News · workshop stays open on public holidays with a lighter schedule ✦ 🇦🇪
clearrechargedu quick pay · Dubai
Top up now →
no.01 · security

Security & data — the honest version

A short page. clearrecharge is a small workshop with a narrow scope, so the security surface is narrow too. This page walks through what is stored, what is not, and what to do if something looks off.

TL;DR Card details never touch this domain. The only data we keep is a du prepaid number, an amount, an email if you gave one, and the timestamp of the ticket. All traffic is HTTPS (TLS 1.3).

Transport

Every page on clearrecharge.org and every form submission goes over HTTPS with TLS 1.3. HTTP is refused at the edge and rewritten to HTTPS. HSTS is enabled with a one-year policy.

What we store

What we do not store

Cards

The invoice we email opens a page on the payment processor’s domain. That is where card details are entered. clearrecharge never sees the full number, only the last four digits and a token, and only for the purpose of matching a paid invoice to a ticket.

Data location & retention

Ticket records live on a server in the UAE for as long as tax law requires (a few years for invoiced orders) and are then deleted. A ticket that never becomes an invoice is deleted after 90 days.

Report an incident

If you think something odd is happening — an unexpected email, a strange charge on a card you used with our invoice — write to [email protected] with the details. The workshop reads that inbox during Dubai working hours and treats security notes as top of the pile.

A machine-readable version of this contact lives at /.well-known/security.txt.