Privacy Policy

Last updated: February 2026

1. Who we are

Mumma (“we”, “us”, “our”) operates the website mummaly.com and related services. We are a digital community platform for mothers in the UAE. For any privacy-related questions, contact us at hello@mummaly.com.

2. Data we collect

We collect the following personal data when you use our services:

  • Account information: name, email address, password (hashed), city of residence, and child age groups you select during registration.
  • Profile information: display name, bio, and avatar image you choose to provide.
  • Payment information: processed securely by Stripe. We store your Stripe customer ID but never your card details.
  • Usage data: pages visited, features used, and interactions with our platform, collected to improve our services.
  • Communications: messages you send via contact forms, partner inquiries, and community Q&A submissions.
  • Device and technical data: IP address, browser type, device type, and operating system for security and analytics purposes.

3. How we use your data

We use your personal data for the following purposes:

  • To create and manage your account and membership.
  • To process payments and manage subscriptions via Stripe.
  • To provide access to WhatsApp community groups.
  • To send you service-related communications (account verification, password resets, membership confirmations).
  • To personalise your experience based on your city and child age groups.
  • To moderate community content and ensure safety.
  • To improve our platform, features, and user experience.

4. Marketing communications

With your explicit consent (opt-in during registration), we may send you marketing communications including newsletters, deals, event announcements, and partner offers. You can withdraw your marketing consent at any time by:

  • Clicking the “unsubscribe” link in any marketing email.
  • Updating your preferences in your profile settings.
  • Contacting us at hello@mummaly.com.

Withdrawing marketing consent does not affect service-related communications necessary for your account.

5. Data processing and consent

By creating an account, you consent to the collection and processing of your personal data as described in this policy. We process your data on the following legal bases:

  • Consent: for marketing communications and optional profile data.
  • Contract performance: to provide membership services you have purchased.
  • Legitimate interest: to improve our services, prevent fraud, and ensure platform safety.

6. Payment processing (Stripe)

Membership payments are processed by Stripe, a PCI DSS Level 1 certified payment processor. When you make a payment:

  • Your card details are sent directly to Stripe and never touch our servers.
  • We store only your Stripe customer ID to manage your subscription.
  • Stripe may collect additional data as described in their privacy policy.

7. Data sharing and third parties

We do not sell your personal data. We share data only with:

  • Supabase: our database and authentication provider (data stored securely with encryption at rest).
  • Stripe: for payment processing.
  • Resend: for sending transactional and marketing emails.
  • Vercel: our hosting provider.

8. Data retention

We retain your personal data for as long as your account is active or as needed to provide our services. When you delete your account:

  • Your profile data is permanently deleted.
  • Your community contributions (questions, reviews) may be anonymised and retained.
  • Payment records are retained for legal and accounting purposes as required by UAE law.

9. Your rights

Under applicable data protection laws, you have the right to:

  • Access your personal data and receive a copy.
  • Correct inaccurate or incomplete data via your profile settings.
  • Delete your account and personal data at any time via profile settings.
  • Withdraw consent for marketing communications.
  • Object to processing based on legitimate interests.
  • Data portability — request your data in a machine-readable format.

To exercise any of these rights, contact us at hello@mummaly.com.

10. UAE compliance

This policy complies with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and its implementing regulations. Data is stored on servers that may be located outside the UAE; by using our services, you consent to the transfer of your data to these servers in accordance with applicable law.

11. Cookies and tracking

We use essential cookies to maintain your session and authentication state. We may also use analytics cookies to understand how our platform is used. You can manage cookie preferences in your browser settings.

12. Children's privacy

Mumma is a platform for mothers and is not intended for use by children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately.

13. Changes to this policy

We may update this privacy policy from time to time. We will notify you of significant changes via email or a prominent notice on our website. Continued use of our services after changes constitutes acceptance of the updated policy.

14. Contact us

For any questions about this privacy policy or your personal data, contact us at: hello@mummaly.com