This Privacy Policy explains how jfloo.com ("we", "us", "our") collects, uses, shares and protects personal data when you visit https://www.jfloo.com/, place an order, or contact us. It is written to meet Regulation (EU) 2016/679 (the "GDPR") and, where local law imposes stricter or additional requirements in the country in which you are located, those requirements as well.
Last updated: 6 August 2026
1. Who we are and how to contact us
The controller of your personal data is:
- Controller: jfloo.com
- Trading name: JFLOO (Fiesta Flowers)
For anything relating to your personal data you can reach us at:
- Email: dubai@jfloo.com
- Local branch for Dubai: dubai@jfloo.com, +66 8 0431 9883
- Local address: Souk Warsan - Shop 329, Ground Floor, Block C - Warsan First - Dubai International City - Dubai - United Arab Emirates
2. What this Policy covers
This Policy covers the website https://www.jfloo.com/ and every city storefront operated under it, together with the ordering, delivery and customer-support processes behind them. It does not cover third-party websites we link to; those sites publish their own privacy notices and we are not responsible for them.
3. What personal data we collect
We collect only what we need to sell and deliver flowers and gifts. Depending on how you use the site, this may include:
- Identity and contact data of the buyer: name, phone number, email address.
- Recipient data: recipient's name, phone number and delivery address. You provide this to us about another person — see section 5.
- Order data: items ordered, price, currency, delivery date and time slot, greeting-card text, delivery instructions, order history.
- Payment data: payment method, payment status, transaction reference and amount. We do not receive or store your full card number, card expiry date or CVC — those go directly to the payment provider.
- Communications: messages, call-back requests and support correspondence, including via messengers where you contact us that way.
- Technical data: IP address, browser type and version, device type, operating system, language and time-zone settings, referring page, and the pages you viewed. Some of this is collected for security and anti-fraud purposes.
- Preference data: selected city, language and currency, and cookie choices.
We do not deliberately collect special categories of personal data (Article 9 GDPR), such as data revealing health, religion, political opinions or sexual orientation. Please do not include such information in greeting-card text or delivery instructions. If you do, you ask us to process it in order to fulfil your order.
4. Why we use your data, and our legal basis
| Purpose |
Data used |
Legal basis (Article 6 GDPR) |
Retention |
| Accepting, processing and delivering your order; arranging delivery with our florist and courier partners; confirming delivery |
Buyer identity and contact data, recipient data, order data, payment status |
Performance of a contract — Art. 6(1)(b). Recipient data: our legitimate interest in fulfilling the order you placed — Art. 6(1)(f) |
Duration of the order plus the statutory limitation period applicable to the contract |
| Taking payment and issuing refunds |
Order data, payment data |
Performance of a contract — Art. 6(1)(b) |
As required by accounting and tax law in the country of sale, typically 5–10 years |
| Customer support, complaints, and responding to your enquiries |
Contact data, order data, correspondence |
Performance of a contract — Art. 6(1)(b); otherwise our legitimate interest in answering enquiries — Art. 6(1)(f) |
3 years from the last contact |
| Accounting, tax and statutory record-keeping |
Order data, payment data, invoice data |
Compliance with a legal obligation — Art. 6(1)(c) |
The period required by applicable law |
| Site security, fraud prevention, and blocking automated abuse |
Technical data, IP address, request patterns |
Our legitimate interest in keeping the service available and preventing fraud — Art. 6(1)(f) |
Up to 12 months, then deleted or aggregated |
| Measuring website traffic in aggregate to improve the site |
Aggregated, non-identifying usage statistics |
Our legitimate interest in understanding and improving the service — Art. 6(1)(f) |
Aggregated data only; no individual profile is retained |
| Sending marketing messages about offers and seasonal promotions |
Name, email address, phone number |
Your consent — Art. 6(1)(a), withdrawable at any time |
Until you withdraw consent, or 2 years of inactivity, whichever is first |
| Establishing, exercising or defending legal claims |
Whatever is relevant to the claim |
Our legitimate interest in defending our rights — Art. 6(1)(f) |
Until the claim and any appeal period ends |
Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. You can object to such processing at any time — see section 11.
5. Data about gift recipients
When you order a delivery for someone else, you give us that person's name, address and phone number. We use it only to deliver the order and to contact the recipient about that delivery. We do not use recipient data for marketing.
By providing it, you confirm you are entitled to share that person's contact details with us for this purpose. If a recipient asks us how we obtained their data, we will tell them, as Article 14 GDPR requires.
6. Who we share your data with
We share personal data only where it is necessary, and only with the following categories of recipients:
- Florist and delivery partners in the destination city, who receive the recipient's name, address, phone number, delivery date and card text in order to prepare and deliver the order.
- Courier and logistics providers, where delivery is not made by our own partner.
- Payment service providers and acquiring banks, who process the payment itself. They act as independent controllers for the payment transaction and apply their own privacy notices.
- Order-management and CRM providers, who host the systems in which we manage orders and customer communications, acting as our processors.
- Messaging and notification providers, used to send order notifications to our operations team and, where you chose that channel, to you.
- Hosting, infrastructure and email-delivery providers, acting as our processors.
- Professional advisers — accountants, auditors and lawyers — where necessary and under a duty of confidentiality.
- Public authorities and courts, where we are legally required to disclose data.
We do not sell your personal data, and we do not share it with third parties for their own marketing.
Every processor acts on our documented instructions under a contract meeting Article 28 GDPR.
7. International transfers
We operate in more than one hundred cities, so your data may be transferred to, or accessed from, a country outside the European Economic Area — including the country to which you are sending the delivery.
Where a transfer is to a country that the European Commission has not recognised as providing an adequate level of protection, we rely on one of the following safeguards under Chapter V GDPR:
- the European Commission's Standard Contractual Clauses, together with supplementary technical and organisational measures where our assessment shows they are needed; or
- Article 49(1)(b) GDPR, where the transfer is necessary to perform the contract you asked us to perform — for example, sending the recipient's address to a florist in the destination country.
You may request a copy of the safeguards we apply by writing to dubai@jfloo.com.
8. How long we keep your data
Retention periods are set out per purpose in the table in section 4. In summary: order and payment records are kept for as long as tax and accounting law requires; support correspondence for 3 years; security logs for up to 12 months; marketing data until you withdraw consent. When a period ends we delete the data or irreversibly anonymise it.
9. How we protect your data
We apply technical and organisational measures appropriate to the risk, including encryption of traffic in transit (HTTPS), access control on a need-to-know basis, separation of payment credentials from our systems, protection against automated abuse, and logging of administrative access. No system is perfectly secure, but we review these measures regularly.
If a personal data breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, and the competent supervisory authority within 72 hours as required by Articles 33 and 34 GDPR.
10. Cookies and similar technologies
We use cookies and similar technologies as described in our Cookie Policy. Cookies that are strictly necessary for the site to work — session, cart, security and language or city selection — are set on the basis of our legitimate interest and cannot be switched off. Any non-essential cookies are set only with your consent, which you can change or withdraw at any time.
11. Your rights
Under the GDPR you have the following rights in relation to your personal data:
- Access (Art. 15) — to be told whether we process your data and to receive a copy of it.
- Rectification (Art. 16) — to have inaccurate data corrected and incomplete data completed.
- Erasure (Art. 17) — to have your data deleted where one of the grounds in Article 17 applies. This does not extend to data we must keep by law, such as invoices.
- Restriction (Art. 18) — to have processing limited in the circumstances listed in Article 18.
- Portability (Art. 20) — to receive data you gave us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
- Objection (Art. 21) — to object at any time to processing based on our legitimate interests. Where you object to direct marketing, we will stop immediately and without exception.
- Withdrawal of consent (Art. 7(3)) — to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Complaint (Art. 77) — to lodge a complaint with a supervisory authority, in particular in the EU or EEA country of your habitual residence, place of work, or the place of the alleged infringement.
12. How to exercise your rights
Write to dubai@jfloo.com, or to the local address in section 1. We will respond within one month of receiving your request. If your request is complex, or if you have made several requests, we may extend that period by up to two further months and will tell you within the first month if we do (Article 12(3) GDPR).
Exercising your rights is free. We may charge a reasonable fee, or refuse to act, only where a request is manifestly unfounded or excessive, and we will explain why if that happens.
We may ask you for information to confirm your identity before we act, so that we do not disclose your data to someone else.
13. Automated decision-making
We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing within the meaning of Article 22 GDPR. Automated checks used to block bots and fraudulent orders may temporarily prevent an order from being submitted; you can always reach a person at dubai@jfloo.com to complete the order manually.
14. Children
The site is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
15. Changes to this Policy
We may update this Policy. The current version is always published on this page, with the date it was last updated. If a change materially affects how we use your data, we will bring it to your attention before it takes effect. Where a change requires your consent, we will ask for it — we will not treat continued use of the site as consent.
16. Complaints
If you are unhappy with how we handle your personal data, please tell us first at dubai@jfloo.com so that we can put it right. You also have the right to complain directly to a supervisory authority in the EU or EEA country of your habitual residence, place of work, or the place where you believe the infringement occurred — you do not need to contact us first.