages, WhatsApp messages, and news feed cards. We provide you the option to receive these interest-based ads. You can opt out by contacting us or by clicking the “UNSUBSCRIBE” link in marketing communications.  

Performance of a Contract: We need your Personal Data to fulfill a contract with you or to take steps before entering into one. This includes your acceptance of applicable terms and conditions or specific terms related to our Services. If you don’t provide Personal Data for these purposes, we might not be able to deliver our Services or enter into a contract with you, potentially leading to service cancellation. We will notify you if this situation arises.  

Legal or Regulatory Obligation: We may collect your Personal Data to comply with applicable laws and/or regulations.  

Legitimate Interests: We may process your Personal Data based on our legitimate business interests and those of our customers. This includes improving our Services, detecting and preventing fraud and abuse to protect our customers, ourselves, or others, and providing you with interest-based advertising.  

7. Sharing Your Personal Data

Your Personal Data is vital for us to provide our Services, and we do not sell it to others. We share your Personal Data only with the third parties outlined below and with businesses that adhere to practices at least as protective as those in this Privacy Policy:  

8. Data Storage and Retention

The Personal Data we collect from you may be transferred to, stored, and processed by staff working for us or one of our service providers. This staff might be involved in activities such as fulfilling your order, processing your payment details, and providing support services.  

We will retain your Personal Data for as long as required to fulfill the purposes stated in this Privacy Policy or as otherwise mandated by law. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the Personal Data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process it, whether we can achieve those purposes through other means, and applicable legal, regulatory, tax, accounting, or other requirements.  

In some instances, we will anonymize your Personal Data (so it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.  

9. Security Measures

We design our systems with your security and privacy as priorities. We implement commercially reasonable technical, administrative, and physical safeguards to ensure your Personal Data is handled securely, in line with this Privacy Policy and applicable laws, and to protect against unauthorized access, alteration, disclosure, or destruction. For example, we might use encryption technology to secure your Personal Data during transmission to the Platforms, along with external and on-host firewalls to prevent network-level attacks. Access to this Personal Data is restricted to authorized employees, contractors, and agents who require it to perform their services. We adhere to the Payment Card Industry Data Security Standard (PCI DSS) when managing credit card data.  

It is crucial for you to protect yourself against unauthorized access to your password and the devices you use to access our Services. You are responsible for keeping your password confidential (e.g., ensure you log out after using a shared device). While we strive to protect your Personal Data, the transmission of information via the internet is unfortunately not completely secure.  

10. Your Data Subject Rights

Under specific circumstances, you possess the following data subject rights:

11. Changes to Our Privacy Policy

As our business constantly evolves, our Privacy Policy may also need to change. We will inform you of any such changes by posting the updated version on the Platforms. Each change will become effective upon posting or on the “effective date” designated by us. We may send periodic email reminders of our notices and conditions, but you should check the Platforms frequently for recent changes. It is your responsibility to regularly review the Privacy Policy. Your continued use of the Platforms after any such change signifies your agreement to the modified Privacy Policy.  

12. Contact Us

If you have any concerns about your Personal Data on the Platforms, please contact us by sending an email to support@samaalfan.com with a detailed description of your query or request, or call us at +971 50 116 5055.