1. Summary
We collect the minimum personal data needed to find you an activity in Sharm El Sheikh, send you tickets, get you picked up from your hotel and let you pay for it. We do not sell your data to anyone. We do not store your card number — that lives with our payment processor, Tap Payments. You can delete your account and ask us to erase your data at any time.
2. Who controls your data
The data controller is App Blender LLC, the publisher of the daynight app, operating from Cairo, Egypt. Contact details:
- Privacy queries: legal@daynighteg.com
- Security incidents: security@app-blender.com
- Postal: c/o App Blender, Cairo, Egypt
3. What we collect
Account & profile
- Name, email and phone number you provide when signing up.
- Profile photo, language preference and home country (optional).
- Apple ID or Google ID if you sign in with those.
Booking & activity
- Hotel and pickup address you enter for each activity.
- Number and ages of guests, dietary needs, accessibility notes.
- Booking history, ratings, reviews and messages with operators.
Device & usage
- Device type, OS version, app version, language locale, IP address.
- Crash reports and basic analytics about which screens you use.
- Push notification tokens (FCM on Android, APNs on iOS).
Location
Approximate location to suggest nearby activities, only while the app is open and only with your explicit permission. We never sell or share your real-time location with vendors, advertisers, or anyone else.
4. Why we use it
- To take, confirm and fulfil your bookings.
- To arrange hotel pickup with the activity operator.
- To translate the experience into your chosen language.
- To send you tickets, receipts and reminders.
- To keep daynight working — fixing bugs, blocking abuse, paying tax.
- To follow up on a complaint, refund or accident report.
5. Legal basis (PDPL Art. 2 & Art. 4)
We process your data on one of these grounds, never more than needed:
- Your explicit consent — for marketing emails, location access, and any optional profile info. You can withdraw at any time from Settings → Privacy or by emailing us.
- Contract performance — to give you the activities, tickets and payouts you booked.
- Legal obligation — Egyptian tax, anti-fraud and consumer-protection laws.
- Legitimate interest — diagnostic logs, fraud prevention and platform integrity, balanced against your rights.
6. Who we share it with
Only the parties who actually need each piece, only for what's listed:
- Activity operators — your name, hotel, party size and dietary notes, so they can deliver the booking. They are bound by a written data-processing agreement.
- Drivers / pickup partners — your name, hotel address and pickup time only. No phone unless you've opted in.
- Tap Payments — your card details to take payment; see §7.
- Cloud and analytics providers — see §8.
- Authorities — only when compelled by Egyptian law or a court order, and only the data specifically required.
We do not sell, rent or trade your personal data with advertisers, brokers or marketing networks.
7. Payment data & Tap Payments
Card payments are processed by Tap Payments Egypt, a licensed payment service provider. When you pay:
- Your card number, CVV and PIN are entered into Tap's secure form, never our app.
- Tap is PCI-DSS compliant; payment is authorised through 3-D Secure.
- We receive a token and the last 4 digits, only for receipts and refunds.
- Refunds always go back to the original card and currency.
Tap is the controller for your card data; please read Tap's privacy policy. If a charge looks wrong, contact your bank and us in parallel.
8. Third-party services
We use a small number of vendors. Each is contractually limited to the data and purpose listed:
- Apple — Sign in with Apple, push notifications (APNs), App Store payments.
- Google — Sign in with Google, Firebase Cloud Messaging, Play Store payments.
- Tap Payments — card payment processing (see §7).
- Mailtrap — transactional email delivery (verifications, receipts).
- Microsoft Azure / SQL Server — hosting, database, backups within the EU/EEA region.
- Crash reporting — anonymised stack traces, no personal data.
9. Your rights under PDPL
Egypt's Personal Data Protection Law (Law No. 151 of 2020) gives you the following rights, free of charge:
- Access — ask for a copy of your personal data.
- Correction — fix anything inaccurate or incomplete.
- Erasure — delete your data, subject to legal hold.
- Withdrawal of consent — at any time, by email or in-app.
- Objection & restriction — to specific kinds of processing.
- Notification of breach — if your data is involved in an incident.
- Complaint — to the Egyptian Personal Data Protection Center.
Email legal@daynighteg.com and we'll reply within 30 days.
10. How long we keep it
- Account data — until you delete the account, then 30 days for backups.
- Booking + payment records — 7 years (Egyptian tax law).
- Diagnostic logs — 90 days.
- Marketing email opt-ins — until you unsubscribe.
11. Security
Data in transit is encrypted with TLS 1.2+. Data at rest in our database is encrypted with AES-256. Passwords are hashed (bcrypt). Access to production data is limited to a small named on-call team and audited monthly. We disclose breaches to affected users and the Egyptian Personal Data Protection Center within 72 hours of confirming them.
12. International transfers
Some of our processors run in the EU/EEA (e.g. Microsoft Azure West Europe). Any transfer outside Egypt happens under standard contractual clauses or an equivalent legal mechanism approved by the PDPL.
13. Children
daynight is not directed to anyone under 13. We don't knowingly collect personal data from children. If you think a child has signed up, email us and we'll erase the account.
14. Changes
If we make a material change we'll notify you in the app and by email before it takes effect. Minor edits will be reflected in the “Effective” date at the top of this page.
15. Contact us
Privacy questions, data requests, complaints — email legal@daynighteg.com. For anything else there's hello@daynighteg.com.
