Privacy Policy

Last updated 14 June 2026

This policy explains how Bare Links handles personal data. We keep data collection to what the service needs, we never sell personal data, and we are transparent about where data is hosted.

1. Who is responsible

For your studio's account and the people who administer it, Bare Links is the data controller. For the member, booking, and payment records your studio loads into the platform, your studio is the controller and Bare Links processes that data on its behalf as a processor.

If you are a client of a studio that uses Bare Links and want to access or delete your data, contact that studio first — they control it. You can also reach us at admin@barelinks.ae and we will route your request to the right studio.

2. What we collect

  • Account data: the names, emails, phone numbers, and roles of the studio staff who use the console.
  • Member data (on your studio's behalf): client names, contact details, optional date of birth, memberships and credit balances, booking history, and any notes your staff add.
  • Payment metadata: amounts, currency, and Stripe references. Card numbers are handled directly by Stripe — Bare Links never sees or stores full card details.
  • Operational logs: an audit trail of sensitive staff actions, and error diagnostics.

3. How we use data

To provide the booking, payments, invoicing, and front-desk features; to send transactional messages (booking confirmations, receipts, class reminders); and to keep the service secure and working.

Marketing messages are only sent to members who have given explicit, opt-in consent, and members can withdraw that consent at any time. Transactional messages tied to a booking or purchase are sent regardless, as they are necessary to deliver the service.

4. Where data is hosted (international transfers)

Bare Links runs on cloud infrastructure provided by Vercel (application hosting) and Neon (database), and uses Stripe for payments and Resend for email. These providers may store and process data on servers located outside the United Arab Emirates.

We do not claim that data is kept exclusively within the UAE. Where data is transferred internationally, we rely on our providers' contractual and technical safeguards to protect it.

5. Cookies

We use only functional cookies: a secure session cookie to keep you signed in, and a small preference cookie that remembers your chosen language. We do not use advertising or cross-site tracking cookies.

6. Retention

We keep data for as long as a studio's account is active and as needed to provide the service and meet legal, tax, and accounting obligations (for example, FTA invoicing records). When a studio offboards, its public surfaces are taken down and data is retained only as required, then deleted.

7. Your rights

Consistent with the UAE Personal Data Protection Law, you may request access to, correction of, or deletion of your personal data, and you may object to or withdraw consent for marketing.

To exercise these rights for your Bare Links staff account, email admin@barelinks.ae. For a studio's client data, the studio handles the request as the controller and we support them.

8. Security

Access is role-based and enforced on the server, every studio's data is isolated, sensitive actions are logged, and traffic is encrypted in transit. No system is perfectly secure, but we work to protect your data and to limit what each person can see to what they need.

9. Contact

Questions about this policy or your data: admin@barelinks.ae — +971 50 252 5201.

This page is a plain-language summary for transparency and is not a substitute for the signed service agreement between Bare Links and your studio, nor for independent legal advice. An Arabic translation is available on request; where versions differ, the English version prevails until a certified Arabic translation is published.