Privacy Policy


Version: v2.0

Revised date: 04.08.2026


The Services (whether accessed through the OGOLD website or the OGOLD mobile application) are provided by OGOLD PRECIOUS METALS TRADING LLC. OGOLD is the trading name of OGOLD PRECIOUS METALS TRADING LLC, with its registered address located at Office 2215-2216, Gold & Diamond Park 2, Al Quoz Industrial Third, Dubai, United Arab Emirates.


In this Policy, “OGOLD PRECIOUS METALS TRADING LLC”, “OGOLD”, “OGOLD Wallet”, “we”, “our”, or “us” refers to the OGOLD PRECIOUS METALS TRADING LLC entity responsible for the collection, use, and handling of Personal Data as described in this document.


This privacy policy describes how and why we might collect, store, use, and/or share (“process”) your information when you use the services that we offer (“Services”), such as when you:

  • Visit our website at https://www.ogold.app/ 
  • Download and use our mobile application (OGOLD Wallet), or any other application of ours that links to this privacy policy
  • Engage with us in other related ways, including any communications, sales, marketing, events, or service interactions


In this Policy, “Personal Data” or “Personal Information” means information relating to an identified or identifiable individual, as applicable under relevant data protection laws.


OGOLD acts as the data controller responsible for determining the purposes and means of processing your Personal Data. We process Personal Data in accordance with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the “UAE PDPL”) and its implementing and executive regulations as issued and amended from time to time, together with any other data protection and sector-specific laws applicable to our Services. Where a specific activity is governed by separate regulatory requirements (for example payment, or anti-money-laundering rules), those requirements apply in addition to this Policy.


If you do not agree with the terms of this privacy policy or do not wish for your Personal Data to be processed as described herein, you should not use the Services.


If you have any questions or concerns about this policy, or how your Personal Data is handled, you may contact us at: [email protected]. Privacy, personal data, or compliance-related queries received through this channel may be routed to the appropriate internal team for review and response.

TABLE OF CONTENTS

1. WHAT INFORMATION DO WE COLLECT?

2. HOW DO WE PROCESS YOUR INFORMATION?

3. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

4. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?

5. HOW LONG DO WE KEEP YOUR INFORMATION?

6. HOW DO WE KEEP YOUR INFORMATION SAFE?

7. DO WE COLLECT INFORMATION FROM MINORS?
8. CROSS-BORDER DATA TRANSFERS

9. WHAT ARE YOUR PRIVACY RIGHTS?

10. DO WE MAKE UPDATES TO THIS POLICY?

11. HOW CAN YOU CONTACT US ABOUT THIS POLICY?

12. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

  • WHAT INFORMATION DO WE COLLECT?

Personal information you disclose to us

We collect personal information that you voluntarily provide to us when you register for an OGOLD Account, complete identity verification, use OGOLD’s precious metals, payment, rewards, marketplace, transaction or account-related features, set goals, participate in rewards, initiate transactions, contact us, or otherwise interact with the Services.

Personal Information Provided by You
The personal information that we collect depends on how you use the Services and may include:

  • Names
  • phone numbers
  • email addresses
  • mailing addresses
  • usernames
  • passwords or authentication credentials
  • contact preferences
  • information contained in identity documents (for example national ID or passport details)
  • address and residency information
  • billing and payment information
  • XP Point balances, redemptions, and accrual history
  • details relating to savings goals, milestones, and reward activities
  • any other information you choose to provide to us voluntarily


Sensitive Information
Where required by law or to enable identity verification, payment, account, transaction, compliance, or anti-fraud functions, we may process additional categories of personal information, including:

  • financial information related to funding, metal holdings, transaction history, purchases, sales, transfers, withdrawals, redemptions, and payment settlement records
  • identity verification information, including government identifiers appearing on identity documents
  • biometric-linked outputs necessary for liveness detection and identity authentication, where facial verification or liveness checks are performed by third-party KYC providers and made available to OGOLD for compliance review

OGOLD does not itself generate biometric templates. Biometric capture and matching processes are performed by third-party KYC providers, and OGOLD may review identity data and verification results for compliance and fraud-prevention purposes.


Payment Data
We may collect payment-related information necessary to process your purchases, sales, transfers, withdrawals, redemptions, refunds, or other supported transactions, such as linked payment method type, masked payment identifiers, payment verification outcomes, settlement references, and transaction references. Sensitive cardholder data such as full card numbers, CVV, and expiry are not stored by OGOLD and are handled by licensed payment processors and approved payment service providers, where applicable.


Application Data
If you use our App, we may collect the following information where access or permission is granted by you:

  • Geolocation Information: We may request access to accurate or approximate location to support certain App features. You may control this permission in your device settings.
  • Mobile Device Data: We automatically collect device-level information, including device identifiers, device model, operating system version, browser type, mobile network, IP address, system configuration, diagnostic logs, and device-related information required to maintain security, authentication, fraud prevention, and App functionality.
  • Push Notifications: We may ask to send you push notifications relating to account status, transactional events, price alerts, or feature updates. You may disable push notifications in your device settings.

This information is required to maintain secure App operation, enable core features, support fraud detection, and provide analytics for service improvement.


Information automatically collected

We automatically collect certain technical information when you access or use the Services, which may include IP address, device characteristics, operating system, language preferences, referring URLs, access timestamps, usage logs, and interaction patterns. This data does not directly identify you by name but may be associated with your account.

As part of this, we also use cookies and similar technologies, as described in Section 4 below.


Google API
Where Google APIs are used, we will adhere to the Google API Services User Data Policy, including Limited Use requirements.

  • HOW DO WE PROCESS YOUR INFORMATION?


We process your personal information to provide, maintain, improve, secure, and operate the Services, fulfil contractual and compliance requirements, support the lawful operation of precious metals, payment, rewards, marketplace, transaction, and account-related functions within the OGOLD ecosystem, comply with applicable legal and regulatory requirements, support security and fraud prevention, protect our rights and legitimate business interests, or where you have provided consent for a specific purpose.


We process personal information for a variety of reasons, depending on how you interact with the Services, including:

  • To facilitate account creation, authentication, and management of user profiles.
  • To conduct identity verification, liveness checks, and Know-Your-Customer and anti-fraud validation with regulated third-party providers.
  • To maintain user eligibility for OGOLD services such as metal purchases, metal sales, transfers, withdrawals, physical redemption, delivery, rewards, and marketplace transactions.
  • To manage metal holdings, process metal-to-fiat conversions where applicable at the time of purchase and record corresponding transaction data and settlement metadata.
  • To manage savings goals, milestone status, and XP Points earned at 25 %, 50 %, 75 %, and 100 % goal completion.
  • To operate XP Points accrual, storage, and redemption features, including the Rewards Marketplace, Spin & Win, vouchers, gift cards, partner offers, and promotional reward events.
  • To fulfil and manage purchases, orders, transfers, sales, withdrawals, refunds, redemptions, deliveries, or other transactions made within or through the App.
  • To respond to user inquiries and provide customer support, troubleshooting, and service assistance.
  • To send operational notices, alerts, confirmations, risk and compliance notices, and updates to our terms and policies.
  • To analyse usage behaviour, service performance, feature interaction, and adoption metrics for product improvement and internal analytics.
  • To protect the Services, including fraud monitoring, security checks, anomaly detection, and prevention of prohibited or high-risk behaviour.
  • To send marketing or promotional communications where permitted by law and in accordance with your communication preferences.
  • To deliver personalised content or offers based on usage, preferences, or interest categories, where applicable.
  • To support the enforcement of our Terms & Conditions, manage disputes, address misuse, and exercise or defend legal rights.
  • To comply with regulatory, licensing, legal, reporting, risk-management, AML/CFT, sanctions, accounting, audit, payment-processing, dispute handling, and financial crime prevention requirements applicable to OGOLD.


We may also process your information for other purposes where required by law, or where you have provided consent for a specific purpose.

Legal Bases on Which We Rely to Process Your Personal Data

Under the UAE PDPL, we must have a valid legal basis to process your Personal Data. Depending on the activity, we rely on one or more of the following legal bases:

  • Consent: where you have given your consent to the processing of your Personal Data for one or more specific purposes (for example certain marketing communications, optional features, or the processing of biometric-derived verification results). Your consent must be freely given, specific, informed, and unambiguous, and you may withdraw it at any time as described in Section 9.
  • Performance of a contract: where processing is necessary to perform our agreement with you, to provide the Services you have requested, or to take steps at your request before entering into a contract (for example opening and operating your OGOLD Account, executing transactions, and processing payments).
  • Compliance with a legal obligation: where processing is necessary to comply with laws and regulatory obligations to which OGOLD is subject, including Know-Your-Customer, anti-money-laundering and counter-terrorist-financing, sanctions, tax, accounting, audit, payment-processing, and other compliance requirements. 
  • Legitimate interests: where processing is necessary for our legitimate interests or those of a third party, except where such interests are overridden by your interests or fundamental rights and freedoms (for example securing the Services, preventing fraud and abuse, ensuring network and information security, and improving and developing our products).
  • Protection of vital interests, public interest, and legal claims: where processing is necessary to protect the vital interests of you or another natural person, to serve the public interest, to establish, exercise, or defend legal claims, or on any other basis permitted under Article 4 of the UAE PDPL.

Where we process Sensitive Personal Data within the meaning of the UAE PDPL (for example biometric-derived outputs generated by our regulated KYC providers for identity verification and liveness detection), we do so on the basis of your explicit consent or another legal basis permitted under the UAE PDPL. We maintain records of our processing activities and of the legal bases on which we rely, and we will make these available to the UAE Data Office where required.


  • WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

We may share your personal information in specific situations described in this section, and with third-party service providers that assist us in delivering the Services. Where we engage such third parties, data sharing is limited to what is necessary for the specific function being performed, and these entities are bound by confidentiality, data-protection, and data-processing obligations.

Vendors, consultants, and other third-party service providers:
We may share your personal information with third-party vendors and processors that perform services for us or on our behalf and require access to such information to support the operation of our Services. These include, for example, entities that provide:

  • infrastructure and cloud hosting
  • identity verification and KYC processing
  • payment processing, payment verification, settlement, and refund support 
  • data storage, backup, and encryption services
  • fraud-monitoring, risk intelligence, and compliance support
  • analytics, performance monitoring, and usage behaviour insights
  • customer communication, messaging, and notification services
  • customer support tools and ticketing services
  • rewards, marketplace, voucher, or gift-card fulfilment services
  • logistics and delivery services (for example for the delivery of physical metal or related items)
  • screening and compliance services (for example sanctions, politically-exposed-person, and anti-money-laundering screening)

Third-party service providers that process personal information solely on our behalf are required to use such information only in accordance with our documented instructions and applicable contractual obligations. Certain regulated partners and payment service providers may also process information where required for their own legal, regulatory, security, fraud prevention, dispute handling, or compliance obligations.

We may also share personal information in the following situations:

  • Business Transfers: We may share or transfer information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or part of our business.
  • Affiliates: We may share information within our corporate group, where such entities are contractually required to honour this Privacy Policy.
  • Business Partners: We may share information with approved partners where this is necessary to offer co-branded or integrated products, services, or promotions.
  • Legal and Regulatory Requests: We may disclose information where required to comply with applicable law, regulatory obligations, law enforcement requests, dispute resolution, financial crime prevention duties, or to exercise or defend legal claims.

We do not sell personal information.

  • DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?

We may use cookies and similar tracking technologies (including pixels, SDKs, and web beacons) to collect and store information when you interact with our Services. These technologies assist with the secure operation of the App, maintain session continuity, support performance and diagnostics, help prevent fraud, remember your preferences, and enable basic App functionality.

We also permit approved third parties to place or access tracking technologies in connection with the Services for analytics, behavioural insights, and service optimisation. These providers may supply anonymised or pseudonymised usage data that helps us understand how the App is being used, improve user experience, measure feature performance, deliver push notifications or in-App messages, and support marketing automation based on your communication preferences.

Some of these technologies may also be used to tailor content or messaging to you based on activity within the App.

You may adjust your browser or device controls to limit or reject cookies or similar technologies. Doing so may impact functionality or performance of certain features within the App or website. Where we use analytics or tracking technologies supplied by external providers, we require that such tools only process data in accordance with applicable law, contractual restrictions, and acceptable-use limitations.

  • HOW LONG DO WE KEEP YOUR INFORMATION?

We keep your personal information only for as long as it is necessary to fulfil the purposes described in this privacy policy, unless a longer retention period is required or permitted by applicable law (for example, financial record keeping, accounting, AML/CFT compliance, statutory audit, dispute resolution, or other legal obligations).

Retention periods may vary depending on the category of data, the nature of the feature used, and the regulatory requirements associated with that type of activity. For example, identity verification information, transaction metadata, reward history, and records relating to purchases, sales, transfers, withdrawals, redemptions, and deliveries may need to be retained for extended periods to comply with legal, regulatory, compliance and statutory audit trail obligations.

When determining how long data should be retained, we consider the amount, nature, and sensitivity of the data, the risk of potential harm arising from unauthorised access or disclosure, the purposes for which the data is processed, whether those purposes can be achieved by alternative means, and the applicable legal, regulatory, and operational requirements that apply to our Services.

Where personal information is no longer required for lawful business, operational, compliance, or archiving purposes, we will take reasonable steps to securely delete, anonymise, or pseudonymise such information in accordance with applicable law and our internal retention policies.

If you would like additional information regarding retention periods applicable to a specific category of data processed by OGOLD, you may contact us using the details in Section 11.

  • HOW DO WE KEEP YOUR INFORMATION SAFE?

We implement appropriate technical and organisational measures designed to protect personal information against unauthorised access, loss, misuse, alteration, or disclosure. We also implement internal user-access controls to ensure that employees and authorised personnel only have access to personal information where that access is necessary for the specific work function being performed (for example, compliance review, fraud investigations, or support triage). Access to relevant systems is role-based and monitored.

We apply industry-recognised security standards and frameworks to safeguard personal data against unauthorised access, disclosure, alteration, and destruction. Our technical and organisational controls may include, as applicable:

  • encryption protocols to secure personal data both in transit and at rest;
  • strict access controls, including role-based permissions and multi-factor authentication (MFA), limiting access to authorised personnel only;
  • continuous monitoring, vulnerability assessments, and regular security audits to detect and respond to potential threats in a timely manner;
  • adherence to the ISO/IEC 27001 standard for information security management;
  • ongoing security awareness training and incident-response planning.

These technical and organisational measures are reviewed and updated regularly to remain aligned with evolving regulatory requirements and threats.

Despite our efforts, no electronic transmission, network, or storage system can be guaranteed to be entirely secure, and we cannot guarantee that unauthorised third parties will never be able to defeat our security controls or misuse personal information. Transmission of personal information to and from the OGOLD Services is therefore at your own risk and you should use secure network environments when accessing the App.

We also require third-party providers and processors who handle personal data on our behalf to apply appropriate security measures in accordance with applicable data protection laws, contractual data protection obligations, confidentiality requirements, and, where relevant, applicable security and regulatory requirements.

In the event of a personal data breach, we will notify the UAE Data Office without undue delay upon becoming aware of the breach where it would prejudice the privacy, confidentiality, or security of your Personal Data, and we will notify affected individuals where the breach is likely to result in a high risk to their rights, in each case in accordance with the UAE PDPL and other applicable law.

  • DO WE COLLECT INFORMATION FROM MINORS?

We do not knowingly collect, solicit data from, or market to people under 18 years of age. The Services are not intended for persons under 18. By using the Services, you represent that you are at least 18 years old. If we learn that personal information from a person under 18 has been collected, we will deactivate the account and take reasonable measures to delete such data from our records, subject to any legal or compliance retention requirements. 

  • CROSS-BORDER DATA TRANSFERS

OGOLD’s primary production hosting environment is located within the United Arab Emirates. However, certain supporting systems and service providers that enable specific App functionalities may process limited data in other jurisdictions outside the United Arab Emirates. Examples of such systems may include analytics platforms, customer engagement tools, messaging automation, fraud-monitoring systems, or performance optimisation technology.

Any cross-border processing is carried out only where the receiving processor applies data-protection standards that are equivalent to, or stronger than, UAE legal requirements, including contractual safeguards, technical controls, encryption standards, confidentiality obligations, and defined retention limitations. All third-party processors are subject to data-processing agreements and may only process personal information strictly for the purpose of delivering the service engaged.

Where data is transferred internationally, OGOLD continues to remain responsible for ensuring that appropriate protections are in place, and for ensuring that all processing remains compliant with applicable law.

Such transfers take place only where permitted under the UAE PDPL, namely: where the receiving country or territory ensures an adequate level of protection for Personal Data as recognised under the UAE PDPL; or, in the absence of such recognition, where appropriate safeguards are in place, such as binding contractual obligations imposed on the recipient that reflect the requirements of the UAE PDPL; or where one of the limited exceptions permitted under the UAE PDPL applies, including your explicit consent or the necessity of the transfer for the performance of a contract with you or for the establishment, exercise, or defence of legal claims.

  • WHAT ARE YOUR PRIVACY RIGHTS?

Depending on applicable law, you may have the right to request access to the personal information we hold about you, to request correction of inaccurate information, to request deletion or restriction of processing, or to object to certain types of processing. You may exercise these rights by contacting us using the details in Section 11 below. We will consider and respond to such requests in accordance with applicable law.

In addition, and depending on the circumstances and applicable law, you may have the right to: receive a copy of the Personal Data you have provided to us in a structured, commonly used, and machine-readable format and, where technically feasible, to have it transmitted to another controller (data portability); object to, and not be subject to, a decision based solely on automated processing, including profiling, where that decision produces legal effects concerning you or similarly significantly affects you; and request that we restrict or stop certain processing of your Personal Data. We will respond to requests to exercise these rights within the period prescribed by the UAE PDPL and applicable law, and we may ask you to verify your identity before acting on a request.

Withdrawing your consent:

Where we rely on consent as a legal basis for processing your personal information, you may withdraw that consent at any time by contacting us. Withdrawal of consent does not affect the lawfulness of processing that occurred prior to the withdrawal, nor does it affect processing carried out on lawful bases other than consent (for example compliance with legal obligations).

Opting out of marketing and promotional communications:

You may opt out from marketing and promotional emails at any time by clicking the unsubscribe link in those emails or by contacting us. Even if you opt out of marketing, we may still send administrative or service-related messages that are necessary for the operation of your account (for example confirmations, security alerts, or operational notices).

Account Information:

If you would like to review or update account information, or request account closure, you may:

  • access your account settings within the App; or
  • contact us using the details provided in this Policy.

Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases. However, we may retain some information in our files to prevent fraud, troubleshoot problems, assist with any investigations, enforce our legal terms and/or comply with applicable legal requirements.

Cookies and similar technologies:

You may adjust your browser or device controls to limit or reject cookies. Doing so may impact functionality or performance of certain features within the App.

If you have questions or would like to exercise any privacy rights, you may contact us at: [email protected]. Privacy, personal data, or compliance-related queries received through this channel may be routed to the appropriate internal team for review and response.

Lodging a complaint with the supervisory authority:

Without prejudice to any other administrative or judicial remedy, if you believe that our processing of your Personal Data infringes the UAE PDPL, you have the right to lodge a complaint with the UAE Data Office, the competent supervisory authority established under Federal Decree-Law No. 44 of 2021. We would, however, welcome the opportunity to address your concerns before you approach the authority, so we encourage you to contact us first.

10. DO WE MAKE UPDATES TO THIS POLICY?

We may update this Privacy Policy from time to time in order to remain compliant with applicable laws and regulatory requirements, to reflect changes in our operational practices, or to update disclosures relating to features, integrations, or third-party service providers used within the OGOLD ecosystem.

The updated version will be indicated by a “Revised date” at the top of this document. If material changes are made, we may notify you by prominently posting a notice within the App or Site, or by directly contacting you using the contact details associated with your OGOLD Account, where legally required or appropriate.

We encourage you to review this Privacy Policy periodically to remain informed of how we collect, use, store, and protect your personal information. Continued use of the Services following publication of an updated version of this Privacy Policy constitutes acceptance of the revised Policy.

11. HOW CAN YOU CONTACT US ABOUT THIS POLICY?

For privacy, personal data, or compliance-related queries, please contact: [email protected]. Queries received through this channel may be routed to the appropriate internal team for review and response.

For any matter relating to the processing of your Personal Data or the exercise of your rights under the UAE PDPL, you may also contact us at [email protected]. Requests relating to data protection that are received at this address are routed to, and handled by, our Data Protection Officer.

  • HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

Subject to applicable UAE data protection laws and any other laws that may apply to your use of the Services, you may have the right to request access to the personal information we hold about you, request details about how it has been processed, request correction of inaccurate information, request deletion where legally permitted, request restriction or cessation of certain processing, or withdraw consent where processing is based on consent.

These rights may be limited in certain circumstances, including where retention or processing is required for legal, regulatory, AML/CFT, sanctions, fraud prevention, accounting, audit, dispute resolution, payment processing, or other legitimate compliance or operational purposes.

If you have questions about our privacy practices, or if you would like help exercising your privacy rights, you can contact us at: [email protected]. Privacy, personal data, or compliance-related queries received through this channel may be routed to the appropriate internal team for review and response.




Start today. It's free

Gold is moving.Are you?

Every rise, every dip is a chance to own more. Buy real gold from AED 1, instantly and securely.