Alshaya’s Privacy Notice for Branded Websites and Loyalty Programs
This Privacy Notice describes how M.H. Alshaya Co. W.L.L. and its affiliates (referred to as "Alshaya Group", "we," "our" "us" or "Alshaya"), as a data controller, collect and process your personal information through this website (“Website”). When we mention "Alshaya," "we," "us" or "our" in this Privacy Notice, we are referring to the relevant company within the Alshaya Group that is responsible for processing your data. Please see details here. "You" or "Your" refers to the data subject (such as Website visitors/ customers / employees) whose personal data is processed by us.
Personal Data We Collect About You
Alshaya currently operates over seventy brands and has loyalty programs, including AURA, Starbucks Rewards and H&M Membership. To learn more about our own loyalty program AURA, please visit: [https://aura-mena.com/en].
The Privacy Notice covers all personal information processing arising from your interactions with us through any brand website and/or loyalty program Websites (and/or related Applications) operated by us, your use of any Alshaya product, service, application or program including any trial where we act as a controller of your personal information (collectively referred to as “Services”), your visits to our physical stores, your registration and participation our events, webinars, and programs, as well as any communications with us by any means, including interactions with our branded social media pages and ads, and your participation in surveys, research or other similar activities organized by us.
We also process information collected by cookies and similar technologies when you interact with our Websites and Applications to provide a more personalized service and to ensure high level of security. For more information about cookies and how we use them, please refer to our Cookie Notice.
You can see examples of personal information collected here [LINK to the table at the end of the document]. Please note that certain information is strictly required for the functionality of our applications, and we will inform you accordingly during the registration process. This does not include optional information such as date of birth, gender or nationality, that if provided will be used for an enhanced user experience, and we will request your consent for the use of any such optional information.
We may also process aggregated data from you which does not directly or indirectly identity you. If we combine this data with other personal information we hold about you, we will process it in accordance with this Privacy Notice.
Third Parties and Third-Party Links
We work with third parties, such as advertising companies, social media networks, search engines and ad serving companies to provide you with ads that are relevant to you. We provide these companies with information about you that helps them to serve you such relevant Alshaya ads as well as to measure the ads effectiveness. We may share your personal data with third party marketing, security and analytics service providers to help us market, secure and understand the use of the Services and our Websites and Applications. These companies will use this data to create a personalized advertising and content profile, to provide you with personalized adverts and content, to measure advertising performance and to develop and improve their services. If you do not wish to see personalized advertising, you can adjust and manage your cookies preferences visiting our Cookies Notice [LINK].
Our Websites and Applications include social media buttons, and both Alshaya and the social media network will process your personal information using cookies and plug-ins for targeting advertising purposes, which is a form of online advertising that focuses on your interests and preferences. We use cookies to track your social media visits. To learn more about how we use cookies, please visit our Cookies Notice [LINK].
Our Websites and Applications may also include links to third party websites. If you decide to leave our Websites or Applications and visit a third-party webs
How We Use Your Personal Data and For What Purposes
We will use your personal data for the several purposes including the ones listed here [LINK to the table at the end of the document]. Please note that we may process your personal data under different legal basis depending on the purpose.
We will only use your personal data when we have a valid legal basis to do so as follows:
Consent: When you give us your consent, for example, to allow us to have access to your location or for a specific purpose that we communicate to you, such us when you join Aura (and accept the terms of the service) you can opting-in to marketing communication through email or SMS or both, and consent to receive communication about products, services, offers, and news for all our Alshaya brands of your choice.
Aura has Friends & Family accounts which allow the account holders to send messages to third parties to collect Points under a common balance and to use Friends & Family Points to redeem against purchases and rewards. If you choose to use our application Friends & Family functionality, you must first obtain their permission to provide their personal information, such as their name, phone number or email address, to us. We encourage you not to send any invitation until you get their consent first. The referred information will be used by us for the purpose of contacting the third party on your behalf to join the Friend & Family group that you created in Aura.
You can withdraw your consent at any time by contacting us at [email protected].
Performance of a Contract: When you enter into a contract with us (for example, by accepting the terms of our loyalty programs) and provide personal information to us that is necessary to perform our services under the contract. Failure to provide the requested data may result in the cancellation of a service. You can expect to hear from Alshaya about all our brands within our loyalty programs because you have accepted the terms of the service.
Legitimate Interest: Legitimate interest applies whenever we use personal data, for example, for detecting and preventing fraud, to protect the security of our customers, ourselves or others, as well as for other purposes listed here
Comply with a legal or regulatory obligation: Which means processing your personal data where it is necessary for compliance with a legal or regulatory obligation that we are subject to.
Children’s Personal Data
Our websites, Alshaya applications, and online services are not intended for use by any data subjects under the age of thirteen. However, we cannot prevent certain users, including children, from falsely representing their age to gain access. If you believe we have collected information about your child, please contact us immediately using the information provided in the “Contact Us” section of this Privacy Notice.
Managing Your Marketing Preferences
We respect your privacy and provide control over our marketing practices:
- We will send you marketing communications that are interesting, relevant, and aligned with your preferences.
- Communications preferences for can be managed within your Preference Center settings that is available on the AURA App.
- You will receive marketing communications based on your requests, purchases, or competition registrations, unless you opt out.
- You can manage your marketing preferences by using the "unsubscribe" link in our emails.
Disclosures of Personal Data
We share your personal data within Alshaya Group, ensuring consistent rules for data protection. Some external third parties may process data outside your country, with appropriate safeguards implemented. For further details of these safeguards please refer to our “Contact Details” section
We will share your personal data with the following parties for the purposes mentioned in this Privacy Notice:
- Companies within Alshaya Group.
- Third-party service providers, professional advisers, regulators, authorities, and authorized law enforcement agencies. Some are based outside the Middle East or in or outside the European Economic Area (EEA).
- Selected Brands with whom Alshaya has a relationship and who may contact you or use your data only for reasons pre-agreed with Alshaya, including sending you marketing communications. Further details of our brands portfolio can be found here
Some of our external third parties are based outside the country where your data is processed or where you are based, so the processing of your personal data will involve a transfer of data outside the applicable country. We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the applicable country data protection legislation.
Where we use certain service providers, we ensure that we have the necessary measures in place to protect your personal data. For more information, please refer to our “Contact Details” section.
Automated Decision Making
We use automated methods to process your data for the purposes of evaluating certain personal aspects of you as an end user (profiling). Examples of these purposes include the improvement of our Services by evaluating how you use them, as well as fraud prevention.
Security of Processing Personal
Data We protect your information using technical, physical, and administrative security measures to reduce the risk of loss, misuse, unauthorised access, disclosure, or modification of your information. You are responsible for protecting your password(s) and maintaining the security of your devices.
We have implemented appropriate security measures to prevent accidental loss, unauthorized access, alteration, or disclosure of your Personal Data. The Personal Data you enter on HTML pages (contact forms) and that we store is transmitted to Alshaya in encrypted form (TLS – Transport Layer Security) via the public data network.
Data Retention
We keep your personal information only for as long as is it is necessary to fulfill the processing purposes described in this notice, as well as to comply with applicable legal or regulatory requirements. For these purposes, we have established the necessary data retention policies and processes.
Your Privacy Rights
If you have any questions as to how we collect and use your personal information, or if you wish to exercise any of the following rights, please contact us at [email protected]. To ensure the security and accuracy of your personal data, we may need to verify your identity or request further information when you contact us.
- Right to request access to the personal information that we hold about you.
- Right to rectify your personal information when the data is inaccurate or incomplete.
- Right to request that we delete your personal information under certain circumstances.
- Right to object to the processing of your personal data; including the right to request that we stop sending you marketing communications.
- Right to request that we transfer your personal information in electronic format to another organization or you.
- Right to withdraw your consent to the processing of your personal data whenever our processing is based on your consent. - Right to obtain a copy of personal information safeguards used for transfers outside the jurisdiction where we process your personal information.
- Right not to be subject to a decision based solely on automated processing (including profiling).
- If you believe your rights have been violated or not satisfied with our privacy practices, you have the right to lodge a complaint with the relevant supervisory authority. We encourage you to contact us first to amicably address any concerns.
Contact Us
Postal Address: Data Protection Officer, Alshaya Group, Burj Alshaya, Al Soor Street, Al Mirqab P.O. Box 181, Safat 13002, Kuwait
Email address: [email protected]
Contact Us
Examples of purposes for Using Your Personal Data