Privacy policy

How Rosarium collects, uses, shares, transfers and retains personal data.

Effective date: 19 August 2026

Who we are

ROSARIUM PLUS FLOWERS L.L.C is the controller of personal data processed through rosarium.me, our shop, customer-service channels and related ordering activities, except where a third-party provider independently determines how it processes data.

Trade licence: 1136724, Dubai Department of Economy and Tourism

TRN: 104049491400003

Address: Rosarium Plus Flowers, Al Wasl Sports Club, opposite Latifa Hospital, Latifa Hospital Street, Al Jadaf, Dubai, United Arab Emirates

Privacy contact: info@rosarium.me | +971 56 544 0082

Scope

This Policy applies when you browse our website, create or manage an account, place or receive an order, contact us, subscribe to marketing, use WhatsApp, visit our shop or otherwise interact with Rosarium. It should be read with any just-in-time privacy information presented when data is collected.

Personal data we collect

Identity and contact data may include names, email addresses, telephone numbers, billing details, recipient details and delivery addresses. Order data may include selected products, quantities, dates, card messages, customisation choices, delivery instructions, complaint evidence, refunds and customer-service correspondence.

Payment data is processed through payment providers and may include payment status, method, transaction reference and limited card or wallet details. Rosarium does not intentionally store complete card numbers or card security codes.

Technical and usage data may include IP address, device and browser information, cookie identifiers, pages viewed, searches, interactions, referral source, approximate location derived from IP, advertising identifiers and website-performance data. Marketing data may include subscriptions, campaign engagement, preferences and consent records.

If you provide data about a recipient or another person, you confirm that you are authorised to provide it and that the information is accurate. Gift messages and delivery instructions should not contain unnecessary sensitive personal information.

How we collect data

We collect data directly from customers, purchasers, recipients and website users; automatically through cookies and similar technologies; from payment, delivery, communications and analytics providers; and from publicly available or lawfully supplied sources where relevant to an order or enquiry.

Purposes and legal bases

We process personal data to receive, verify, prepare, deliver and support orders; process payments and refunds; communicate with purchasers and recipients; provide accounts and customer service; prevent fraud and secure our systems; maintain records; comply with tax, accounting, consumer-protection and other legal obligations; improve products and website performance; measure advertising; and send marketing where permitted.

Depending on the activity, processing is based on consent, steps requested before entering into a contract, performance of a contract, compliance with legal obligations, protection of rights and security, or legitimate interests recognised by applicable law. Where consent is the basis, it may be withdrawn without affecting processing already carried out lawfully.

Service providers and recipients

We disclose personal data only as reasonably necessary to operate the business, fulfil orders, comply with law or protect rights. Recipients may include Shopify for e-commerce hosting and store functions; DPO Pay, banks, card networks, Apple Pay and Google Pay for payments; Bird and other authorised delivery personnel for fulfilment; Mailchimp for email marketing; WhatsApp and Meta services for communications and advertising; and Google Analytics, Google Ads and Google Tag Manager for analytics, campaign measurement and advertising.

We may also disclose data to professional advisers, insurers, auditors, technology and security providers, government bodies, regulators, courts, law-enforcement authorities and prospective parties to a genuine business restructuring, subject to appropriate confidentiality and legal requirements.

International data transfers

Some service providers operate or store data outside the United Arab Emirates. This may result in personal data being transferred to or accessed from other countries whose laws may differ from UAE law. Rosarium will use a transfer mechanism, contractual protection, consent or other safeguard required by applicable UAE data-protection law and will take reasonable steps to require appropriate confidentiality and security from its providers.

Cookies and similar technologies

Cookies are small files or identifiers stored on or accessed from a device. Strictly necessary cookies support security, network management, language, cart, checkout, account and consent functions. Functional cookies remember choices and improve convenience. Analytics cookies help measure traffic and performance. Advertising cookies and pixels help measure campaigns, create audiences and deliver relevant advertising.

Non-essential analytics and advertising cookies are activated only after the user provides consent through the available cookie controls. Users may accept, reject or change non-essential cookie preferences at any time. Strictly necessary cookies cannot generally be disabled through our controls because the website may not function without them, although browser settings may block them.

The specific names and durations of cookies can change when providers update their services. Our cookie-preference centre or cookie list provides current information about active providers, purposes and expiry periods.

Analytics and advertising

With consent where required, Google and Meta technologies may collect device, usage, conversion and advertising information. These providers may combine information with data collected through other websites or services in accordance with their own policies and user settings. Rejecting advertising cookies does not prevent all advertising, but should prevent Rosarium from using non-essential website tracking for personalised advertising.

Marketing communications

Rosarium sends promotional email, WhatsApp or other electronic marketing only where permitted and with the required consent. Marketing consent is separate from the acceptance of an order. You may unsubscribe through a message link, reply with an opt-out request where available, adjust preferences or contact info@rosarium.me. Service messages about an order are not marketing and may continue where necessary to fulfil the order.

Retention

We retain personal data only for as long as reasonably necessary for the relevant purpose, legal obligations, disputes and security. Enquiry records are generally retained for 24 months. Abandoned-cart data is generally retained for 90 days. Order, invoice and tax records are generally retained for seven years. Marketing records are retained until consent is withdrawn or for 24 months after inactivity, subject to a minimal suppression record being kept where necessary to honour an opt-out.

A longer or shorter period may apply where required by law, necessary for a legal claim, requested by a competent authority, required for security or justified by the nature of a particular record. Data may be anonymised so that it no longer identifies an individual.

Your rights

Subject to the conditions and exceptions in applicable law, you may request access to personal data, correction of inaccurate data, deletion, restriction or cessation of processing, objection to certain processing, withdrawal of consent, and transfer of data in a structured and machine-readable format. You may also ask for information about processing and complain to the competent UAE authority.

Send requests to info@rosarium.me. We may request reasonable information to verify identity and authority. We will respond within the period required by applicable law and will explain if a request cannot be fulfilled in whole or in part.

Security

Rosarium uses reasonable organisational and technical measures designed to protect personal data against unauthorised access, disclosure, alteration, loss or destruction. Measures may include access controls, secure payment processing, encryption in transit, staff and provider controls, monitoring and incident response. No internet service can guarantee absolute security, and users should protect their account credentials and devices.

Children

The website and ordering services are intended for people aged 18 or older. We do not knowingly invite children to create accounts or place orders. If you believe a child has provided personal data without appropriate authorisation, contact info@rosarium.me.

Third-party links and services

Links or integrations may lead to third-party services with their own privacy policies. Rosarium is not responsible for an independent third party's privacy practices, although we remain responsible for our own selection and use of processors as required by law.

Changes to this Policy

We may update this Policy to reflect legal, technical or business changes. The revised effective date will be displayed when an update is published. Where required, we will provide additional notice or obtain renewed consent.

Contact and complaints

Privacy questions and rights requests should be sent to ROSARIUM PLUS FLOWERS L.L.C at info@rosarium.me, +971 56 544 0082, or Rosarium Plus Flowers, Al Wasl Sports Club, opposite Latifa Hospital, Latifa Hospital Street, Al Jadaf, Dubai, United Arab Emirates. You may also raise a complaint with the competent UAE data-protection or consumer-protection authority.