Privacy Policy
This Privacy Policy has been updated to reflect compliance with UAE Federal Decree Law No. 45 of 2021 (Personal Data Protection Law) and, where applicable, the EU General Data Protection Regulation (GDPR).
1. Introduction
Bamboo Electronic Cards Trading LLC, operating as Bamboo Card ("Bamboo Card", "we", "our", or "us"), is a digital gift card infrastructure and rewards distribution platform headquartered in Dubai, United Arab Emirates. We are committed to protecting the personal data of all individuals who interact with our website, platform, portal, API, and related services (collectively, the "Services").
This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and what rights you have over it. It applies to all users of our Services including business clients, API partners, individual portal users, and visitors to www.bamboo-card.com.
By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this Policy, you should discontinue use of our Services immediately.
2. Legal Framework and Governing Law
Our processing of personal data is governed by the following legal frameworks:
UAE Personal Data Protection Law (PDPL) — Federal Decree Law No. 45 of 2021, as amended. This applies to all personal data processed in connection with our operations within the UAE.
EU General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679. This applies to the extent that we process personal data of individuals located in the European Economic Area (EEA).
UK GDPR — Applies where we process personal data of individuals located in the United Kingdom.
Where a conflict arises between these frameworks, we apply the more protective standard to the data subject concerned.
3. Definitions
Personal Data — Any information relating to an identified or identifiable natural person, including name, identification number, location data, or online identifiers.
Processing — Any operation performed on personal data, including collection, recording, storage, use, disclosure, or deletion.
Data Controller — Bamboo Electronic Cards Trading LLC, which determines the purposes and means of processing personal data.
Data Processor — A third party that processes personal data on behalf of Bamboo Card under a data processing agreement.
Data Subject — The natural person whose personal data is being processed.
Lawful Basis — The legal ground under which we are permitted to process personal data.
Sensitive Data — Data revealing racial or ethnic origin, political opinions, religious beliefs, biometric data, health data, or financial account data.
4. Data We Collect
4.1 Data Provided Directly by You
Identity Data: Full name, date of birth, job title, company name, trade licence details.
Contact Data: Email address, telephone number, postal address.
Account Data: Username, password (stored in encrypted form), account preferences and settings.
Transactional Data: Gift card orders, redemption records, transaction amounts, currencies, order history, wallet balances and top-up records.
Payment Data: Billing address, payment method details. Note: full card numbers are not stored by Bamboo Card; payment processing is handled by PCI-DSS compliant third-party processors.
KYC and Compliance Data: Identification documents, business registration details, and other verification information required for regulatory compliance and fraud prevention.
Communications Data: Records of correspondence with our team, including support requests and their resolutions.
4.2 Data Collected Automatically
Technical Data: IP address, browser type, operating system, device identifiers, screen resolution, and referring URL.
Usage Data: Pages visited, features used, session duration, click patterns, error logs, and API call metadata.
Cookie Data: Data collected through cookies and similar tracking technologies. See Section 11 and our Cookie Policy for full details.
API Integration Data: API keys, endpoint call logs, request and response metadata, and integration configuration data.
4.3 Data Received from Third Parties
Identity Verification Partners: KYC/AML verification data from identity verification providers.
Payment Processors: Transaction confirmation and status data.
Brand Partners: Gift card fulfilment confirmation and redemption status from brand partners integrated into our catalogue.
Publicly Available Sources: Business registration records, publicly available contact information for corporate onboarding purposes.
5. Lawful Basis for Processing
Under the UAE PDPL and, where applicable, GDPR, we rely on the following lawful bases for processing personal data:
Performance of a Contract (Article 6(1)(b) GDPR / UAE PDPL): Processing necessary to provide our Services to you, including account management, order processing, and fulfilment.
Legal Obligation (Article 6(1)(c) GDPR / UAE PDPL): Processing required to comply with AML/CFT regulations, tax obligations, financial services law, and applicable data protection legislation.
Legitimate Interests (Article 6(1)(f) GDPR / UAE PDPL): Processing for fraud prevention, platform security, business analytics, product improvement, and direct marketing to existing clients. We have conducted legitimate interest assessments where required.
Consent (Article 6(1)(a) GDPR / UAE PDPL): Processing for non-essential cookies, marketing communications to prospective clients, and any processing beyond the scope of the above bases. Consent may be withdrawn at any time without affecting prior lawful processing.
Vital Interests and Public Task: In exceptional circumstances where processing is necessary to protect life or fulfil a public interest obligation.
6. Purposes of Processing
Account creation, management, and authentication
Processing gift card orders, payments, and fulfilment
Providing customer and technical support
Fraud prevention, AML/CFT screening, and transaction monitoring
Platform performance monitoring, debugging, and improvement
API integration support and developer documentation
Compliance with applicable law, regulations, and regulatory requests
Sending transactional communications (order confirmations, delivery notifications)
Sending marketing communications where consent has been obtained or legitimate interest applies
Conducting business analytics and reporting
Corporate onboarding and due diligence
Responding to legal claims or regulatory investigations
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes set out in this Policy, unless a longer retention period is required or permitted by law. Our general retention periods are as follows:
Account and Identity Data: Retained for the duration of the contractual relationship and for seven (7) years thereafter, in accordance with UAE commercial record-keeping requirements.
Transactional Data: Retained for seven (7) years in accordance with UAE Federal Law No. 2 of 2015 on Commercial Companies and applicable AML regulations.
KYC and Compliance Data: Retained for five (5) years from the end of the business relationship, or longer if required by applicable AML/CFT law.
Technical and Usage Data: Retained for up to twenty-four (24) months and then anonymised or deleted.
Marketing Consent Records: Retained for three (3) years from the date of last interaction or until consent is withdrawn.
Support Communications: Retained for three (3) years from resolution of the support request.
Upon expiry of the applicable retention period, personal data is securely deleted or anonymised in a manner that prevents re-identification.
8. Sharing of Personal Data
8.1 Categories of Recipients
Brand Partners: Gift card fulfilment requires transmission of order data (denomination, currency, quantity) to brand partners. Bamboo Card does not share personal identity data with brand partners beyond what is required to fulfil an order.
Payment Processors: PCI-DSS compliant payment service providers who process payment transactions on our behalf.
Identity Verification Providers: KYC/AML verification partners for regulatory onboarding requirements.
Technology and Infrastructure Providers: Cloud hosting, database management, and platform infrastructure providers.
Analytics Providers: Web and product analytics platforms, subject to data processing agreements.
Legal and Regulatory Authorities: Disclosed where required by UAE law, a valid court order, regulatory direction, or for the prevention or detection of crime.
Professional Advisers: Lawyers, auditors, and financial advisers subject to professional confidentiality obligations.
Business Successors: In connection with any merger, acquisition, or sale of all or part of Bamboo Card’s business, subject to equivalent data protection obligations being imposed on the successor entity.
8.2 Data Processing Agreements
All third-party processors are engaged pursuant to written data processing agreements that impose data protection obligations consistent with the UAE PDPL and, where applicable, GDPR Article 28 requirements. We do not sell personal data to any third party.
9. International Data Transfers
As a global platform operating across 80+ countries, some of the personal data we process may be transferred to and stored in jurisdictions outside the UAE. Where such transfers occur, we implement appropriate safeguards, which may include:
Standard Contractual Clauses (SCCs) approved under GDPR, where transfers involve EEA data
Binding Corporate Rules or equivalent mechanisms
Transfers to jurisdictions recognised as providing adequate protection by the UAE Data Office
Consent-based transfers where no other safeguard applies and the transfer is non-repetitive
Data subjects located in the EEA may request further information about the safeguards applicable to their data transfer by contacting us at the address in Section 16.
10. Your Rights
Subject to applicable law and verification of identity, you have the following rights regarding your personal data:
Right of Access: You may request a copy of the personal data we hold about you (UAE PDPL Article 14; GDPR Article 15).
Right to Rectification: You may request correction of inaccurate or incomplete personal data (UAE PDPL Article 15; GDPR Article 16).
Right to Erasure: You may request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, subject to our legal retention obligations (UAE PDPL Article 16; GDPR Article 17).
Right to Restriction: You may request that we restrict processing of your data in certain circumstances (GDPR Article 18).
Right to Data Portability: Where processing is based on consent or contract, you may request a copy of your data in a structured, machine-readable format (GDPR Article 20).
Right to Object: You may object to processing based on legitimate interests or for direct marketing purposes (GDPR Article 21).
Right to Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.
Right to Lodge a Complaint: You have the right to lodge a complaint with the UAE Data Office or, if located in the EEA, with your local data protection supervisory authority.
To exercise any of these rights, submit a written request to privacy@bamboo-card.com. We will respond within thirty (30) calendar days of receipt of your verified request. In complex cases, this period may be extended by a further sixty (60) days, of which we will notify you.
11. Cookies and Tracking Technologies
We use cookies and similar tracking technologies on our website and platform. Our use of cookies is governed by our Cookie Policy, available at www.bamboo-card.com/cookie-policy, which should be read alongside this Privacy Policy. We obtain consent for non-essential cookies through a consent management platform presented upon first visit to our website.
12. Children’s Data
Our Services are not directed at individuals under the age of eighteen (18). We do not knowingly collect personal data from minors. If we become aware that personal data has been collected from a person under 18 without appropriate consent from a parent or legal guardian, we will delete such data promptly. If you believe we have inadvertently collected data from a minor, please contact us immediately at privacy@bamboo-card.com.
13. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, or disclosure. These measures include, but are not limited to:
Encryption of personal data in transit using TLS 1.2 or higher
Encryption of personal data at rest using industry-standard protocols
Role-based access controls limiting data access to authorised personnel
Regular security assessments, penetration testing, and vulnerability management
ISO 27001-aligned information security management practices
Employee data protection training and confidentiality obligations
Incident response procedures for detection and management of data breaches
In the event of a personal data breach that poses a risk to the rights and freedoms of data subjects, we will notify the relevant supervisory authority within seventy-two (72) hours of becoming aware of the breach, and affected data subjects without undue delay, in accordance with GDPR Article 33-34 and applicable UAE PDPL requirements.
No method of electronic transmission or storage is completely secure. While we take all reasonable steps to protect your data, we cannot guarantee absolute security.
14. Third-Party Links
Our website and platform may contain links to third-party websites, services, or applications. This Privacy Policy does not apply to any third-party site or service. We are not responsible for the privacy practices of third parties. We encourage you to review the privacy policies of any third-party sites you access through our platform.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing activities, applicable law, or regulatory guidance. Where we make material changes, we will notify you by email (if we hold your contact details) or by posting a prominent notice on our website prior to the change becoming effective. The date of the most recent revision is indicated at the top of this Policy. Continued use of our Services following notification of changes constitutes acceptance of the updated Policy.
16. Contact and Data Protection Enquiries
For all data protection enquiries, requests to exercise your rights, or to report a concern, please contact:
Data Controller: Bamboo Electronic Cards Trading LLC
Email: privacy@bamboo-card.com
Support: support@bamboo-card.com
Website: www.bamboo-card.com
Address: Bamboo Electronic Cards Trading LLC, Dubai, United Arab Emirates
Complaints regarding our handling of personal data may also be directed to the UAE Data Office (www.dataoffice.gov.ae) or, for EEA residents, to your relevant national supervisory authority.
Version 3.0 — April 2026. This document supersedes all prior versions of the Bamboo Card Privacy Policy.