Skip to the content.

Privacy Policy — Gulf Card

Last updated: 2026-05-03 Effective date: 2026-05-03


This Privacy Policy explains how Gulf Card (“we”, “us”, “the app”) collects, uses, and protects your information when you use the iOS app. Gulf Card is operated by Hamam Alabdulla, based in Saudi Arabia. By using the app you agree to the practices described in this policy.

1. Information we collect

From you, when you sign in or play

From your gameplay

From your device

2. How we use your information

We do not sell your personal information.

3. Sharing your information

We share data only with:

4. Your rights

If you are in Saudi Arabia, the Personal Data Protection Law (PDPL) grants you these rights:

If you are in the European Economic Area or the United Kingdom, the GDPR / UK-GDPR grants you the same set of rights, plus the right to lodge a complaint with your supervisory authority.

If you are in California, the CCPA / CPRA grants you the right to know, delete, correct, and opt out of “sale” — though we do not sell personal information.

To exercise any of these rights, use the in-app flows in Profile → Privacy:

For inquiries the in-app flows don’t cover, contact us at the address in section 12.

5. Data retention

Data category Retention period
Active account profile Until you request deletion
Match state (live) Cleared at match end, except for shuffle proofs (see below)
Shuffle proofs (/shuffleProofs/) 90 days post match-end (provably-fair audit)
Audit log (anti-cheat) 90 days post match-end
Crash logs (Crashlytics) 90 days (Firebase default)
Analytics events 14 months (Firebase default)
Purchase records 7 years (tax / legal retention)
Deleted account residue Up to 90 days for anti-fraud, then irreversibly deleted

6. International data transfers

Firebase and AdMob are operated by Google in data centers worldwide. Your data is currently primarily processed in Google Cloud’s us-central1 region. We will migrate to me-central1 (Saudi Arabia / UAE) when that region becomes generally available for Firestore.

For transfers out of the European Economic Area we rely on the EU-US Data Privacy Framework (where applicable) or Standard Contractual Clauses (SCCs) approved by the European Commission.

7. Age restriction (17+)

Gulf Card is rated 17+. We collect a date of birth at sign-up to verify you meet this minimum. If you indicate you are under 17, your sign-up is blocked and no account is created.

The app uses virtual chips for in-game wagering. Chips have no real-money value — they cannot be cashed out, traded for currency, or used outside the app. There is no real-money gambling.

8. Children’s privacy

Gulf Card is not directed at children under 17. We do not knowingly collect personal data from anyone under that age. If we discover that data has been collected from a person under 17, we will delete it and the associated account.

If you are a parent or guardian who believes your child has provided us data, please contact us at the address in section 12.

9. Security

No system is perfectly secure. If you believe your account has been compromised, please contact us immediately.

10. Cookies and similar technologies

Gulf Card does not use browser cookies. The app stores small amounts of preference data (theme, language, hand-sort preference, feature flags) in iOS UserDefaults — this storage never leaves your device.

11. Changes to this policy

We will post any change here, update the “Last updated” date at the top, and — for changes that materially expand what data we collect or how we use it — show an in-app notification at next launch with a summary of the change. By continuing to use the app after a change you accept the updated policy.

12. Contact / Data Protection Officer

For privacy questions, requests, or complaints:

We aim to respond to data-rights requests within 30 days.


This policy is published in English only.