Skip to content

Privacy notice

What we collect when you use Talli, why we need it, who else sees it, and what you can ask us to do about it.

Last updated 11 September 2026.

Who is responsible for your data

Talli is a food discovery and ordering platform for the United Arab Emirates. We decide what personal data is collected through this service and why, which makes us the controller of it.

For anything in this notice, write to [email protected]. We answer data requests from that address.

What we collect, and why

We collect only what a specific part of the service needs in order to work. Nothing below is collected for its own sake, and we do not buy personal data from anyone else.

Your account
Your name, email address and password. The password is stored only as a hash — we never see or store the password itself. We need this to keep your account yours and to let you sign back in.
Your delivery details
Phone number, delivery address, the area and city, and any note you leave for the rider. Saved so checkout can fill itself in next time, and passed on so the food can reach you. You can edit or clear them at any time from your profile.
Your orders
What you ordered, from whom, the amount, the delivery address and phone you gave for that order, and the status it reached. We keep this because it is the record of a transaction between you and a restaurant, and because you may need to refer to it.
How you use the app
Which dishes you viewed, saved and tapped through to order, together with a random per-tab identifier, your browser’s user-agent string, the page you came from and the page you were on. This is how restaurants learn which dishes convert and how we know which parts of the app are worth keeping. It is only collected once you allow it.
If you deliver for Talli
Your vehicle type, licence plate and, while you are on shift, your current position. Position is used to dispatch work to you and stops being collected when you go offline.
If you list a restaurant
Your name and email as the owner, and the restaurant’s trading name, address, phone and WhatsApp number. Most of that is published on your public restaurant page, which is the point of it.
Technical records
Our servers record the IP address a request came from in order to apply rate limits and to spot abuse. Privileged actions — an administrator approving a restaurant, for instance — are written to an audit log with the identity of whoever performed them.

Why we are allowed to hold it

Under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) personal data needs a lawful basis. Ours are these:

  • To give you what you asked for. Your account, your delivery details and your orders exist because you asked us to take an order. Without them there is no service.
  • Because you said yes. Usage analytics and marketing email are only collected or sent if you consent, and you can withdraw that at any time without losing anything else — see the cookie notice.
  • Because we have to. Some records are kept to meet tax, accounting and food-safety obligations.
  • To keep the service standing up. Rate limiting, abuse detection and audit logging protect every user of the platform, and are limited to what that protection needs.

Who else sees it

We do not sell personal data, and we do not share it for anyone else’s advertising. It is passed on in exactly these situations:

  • The restaurant you ordered from receives your name, delivery address, phone number, the items and any note. It cannot see your other orders or any other customer.
  • The rider delivering it. Before a rider accepts a job they are shown the area only. Your full address, your phone number and your note are released the moment they accept, because until then the job may be passed to somebody else.
  • Our email provider receives your email address and the contents of the message we are asking it to send — confirmations, password resets, order updates.
  • Our hosting provider runs the servers the application and its database sit on. They do not use the data for anything of their own.
  • A public authority, where the law requires it of us.

Whether it leaves the UAE

The application and its database run on infrastructure we control, in a single region. Traffic to the site passes through a content delivery network with points of presence in several countries, which means request metadata — the address you connected from, the page you asked for — is processed outside the UAE in transit. Our email provider may also process a message outside the UAE in order to deliver it.

Where a transfer of that kind happens, it is covered by contractual terms with the provider requiring a level of protection equivalent to the one the PDPL requires of us. Write to [email protected] if you want the current list of providers and where each one processes data.

How long we keep it

  • Your account and profile for as long as the account exists. Delete the account and they go with it.
  • Orders for as long as tax and accounting rules require, which is longer than the account. After an account is deleted the order rows are kept without the identity attached to them.
  • Usage analytics in a form that is not tied to your account. The per-tab identifier is discarded when you close the tab, and nothing in those records names you.
  • Rider position only while the shift it belongs to is running. It is not kept as a history.
  • Audit records of privileged actions for as long as they may be needed to investigate something, because that is what they are for.

What you can ask us to do

The PDPL gives you rights over your own data, and they are yours to use — asking costs nothing and we will not treat you differently for it.

  • See it. Ask for a copy of what we hold about you.
  • Correct it. Most of it you can correct yourself from your profile; for the rest, tell us.
  • Have it deleted. Except where we are required to keep a record, such as a completed order.
  • Take it with you in a machine-readable form.
  • Restrict or object to a particular use of it.
  • Change your mind. Withdrawing consent to analytics or to marketing email is one tap, and it does not affect anything that was lawful before you withdrew it.

Write to [email protected] and we will answer within 30 days. If we cannot do what you asked, we will tell you why. If you are not satisfied with how we handled it, you can complain to the UAE Data Office.

How it is protected

Traffic to the site is encrypted end to end. Passwords are stored only as hashes. Access to the database is limited to the application and to named operators, and privileged actions are logged with the identity of whoever performed them. Every request that reads or changes something checks that the record belongs to the person asking, rather than checking only that somebody is signed in.

No system is beyond reach. If a breach happens that is likely to harm you, we will tell you and the UAE Data Office as the law requires.

Children

Talli is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, write to [email protected] and we will remove it.

Changes to this notice

When the product starts doing something new with personal data, this page changes at the same time, and the date at the top changes with it. If a change materially affects you we will say so in the app rather than leaving you to notice.