Security & data — the honest version
A short page. clearrecharge is a small workshop with a narrow scope, so the security surface is narrow too. This page walks through what is stored, what is not, and what to do if something looks off.
Transport
Every page on clearrecharge.org and every form submission goes over HTTPS with TLS 1.3. HTTP is refused at the edge and rewritten to HTTPS. HSTS is enabled with a one-year policy.
What we store
- The du prepaid number you type (needed to apply the top-up).
- The AED amount you picked.
- The email address you optionally provided (needed to send confirmation and invoice).
- Timestamp and originating country of the ticket (for fraud spot-checks).
- Whatever you write in a contact-form message.
What we do not store
- Card numbers, CVV, expiry dates, cardholder names — these never touch our site.
- Browser fingerprints, session recordings, third-party analytics identifiers.
- Marketing lists — an email you gave for a ticket is not added to any newsletter.
Cards
The invoice we email opens a page on the payment processor’s domain. That is where card details are entered. clearrecharge never sees the full number, only the last four digits and a token, and only for the purpose of matching a paid invoice to a ticket.
Data location & retention
Ticket records live on a server in the UAE for as long as tax law requires (a few years for invoiced orders) and are then deleted. A ticket that never becomes an invoice is deleted after 90 days.
Report an incident
If you think something odd is happening — an unexpected email, a strange charge on a card you used with our invoice — write to [email protected] with the details. The workshop reads that inbox during Dubai working hours and treats security notes as top of the pile.
A machine-readable version of this contact lives at /.well-known/security.txt.