Quick summary
We collect what we need to deliver your card, host your profile, and ship to your address. Nothing else. We never sell or rent your data. You can export or delete everything at any time. We host in the EU and the GCC. We respond to data requests within 7 days.
Who is the data controller
For data collected through the Platform and any Wavelink product, the data controller is:
Wavelink
Sharjah Publishing City Free Zone Authority, Sharjah, UAE
Data Protection Officer: privacy@getwaved.ai
For EU residents, our EU representative is reachable at the same address. For UK residents, we rely on the UK Extension of the GDPR Adequacy Decision.
What we collect
We keep the data we need. Nothing extra. Categories:
Data you give us
- Account — Account — email address, name as it appears on your card.
- Profile — Profile — name, title, company, photo, contact methods (phone, email, social handles) you choose to publish.
- Shipping — Shipping — name, street address, city, country, postcode, phone number for delivery.
- Payment — Payment — handled by our payment processor; we see the last 4 digits and the brand, never the full PAN.
Data we collect automatically
- Profile view logs — Profile view logs — IP-derived country, timestamp, viewer user-agent. We do not log names of viewers unless they tap to share back.
- Card stand taps — Card stand taps — timestamp and short locale hash for abuse prevention.
- Platform analytics — Platform analytics — aggregated page-view counts via Microsoft Clarity. Recordings are masked: no form fields, no input.
Data we never collect
- Precise GPS coordinates of taps.
- Contacts list, photos library, or microphone.
- Biometric data.
- Data broker profiles or third-party enrichment.
Why we collect it
We collect data for these specific purposes, each with a lawful basis under UAE PDPL.
| Purpose | Lawful basis (UAE PDPL) |
|---|---|
| Print, encode and ship your card | Performance of contract |
| Host and serve your public profile | Performance of contract |
| Process payment and refunds | Performance of contract · Legal obligation |
| Prevent fraud and protect the Platform | Legitimate interest |
| Send service messages (delivery, security) | Performance of contract |
| Send marketing (if you opt in) | Consent — withdrawable any time |
Where it is stored
Your data lives in two places by design:
- European Union — European Union — Cloudflare D1 database (wavelink-open-data) for EU residents.
- GCC mirror — GCC mirror — for delivery routing only; no extra data is copied there.
Static assets (logos, profile images) are served from Cloudflare's global edge, with strict cache and no third-party analytics scripts loaded from the document.
Encryption: in transit (TLS 1.3). At rest (AES-256 on Cloudflare D1). Backups encrypted at rest, retained 30 days, then destroyed.
Who we share with
We share only with the parties needed to deliver the service. None of these parties may use your data for their own marketing:
| Recipient | What they see | Why |
|---|---|---|
| Cloudflare | Hosting, database | Operate the Platform |
| Payment processor | Card details | Take payment |
| Courier / postal operator | Name, address, phone | Ship your order |
| Microsoft Clarity | Masked session recording | Improve the Platform |
| Government authority | Only on lawful order | Legal obligation |
We do not sell your data. We do not rent it. We do not share it with data brokers, advertising networks, or analytics companies beyond the operator above.
Your rights
You can always:
- Read — Read — request a copy of everything we hold on you. We deliver within 7 days.
- Correct — Correct — change your profile data any time from your account.
- Delete — Delete — request full erasure. We action within 30 days. After that, only the records we must keep (invoices, tax) remain.
- Export — Export — get a portable JSON copy of your profile data.
- Restrict — Restrict — pause processing for a specific purpose (for example, marketing).
- Object — Object — to any processing we claim under legitimate interest. We then stop or demonstrate our overriding grounds.
- Withdraw consent — Withdraw consent — for marketing or optional cookies, at any time.
- Complain — Complain — to the supervisory authority in your country. EU residents have the right under GDPR Article 77.
To exercise any right, write to privacy@getwaved.ai from the email on your account. We reply within 7 days.
How long we keep it
Retention periods for each category of data we hold.
| Data | Retention |
|---|---|
| Order invoices and tax records | 7 years (UAE tax law) |
| Shipping data after delivery | 3 years (claims window) |
| Profile data while card is active | For the life of the card |
| Profile data after deletion request | 30 days, then purged |
| Profile view logs | 90 days, then aggregated |
| Backups | 30 days rolling |
| Marketing consent record | Until withdrawn + 2 years proof |
Cross-border transfers
For customers in the GCC and Bangladesh, data is hosted in the EU (primary) with delivery routing data in the GCC. For customers in the EU, data stays in the EU.
We do not"Not" included for clarity. There are no current transfers to countries lacking adequacy. If that changes, we will update this section 30 days before. transfer personal data to jurisdictions that lack an adequacy decision under GDPR, PDPL, or applicable equivalent.
Children
The Platform is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has created an account, write to privacy@getwaved.ai and we will delete the account within 7 days.
Changes to this policy
We update this policy when our practices change. The "Last updated" date at the top is the source of truth. Material changes are emailed to account holders at least 14 days before they take effect.
Previous versions are available on request.
Contact the DPO
For privacy questions, data requests, or to exercise your rights:
- Email: privacy@getwaved.ai (Data Protection Officer)
- Postal: Sharjah Publishing City Free Zone Authority, Sharjah, UAE
- Response time: within 7 days
EU residents may also contact their national supervisory authority. A list is published by the European Data Protection Board.