Privacy Policy
Bucket helps UAE households bring their bills into one place. This policy explains what personal data we collect, why, how we protect it, and the choices you have — in line with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, “PDPL”).
Who we are
Bucket (“Bucket”, “we”, “us”) is the data controller for the personal data described here. You can reach our privacy team any time at [email protected].
What we collect
Identity & verification
When you sign in with UAE PASS, we receive your verified name and Emirates ID and a confirmation that your identity is verified. If you sign up with a phone number, we collect that mobile number and verify it by one-time code.
Your bills & household
- Biller accounts you connect (biller name and the account number you enter)
- Bill amounts, due dates and payment history that result from those connections
- Household members you invite and the bills shared within your household
Payments
When you choose to pay a bill, payment is processed by a licensed payment partner. Card details are entered into the partner’s secure fields and tokenised — Bucket stores only a masked reference (e.g. card brand and last four digits), never your full card number.
Device & usage
We collect basic device and app information (device type, app version, push token, and crash/diagnostic data) to keep Bucket reliable and secure.
How we use your data
- To provide the service — fetch and organise your bills, send reminders, and let you pay
- To verify your identity and secure your account
- To detect duplicate subscriptions across your household and show potential savings
- To send you service notifications you’ve enabled (e.g. bill-due reminders)
- To prevent fraud, meet legal obligations, and improve reliability
Legal basis
We process your data on the basis of your consent (which you can withdraw at any time), the performance of our contract with you, and where necessary to meet legal obligations. Each adult in a household consents to their own data being included in a shared view.
Who we share with
We do not sell your personal data. We share it only with:
- Billers & aggregators — to fetch your bills and confirm payments, using the account details you provide
- Licensed payment partners — to process the payments you initiate
- Service providers — such as cloud hosting, SMS delivery and error monitoring, under contract and only as needed to run Bucket
- Authorities — where required by law
Where your data lives
We host Bucket’s data with the goal of keeping personal data of UAE users within the UAE region, and we apply appropriate safeguards for any processing by our service providers.
How long we keep it
We keep your data for as long as your account is active and as needed to provide the service and meet legal and financial-record obligations. When you delete your account, we delete or anonymise your personal data, except where we must retain limited records by law.
Security
We protect your data with encryption in transit, access controls, and sensible operational safeguards. No system is perfectly secure, but we work to protect your information and to notify you and the authorities of any incident as required by the PDPL.
Your rights
Under the PDPL you may:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data and close your account (in-app: Profile → Log out → delete account, or email us)
- Withdraw consent, or object to or restrict certain processing
- Request a copy of your data in a portable format
To exercise any of these, email [email protected]. You also have the right to complain to the UAE Data Office.
Children
Bucket is for adults (18+). We do not knowingly collect data from children.
Changes
If we update this policy, we’ll change the date above and, for material changes, notify you in the app.