This Privacy Policy explains how APDV PORTAL L.L.C, trading through the GoRush platform (“GoRush”, “we”, “us”, “our”), collects and processes personal data when customers, visitors and service providers use gorush.ae, create accounts, list or book services, make or receive payments, communicate with us, or otherwise use the platform.
This Policy is intended to operate in accordance with UAE Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data (PDPL), together with other applicable UAE laws. Where mandatory law provides greater rights or protections, mandatory law prevails.
1. Who We Are
Controller: APDV PORTAL L.L.C, a Dubai limited liability company (single owner), Trade Licence No. 1110778, Commercial Register No. 2933100, licensed for the activity “Portal”.
Registered/business address: Office No. 413-101, Bur Dubai, Al Souq Al Kabeer, Dubai, United Arab Emirates. Contact email: director@istlift.ru.
GoRush is an online marketplace and booking platform connecting customers with independent providers of adventure, leisure, tourism, recreational and other services.
2. Personal Data We May Collect
- Account and identity data: name, username/account identifiers, mobile number, email address and authentication information.
- Booking data: selected service, date/time, participants, booking reference, special requests, cancellation/rebooking information and communications relating to the booking.
- Payment and transaction data: payment status, amount, currency, refunds, chargebacks, transaction identifiers and limited payment metadata. Card credentials are processed by authorised payment service providers and are not intended to be stored by GoRush.
- Provider data: legal/business name, licence and permit information, contact persons, bank/settlement information, service listings, availability, pricing, insurance and compliance documents.
- Technical and usage data: IP address, device/browser information, logs, security events, cookie identifiers and information about use of the website and account.
- Customer support and communications: messages, complaints, refund requests, reviews and other information submitted to us.
3. How We Use Personal Data
- Create and administer user and provider accounts.
- Display provider listings and availability and operate booking calendars.
- Create, confirm, modify and cancel bookings.
- Facilitate online payments, settlements, refunds and chargeback handling through payment service providers, including Mamo where used.
- Share booking information with the relevant service provider so the booked service can be delivered and the customer can be identified.
- Provide customer and provider support, resolve complaints and prevent duplicate or fraudulent bookings.
- Comply with legal, regulatory, accounting, tax, law-enforcement and court requirements.
- Protect the security, integrity and availability of the platform and prevent fraud or misuse.
- Improve platform functionality, analytics and user experience, subject to applicable consent requirements.
4. Legal Grounds
Depending on the processing activity, we process personal data on one or more grounds permitted by the PDPL, including consent where required, necessity to perform or take steps relating to a contract, compliance with legal obligations, establishment or defence of legal claims, and other lawful grounds recognised by applicable UAE law. Where processing relies on consent, consent may be withdrawn as permitted by law without affecting processing already lawfully carried out.
6. International Transfers
Some processors or technology suppliers may process data outside the UAE. Where personal data is transferred outside the UAE, we will use a transfer mechanism permitted by the PDPL, including transfer to jurisdictions providing an adequate level of protection or appropriate contractual or other safeguards where required.
7. Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including booking fulfilment, account administration, dispute handling, fraud prevention and compliance with legal, accounting and regulatory retention obligations. Retention periods may differ by data category. Data that is no longer required will be deleted, anonymised or securely isolated where deletion is not immediately possible.
8. Security
We apply appropriate technical and organisational safeguards proportionate to the nature of the data and risks, including access controls, account-security measures, logging, vendor controls and reasonable measures designed to protect data against unauthorised access, alteration, loss, destruction or disclosure. No internet service can guarantee absolute security.
9. Your Rights
Subject to the PDPL and any lawful limitations or exceptions, data subjects may have rights to obtain information about processing, request access or transfer where applicable, request correction of inaccurate data, request erasure in qualifying cases, restrict or object to certain processing, and withdraw consent where consent is the applicable basis. Requests may be sent to the contact details below. We may need to verify identity before acting on a request.
11. Children and Age-Restricted Activities
A GoRush account and online contracting functionality are intended for persons legally capable of entering into the relevant transaction. Certain activities may have provider-specific minimum-age, health, licence or guardian requirements. Providers are responsible for clearly displaying such eligibility and safety requirements. Where information about minors is required for a booking, it should be collected only to the extent necessary and in accordance with applicable law.
12. Payment Processing
Online payments may be processed by Mamo or another authorised payment service provider. Payment processing is also subject to the processor’s own terms and privacy notice. GoRush receives transaction information needed to confirm payment, administer bookings, refunds, settlements and disputes, but does not intend to store full payment-card credentials.
13. Changes to this Policy
We may update this Policy to reflect changes in law, technology, platform functionality or business operations. The current version will be posted on the platform with an updated effective date. Where required, we will provide additional notice or obtain consent.
14. Contact
Privacy and data-protection enquiries may be sent to director@istlift.ru or by post to APDV PORTAL L.L.C, Office No. 413-101, Bur Dubai, Al Souq Al Kabeer, Dubai, United Arab Emirates, P.O. Box 2128, Dubai, UAE.
Legal Reference Note
This document was updated with reference to UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, Federal Decree-Law No. 46 of 2021 on Electronic Transactions and Trust Services, Federal Law No. 15 of 2020 on Consumer Protection and its Executive Regulations, and Federal Decree-Law No. 14 of 2023 Concerning the Modern Technology-Based Trade.
privacy-policy · 2026-10-01 · SHA-256 629859d3298ab63ee28fe47493e9c691e71530f6927556c17240da2dd198427c