Release to refresh
← Back

Dubuz — Global Privacy Policy

Last updated: 22 September 2026 Applies to: the Dubuz websites, including https://dubuz.com and our regional addresses, and the Dubuz mobile applications we publish.

This is a jurisdiction-neutral policy written to be used wherever Dubuz operates. It does not treat the law of any single country as the governing framework. Region-specific detail is kept in the Annex at the end and can be filled in as we expand.

1. Who we are and what this policy covers

Dubuz is a multi-region online classifieds marketplace. People use it to advertise things for sale, look for work or hire, run business profiles, message each other, and post short videos and stories.

This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the choices and rights you have.

It applies to:

  • our websites, including https://dubuz.com and the regional addresses we operate;
  • the Dubuz mobile applications we publish;
  • everyone who uses them: visitors who browse without an account, registered users, business accounts, and people who contact us.

It does not apply to third-party websites or services you reach through Dubuz, such as payment provider pages, advertising, or a seller's own website. Those have their own privacy policies.

Dubuz serves more than one country. We detect your approximate country from your IP address so we can show the right region, currency and language, but you can change it.

2. The organisation responsible for your data, and how to contact us

The organisation responsible for your personal data (the "data controller") is the operator of the Dubuz marketplace, referred to in this policy as "Dubuz", "we" or "us". Where a legal entity name or registered address is required by the law that applies to you, we will provide it on request using the contact details below.

For any privacy question or request — including the rights described in section 9 — use the contact details above. We aim to respond within a reasonable period and within any deadline the law that applies to you requires.

If we are required to appoint a statutory Data Protection Officer, a privacy lead, or a local representative in a country where you live, we will publish their contact details on this page.

3. What personal data we collect

"Personal data" means information that identifies you or can be linked to you. We collect the categories below.

3.1 Account and identity data

  • Name, email address, and phone number (if you provide one).
  • Password. We store passwords in hashed form; we do not keep your password in plain text.
  • Date of birth, where you provide it. See section 11 for how we use it and its limits.
  • Social sign-in identifiers: your Google account identifier and your Firebase user identifier, plus the name, email address and profile photo your provider shares with us.
  • Whether your email address and phone number are verified.
  • City, country, preferred language, and theme preference.
  • Account status, suspension information, and any appeal deadline.
  • Activity timestamps, such as when you last signed in and when you were last active.

3.2 Business profile data

If you use a business account: business name and public URL, logo, cover photo, description, category, website, city, business phone number, verification and approval status, package/subscription, and listing limits.

3.3 Verification documents

If you ask us to verify you or your business, you may upload a photo or scan of your personal ID or passport, your trade licence, and proof of address. We also store the document type, the original file name, the review status, an expiry date where relevant, and internal review notes.

These are sensitive documents, collected for verification only. They are used by our review team to verify you or your business. They are not published, listed, searchable, or otherwise made available to other users or the general public. Please read section 8 for how they are stored and served.

3.4 CVs, résumés and job applications

  • CV files you upload, their original file names, and CV content such as personal details, education, experience, skills, languages, and any photo you add.
  • When you apply for a job listing: the CV you send, a cover letter or message, and the contact name, email address and phone number you provide. Employers may also keep private notes about your application.

3.5 Listings and content you post

  • Listing title, description, price, currency, category, and any custom fields.
  • Contact name, phone number and WhatsApp number, and whether you chose to hide your phone number.
  • Photos, videos, and story/reel media and thumbnails.
  • The location you choose for a listing, including precise latitude and longitude, city, and country.
  • Activity counts and status, such as views, contact clicks, expiry, and reposting.

3.6 Messages and conversations

  • Messages you send and receive: content, sender and recipient, subject, read status, and attachments.
  • If someone contacts a seller without an account, we store the guest name, email address and phone number they type in.
  • Conversation records, including participants and subject.

3.7 Social and engagement data

Reviews and ratings, comments, reactions and likes, shares, saved listings, saved searches, business follows, and reel/story interactions (reactions, comments and views).

3.8 Recommendations and profiling

To build content recommendations, we keep records of how the marketplace is used: which items were viewed, saved or contacted, with the listing, category or reel and a session identifier; interest scores linked to your account; and feed sessions (which listings and reels were shown, page count, and last activity). These are behavioural profiles linked to your account or session.

3.9 Payments and transactions

  • Amount, currency, status, type, the package or listing involved, a transaction reference, and the payment method.
  • Limited card details returned to us by the payment provider: card brand, card type, and the last four digits.
  • We do not store your full card number or your card security code (CVV). Card details are entered on the payment provider's systems and handled by them.

3.10 Location data

Listing coordinates (latitude and longitude), and your city and country. Device location, if you grant the app location permission, is used when you pick a location for a listing or use a map. We use your IP address to detect your approximate country so we can show the right region, currency and language.

3.11 Device, technical and security data

  • Push/device details for notifications: device token, platform, device identifier, app version, and last seen time.
  • Session data: IP address, browser user agent, session data, and last activity.
  • Page-view records: the page address, referrer, browser user agent, IP address, session identifier, your internal account reference if you are signed in, device type, and time of visit.
  • Activity and audit records: the action taken, the item it relates to, a description, additional data, and IP address.
  • Password-reset records, API access tokens, one-time codes for phone and email verification (stored as hashes, with attempt counts and expiry), and account-deletion confirmation tokens (stored as a hash, together with the IP address that requested the link).

3.12 Reports and abuse prevention

Listing and reel reports (reason, message, and administrator notes), replies to reports, and blacklist entries (email address, phone number, IP address or domain) used to prevent abuse.

3.13 Analytics

We measure page views using our own first-party records. We do not load a third-party web analytics product, such as Google Analytics, on our public pages. We do serve third-party advertising, described in section 12.

3.14 Age

Dubuz is an 18+ service. By using Dubuz you confirm that you are 18 years of age or older. We do not verify age against identity documents. See section 11.

4. Why we collect it, and our lawful basis

Data-protection laws generally require a "lawful basis" for processing personal data. We rely on the following bases, as they apply to the relevant processing and to the laws that apply to you:

  • your consent;
  • performance of a contract with you;
  • compliance with a legal obligation;
  • protection of vital interests;
  • a public-interest task; and
  • our legitimate interests, balanced against your rights.

Because we operate in more than one country, more than one framework may apply. Where the law that applies to you gives you stronger protections than this policy describes, those protections apply. We do not treat the law of any one country as governing the whole policy. The law applicable at our place of establishment applies to us, without prejudice to mandatory consumer and data-protection protections available to you in your country of residence.

We process personal data to:

  1. Create and run your account and provide the service you asked for — posting and browsing listings, messaging, saving items, applying for jobs, and running a business profile. Basis: performance of a contract.
  2. Verify identity and business documents, approve listings and businesses, moderate content, and prevent fraud, spam and abuse. Basis: performance of a contract, our legitimate interests in keeping the marketplace safe, and in some cases a legal obligation.
  3. Take payments and keep transaction records. Basis: performance of a contract and legal obligations such as tax and accounting rules.
  4. Show the right region, currency and language, and locate listings on a map. Basis: performance of a contract and our legitimate interests; your consent where your device asks for location permission.
  5. Build recommendations and measure how features are used. Basis: our legitimate interests; where required, your consent.
  6. Send service messages such as verification codes, security alerts and account-deletion links, and app notifications. Basis: performance of a contract and our legitimate interests; consent for any marketing.
  7. Show advertising on public pages through Google AdSense. Basis: our legitimate interests in funding a service that is free to use, balanced against your rights, and your consent where the law requires it. Advertising is currently served without a consent gate; see section 12.
  8. Comply with the law, respond to lawful requests, and enforce our Terms. Basis: legal obligation and our legitimate interests.
  9. Keep the service secure, prevent misuse, and diagnose problems. Basis: legal obligation and our legitimate interests.

Where we rely on consent, you can withdraw it at any time (section 9). Withdrawing consent does not affect processing already carried out.

We do not use automated decision-making that produces legal or similarly significant effects about you. Our recommendation feed is automated, but it only affects which content is shown.

5. Who we share your personal data with

We do not sell your personal data.

We share data with the providers below so the service can run. Some act on our instructions; others are independent organisations with their own privacy policies.

Identity and sign-in

  • Google Firebase Authentication (Google LLC, United States) — used for Google and social sign-in. It receives authentication tokens and the account details your provider shares (email address, name, photo).

Maps and location

  • Google Maps, Places and Geocoding (Google LLC, United States) — receive listing coordinates and the addresses and places you look up or pick on a map, together with the map requests.

Fraud and bot protection

  • Google reCAPTCHA v2 (Google LLC, United States) — receives the reCAPTCHA response token and your IP address to decide whether a form submission is human.

Advertising

  • Google AdSense (Google LLC, United States) — serves advertising on public pages. It receives device and browser signals and sets its own cookies.

Payment providers. Which providers are active depends on your country; each may be enabled for some countries only.

  • PayPal — receives the order amount and currency, a reference, a description that can include the listing title, and your buyer country. It returns card brand and last four digits, which we store.
  • Stripe — receives the Checkout line item (package and listing title), the amount, and an internal payment reference.
  • Ziina — receives the amount, currency code, a message built from the listing or package title, and success/cancel/failure addresses.
  • JazzCash — receives the merchant identifier, amount, a description that can include the listing title, and a bill reference.
  • EasyPaisa — receives the payment details needed to process the payment.

Hosting, email and content delivery

  • Hostinger — hosting, the content delivery network that receives your IP address as the connection's edge, and email delivery. Email delivery receives recipient email addresses, names and message content, including notification emails, one-time codes and account-deletion links.
  • cdnjs.cloudflare.com (Cloudflare, Inc., United States) and Google Fonts — these load from our pages and receive your IP address as part of the request.

Visitor geolocation

  • ip-api.com — we send your IP address to this service to detect your country. This request is currently made over unencrypted HTTP; we are working to move it to an encrypted connection.

Not currently active. These do not receive your data today:

  • SMS delivery — no SMS provider is active; one-time codes may be written to a local log instead. If we enable SMS, this policy will be updated first.
  • Server-side push (Firebase Cloud Messaging and OneSignal) — server-side push is not sending today. We do store app device tokens in our database for when it is enabled.

Legal and business transfers

  • We may disclose personal data where the law requires it, to respond to lawful requests from public authorities, to protect our rights or the safety of others, or to prevent fraud.
  • If we are involved in a merger, acquisition or sale of assets, personal data may be transferred as part of that transaction, and will remain subject to this policy.

Some of these providers are controllers in their own right, and handle data under their own terms and privacy policies. See section 15.

6. International transfers

We operate a multi-region service and use providers in several countries. Your personal data goes to services operated in the United States, including Google (sign-in, maps, reCAPTCHA, advertising, fonts), PayPal and Stripe, and to ip-api.com. Our hosting, content-delivery and email delivery provider may process data in the country in which we operate and in the locations of its data centres.

Where personal data is transferred out of the country you are in, we rely on a transfer mechanism that the applicable law requires or permits, such as a contractual mechanism imposing protections equivalent to those in your country, your consent, necessity for the performance of a contract, or another lawful ground. Which mechanism applies is assessed for each transfer, taking account of the law applicable at our place of establishment and any mandatory rules in your country of residence.

7. How long we keep personal data

We keep personal data only as long as we need it for the purposes in section 4, or as the law requires, and then we delete or anonymise it. The periods we can state today are:

  • Reels and stories — about 3 days after posting. Administrators can set this between 1 and 90 days. Expired reels and their media files are deleted automatically.
  • Notifications — pruned after about 30 days by default.
  • One-time codes (phone and email) — expire shortly after they are issued and are replaced when a new code is created.
  • Account-deletion links — single use, and they expire (currently after 45 minutes).
  • Listings — a listing is marked expired after about 60 days by default (the period is configurable in our admin settings). Expiry is a status change; it does not delete the listing or its photos.

For the other categories of personal data — identity and business verification documents, CVs and job applications, messages and attachments, payment and transaction records, page-view analytics, activity and audit logs, session and device data, server logs, and backups — we retain them only for as long as necessary for the purposes described in this policy, or for as long as the law requires. Where a legal or accounting rule sets a minimum period, we keep the minimum it requires. We are formalising specific published periods for each of these categories; until they are published, this policy does not promise a fixed number of days for them, and we handle them on the principle of keeping the minimum necessary.

When you delete your account, the process is described in section 10. In short: deletion currently closes and deactivates the account first, and permanent erasure happens on request. Some records are removed; some are kept with your account reference removed; and some are kept for legal reasons. We do not currently operate a fully automated anonymisation process.

8. How we protect your personal data

We use a range of measures:

  • Encryption in transit. Traffic to our websites and apps uses HTTPS/TLS.
  • Hashed secrets. Passwords are stored as one-way hashes. One-time codes and account-deletion tokens are also stored as hashes. API access tokens are issued per device or session, and can be revoked.
  • Session protection. Session cookies are set with Secure, HttpOnly (the session cookie) and SameSite=Lax attributes, and expire after about two hours of inactivity.
  • Access control. Administrative functions are limited to administrator and staff accounts, and privileged actions are recorded in an activity log.
  • No card storage. We do not store full card numbers or card security codes; payment providers handle card data.

We must also be transparent about current limitations, which we are working to fix:

  • Verification documents and other sensitive uploads. Identity and business verification documents (ID/passport, trade licence, address proof), CVs and CV photos, job-application CVs and message attachments are intended for internal review and are not published to other users or the general public. We are tightening how these are stored and served: our target design is to keep them on a private, non-web-served storage area and deliver them only through routes that check, on each request, whether you are the owner, the employer or conversation participant concerned, or an authorised reviewer. Files uploaded before that change may still sit on the previously used storage area, where a legacy direct address could resolve, and we are completing the migration that removes them. Until that migration is complete, we cannot claim that every historical sensitive file is already fully behind the private system.
  • No cookie-consent mechanism yet. Advertising and other third-party scripts load for all visitors (section 12).
  • GeoIP over plain HTTP. Visitor IP addresses are sent to our geolocation provider over unencrypted HTTP (section 5).
  • Analytics retains identifiers. Our analytics table keeps an IP address and a session identifier alongside your internal account reference (sections 3.11 and 7).

No method of transmission or storage is perfectly secure. If a data breach affects your rights, we will notify you and the relevant authorities as required by the law that applies.

9. Your rights

Depending on where you live and which law applies, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete personal data.
  • Delete your personal data (see section 10).
  • Portability — receive certain data you gave us in a structured, commonly used format.
  • Object to or restrict certain processing, including processing based on our legitimate interests.
  • Withdraw consent at any time, where we rely on consent.
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not carry out such decisions.
  • Complain to a data-protection authority (section 14).

How to exercise your rights. Email support@dubuz.com. Tell us what you want and which account it concerns. We will verify your identity before acting, especially for deletion (section 10). We will respond within the time required by the law that applies to you, and if we need longer we will tell you why.

Data portability. We do not yet offer a self-service download of your data; requests are handled manually by our team. While your account is active, you can export a CV you created from your account.

10. Deleting your account and your data

You can close and delete your Dubuz account in a few ways.

Option 1 — delete it yourself (fastest).

  • Website: sign in, open your account dashboard, choose Delete Account, enter your password, confirm, and submit.
  • Mobile app: open the Account tab, go to Settings, choose Delete Account, confirm with your password and submit.

This closes and deactivates your account immediately and signs you out of all sessions. If you also want the account records permanently erased, use Option 2 as well.

Option 2 — request deletion if you can no longer sign in.

Go to https://dubuz.com/delete-account. You do not need to sign in. You can send a deletion request using the form, or email support@dubuz.com with the subject "Account deletion request" from the address registered to the account. This page also covers the case where you signed up with Google or another provider and have no password. We verify that the account belongs to you before erasing it, and we never act on a request we cannot verify.

What happens when an account is erased. We remove your profile details, linked sign-in identifiers, business profile details, your listings and their media, reviews, reactions, comments and shares, saved listings and searches, CVs and job applications, verification documents, notifications and device tokens, and payment records linked to you.

What may be kept, and why.

  • Closed but not yet erased. Closing your account deactivates it and hides your profile and listings from other users, but the account record is kept in a closed state until permanent erasure is completed. If you want the records erased too, use Option 2 as well.
  • Legal, accounting and anti-abuse records. Where the law requires it, we keep the minimum necessary records, for example tax and accounting records and information needed to prevent fraud or enforce our Terms.
  • Records with your account reference removed. Some records may remain with the link to your account removed — for example audit and activity records, message records, listing reports, and offers. Message content, and any guest contact details typed into a message, may be retained.
  • Analytics. Our internal analytics records use an internal numeric account reference rather than your name, email address or phone number. They also include the page address, referrer, device and browser information, and IP address.
  • Backups. Disaster-recovery database backups may still contain a copy of deleted data for a limited period. Backups are handled by our administrators and are not used for any other purpose.
  • Aggregated statistics. Anonymous aggregated figures that no longer identify you may be kept.
  • Admin and staff accounts cannot be self-deleted; they are removed through the Admin Panel.

You can read the detailed deletion page at https://dubuz.com/delete-account.

11. Children's privacy and the 18+ rule

Dubuz is an 18+ service. You must be 18 years of age or older to open an account and use Dubuz, and by using Dubuz you confirm that you meet this requirement. Dubuz is not directed at, and is not intended for, anyone under 18, and we do not knowingly collect personal data from under-18s.

Where we ask for a date of birth, it is a self-declared attestation, not age verification: we do not check it against identity documents, and it is not a guarantee of a person's true age. Accounts created before we began collecting it may not have a date of birth on file. We are strengthening how the 18+ condition is enforced at sign-up across our websites and apps.

If we become aware that a person under 18 has registered, or that we have otherwise collected personal data from an under-18, we will take steps to delete that data and close the associated account. If you believe an under-18 has given us personal data, contact support@dubuz.com.

Some countries apply specific child or minor protections on top of their general data-protection rules. We respect those protections where they apply to you, and section 14 and the Annex set out how to contact us and where to complain.

12. Cookies, advertising and tracking

We use cookies and similar technologies. There is currently no cookie-consent banner. Please read the note at the end of this section.

Cookies we set

  • dubuz_session — keeps you signed in. HttpOnly, Secure, SameSite=Lax, about 2 hours.
  • XSRF-TOKEN — protects forms against cross-site request forgery. Secure, SameSite=Lax, about 2 hours.
  • ipCountryCodeV2 — remembers the country we detected so you see the right region and currency. About 1 year. You can change the country manually.

Third parties on our pages

  • Google AdSense serves advertising on public pages, including for signed-out visitors, and uses its own cookies and device/browser signals.
  • Google reCAPTCHA, Google Fonts, cdnjs (Cloudflare) and Google Maps load on our pages and receive your IP address as part of the request.
  • Payment providers set their own cookies when you use their hosted payment pages.

Analytics

We measure page views using our own first-party records (section 3.11). We do not load a third-party web analytics product on our public pages.

Important note on consent

We do not currently operate a cookie banner or a consent store, and advertising and third-party scripts load for all visitors regardless of location. In regions where prior consent is required, this is being addressed. Where consent is required and has been given, you can withdraw it at any time by contacting us at support@dubuz.com.

You can also control cookies through your browser settings, and you can opt out of personalised advertising through Google's ad settings. Blocking cookies may stop parts of the service from working.

13. Changes to this policy

We may update this policy from time to time. We will publish the new version here with a new "Last updated" date. Where a change is material, we will notify you in the app or by email, and where the law requires it we will ask for your consent. Continuing to use Dubuz after an update takes effect means you accept the updated policy, to the extent permitted by law.

14. How to contact us and how to complain

Contact us

Complaints

If you are unhappy with how we handle your personal data, please contact us first and we will try to resolve it. You can also complain to the data-protection authority that applies to you. The Annex lists the routes we are aware of; where your country has an authority, you may contact it directly. Nothing in this policy removes any right you have to complain to a regulator.

15. Our responsibility, third-party services and user content

This section limits our responsibility. It does not reduce your data-protection rights, and it does not limit our own legal duties as a data controller.

  • Third-party services. Payment providers, Google services, our hosting and content delivery, email/SMS and geolocation providers are separate organisations. Their services are governed by their own terms and privacy policies. We are not responsible for their acts or omissions, except where the law makes us responsible. Where we choose a provider and instruct it, we remain responsible for our own decisions as a controller.
  • User content. Dubuz is a marketplace. Users, not Dubuz, are responsible for the content they post, including any personal data about other people that they include in listings, messages, CVs or job applications. Do not post other people's personal data without a lawful reason. If content breaks our Terms or the law, you can report it — see section 3.12 and our Terms of Use — and we may remove it.
  • Service availability. We provide the service "as is" and do not promise it will be uninterrupted or error-free. To the maximum extent permitted by applicable law, we are not liable for indirect or consequential loss arising from your use of the service.
  • Nothing is excluded that cannot be excluded. Nothing in this policy excludes or limits any liability, or any obligation, that cannot be excluded or limited under applicable law — including our obligations to protect personal data, to honour your statutory privacy rights, and your non-waivable rights as a consumer.

Annex — regional notes (to be completed as we expand)

This annex is where region-specific detail is recorded. It is deliberately short: naming a regulator or a specific statute in one region does not make that region's law the governing framework for the rest of the policy.

  • United Arab Emirates (including DIFC and ADGM): the UAE has a general federal data-protection law and separate free-zone regimes; those free-zone regimes can apply in addition. Complaint route and any local representative to be confirmed.
  • Pakistan: for unauthorised access to data, the relevant authority is the cybercrime wing of the Federal Investigation Agency. Pakistan does not currently have a single comprehensive data-protection authority; we will update this annex if that changes.
  • European Union / European Economic Area and the United Kingdom: where the GDPR or UK GDPR applies to you, you have the rights in section 9 and may complain to your national supervisory authority or the UK Information Commissioner's Office.
  • California and other United States states with privacy statutes: where a state privacy statute applies to you, you have the corresponding rights in section 9, including the right to know, delete, and opt out of sale or sharing. We do not sell personal data.
  • Other regions: add the regulator, any local representative, and any mandatory local wording here before publishing in that region.

This document is a policy, not legal advice. It is written to be used across regions; before publishing in a specific country, confirm that country's mandatory wording, regulator details and any local-representative requirement with qualified counsel there.