- Home
- Legal information
- Privacy policy
Legal information
Privacy policy
We take your privacy seriously. This policy explains what personal information we collect, why, to whom we pass it and what rights you have. It was written in accordance with the Protection of Privacy Law, 5741-1981, including Amendment No. 13 to the Law, which came into force in August 2025, and in accordance with the regulations enacted under it.
The policy applies to information given to us through the site, on WhatsApp, by email and through any other channel in which you contact us or book a service.
Who is responsible for the information
The party responsible for the information, that is, the controller of the database, is מאי דובאי תיירות פרימיום (My Dubai Premium Tourism), registration number: Licensed dealer (Osek Murshe) no. 211418942. For any question or request regarding privacy, contact us by email: privacy@mydubai-travel.com.
Where the information comes from
Most of the information comes directly from you, when you contact us or book. Some of the information comes from the suppliers during the booking, for example a confirmation number, a final pick-up time or a change in the time of the service. If a booking was made for you by another person, your details reached us from that person, and this policy applies to them as well.
Providing information is voluntary
There is no legal obligation to give us personal information, and providing information depends on your will and consent. However, without certain details, such as name, date and number of participants, we will not be able to check availability or book a service for you.
What information is collected
- The availability widget: in the widget you choose an attraction, ticket type, date and number of participants, and your choice becomes a WhatsApp message that you send yourself. The site does not store the content of the widget on the server, and the information reaches us only if you chose to send the message. WhatsApp is a third-party service with its own privacy policy.
- The enquiry form ("Holiday planner"): an enquiry you send through the form is stored by us in an internal management system of the business, and is not only sent by email. Stored there are: name, phone, email address if you gave one, preferred method of contact, the trip details you filled in (dates, number of participants, ages, destination, hotel level, meals, interests, transfers, budget and free-text notes), the page from which the enquiry was sent and the source through which you reached the site. Your IP address is not stored with the enquiry; it is used only to prevent automated submissions and is not stored alongside the details. Access to enquiries is limited to the business's staff according to permissions, and actions in the system are logged. Retention period: an enquiry is kept by us as long as you have not asked us to delete it. We do not delete enquiries on our own initiative, so that we can continue to serve you, handle repeat enquiries and comply with the obligations the law imposes on us. At any time you may ask us to delete your enquiry, and we will do so within the time limits set by law — see "Your rights" below.
- Source of arrival: if you reached the site through an advertising link or a search engine, the campaign details in the address (utm) and the referring site are stored with the enquiry, so that we know which channel brought you. These details are kept in your browser for the duration of the visit and are sent only if you sent an enquiry.
- Details for booking: when you book, we may ask for additional details that the supplier requires, such as the full names of the travellers as they appear in the passport. We will ask only for what is needed for the specific service.
- Sensitive information: if you choose to tell us about a medical need, a limitation or an accessibility need, we will use the information only to adapt the service, and will pass to the supplier only what is needed for that purpose.
- Payment information: the site does not collect credit card details. Only the transaction details required for bookkeeping and for reporting under the law are kept.
- Technical information: the site's hosting server may log basic technical data, such as IP address, browser type and time of visit, for security and operational purposes. The site does not run measurement or advertising tools without consent. See the Cookie policy.
- Measurement of site usage (only if you approved): if you clicked "Allow analytics" in the cookie banner, usage data is sent to the measurement server of MY DUBAI itself (hub.mydubai-travel.com): which pages you viewed, for how long and how far you scrolled, which buttons and links you clicked, which options you selected from a list in the widgets (attraction, ticket type, date, number of participants), whether an enquiry was sent (the enquiry code only) or a newsletter sign-up, the device type (mobile, tablet or computer), and the site or campaign you came from. No text you typed is sent: not a name, not a phone number, not an email address, and not a flight number or a hotel name. The IP address is not stored: a hash of it and of the browser type is stored, with a key that changes every day, so that visits from different days cannot be linked. If you did not approve, the tool is not loaded at all.
- External providers loaded in the page: none. The fonts, style files, scripts and images are all served from the site's server. Your browser does not contact a third-party server while browsing, and therefore your IP address is not exposed to anyone other than us. The measurement server (hub.mydubai-travel.com) belongs to MY DUBAI and is not a third party.
Summary: what, why and to whom
| Information | Purpose | Who receives it |
|---|---|---|
| Name and phone | Responding to the enquiry, coordination and updates | Us, and the supplier when it needs to contact you on the day of the service |
| Dates, participants and children's ages | Checking availability, price and booking | Us and the supplier |
| Hotel and flight number | Pick-ups and transfers | Us and the supplier carrying out the pick-up |
| Names as in the passport | Issuing a ticket or registering at the hotel, when the supplier requires it | Us and the supplier |
| Medical or accessibility need | Adapting the service | Us, and the supplier only to the extent necessary |
| Email for the mailing list | Offers and updates, with your consent | Us only |
| Enquiry from the "Holiday planner" form | Responding to the enquiry, building an offer and following it up | Us only, in an internal management system |
| Source of arrival at the site (utm, referring site) | Knowing which advertising channel brought the enquiry | Us only |
| Site usage data (only with consent to analytics) | Improving the site and knowing which pages bring enquiries | Us only, on our measurement server |
Data minimisation
We collect only the information needed for the purposes set out here, and keep it only as long as it is needed. Therefore:
- Do not send us a passport photo, an identity number or credit card details, unless we have explicitly asked for a specific detail for a specific service.
- Do not send information about other people without their knowledge and consent. When you book for additional travellers, tell them that their details have been passed to us for the purpose of the booking.
Why we use the information
- To check availability and price, and to respond to your enquiry.
- To book the service for you, coordinate it with the supplier and send you a booking confirmation.
- To provide service before and during the trip, such as an update about a change in pick-up time.
- To handle cancellations, changes, refunds and complaints.
- To comply with obligations under the law, such as bookkeeping, and to protect our rights in the event of a dispute.
- To maintain the security of the site and prevent misuse.
We will not use the information for another purpose without consent, and we will not sell it to anyone.
WhatsApp conversations
Correspondence with us is kept in the business's WhatsApp application, so that we can go back to the booking history and serve you. You can ask us to delete the correspondence after the booking has ended, subject to the information the law requires us to keep. The encryption of the messages and their storage on WhatsApp's servers are subject to WhatsApp's policy.
No profiling and no automated decisions
We do not build a marketing profile of you, do not combine the information with other databases and do not make automated decisions about you. Every request is handled by a person.
Marketing mailings and the mailing list
We will not send you advertising messages without prior explicit consent, in accordance with the Communications (Telecommunications and Broadcasting) Law, 5742-1982. Service messages about an existing booking are not marketing mailings.
- Joining: anyone who enters their email address in the "Stay in the loop" form on the site agrees to receive mailings from us: offers, updates and holiday tips. Only the email address and the time of joining are stored.
- Use: the list is used by us only. We do not sell it and do not pass it to any other party for mailing purposes.
- Removal: every mailing we send includes a one-click unsubscribe link. You can also write to us at privacy@mydubai-travel.com or on WhatsApp, and we will remove you immediately. An address that has been removed no longer receives mailings.
Who the information is passed to
- Local suppliers: attraction operators, tour companies, transfer companies and hotels in the United Arab Emirates, which provide you with the service. They receive only what is needed to carry out the booking.
- Service providers to the business: website hosting, communication services and bookkeeping, for the purpose of operating the business only.
- Authorities: when the law requires it, or under an order of a competent authority.
Our obligations regarding the information
- To use the information only for the purposes for which it was given, or for a purpose to which you consented.
- To keep information accurate and up to date, and to correct it when you ask.
- To require service providers that hold information on our behalf to protect it, secure it and use it only according to our instructions.
- To limit access to the information only to those who need it in order to serve you.
Transfer of information abroad
The services are provided in the United Arab Emirates, and therefore the booking details are transferred to the suppliers there. Some of the service providers to the business may also store information in other countries. Transfer of information outside Israel is carried out in accordance with the Protection of Privacy (Transfer of Data to Databases Abroad) Regulations, 5761-2001. We transfer only what is needed to perform the service you booked, and by providing the details for a booking you consent to this transfer. The law that applies to data protection in the United Arab Emirates differs from the law in Israel.
Information security
We take reasonable organisational and technological measures to protect the personal information in our possession, in accordance with the nature of the information and the requirements of the law.
Access to the system in which enquiries are stored is limited to authorised users only. Each user has a separate personal account, and access is protected by strong means of authentication — two-step verification or a personal security key (Passkey) tied to a device. Actions in the system are logged, and access permissions are granted according to operational need.
The site uses encrypted communication, and we take measures to reduce unauthorised access, misuse, alteration, loss or exposure of information.
An IP address is not stored as part of the enquiry record and is not attached to the notification email. For the purposes of site security, preventing misuse and operating the server, an IP address may appear temporarily in technical logs managed by the hosting provider, in accordance with its settings and the requirements of the law.
No security system is completely immune to intrusion, malfunction or unauthorised use. In the event of a security incident, we will act in accordance with the provisions of law that apply to us.
If your information is exposed
If you suspect that someone has gained unauthorised access to information you gave us, or you received a message impersonating MY DUBAI, contact us immediately by email or on WhatsApp. We never ask for credit card details or passwords in a message, and we will not ask you to install software or to click a payment link that did not appear in the booking confirmation.
How long the information is kept
Measurement data is kept for 13 months, and is then deleted.
Information is kept as long as it is needed for the purposes in this policy, and as long as the law requires it to be kept, for example for bookkeeping purposes or the limitation period for claims. After that it is deleted or anonymised. We do not set in advance a date for deletion on our own initiative: information is kept as long as you have not requested its deletion, and subject to the retention obligations the law imposes on us. A deletion request is the way to delete information kept about you, and it is always available to you, without conditions and free of charge.
Your rights
- Access: to ask to review the information kept about you.
- Correction and deletion: to ask to correct information that is not correct, complete, clear or up to date, or to delete it. A deletion request applies to all copies in our possession — the record in the enquiry system, the correspondence in our mailbox and any other working copy. Information that the law requires us to keep, such as the accounting documents of a booking that was carried out, will be kept until the end of the period set by law, and we will tell you what is kept and why.
- Removal from mailings: to ask that we not send you advertising, and to ask that your details be deleted from the mailing list.
- Withdrawal of consent: to withdraw consent you gave, for example to the operation of a measurement tool, at any time. The withdrawal does not apply to use made before it.
Send the request by email to privacy@mydubai-travel.com. To protect you, we may ask to verify your identity before we provide information. We will respond within the time limits set by law. If a request for correction or deletion is refused, we will explain why. If you are not satisfied with the answer, you may contact the Privacy Protection Authority or the court, in accordance with the law.
How to contact us about privacy
So that we can handle the request quickly, state in it the name and the phone number you used when contacting us, what you are requesting (access, correction, deletion or removal from mailings) and the relevant information. If a booking was made for you by another person, for example a family member, you may contact us directly regarding your information. In response to an access request, you will receive the information kept about you in a clear and understandable form.
Minors
The site is intended for adults. Anyone under the age of 18 should not send us personal information. The ages of children and the details of minors taking part in the service are provided by their parents or by those responsible for them.
Database registration and privacy protection officer
As of the date this policy was updated, and in accordance with the nature of the business's activity, the purposes of processing the information and the scope of the information stored, the database used by MY DUBAI is not among the types of databases required to be registered in the Register of Databases under the Protection of Privacy Law.
Likewise, as of this date, MY DUBAI is not subject to an obligation to appoint a privacy protection officer.
The fact that the database is not required to be registered, or that there is no obligation to appoint an officer, does not derogate from the obligations that apply to the business under the Protection of Privacy Law and the regulations made under it, including the obligations concerning information security, the use of information for the purposes for which it was collected, keeping it only as long as it is needed, limiting access to it and safeguarding the rights of data subjects.
If in the future the nature of the activity, the scope of the database, the types of information processed or the provisions of the law change in a way that requires registering a database, giving notice to the Privacy Protection Authority or appointing a privacy protection officer, we will act accordingly and update the policy as necessary.
Changes to the policy
We may change this policy. The current version is always published on this page, and a material change in the way information is used will be made only in accordance with the law.