Privacy Policy
LAST UPDATED 3 AUGUST 2026
This describes what THENU actually stores, taken from our live database schema — not a template. If a section says we do not collect something, we do not have a column for it.
1. Who we are
THENU is a services app for international students in Dubai, United Arab Emirates. We connect students with verified partners for meals, laundry, airport transfers, accommodation enquiries and mobile plans. For the data described here, THENU is the data controller.
2. What we collect
You give us
- Account: name, email, and your Google or Apple sign-in identifier.
- Profile: university, gender, home-country phone number, UAE phone number, and which of the two we should call.
- Addresses: the delivery and pickup addresses you save.
- Booking details: flight number, airline, arrival time, terminal, passenger and luggage counts, meal preferences, laundry item counts, and any notes you write.
- Documents (optional): passport, visa, Emirates ID, offer letter, tenancy contract or insurance, if you choose to upload them to your private vault.
- Emergency contacts (optional): a name and number you nominate.
- Roommate profile (optional): lifestyle answers used for matching, and messages you send in roommate chat.
We generate
- Order, booking and payment records, including amounts and status.
- Device session records, including a device name and push-notification token, so we can notify you and you can sign out of a lost phone.
- Support tickets and dispute records you open.
We do not collect
- Your location. The app does not request GPS. Addresses are only what you type.
- Card numbers. When card payments are enabled, they are handled entirely by our payment provider. Card details never reach THENU's systems.
- Your contacts, photos, microphone or camera roll.
3. Why we use it
| Purpose | Data | Basis |
|---|---|---|
| Deliver a service you booked | Name, phone, address, booking details | Performance of a contract |
| Tell you what is happening with an order | Push token, order status | Performance of a contract |
| Roommate matching | Gender, university, lifestyle answers | Your consent — optional feature |
| Document vault | Documents you upload | Your consent — optional feature |
| Fraud prevention and safety | Order history, device sessions | Legitimate interest |
| Legal and tax records | Transaction records | Legal obligation |
4. Who sees your data
Partners see only what they need to serve you. A kitchen sees your name, delivery address, phone number and meal preferences. A driver sees your name, phone, flight and destination. A laundry sees your name, address, phone and item list. No partner ever sees your documents, your other bookings, your roommate profile or your emergency contacts.
Our processors: Supabase (database and file storage), Google Firebase (push notifications and crash reporting), Vercel (website hosting), SendGrid (email), and our payment provider once card payments are live. Each processes data only on our instructions.
We do not sell your data. We do not share it for advertising.
5. Documents you upload
Uploading a passport or visa is entirely optional — the app works without it. Documents are stored in a private bucket where access is locked to your account at the database level; links we generate expire after five minutes. Staff do not browse them. You can delete any document at any time from Profile → Documents, and deletion is immediate and permanent.
6. How long we keep it
| Data | Kept for |
|---|---|
| Account and profile | Until you delete your account |
| Uploaded documents | Until you delete them, or your account |
| Order, booking and payment records | 7 years after the transaction (UAE tax and commercial record-keeping) |
| Roommate chat messages | Until you delete your account |
| Push tokens / device sessions | Until you sign out of that device or delete your account |
| Support tickets | 3 years after the ticket closes |
When you delete your account, your profile, documents, roommate data and contacts are removed. Transaction records are retained in anonymised form — the amounts and dates remain for tax purposes, but they are no longer linked to you by name.
7. Your rights
- Access — ask for a copy of your data.
- Correction — most of it is editable in Profile; email us for the rest.
- Deletion — Profile → Privacy → Delete account, or email us. No dark pattern, no retention call.
- Withdraw consent — delete your documents or roommate profile without affecting the rest of your account.
- Object or complain — write to us first; you may also complain to the relevant UAE authority.
We answer requests within 30 days at support@thenu.app.
8. Security
Every table in our database enforces row-level security, so one student's records are unreachable by another even if the app were bypassed. Documents sit in a private bucket keyed to your account. Traffic is encrypted in transit. Administrative access requires two-factor authentication and is logged. We test these controls by attacking our own system before each release; the most recent sweep of 18 probes returned no data.
No system is perfect. If we ever discover a breach affecting you, we will tell you and the relevant authority — we will not wait to be asked.
9. Children
THENU is for university students and is not intended for anyone under 16. If you believe a child has an account, contact us and we will remove it.
10. International transfers
Our infrastructure providers may process data outside the UAE, including in the EU and the US, under their standard contractual protections.
11. Changes
If we change this policy materially, we will notify you in the app before the change takes effect. The date at the top always reflects the current version.
THENU Technologies – FZCO, trade licence 90781, Premises No. DSO-IFZA, IFZA Properties, Dubai Silicon Oasis, Dubai, UAE.
Questions about this document: support@thenu.app
thenu © 2026 THENU FZCO