Privacy Policy
- Applies to
- Distressed Deals mobile app
- Version
- 1.0
- In effect from
- 19 August 2026
This policy explains what personal data the Distressed Deals app collects, why we collect it, who else sees it, how long we keep it, and what you can ask us to do about it. It is written for the person using the app, not for a lawyer, and it describes what the app actually does today rather than everything an app of this kind might conceivably do.
The short version: we collect what you type when you register, a mobile number we verify by WhatsApp, technical records about the device and session so that our listings cannot be harvested automatically, what you tap inside the app, and whatever you deliberately send us — a property submission, a support message, a saved listing. We do not ask for your location, camera, photos or contacts, we do not use advertising identifiers, and we do not sell personal data.
Each section opens with a plain-language summary, set off by a rule on the left. Terms on which our business clients buy contact packages are a separate document — see the Customer Agreement.
1.Who we are, and what this policy covers
This is the privacy policy for the mobile app. It explains what the app collects, why, who else sees it, and what you can ask us to do about it.
Distressed Deals (the App) is published by Apex Vertex Software L.L.C of Office 402, Al Suwaidi Tower, Business Bay, Dubai, United Arab Emirates (we, us, our). We decide what personal data the App collects and why, which makes us the controller of that data.
This policy covers the App and the Distresy servers it talks to. It does not cover:
- (a)the separate agreement under which business clients buy contact packages from us — that relationship is governed by the Customer Agreement, and this policy sits alongside it rather than replacing it;
- (b)WhatsApp, or any other application the App hands you off to. Tapping a contact button opens WhatsApp with a message prepared for you; from the moment it opens, what happens is between you, the person you are messaging, and WhatsApp's own privacy policy;
- (c)a property portal, developer site or third-party page you reach from a link shown in the App.
The App is offered in the United Arab Emirates and is intended for people in that market. Wherever you use it from, the data reaches servers we operate and the processors named in section 4.
Each section opens with a short plain-language summary, set off by a rule on the left. Those summaries exist to help you find your way around; where a summary and the clauses beneath it differ, the clauses are what we are held to.
2.What the App collects
Account details you type, a phone number we verify, technical facts about the device and session, what you tap inside the App, and anything you send us — a property submission, a support message, a saved listing.
When you create an account, we collect what the sign-up form asks for and nothing beyond it:
- Name
- — your full name, as you enter it. Used to address you and to identify you to our team when you get in touch.
- Email address
- — your sign-in identifier. It must be unique to one account, so it is also how we tell two accounts apart.
- Password
- — never stored as you typed it. We keep a one-way hash, which lets us check a password at sign-in without being able to read it, including by us.
- Mobile number
- — required, because it is where the verification code goes and because a property submission with no reachable owner is not something our team can act on. Held with a flag recording whether it has been verified.
- Account type
- — whether you are using the App as an owner or as a buyer. It decides what the App shows you.
To verify your number, we generate a one-time code, store it with an expiry alongside your account until it is used or lapses, and send it to you over WhatsApp. The code is deleted or marked spent once used; we do not keep a record of the message body beyond that.
Because unauthorised bulk copying of our listings is the single largest risk to this service, the App registers the device it is running on and we keep security data about each session:
- Device record
- — the platform (Android or iOS), an installation identifier the App generates for itself, an optional device label, the result of the integrity check described below, and — if you allow notifications — a push token.
- Device integrity check
- — on Android, a Play Integrity token; on iOS, an App Attest assertion. These are produced by the operating system, tell us whether the App is a genuine unmodified install on a genuine device, and are the reason a scraper cannot simply automate the App. They do not identify you personally.
- Session record
- — a hash of your refresh token (not the token itself), the IP address and user-agent the session was created from and last used from, and the times it was created, last used, and revoked. This is what lets us end a session, show you a device you do not recognise, and detect a stolen token being replayed.
Inside the App, we record how it is used. Two kinds of records, and it is worth being precise about the second:
- Named events
- — sign-up, sign-in and sign-out; screens viewed; a listing opened; a listing saved or unsaved; a search run and the filters applied to it; a contact button pressed; a notification opened; the App moving to the background or foreground.
- Tap capture
- — the App also logs taps automatically, identified by the accessibility label of whatever was tapped — a button's name, not its contents. We do this so that a screen nobody remembered to instrument still tells us whether it works. It records what you touched, not what you typed.
- Crash reports
- — when the App crashes, a diagnostic report is sent containing the error, the stack trace, the device model and operating system version, and the identifier of the account signed in at the time.
We collect what you deliberately send us:
- Property submissions
- — the emirate, community, building and unit, property type, asking price, beds, baths and area, any notes you add, and a contact number for the person our team should call. A submission is reviewed by our operations team before it appears anywhere.
- Saved listings
- — which properties you have added to your watchlist, and when.
- Preferences
- — the answers you give during onboarding — your investment goal, budget range and the kind of property you are looking for.
- Support messages
- — the subject and full text of any support conversation you start, and our replies, kept as a thread against your account.
We do not collect certain things, and we would rather say so plainly than leave it to inference. The App asks for one permission — notifications — and no other. It does not request or use your location, camera, photo library, contacts, calendar, microphone, or the advertising identifier on your device. We do not buy personal data about you from data brokers, and we do not sell or rent your personal data to anyone.
3.Why we use it
To run your account, to verify you are a real person on a real device, to show you relevant listings, to answer you, to keep the service secure, and to comply with the law.
We use the data described in section 2 for the following purposes, and we do not use it for a materially different purpose without telling you first:
- (a)creating and running your account, signing you in, and keeping you signed in across app restarts;
- (b)verifying your mobile number, so that a submission can be followed up and one number cannot back several accounts;
- (c)showing you property listings, running your searches, and keeping your watchlist and preferences;
- (d)receiving property submissions and passing them to our operations team to review, price and, if accepted, publish;
- (e)answering your support messages;
- (f)sending you notifications about your account and, if you allow them, about new listings and offers — see section 6;
- (g)protecting the service: detecting automated access and bulk extraction of listings, enforcing one active session per device, investigating a session that looks stolen, and enforcing our terms;
- (h)understanding how the App is used in aggregate, so we can fix what is broken and drop what nobody opens;
- (i)keeping records we are required to keep, and responding to a lawful request from a competent authority.
Where the United Arab Emirates Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, or a comparable law of another country, requires a lawful basis for each purpose, we rely on: the performance of our contract with you for everything needed to run your account and the service; your consent for notifications and for the analytics described in section 2.4, which you may withdraw at any time; our legitimate interest in protecting the service for the security purposes above; and legal obligation where a law requires us to keep or produce a record.
We do not make decisions about you by automated means alone that produce a legal effect or a similarly significant effect on you. A property submission is reviewed by a person before anything happens to it.
5.Where the data goes
Some of the providers above process data outside the UAE. We only use providers that offer an adequate standard of protection or contract for it.
The service is operated for the United Arab Emirates market, but the processors named in section 4 operate globally, and personal data may therefore be processed in a country other than the one you are in.
Where personal data is transferred out of the UAE, we transfer it only to a country recognised as providing an adequate level of protection, or under a contract with the recipient imposing protections equivalent to those required by UAE data protection law, or with your explicit consent where the law allows that basis.
You can ask us which countries your data is processed in, and on what basis it is transferred, by writing to privacy@distresy.com.
6.Notifications and messages
Notifications are opt-in and can be switched off in your device settings. We will still contact you about your account and your submissions.
The App asks for permission to send notifications. If you refuse, the App works normally and simply does not notify you; nothing else about your account changes.
If you allow them, we may send notifications about new or price-reduced listings, about the progress of a property you submitted, and about the service itself. We limit how often a promotional notification may be sent to the same device.
You can withdraw permission at any time in your device's settings for the App. Withdrawing it stops the notifications; it does not stop us contacting you by email or WhatsApp about something specific to your account, such as a verification code, a security alert, or a reply to a support message you started.
7.How long we keep it
For as long as your account exists, and after that only for as long as we have a reason. Security and verification records age out much sooner.
Account data — your name, email, mobile number, account type, preferences, watchlist and submissions — is kept for as long as your account is open.
Some categories are kept on their own, shorter clocks:
- Verification codes
- — valid for minutes, and marked spent as soon as they are used. Expired codes are cleared out.
- Sessions
- — a session record ends when it expires or when you sign out; we retain the record of it, including the IP addresses it was used from, for a limited period afterwards so that a compromised account can still be investigated.
- Support threads
- — kept while your account is open, so that a later conversation has its history.
- Analytics and crash reports
- — retained by our analytics provider under the retention period we configure with it, after which they are deleted or aggregated to the point where you cannot be identified from them.
When your account is deleted, we delete or irreversibly anonymise the personal data associated with it, other than: records we are required by law to keep for a defined period; the minimum record needed to enforce a ban where an account was closed for abuse of the service; and property listings already published, which stay in the system as business records with your personal details removed. Backups are overwritten on their own cycle and any residual copy is gone within 90 days.
8.How it is protected
Passwords are hashed, sign-in tokens are held in the device's secure hardware store, every session is tied to an attested device, and staff access is limited by role.
Passwords are stored only as a one-way hash. Nobody at this company can read your password, and we will never ask you for it.
The credentials that keep you signed in are stored in the Keychain on iOS and the Keystore on Android — the operating system's own protected storage — rather than in ordinary app storage that another application on a compromised device could read.
Sign-in tokens are short-lived and rotate. If a refresh token is ever used twice, we treat the whole session family as compromised and revoke it, which ends the session on every device it covers.
Traffic between the App and our servers is encrypted in transit. Staff access to production data is by named account with role-based limits, and privileged actions are logged.
No system is perfectly secure, and we do not claim otherwise. If a breach occurs that is likely to result in a risk to your rights, we will notify the competent authority and, where the law requires it, you.
9.Your rights
You can ask for a copy of your data, ask us to correct or delete it, object to some uses, withdraw consent, and complain to the regulator.
Subject to the conditions and exceptions in applicable data protection law, you have the right to:
- (a)be told what personal data we hold about you and why, which is what this document is for;
- (b)receive a copy of the personal data you have given us, in a structured, commonly used, machine-readable format;
- (c)have inaccurate data corrected, and incomplete data completed;
- (d)have your data deleted, where we no longer have a lawful reason to keep it — see section 11;
- (e)restrict how we use your data while a dispute about its accuracy or our use of it is being resolved;
- (f)object to processing we carry out on the basis of a legitimate interest;
- (g)withdraw consent, at any time, where consent is what we relied on — withdrawing it does not affect anything done before you withdrew it;
- (h)not be subject to a decision made solely by automated means that significantly affects you.
To exercise any of these, write to privacy@distresy.com from the email address on your account, or open a support conversation in the App. We may need to verify your identity before we act, precisely so that somebody else cannot exercise your rights for you.
We will respond within 30 days. If a request is unusually complex and we need longer, we will tell you within that period, explain why, and give you a date.
If you are not satisfied with our answer, you may complain to the UAE Data Office, or to the data protection authority of the country you live in if that country's law applies to you. We would rather you told us first, at privacy@distresy.com, so that we have the chance to put it right.
10.Children
The App is for adults. We do not knowingly hold data about a child.
The App is intended for people aged 18 or over, because it concerns the purchase and sale of property. It is not directed at children and we do not knowingly collect personal data from anyone under 18.
If you believe a child has given us personal data, write to privacy@distresy.com and we will delete the account and its data.
11.Deleting your account
Ask us, from the App or by email, and we delete the account and its data within 30 days.
You can ask us to delete your account and the personal data attached to it at any time. Open a support conversation in the App, or write to privacy@distresy.com from the email address the account is registered to.
Tell us the email address on the account. We will confirm the request, verify that it comes from you, and then delete the account.
Deletion happens within 30 days of us verifying the request. What survives it, and why, is set out in section 7.4 — in short: records the law requires us to keep, and published listings, with your personal details removed from them.
Deleting your account signs you out on every device and revokes every session. It cannot be undone, and a new account with the same email address starts empty.
12.Changes to this policy
We will keep this current. If a change matters to you, we will tell you rather than quietly re-dating the page.
We may update this policy as the App changes. The version number and effective date at the top of this page always describe the version you are reading.
Where a change materially affects how we use your personal data — a new purpose, a new category collected, or a new recipient — we will bring it to your attention in the App or by email before it takes effect, and where the law requires your consent for it, we will ask for it.
Earlier versions are retained and are available on request.
13.How to reach us
One address for anything in this document.
Questions, requests and complaints about this policy or about how we handle your personal data should go to privacy@distresy.com, or by post to Apex Vertex Software L.L.C, Office 402, Al Suwaidi Tower, Business Bay, Dubai, United Arab Emirates.
Matters about the commercial terms on which contact packages are supplied — rather than about personal data — should go to legal@distresy.com and are governed by the Customer Agreement.
Privacy questions, access requests and account-deletion requests should be addressed to privacy@distresy.com, or by post to Apex Vertex Software L.L.C, Office 402, Al Suwaidi Tower, Business Bay, Dubai, United Arab Emirates.
Version 1.0, in effect from 19 August 2026. Earlier versions are retained by us and are available on request.