Effective Date: 13 May 2026 | Last Updated: 13 May 2026
This Privacy Policy explains how Ring n Bring FZ-LLC (“Ring n Bring,” “we,” “our,” or “us”) collects, uses, shares, and protects personal data when you visit ringnbring.com, use our web, mobile, or smartwatch applications, interact with our sales and admin portals, or use our QR-based ordering, dispatching, and feedback services (including Ring n Rate) at a participating hotel, restaurant, beach club, or other hospitality venue (a “Venue”).
We are committed to processing personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”), the UK GDPR, and other applicable data protection laws, including the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the “UAE PDPL”).
Please read this Policy carefully. By using our website or services, you acknowledge that you have read and understood this Policy.
Ring n Bring is an all-in-one guest experience and operations management platform for the hospitality industry. Our services let venue guests scan a QR code to view menus, place food and beverage orders, request services (housekeeping, towels, the bill, the waiter), make reservations, pay and tip, and submit feedback via Ring n Rate. Venue staff receive and action these requests through our web dashboard and smartwatch applications.
Data Controller (corporate entity): Ring n Bring FZ-LLC
General contact: support@ringnbring.com | +971585777667 | ringnbring.com
Privacy contact / Data Protection enquiries: support@ringnbring.com
If we are required to appoint a Data Protection Officer (DPO) or an EU/UK Representative under Articles 27 and 37 of the GDPR, their contact details will be published here. Until such appointment, all enquiries should be directed to privacy@ringnbring.com.
Under the GDPR, Ring n Bring acts in two distinct capacities depending on who you are and how you interact with us. This distinction matters because it determines who is responsible for your data and who you should contact to exercise your rights.
We act as a Data Controller — meaning we determine the purposes and means of processing — when:
We act as a Data Processor — meaning we process personal data on documented instructions from another controller — when you are a guest at a Venue and you use our QR codes, ordering interface, payment flow, or feedback system. In this scenario:
The categories of personal data we collect depend on how you interact with us. We do not collect special categories of personal data (such as health, religion, or biometric data) in the ordinary course of our business.
| Context | Categories of Personal Data |
|---|---|
| B2B account creation (Venue operators and staff) | Full name, business email, mobile/phone number, job title, Venue name, Venue address, login credentials (hashed). |
| Subscription and billing | Company name, billing address, VAT/tax ID, billing contact, payment instrument details (handled by our payment processors — we do not store full card numbers). |
| Guest ordering and service requests | First name (optional), room number, table number, sunbed or cabana number, items ordered, requests issued, allergens or dietary notes you choose to share, special instructions. |
| Reservations | Name, contact details (email and/or phone), party size, date, time, and any preferences you share. |
| Payments and tipping | Tokenised card or wallet details (handled by Stripe, CC Avenue, PayTabs, or Urway), amount, currency, transaction reference. |
| Feedback (Ring n Rate) | Ratings, comments, optional name and contact details, and the staff member or service area being rated. |
| Support and communications | Your name, contact details, the content of your message, and any attachments. |
| Category | Examples |
|---|---|
| Device and connection data | IP address, device type, operating system, browser type and version, screen size, language, time zone. |
| Usage data | Pages visited, features used, QR codes scanned, buttons clicked, session duration, referring URL, timestamps. |
| Location data | Approximate location derived from IP address. Where the Venue has enabled Geo Location Lock, precise location (with your consent) to confirm you are physically present at the Venue and prevent fraudulent remote ordering. |
| Cookie and tracking identifiers | First- and third-party cookie IDs, advertising IDs, and pixel identifiers — see Section 6. |
We use personal data for the following purposes:
| Purpose | Description |
|---|---|
| Service delivery | Route your orders and service requests to the correct staff member on a smartwatch or dashboard; manage reservations; process bills, splits, and tipping; deliver receipts; verify physical presence at a Venue. |
| Account management | Create and maintain your B2B account; authenticate users; manage roles and permissions; provide customer support. |
| Billing and finance | Process subscription payments, generate invoices, manage refunds, and meet tax and accounting obligations. |
| Analytics and product improvement | Understand how the platform is used, measure staff response times and operational efficiency, identify bugs, and improve features. |
| Marketing (with consent where required) | Send product updates, run advertising campaigns on Google, Meta, and LinkedIn, build lookalike audiences, and serve retargeted ads. |
| Fraud prevention and security | Detect, prevent, and investigate fraudulent transactions, abuse, and security incidents. |
| Legal compliance | Comply with applicable laws, respond to lawful requests from public authorities, and defend our legal rights. |
We only process personal data when we have a valid legal basis. The legal basis depends on the specific processing activity.
| Legal Basis | When We Rely On It |
|---|---|
| Performance of a contract (Art. 6(1)(b)) | To provide the services you or the Venue have engaged us to deliver — routing orders, managing reservations, processing payments, providing customer support. |
| Legitimate interests (Art. 6(1)(f)) | To analyse and improve our platform, secure our services, prevent fraud, conduct B2B direct marketing where permitted, and defend our legal rights. We balance our interests against your rights and freedoms before relying on this basis. |
| Consent (Art. 6(1)(a)) | For non-essential cookies and tracking pixels (Google Ads, Meta Pixel, LinkedIn Insight Tag), for electronic marketing communications where required, and for precise geolocation in Geo Location Lock. You can withdraw consent at any time without affecting prior processing. |
| Legal obligation (Art. 6(1)(c)) | To comply with tax, accounting, anti-money-laundering, and other statutory obligations, and to respond to lawful requests from public authorities. |
| Vital interests (Art. 6(1)(d)) | Only in rare circumstances where processing is necessary to protect the vital interests of an individual. |
We use cookies, pixels, SDKs, and similar technologies to operate ringnbring.com, remember your preferences, analyse traffic, and run marketing campaigns. We deploy and manage these tags through Google Tag Manager.
When you first visit our website, you will see a Cookie Consent Banner. You may accept all cookies, reject all non-essential cookies, or manage your preferences by category. Strictly necessary cookies are always active because the website cannot function without them. You can change your preferences at any time via the “Cookie Settings” link in the website footer.
| Category | Purpose | Examples | Legal Basis |
|---|---|---|---|
| Strictly necessary | Authentication, security, load balancing, remembering your cookie choices. | Session cookies, CSRF tokens, consent state. | Legitimate interests / contractual necessity. No consent required. |
| Analytics | Measure how visitors use the site, count visits, identify popular pages, diagnose errors. | Google Analytics 4 (_ga, _gid). | Consent. |
| Advertising – Search | Measure conversions from Google Ads, retarget visitors, and build advertising audiences. | Google Ads conversion tag, remarketing tag. | Consent. |
| Advertising – Social | Track conversions from Meta (Facebook, Instagram) ads, optimise ad delivery, build custom and lookalike audiences, retarget. | Meta Pixel (_fbp, _fbc). | Consent. |
| Advertising – B2B | Track conversions from LinkedIn campaigns, retarget professional audiences, derive demographic insights. | LinkedIn Insight Tag. | Consent. |
| Tag management | Container that loads the tags above based on your consent choices. | Google Tag Manager. | Operates only when underlying tags are permitted. |
We implement Google Consent Mode v2 so that Google tags adjust their behaviour based on your consent choices. Where analytics or advertising consent is denied, only anonymised, cookieless signals are sent. We enable IP anonymisation in Google Analytics so the last octet of your IP address is truncated before storage.
We honour the Global Privacy Control (GPC) signal where technically feasible by treating it as a withdrawal of consent to non-essential cookies. We do not currently respond to legacy “Do Not Track” browser headers because no consistent industry standard exists.
Refusing analytics or advertising cookies will not prevent you from using the core ordering, service request, payment, or feedback functionality of the Ring n Bring platform at a Venue.
We do not sell your personal data. We share personal data only in the circumstances set out below.
The categories below set out the third parties we rely on to deliver our services. The current list of named sub-processors is maintained at ringnbring.com/subprocessors and is updated when we add, remove, or change a sub-processor.
| Category | Purpose | Examples |
|---|---|---|
| Payment processing | Securely process card payments, wallets, and refunds. | Stripe, CC Avenue, PayTabs, Urway. |
| POS and PMS integration | Route orders into Venue systems; sync folios. | Oracle Micros, Opera, Simphony. |
| Cloud hosting and storage | Run our application and database infrastructure. | AWS, Microsoft Azure. |
| Email and communications | Send transactional and marketing emails and SMS. | SendGrid, Twilio. |
| Analytics and tag management | Measure usage, manage tags. | Google Analytics, Google Tag Manager. |
| Advertising and marketing | Run and measure advertising campaigns. | Google Ads, Meta, LinkedIn. |
| Customer support | Manage support tickets and live chat. | Intercom or similar. |
| Productivity and CRM | Manage internal records and customer relationships. | Google Workspace, HubSpot. |
We carry out due diligence on every sub-processor and require them to provide appropriate technical and organisational measures to protect personal data.
Ring n Bring operates internationally. Your personal data may be transferred to, stored in, and processed in countries outside your country of residence, including the United Arab Emirates, the United Kingdom, the European Economic Area (EEA), and the United States.
Where we transfer personal data out of the United Arab Emirates, we do so in accordance with the UAE PDPL — only where the destination jurisdiction ensures an adequate level of protection, where appropriate safeguards (such as standard contractual clauses) are in place, or where you have given your explicit consent to the transfer after being informed of any associated risks.
Where we transfer personal data from the EEA, the UK, or Switzerland to a country that has not received an adequacy decision from the European Commission or the UK Information Commissioner, we put one or more of the following safeguards in place under Chapter V of the GDPR:
You may request a copy of the safeguards we rely on for a specific transfer by contacting privacy@ringnbring.com.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements.
| Category | Retention Period |
|---|---|
| B2B account data | For the duration of the contract with the Venue, plus 7 years for tax and accounting purposes. |
| Guest order, payment, and request data | Up to 24 months from the date of the transaction (configurable by the Venue), then deleted or anonymised. |
| Feedback (Ring n Rate) | Up to 36 months, after which feedback is anonymised for analytics. |
| Marketing data and prospect records | Up to 24 months from the last meaningful interaction, or until you opt out, whichever is earlier. |
| Website analytics | Google Analytics retention is set to the minimum supported (2 months for event data; 14 months where required for measurement). |
| Cookie consent records | 12 months from collection, or until you change your preference. |
| Support communications | 24 months from resolution. |
| Backups | Encrypted backups are retained for up to 90 days for disaster recovery, after which they are securely overwritten. |
For guest data that we process on behalf of a Venue as a Processor, retention is also governed by the Venue's own instructions and policies as the Controller.
Where we cannot delete data immediately (for example because it is held in encrypted backups), we will isolate it from active processing until deletion is possible.
Ring n Bring is ISO/IEC 27001 certified, and our Information Security Management System (ISMS) is independently audited against this international standard. We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, damage, alteration, or disclosure, including:
No method of transmission over the internet or method of electronic storage is completely secure. While we strive to use commercially acceptable means to protect personal data, we cannot guarantee absolute security.
If you are located in the EEA, the UK, or Switzerland, you have the following rights in relation to your personal data. Equivalent rights are available under the UAE PDPL — see Section 12.1.
As a UAE-based company, we comply with the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the “UAE PDPL”) and apply its principles to our processing of UAE residents' personal data. Where the PDPL applies to you, you have rights that closely mirror those described above, including:
The UAE Data Office (and its successor federal authority responsible for data protection) supervises compliance with the PDPL. To exercise any PDPL right, email privacy@ringnbring.com. You also retain the right to lodge a complaint with the competent UAE authority.
To exercise any of your rights, email privacy@ringnbring.com. We may need to verify your identity before responding. We will respond within one month of receipt of your request. We may extend this period by up to two further months where necessary, taking into account the complexity and number of requests; in that case we will inform you within the first month.
There is no fee for exercising your rights. However, we may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive.
Guest data held by a Venue: If your request relates to personal data we process on behalf of a Venue as a Processor, please contact the Venue directly. We will assist the Venue in responding to your request.
You have the right to lodge a complaint with a data protection supervisory authority if you believe our processing of your personal data infringes the GDPR or other applicable data protection law. You may complain in the EU member state of your habitual residence, place of work, or place of the alleged infringement. Useful starting points include:
We would, however, appreciate the opportunity to address your concerns before you approach a supervisory authority.
We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you within the meaning of Article 22 of the GDPR.
We do use automated logic for operational purposes such as routing requests to the nearest available staff member, prioritising service queues, and surfacing analytics insights for Venues. These activities do not produce legal or similarly significant effects on you. If this changes, we will update this Policy and provide the information required by Articles 13 and 14 of the GDPR.
Our services are not directed to children under the age of 16, and we do not knowingly collect personal data from children. Where a Venue’s offering is directed at families, the relevant adult guest is responsible for any orders or requests made on behalf of a minor in their care. If we become aware that we have collected personal data from a child under 16 without verified parental or guardian consent, we will delete that data promptly. Please contact privacy@ringnbring.com if you believe we may hold such data.
If a personal data breach occurs, we will notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay.
Where we act as a Processor, we will notify the relevant Venue (Controller) without undue delay after becoming aware of a personal data breach affecting data we process on their behalf.
We may update this Privacy Policy from time to time to reflect changes to our services, our tracking technologies, or legal or regulatory requirements. The “Last Updated” date at the top of the Policy will always indicate when it was most recently revised. Where the changes are material, we will provide a more prominent notice (for example, by email to B2B account holders or by a banner on the website) before the changes take effect.
We encourage you to review this Policy periodically. Your continued use of our services after a revised Policy takes effect constitutes your acceptance of the revised Policy to the extent permitted by law.
If you have any questions about this Privacy Policy or our processing of your personal data, please contact us:
| Channel | Detail |
|---|---|
| Privacy enquiries | privacy@ringnbring.com |
| General enquiries | info@ringnbring.com |
| Phone | +971585777667 |
| Website | ringnbring.com |
| Postal address | Al Shmookh Business Center, One UAQ, Umm Al Quwain, United Arab Emirates |
End of Privacy Policy.