Privacy policy
In short: the site needs no sign-up, shows no ads and sets no cookies of its own. Everything you choose — cards, favourites, settings — stays in your browser and is not sent anywhere.
What is stored in your browser
- The cards you picked and their tiers, favourites, catalog filters, the section you had open.
- Sound and music settings, and flags for hints you have seen and for this notice.
- If you tap “Near me” — an approximate point (about 10 m) used to show distances. It is not sent to our server.
- This is browser storage (localStorage), not cookies. To delete it all, clear site data for hasm.ae in your browser settings.
How visits are counted
- Vercel Web Analytics — anonymous page-view statistics without cookies.
- Our own onboarding counter: for each day we keep only the number of events (“card picker shown”, “cards selected”, etc.) and the page language — no addresses, devices or identifiers.
- Each event is sent at most once per session; there are no advertising or third-party trackers.
Services the site relies on
- Vercel — hosting: like any server, it keeps technical request logs (including IP address).
- Supabase — the database the offer catalog is loaded from.
- Google Fonts — your browser loads the fonts from Google’s servers.
- “Terms at partner” links open the programs’ and banks’ own sites, where their own policies apply.
The Telegram bot @skidkiuaebot (if you use it)
- We store your Telegram ID, language, chosen cards and profile settings, the last location you sent, your questions and the answers, and your ratings — to answer for your cards and improve the answers.
- Answers are written by Claude (Anthropic), voice messages are transcribed and voiced by ElevenLabs, data is stored in Supabase, and messages go through Telegram.
- The /forget command deletes your profile and everything linked to it.
What we don’t do
- We don’t sell data or share it for advertising.
- We don’t collect e-mails, phone numbers or card details — the site takes no payments and needs no sign-up.
Who is responsible for your data
The data controller under the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the “Law”) is Ivan Doronin, who runs the project and is also the contact for data-protection matters. No Data Protection Officer is appointed: Article 10 requires one for high-risk processing, systematic assessment or large volumes of sensitive data, and neither the site nor the bot processes such data. How to reach us: e-mail ivan.doronin@gmail.com, a message to the bot or the link at the bottom of this page (Article 19).
Legal basis
- The site: we do not process your personal data on our servers — your choices and settings stay in the browser and the counters are anonymised (Article 1, “Anonymisation”).
- The bot: you write to it and ask for an answer — processing is needed to act on your request (Article 4(9)) and is based on your consent given by that action (Article 6). You can withdraw consent at any time with /forget; this does not affect processing before withdrawal (Article 6(2)).
- We collect only what an answer needs, for a clear purpose, and keep it no longer than needed (Article 5).
How long we keep data
- In your browser — until you clear the site data yourself.
- The bot profile, questions and answers — while you use the bot; /forget deletes them immediately. Your offer reports (“worked”, “not accepted”, a comment) then stay without any link to you — we use them to fix the catalogue.
- Anonymous counters (how many times a day the card picker was shown, etc.) are kept indefinitely: they cannot identify anyone.
Transfers outside the UAE
The services the site and bot run on (Vercel, Supabase, Anthropic, ElevenLabs, Telegram) host servers outside the UAE as well. Bot data is passed to them because this is needed to answer your request and with your consent (Article 23(1)(b) and (d)). We choose providers that encrypt data and are contractually bound to protect it.
How we protect data
- Encryption in transit: the whole site is HTTPS-only with a two-year HSTS policy, and http requests are redirected. The bot, database and services exchange data over TLS (Article 20(1)(a)).
- Encryption at rest: the Supabase database encrypts disks and backups with AES-256 (Article 20(1)(a)).
- Access control: every bot table has row-level security with no public rules — only the bot server and the project owner can read or write; keys live in protected hosting secrets, not in the code (Articles 7 and 20).
- Pseudonymisation and minimisation: in the database a user is an internal number and a Telegram ID, with no name, phone or e-mail; reports to the owner contain no user identifiers (Article 7(2)).
- Site hardening: a Content Security Policy, MIME-sniffing protection and a strict referrer policy.
- Testing: every code change is automatically checked for keys in the repository and for user identifiers in reports; measures are reviewed whenever processing changes (Article 20(1)(d)).
If a data breach happens
- The incident owner is Ivan Doronin. When we learn of a possible breach (ourselves, from a provider or from a user), we shut off access immediately, work out whose data and what data is affected, and document the incident.
- We notify the UAE Data Office with a description of the breach, its effects and the measures taken — within the period and in the manner set by the Law’s Executive Regulations (Article 9(1)).
- If the breach could harm the confidentiality of your data, we tell you in a bot message and explain what we have done (Article 9(2)).
- Providers processing data on our behalf must tell us about a breach as soon as they learn of it (Article 9(3)).
Your rights
- Find out, free of charge, what data of yours is processed, why, who it is shared with and how long it is kept (Article 13).
- Receive your data in a machine-readable form or have it moved to another service (Article 14).
- Correct inaccurate data or have it erased (Article 15): change cards and settings in the bot with /settings; /forget deletes everything.
- Restrict processing (Article 16) or object to it (Article 17).
- Ask a person to review the result of automated processing (Article 18).
- Withdraw consent at any time (Article 6(2)) and complain to the UAE Data Office (Article 24).
How to make a request: e-mail ivan.doronin@gmail.com or message @skidkiuaebot from the Telegram account the data belongs to — this is how we confirm the request is yours (for bot data, include your Telegram username in the e-mail and we will confirm in the bot). We reply within 30 days, free of charge.
Automated processing
- Bot answers are written by an AI model (Claude, Anthropic) from your question, your chosen cards and, if you sent it, your location. They are suggestions about where it pays to use a card — not decisions with legal or similarly significant effects on you.
- The order of places in the catalogue and the card picker on the site are computed in your browser from your own answers and settings; there is no profiling for advertising or marketing.
- You can ask for a person to review an answer (Article 18(4)) and to learn how it was produced (Article 13(1)(c)).
Questions and requests
The project is run by Ivan Doronin. For questions about your data, or to ask us to delete or correct something, e-mail ivan.doronin@gmail.com or message me on LinkedIn. If this policy changes, the date above will change too.