Privacy Policy
Last updated: May 2026
1. Data Controller & Collection
YallaTonight ("Data Controller") collects personal data strictly necessary for the provision of its technical booking and payment facilitation services. Data collected includes:
- Identity Data: Full name, phone number, and email address.
- Transactional Data: Booking history, ticket details, loyalty points.
- Payment Data: Payment reference numbers only. Card details are processed and stored exclusively by PCI-DSS compliant payment processors. YallaTonight does not store card numbers.
- Technical Data: IP address, browser type, device ID, and session data for security and fraud prevention purposes.
- KYC Data (Partners only): Government-issued ID documents for identity verification, stored with restricted access.
2. Legal Basis & Purpose of Processing
YallaTonight processes personal data on the following legal bases: (i) contractual necessity — to execute bookings and deliver tickets; (ii) legitimate interests — to prevent fraud, maintain platform security, and improve services; (iii) legal obligation — to comply with Egyptian financial regulations and anti-money laundering requirements; and (iv) consent — for marketing communications, which may be withdrawn at any time.
Data is used exclusively to: process and confirm bookings; issue digital tickets; facilitate secure payments; send transaction and event notifications; prevent fraudulent activity; and improve platform functionality.
3. Data Sharing & Third Parties
YallaTonight does not sell, rent, or trade personal data to any third party. Data is shared only with:
- Event Organizers: Guest name, ticket quantity, and booking reference — solely for event entry management.
- Payment Processors (Paymob, Fawry): Transaction-specific data required to process payments securely.
- Competent Legal Authorities: When required by Egyptian law, judicial order, or regulatory authority.
All third-party processors are contractually bound to handle your data in accordance with applicable data protection standards.
4. Data Security & Retention
YallaTonight implements industry-standard technical and organizational security measures including TLS/SSL encryption for data in transit, bcrypt password hashing, CSRF token protection, rate limiting, and role-based access control. Despite these measures, no internet system is 100% secure, and YallaTonight cannot guarantee absolute security against all threats.
Retention: Active account and booking data is retained for the duration of your account plus 3 years for legal and accounting compliance. KYC documents are retained for 5 years. Access logs are purged after 90 days. You may request deletion of non-legally-required data by contacting our support team.
5. Cookies & Tracking
The Platform uses only functional, first-party session cookies strictly necessary for authentication, language preferences, and security (CSRF tokens). We do not deploy any third-party advertising, analytics, or tracking cookies. Disabling cookies in your browser will prevent you from using authenticated features of the Platform.
6. Your Rights as a Data Subject
In accordance with applicable Egyptian data protection principles and international best practices, you have the right to:
- Access: Request a copy of personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of data where it is no longer necessary, subject to legal retention obligations.
- Portability: Request your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests.
To exercise any of these rights, submit a request via our Support page. We will respond within 30 calendar days.
7. International Transfers
Your data is primarily stored and processed within the Arab Republic of Egypt. Where data processing involves systems operated by internationally-based payment processors, such transfers are governed by the respective processor's data transfer agreements and are conducted under appropriate safeguards. By using the Platform, you consent to such transfers as necessary for the provision of our payment facilitation services.
8. Changes to This Privacy Policy
YallaTonight may update this Privacy Policy to reflect changes in applicable law or our data processing activities. Material changes will be announced via email to registered users and/or a prominent notice on the Platform. The date of the last revision is displayed at the top of this page. Continued use of the Platform after the effective date of any revision constitutes your acceptance of the updated Privacy Policy.