GCCO

Privacy Policy

Last updated: November 2025

Last updated: August 2026

This policy explains what personal data Gulf Coasts Co. LLC ("GCCO", "we", "us") — a company registered in the United Arab Emirates under Licence No. CN-1106737, at Al Nahda St, Industrial Area 8, Sharjah — collects through gcco.ae, why we collect it, who else receives it, how long we keep it, and what you can ask us to do about it.

It is written to describe what this website actually does, item by item. GCCO is the controller of the data described here. Our processing is carried out in line with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. Where a visitor is in the EEA or the UK, the rights set out in section 8 are made available to them as well.

1. What we collect, and when

When you create an account or sign in. Your mobile number — this is how you sign in, so it is required. Optionally your first and last name, an email address and a profile picture. We do not use a password for customer accounts: you sign in with a one-time code sent to your phone by SMS.

When you place an order. Your name, mobile number, and email address if you give one; whether you chose collection at a branch or delivery; the emirate and delivery address if you chose delivery; any note you add to the order; the items, prices and total; the payment method and the reference the payment provider returns; and any discount code used.

When you write a review. The name you choose to display, your rating and your comment. Reviews are published on the product page after approval.

When you use the contact form. Your name, email address, phone number and message. These are emailed to our sales team and are not stored in this website's database. They then live in our mailbox for as long as we keep correspondence.

Automatically, as you browse. We count page views and clicks on our WhatsApp buttons using our own counter, which is built to be anonymous:

  • It stores no cookie and no identifier in your browser.
  • Instead of an identifier it stores a one-way code derived from your IP address and browser, mixed with a secret and with today's date. Because the date is part of it, the code changes every day, so the same visitor cannot be followed from one day to the next — by us or by anyone reading the data.
  • It records only the page address, whether it was a view or a WhatsApp click, and the time. Your IP address itself is not stored.
  • It is not sent while a member of staff is signed in, so our own work is not counted as customer demand.

For security and fault-finding. When a request fails, our error log records the address requested, the error, your IP address and your browser's user-agent string. Actions taken by staff in the admin panel are recorded with the staff member's name and IP address. Both are deleted automatically — see section 7.

2. Why we use it, and on what basis

  • To take and fulfil your order — including delivery, fitting, invoicing and warranty. Basis: performance of our contract with you.
  • To send you messages about your order — the sign-in code, and updates when an order is placed, confirmed, ready or completed. These are service messages, not marketing. Basis: performance of the contract.
  • To answer your enquiries. Basis: your request, and our legitimate interest in responding.
  • To keep the site secure and working — rate limits, blocking abuse, error logs, staff action logs. Basis: our legitimate interest in protecting the site and our customers.
  • To understand how the site is used and improve it. Basis: our legitimate interest in running and improving our business.
  • To meet legal obligations — in particular keeping tax and accounting records. Basis: compliance with UAE law.

We do not sell, rent or trade your personal data, and we do not send marketing messages from this website. Every SMS and email the site sends is one of: your sign-in code, an update about an order you placed, or a reply to a message you sent us.

3. Your card details never reach us

When you pay by card, you are taken to a payment page hosted by our payment provider and you enter your card details there. Full card numbers never pass through this website and are never stored by us. We keep only the payment method, the provider's reference for the transaction, and whether it succeeded.

4. Who else receives your data

We share only what each provider needs to do its job:

  • Network International (N-Genius) — card payments. Receives the amount, our order reference and, if you gave one, your email address.
  • Tabby — if you choose to pay in instalments. Because Tabby is entering into a credit arrangement with you, it receives more: your name, mobile number, email address, emirate and delivery address, the items in the order, and how long you have had an account with us. Tabby then acts as its own controller for that decision and applies its own privacy policy.
  • MyInboxMedia (UAE) — sends our SMS messages. Receives your mobile number and the message text.
  • Hostinger — delivers our email. Receives your email address and the message content.
  • Google — Tag Manager and Analytics measure how the site is used; Google Maps shows our branch locations. They receive usage and device information, including your IP address.
  • Google reCAPTCHA — protects our sign-in forms. When you open a sign-in form it receives your IP address and information about how you interacted with the page, and sets a cookie, so that Google can tell a person apart from an automated script trying passwords or draining our SMS credit. It runs on the sign-in forms only, not while you browse, and there is nothing for you to solve.
  • Microsoft Clarity — produces aggregated heat-maps and usage recordings that show how pages are used, so we can fix confusing layouts.
  • Cloudflare — sits in front of the website to make it fast and to absorb attacks, so all traffic passes through it, and it also counts visits for us without cookies.
  • Cloudflare R2 — stores our off-site backups. The database backup is encrypted before it leaves our server, so the provider cannot read it.

We also disclose data where UAE law or a court order requires it, and to professional advisers where necessary.

5. Where your data is processed

The website and its database run on a server we control, and our SMS provider operates in the UAE. The other providers listed above — Google, Microsoft, Cloudflare and Hostinger — are international services and will process data outside the UAE. Where we transfer personal data abroad we rely on the provider's contractual data-protection commitments.

6. Cookies and tracking

This website sets one cookie of its own: the sign-in cookie that keeps you logged in after you enter your one-time code. It cannot be read by scripts, is limited to this site, and is tied to your device so that a copied cookie is useless. It exists only once you sign in.

Your cart and display preferences are kept in your browser's own storage; they stay on your device.

We do not show a cookie banner. The measurement tools described above run for every visitor by default. If you would rather not be measured, you can:

  • block or delete cookies in your browser's settings, and block third-party trackers;
  • use a tracker-blocking extension, or your browser's private mode;
  • install Google's own Analytics opt-out add-on.

Blocking them does not affect your ability to browse, order or sign in. Our own visit counter described in section 1 is not affected by cookie settings, because it uses no cookie — but it holds nothing that identifies you.

Our Cookie Policy lists each item individually.

7. How long we keep it

  • Orders, invoices and payment records — kept for as long as UAE tax and accounting law requires us to retain commercial records, and thereafter while needed for warranty claims.
  • Your account — until you ask us to delete it.
  • Visit and message counters — deleted automatically after 400 days.
  • Error logs (including IP address and browser) — deleted automatically after 30 days.
  • Staff action logs — deleted automatically after 180 days.
  • Contact-form messages — held in our mailbox as ordinary correspondence.

8. Your rights

You may ask us to:

  • tell you what personal data we hold about you, and give you a copy;
  • correct anything that is wrong or incomplete;
  • delete your data, where we are not required to keep it (an order we must retain for tax purposes cannot be deleted on request);
  • restrict or object to processing we carry out on the basis of our legitimate interests;
  • receive the data you gave us in a portable form;
  • stop sending you anything you did not ask for.

There is no self-service delete button on the site, so please contact us and we will act on your request. We will ask you to confirm your identity — normally by replying from the email address or phone number on the account — and will respond within 30 days.

If you are not satisfied with our response, you may complain to the UAE Data Office. Visitors in the EEA or the UK may complain to their local data protection authority.

9. Children

This website is not intended for anyone under 18, and orders may only be placed by adults. We do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.

10. How we protect your data

  • The whole site is served over HTTPS.
  • Staff passwords are stored only as salted hashes, never as text, and staff accounts require a second factor to sign in.
  • The sign-in cookie cannot be read by scripts and is bound to the device it was issued to.
  • The database accepts connections only from the server itself, and the website connects to it with a restricted account rather than an administrative one.
  • Backups are taken daily and the database backup is encrypted before it leaves the server.
  • Administrative access is restricted, logged, and rate-limited against guessing.
  • Our sign-in forms are checked by Google reCAPTCHA, which scores each attempt so that automated password guessing and bulk requests for verification codes are refused before they reach your account.

No system can be guaranteed perfectly secure, but if a breach affecting your personal data occurs we will act on it and notify you and the authorities where the law requires.

11. Changes to this policy

If we change how we use personal data we will update this page and the date at the top. Material changes will be highlighted on the site.

12. Contact us

For any question about this policy, or to exercise any of the rights in section 8:

  • Email: [email protected]
  • Phone: 800 525 (UAE) or +971 6 561 6004
  • Post: Gulf Coasts Co. LLC, Al Nahda St, Industrial Area 8, Sharjah, United Arab Emirates

Contact Information

Gulf Coasts Co. LLC (GCCO)