Privacy Policy

Effective Date: 13 May 2026   |   Last Updated: 13 May 2026

This Privacy Policy explains how Ring n Bring FZ-LLC (“Ring n Bring,” “we,” “our,” or “us”) collects, uses, shares, and protects personal data when you visit ringnbring.com, use our web, mobile, or smartwatch applications, interact with our sales and admin portals, or use our QR-based ordering, dispatching, and feedback services (including Ring n Rate) at a participating hotel, restaurant, beach club, or other hospitality venue (a “Venue”).

We are committed to processing personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”), the UK GDPR, and other applicable data protection laws, including the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the “UAE PDPL”).

Please read this Policy carefully. By using our website or services, you acknowledge that you have read and understood this Policy.

Contents

  1. Who We Are and How to Contact Us
  2. Our Role: Controller vs. Processor
  3. Personal Data We Collect
  4. How and Why We Use Your Personal Data
  5. Legal Bases for Processing (GDPR Article 6)
  6. Cookies and Similar Tracking Technologies
  7. How We Share Your Personal Data
  8. Sub-Processors and Service Providers
  9. International Data Transfers
  10. Data Retention
  11. Data Security
  12. Your Rights Under the GDPR and UK GDPR
  13. How to Exercise Your Rights and Lodge a Complaint
  14. Automated Decision-Making and Profiling
  15. Children’s Data
  16. Data Breach Notification
  17. Changes to This Privacy Policy
  18. Contact Us

1. Who We Are and How to Contact Us

Ring n Bring is an all-in-one guest experience and operations management platform for the hospitality industry. Our services let venue guests scan a QR code to view menus, place food and beverage orders, request services (housekeeping, towels, the bill, the waiter), make reservations, pay and tip, and submit feedback via Ring n Rate. Venue staff receive and action these requests through our web dashboard and smartwatch applications.

Data Controller (corporate entity): Ring n Bring FZ-LLC
General contact: support@ringnbring.com  |  +971585777667  |  ringnbring.com
Privacy contact / Data Protection enquiries: support@ringnbring.com

If we are required to appoint a Data Protection Officer (DPO) or an EU/UK Representative under Articles 27 and 37 of the GDPR, their contact details will be published here. Until such appointment, all enquiries should be directed to privacy@ringnbring.com.

2. Our Role: Controller vs. Processor

Under the GDPR, Ring n Bring acts in two distinct capacities depending on who you are and how you interact with us. This distinction matters because it determines who is responsible for your data and who you should contact to exercise your rights.

2.1 When We Are a Data Controller

We act as a Data Controller — meaning we determine the purposes and means of processing — when:

  • You visit ringnbring.com or interact with our marketing channels (LinkedIn, Meta, Google);
  • You sign up for a Ring n Bring B2B account as a venue operator or a member of venue staff;
  • You contact us directly by email, phone, or web form;
  • You apply for a role or interact with us as a business partner.

2.2 When We Are a Data Processor

We act as a Data Processor — meaning we process personal data on documented instructions from another controller — when you are a guest at a Venue and you use our QR codes, ordering interface, payment flow, or feedback system. In this scenario:

  • The Venue (the hotel, restaurant, or beach club) is the Data Controller;
  • Ring n Bring processes your personal data on behalf of and on the instructions of the Venue, under a Data Processing Agreement (DPA);
  • Requests to exercise data subject rights in respect of guest data should normally be directed to the Venue. We will assist the Venue in responding.

3. Personal Data We Collect

The categories of personal data we collect depend on how you interact with us. We do not collect special categories of personal data (such as health, religion, or biometric data) in the ordinary course of our business.

3.1 Data You Provide Directly

ContextCategories of Personal Data
B2B account creation (Venue operators and staff)Full name, business email, mobile/phone number, job title, Venue name, Venue address, login credentials (hashed).
Subscription and billingCompany name, billing address, VAT/tax ID, billing contact, payment instrument details (handled by our payment processors — we do not store full card numbers).
Guest ordering and service requestsFirst name (optional), room number, table number, sunbed or cabana number, items ordered, requests issued, allergens or dietary notes you choose to share, special instructions.
ReservationsName, contact details (email and/or phone), party size, date, time, and any preferences you share.
Payments and tippingTokenised card or wallet details (handled by Stripe, CC Avenue, PayTabs, or Urway), amount, currency, transaction reference.
Feedback (Ring n Rate)Ratings, comments, optional name and contact details, and the staff member or service area being rated.
Support and communicationsYour name, contact details, the content of your message, and any attachments.

3.2 Data We Collect Automatically

CategoryExamples
Device and connection dataIP address, device type, operating system, browser type and version, screen size, language, time zone.
Usage dataPages visited, features used, QR codes scanned, buttons clicked, session duration, referring URL, timestamps.
Location dataApproximate location derived from IP address. Where the Venue has enabled Geo Location Lock, precise location (with your consent) to confirm you are physically present at the Venue and prevent fraudulent remote ordering.
Cookie and tracking identifiersFirst- and third-party cookie IDs, advertising IDs, and pixel identifiers — see Section 6.

3.3 Data We Receive From Third Parties

  • Payment processors (Stripe, CC Avenue, PayTabs, Urway) — transaction status, fraud signals, tokenised payment references.
  • POS and PMS integrations (e.g., Oracle Micros, Opera) — order routing acknowledgements, room status, folio references.
  • Advertising and analytics platforms (Google, Meta, LinkedIn) — campaign performance, audience signals.
  • The Venue — your room number, guest profile reference, or loyalty identifier, where the Venue has integrated these into our platform.

4. How and Why We Use Your Personal Data

We use personal data for the following purposes:

PurposeDescription
Service deliveryRoute your orders and service requests to the correct staff member on a smartwatch or dashboard; manage reservations; process bills, splits, and tipping; deliver receipts; verify physical presence at a Venue.
Account managementCreate and maintain your B2B account; authenticate users; manage roles and permissions; provide customer support.
Billing and financeProcess subscription payments, generate invoices, manage refunds, and meet tax and accounting obligations.
Analytics and product improvementUnderstand how the platform is used, measure staff response times and operational efficiency, identify bugs, and improve features.
Marketing (with consent where required)Send product updates, run advertising campaigns on Google, Meta, and LinkedIn, build lookalike audiences, and serve retargeted ads.
Fraud prevention and securityDetect, prevent, and investigate fraudulent transactions, abuse, and security incidents.
Legal complianceComply with applicable laws, respond to lawful requests from public authorities, and defend our legal rights.

5. Legal Bases for Processing (GDPR Article 6)

We only process personal data when we have a valid legal basis. The legal basis depends on the specific processing activity.

Legal BasisWhen We Rely On It
Performance of a contract (Art. 6(1)(b))To provide the services you or the Venue have engaged us to deliver — routing orders, managing reservations, processing payments, providing customer support.
Legitimate interests (Art. 6(1)(f))To analyse and improve our platform, secure our services, prevent fraud, conduct B2B direct marketing where permitted, and defend our legal rights. We balance our interests against your rights and freedoms before relying on this basis.
Consent (Art. 6(1)(a))For non-essential cookies and tracking pixels (Google Ads, Meta Pixel, LinkedIn Insight Tag), for electronic marketing communications where required, and for precise geolocation in Geo Location Lock. You can withdraw consent at any time without affecting prior processing.
Legal obligation (Art. 6(1)(c))To comply with tax, accounting, anti-money-laundering, and other statutory obligations, and to respond to lawful requests from public authorities.
Vital interests (Art. 6(1)(d))Only in rare circumstances where processing is necessary to protect the vital interests of an individual.

6. Cookies and Similar Tracking Technologies

We use cookies, pixels, SDKs, and similar technologies to operate ringnbring.com, remember your preferences, analyse traffic, and run marketing campaigns. We deploy and manage these tags through Google Tag Manager.

When you first visit our website, you will see a Cookie Consent Banner. You may accept all cookies, reject all non-essential cookies, or manage your preferences by category. Strictly necessary cookies are always active because the website cannot function without them. You can change your preferences at any time via the “Cookie Settings” link in the website footer.

6.1 Categories of Cookies We Use

CategoryPurposeExamplesLegal Basis
Strictly necessaryAuthentication, security, load balancing, remembering your cookie choices.Session cookies, CSRF tokens, consent state.Legitimate interests / contractual necessity. No consent required.
AnalyticsMeasure how visitors use the site, count visits, identify popular pages, diagnose errors.Google Analytics 4 (_ga, _gid).Consent.
Advertising – SearchMeasure conversions from Google Ads, retarget visitors, and build advertising audiences.Google Ads conversion tag, remarketing tag.Consent.
Advertising – SocialTrack conversions from Meta (Facebook, Instagram) ads, optimise ad delivery, build custom and lookalike audiences, retarget.Meta Pixel (_fbp, _fbc).Consent.
Advertising – B2BTrack conversions from LinkedIn campaigns, retarget professional audiences, derive demographic insights.LinkedIn Insight Tag.Consent.
Tag managementContainer that loads the tags above based on your consent choices.Google Tag Manager.Operates only when underlying tags are permitted.

6.2 Google Consent Mode and IP Anonymisation

We implement Google Consent Mode v2 so that Google tags adjust their behaviour based on your consent choices. Where analytics or advertising consent is denied, only anonymised, cookieless signals are sent. We enable IP anonymisation in Google Analytics so the last octet of your IP address is truncated before storage.

6.3 Do Not Track and Global Privacy Control

We honour the Global Privacy Control (GPC) signal where technically feasible by treating it as a withdrawal of consent to non-essential cookies. We do not currently respond to legacy “Do Not Track” browser headers because no consistent industry standard exists.

6.4 Refusing Cookies Does Not Break the Service

Refusing analytics or advertising cookies will not prevent you from using the core ordering, service request, payment, or feedback functionality of the Ring n Bring platform at a Venue.

7. How We Share Your Personal Data

We do not sell your personal data. We share personal data only in the circumstances set out below.

  • The Venue: When you use our system as a guest, your order details, room or table number, request content, and feedback are shared with the Venue and its staff so they can fulfil your requests. The Venue is the controller of this data.
  • Sub-processors and service providers: Trusted third parties who process personal data on our behalf under written contracts that include GDPR-compliant terms — see Section 8.
  • Professional advisors: Lawyers, auditors, accountants, and insurers, where necessary and bound by confidentiality.
  • Public authorities: Where we are required by law, regulation, court order, or valid legal process, or where disclosure is necessary to protect the rights, property, or safety of Ring n Bring, our users, or others.
  • Business transfers: In connection with a merger, acquisition, financing, reorganisation, or sale of all or part of our business, in which case we will require the recipient to honour the commitments in this Policy.

8. Sub-Processors and Service Providers

The categories below set out the third parties we rely on to deliver our services. The current list of named sub-processors is maintained at ringnbring.com/subprocessors and is updated when we add, remove, or change a sub-processor.

CategoryPurposeExamples
Payment processingSecurely process card payments, wallets, and refunds.Stripe, CC Avenue, PayTabs, Urway.
POS and PMS integrationRoute orders into Venue systems; sync folios.Oracle Micros, Opera, Simphony.
Cloud hosting and storageRun our application and database infrastructure.AWS, Microsoft Azure.
Email and communicationsSend transactional and marketing emails and SMS.SendGrid, Twilio.
Analytics and tag managementMeasure usage, manage tags.Google Analytics, Google Tag Manager.
Advertising and marketingRun and measure advertising campaigns.Google Ads, Meta, LinkedIn.
Customer supportManage support tickets and live chat.Intercom or similar.
Productivity and CRMManage internal records and customer relationships.Google Workspace, HubSpot.

We carry out due diligence on every sub-processor and require them to provide appropriate technical and organisational measures to protect personal data.

9. International Data Transfers

Ring n Bring operates internationally. Your personal data may be transferred to, stored in, and processed in countries outside your country of residence, including the United Arab Emirates, the United Kingdom, the European Economic Area (EEA), and the United States.

Where we transfer personal data out of the United Arab Emirates, we do so in accordance with the UAE PDPL — only where the destination jurisdiction ensures an adequate level of protection, where appropriate safeguards (such as standard contractual clauses) are in place, or where you have given your explicit consent to the transfer after being informed of any associated risks.

Where we transfer personal data from the EEA, the UK, or Switzerland to a country that has not received an adequacy decision from the European Commission or the UK Information Commissioner, we put one or more of the following safeguards in place under Chapter V of the GDPR:

You may request a copy of the safeguards we rely on for a specific transfer by contacting privacy@ringnbring.com.

10. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements.

CategoryRetention Period
B2B account dataFor the duration of the contract with the Venue, plus 7 years for tax and accounting purposes.
Guest order, payment, and request dataUp to 24 months from the date of the transaction (configurable by the Venue), then deleted or anonymised.
Feedback (Ring n Rate)Up to 36 months, after which feedback is anonymised for analytics.
Marketing data and prospect recordsUp to 24 months from the last meaningful interaction, or until you opt out, whichever is earlier.
Website analyticsGoogle Analytics retention is set to the minimum supported (2 months for event data; 14 months where required for measurement).
Cookie consent records12 months from collection, or until you change your preference.
Support communications24 months from resolution.
BackupsEncrypted backups are retained for up to 90 days for disaster recovery, after which they are securely overwritten.

For guest data that we process on behalf of a Venue as a Processor, retention is also governed by the Venue's own instructions and policies as the Controller.

Where we cannot delete data immediately (for example because it is held in encrypted backups), we will isolate it from active processing until deletion is possible.

11. Data Security

Ring n Bring is ISO/IEC 27001 certified, and our Information Security Management System (ISMS) is independently audited against this international standard. We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, damage, alteration, or disclosure, including:

No method of transmission over the internet or method of electronic storage is completely secure. While we strive to use commercially acceptable means to protect personal data, we cannot guarantee absolute security.

12. Your Rights Under the GDPR and UK GDPR

If you are located in the EEA, the UK, or Switzerland, you have the following rights in relation to your personal data. Equivalent rights are available under the UAE PDPL — see Section 12.1.

12.1 Your Rights Under the UAE PDPL

As a UAE-based company, we comply with the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the “UAE PDPL”) and apply its principles to our processing of UAE residents' personal data. Where the PDPL applies to you, you have rights that closely mirror those described above, including:

The UAE Data Office (and its successor federal authority responsible for data protection) supervises compliance with the PDPL. To exercise any PDPL right, email privacy@ringnbring.com. You also retain the right to lodge a complaint with the competent UAE authority.

13. How to Exercise Your Rights and Lodge a Complaint

To exercise any of your rights, email privacy@ringnbring.com. We may need to verify your identity before responding. We will respond within one month of receipt of your request. We may extend this period by up to two further months where necessary, taking into account the complexity and number of requests; in that case we will inform you within the first month.

There is no fee for exercising your rights. However, we may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive.

Guest data held by a Venue: If your request relates to personal data we process on behalf of a Venue as a Processor, please contact the Venue directly. We will assist the Venue in responding to your request.

13.1 Supervisory Authorities

You have the right to lodge a complaint with a data protection supervisory authority if you believe our processing of your personal data infringes the GDPR or other applicable data protection law. You may complain in the EU member state of your habitual residence, place of work, or place of the alleged infringement. Useful starting points include:

We would, however, appreciate the opportunity to address your concerns before you approach a supervisory authority.

14. Automated Decision-Making and Profiling

We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you within the meaning of Article 22 of the GDPR.

We do use automated logic for operational purposes such as routing requests to the nearest available staff member, prioritising service queues, and surfacing analytics insights for Venues. These activities do not produce legal or similarly significant effects on you. If this changes, we will update this Policy and provide the information required by Articles 13 and 14 of the GDPR.

15. Children’s Data

Our services are not directed to children under the age of 16, and we do not knowingly collect personal data from children. Where a Venue’s offering is directed at families, the relevant adult guest is responsible for any orders or requests made on behalf of a minor in their care. If we become aware that we have collected personal data from a child under 16 without verified parental or guardian consent, we will delete that data promptly. Please contact privacy@ringnbring.com if you believe we may hold such data.

16. Data Breach Notification

If a personal data breach occurs, we will notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay.

Where we act as a Processor, we will notify the relevant Venue (Controller) without undue delay after becoming aware of a personal data breach affecting data we process on their behalf.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our services, our tracking technologies, or legal or regulatory requirements. The “Last Updated” date at the top of the Policy will always indicate when it was most recently revised. Where the changes are material, we will provide a more prominent notice (for example, by email to B2B account holders or by a banner on the website) before the changes take effect.

We encourage you to review this Policy periodically. Your continued use of our services after a revised Policy takes effect constitutes your acceptance of the revised Policy to the extent permitted by law.

18. Contact Us

If you have any questions about this Privacy Policy or our processing of your personal data, please contact us:

ChannelDetail
Privacy enquiriesprivacy@ringnbring.com
General enquiriesinfo@ringnbring.com
Phone+971585777667
Websiteringnbring.com
Postal addressAl Shmookh Business Center, One UAQ, Umm Al Quwain, United Arab Emirates

End of Privacy Policy.