Privacy Policy

Last updated: 4 August 2026

1. Who we are

Crab&Grab is operated by Crab Venture Restaurant L.L.C, registered in Dubai, United Arab Emirates. This policy explains how we collect, use, and protect your personal data in compliance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("PDPL") and DIFC/ADGM data protection regulations where applicable.

2. Data we collect

Data typeWhen collectedPurpose
Full name, email, phoneCheckout, account creationProcess and deliver your order, send confirmations
Delivery addressCheckoutDeliver your order
Payment informationCheckout (via Stripe)Process payment — we never store card details; Stripe handles this as a PCI-DSS compliant processor
Order historyEach purchaseOrder tracking and account history
Device/browser info, IP addressSite visitsWebsite analytics, fraud prevention
Survey responsesVoluntary product surveyUnderstand product demand

3. Legal basis for processing

We process your data on the following grounds under the PDPL:

  • Contractual necessity — to fulfil your order and deliver products
  • Legitimate interest — fraud prevention, website security, service improvement
  • Consent — marketing communications (you may withdraw consent at any time)

4. How we use your data

  • Process and fulfil orders
  • Send order confirmation and delivery notifications
  • Respond to customer enquiries via WhatsApp, email, or phone
  • Improve our products and services
  • Send promotional offers (only with your consent)

5. Data sharing

We share your data only with:

  • Stripe — payment processing (servers outside UAE; data transferred under adequate safeguards as required by the PDPL)
  • Resend — transactional email delivery (servers outside UAE; data transferred under adequate safeguards)
  • Delivery partners — name, phone, and address for order delivery
  • Law enforcement — if required by UAE law or court order

We do not sell your personal data to third parties.

6. Cross-border data transfers

Some of our service providers (Stripe, Resend) process data on servers located outside the United Arab Emirates. Where personal data is transferred internationally, we ensure that adequate safeguards are in place in accordance with Article 22 of the PDPL, including contractual protections and the use of providers that maintain internationally recognised security certifications.

7. Data retention

  • Order records: 5 years (UAE commercial record-keeping requirements)
  • Account data: until you request deletion
  • Marketing preferences: until you unsubscribe

8. Your rights

Under the PDPL, you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data (subject to legal retention requirements)
  • Withdraw consent for marketing at any time
  • Lodge a complaint with the UAE Data Office

9. Data security

We use SSL/TLS encryption, secure payment processing via Stripe, and access controls to protect your data. Payment card details are never stored on our servers.

10. Cookies

We use essential cookies for site functionality and cart persistence. No third-party advertising cookies are used. If analytics cookies are introduced in the future, we will update this policy and request your consent where required.

11. Children's data

Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have collected data from a person under 18, please contact us and we will promptly delete it.

12. Contact us

For data protection enquiries: