QembaraQembara
Explore ExperiencesBecome a hostHelp
Qembara

Curated local experiences across Singapore, Batam, and Riyadh. Fewer, better, trusted.

Explore

  • Experiences
  • Help Centre
  • Contact Us

Host

  • Become a Host
  • Host Login
  • Terms & Conditions
  • Host Code of Conduct
  • Listing Policy

Legal

  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy
  • Cancellation & Refunds
  • Payment Terms

Policies

  • Pricing & Fee Policy
  • Currency Policy
  • Community Standards
  • Safety & Incidents
  • Reviews & Content
© 2026 Qembara Experiences Pte Ltd. All rights reserved.🌙 Muslim friendly experiences • Halal options available
Singapore•Batam•Riyadh

Privacy Policy

How Qembara collects, uses, shares and protects personal data.

1. Who We Are and What This Policy Covers

Qembara Experiences Pte Ltd (“Qembara”, “we”, “us” or “our”) operates the Qembara online marketplace, including its websites, applications, communications, booking, payment-facilitation, trust, safety and support services (the “Platform”). This Policy applies whenever you browse or use the Platform, create an account, list or book an Experience, participate in an Experience, contact us or otherwise interact with Qembara.

Qembara is the organisation responsible for deciding why and how it processes personal data for its own Platform purposes. Where Qembara processes data solely on another party’s documented instructions, a separate written arrangement will define the parties’ roles.

A Host is ordinarily the independent supplier of an Experience. Privacy roles are determined activity by activity from the parties’ actual decisions and conduct, not by a general label. A Host may independently control information genuinely needed to prepare for or deliver an Experience, manage safety, meet legal duties or keep required records. Qembara may instead act as controller, processor or joint decision-maker for a particular activity where the facts require. Qembara and the Host are each responsible for processing under their respective control. Nothing in this Policy excludes responsibility imposed by law. Qembara remains responsible for its disclosure choices, Platform security, role classification and enforcement of Host data-use restrictions.

This Policy does not govern an independent third-party website, application, payment service or social-media service. The third party’s own notice may also apply. The Privacy Centre identifies the privacy framework governing Qembara, the current complaint route and the rights and service options available to users, without requiring an account or login.

2. Key Terms and People Covered

TermMeaning
GuestA person who browses, creates an account, requests or makes a Booking, or contacts Qembara about an Experience.
Booking GuestThe Guest aged 21 or older who makes and is responsible for a Booking.
ParticipantAny other person included in or attending a Booking, including a minor where permitted.
HostThe person or entity that lists and ordinarily supplies an Experience.
Personal dataInformation about an identifiable individual, whether true or not, held electronically or in another form.
Sensitive informationInformation needing enhanced care because misuse could cause significant harm, including health, disability, biometric, identity-document, precise-location, religious or criminal-allegation information.

3. Personal Data We Collect

3.1 Information you provide

Account and identity information: name, contact details, age confirmation, profile photograph, preferred language, country and account credentials.

Booking and Participant information: Experience, date, participant count, names where genuinely needed, age band, accessibility needs, dietary information, allergies, emergency information and messages.

Host information: legal and trading identity, registration and tax details, licences, qualifications, insurance, listing content, availability, payout instructions and representatives.

Payment and transaction information: payment token, billing information, currency, amounts, refunds, chargebacks and payout records. Qembara ordinarily does not retain full card details handled by a payment provider.

Communications and content: support requests, complaints, reviews, ratings, photos, recordings, surveys, incident reports and dispute evidence.

Verification and compliance information: identity documents, liveness checks where lawfully used, verification results, tax identifiers, fraud indicators and information required by law or payment providers.

3.2 Information collected automatically

Device and network data: IP address, device identifiers, browser, operating system, language, time zone and approximate location derived from IP.

Usage data: pages viewed, searches, clicks, referral source, booking funnel, timestamps, session activity, errors and message interactions.

Cookie and similar-technology data for essential operation, security, preferences, measurement and, where consented to, personalisation or advertising.

Security data: login attempts, authentication events, suspicious activity, device reputation and Platform communications reasonably reviewed for support, safety or fraud prevention.

3.3 Information from others

A Booking Guest may provide only the Participant information genuinely needed for a Booking. Before any third-party information is entered, Qembara will display or link to a direct, shareable Participant privacy notice. Where Qembara will receive sensitive information about another adult and consent is required, Qembara will control the consent flow through a direct Participant link, record the notice and consent version, and provide a direct route to withdraw consent and exercise applicable rights. A Host may obtain consent outside the Platform only for processing the Host independently determines and where Qembara does not receive that sensitive information.

Hosts, payment and verification providers, fraud-prevention services, authorities, insurers, advisers, public sources and other users may provide information relevant to attendance, transactions, safety, fraud, claims or legal compliance.

4. Why We Use Personal Data

PurposeWhat we use and why
Accounts and PlatformIdentity, contact, credentials, device and usage data to provide requested services and manage the user relationship.
Bookings and ExperiencesBooking, Participant, Host, communication and transaction data to arrange and administer a Booking and support delivery by the Host.
Payments and payoutsIdentity, transaction, billing, payout and fraud data for payment administration, contractual performance and legal compliance.
Trust, safety and supportMessages, incident evidence, identity, device and booking data for safety, support, legal obligations and emergency protection.
Fraud and misuseAccount, device, network, payment and behavioural signals to prevent fraud, secure the Platform and enforce terms.
Host and listing checksBusiness identity, qualifications, licences, insurance and listing data for marketplace integrity, legal compliance and safety.
Service and legal noticesContact, account and booking data for operational communications and notices.
Improvement and analyticsUsage, search, support and aggregated transaction data to measure and improve the Platform, subject to applicable choices.
MarketingContact, preferences, usage and campaign data only with valid consent or another basis permitted by law; users may opt out at any time.
Law and claimsRelevant account, transaction, identity, tax, safety and evidence data to comply with law and establish, exercise or defend claims.

This Policy is notice, not blanket consent. Qembara will request consent separately when required, especially for optional marketing, non-essential cookies, sensitive information or a new optional use. Consent will be specific, informed, recorded and as easy to withdraw as to give. Withdrawal does not affect earlier lawful processing but may prevent a feature or accommodation that genuinely requires the information.

Qembara will not use personal data for a materially incompatible new purpose without appropriate notice and, where required, fresh consent.

5. Sensitive Information, Participants and Safety

At each sensitive-data field, Qembara will explain why the information is requested, whether it is optional, whether Qembara, the identified Host or both will receive it, whether access may occur outside the place of collection, the relevant retention period and how consent may be withdrawn.

Collect only what is reasonably needed to assess suitability, provide an agreed accommodation, manage safety or comply with law.

Do not display sensitive information publicly or use it for marketing, profiling or unrelated purposes.

Restrict access to people who genuinely need it for the disclosed purpose.

Use a secure upload route for identity documents, medical records and other highly sensitive material; do not use ordinary messages.

In an emergency, disclose relevant information only where lawful and reasonably necessary to protect life, health or safety.

6. How We Share Personal Data

Qembara does not sell, rent or trade personal data and does not permit Hosts to do so. Qembara shares information only as reasonably necessary for the purposes below, with proportionate safeguards.

6.1 Guests and Hosts

Before confirmation, Qembara may share limited profile and inquiry information needed to answer questions. After confirmation, it may give the Host the Booking Guest’s name, a permitted contact route, participant count and information genuinely needed to prepare for and deliver the Experience. Precise meeting or direct-contact details are released only when operationally necessary.

Hosts may use Qembara-sourced information only to administer and deliver the Booking, meet legal duties, address a genuine safety issue or keep legally required records. Binding Host Terms and the Host Privacy and Data-Use Standard prohibit unrelated marketing, sale or trade, unnecessary checks, copying into unrelated systems, unauthorised downloads and retention beyond the permitted period; require deletion, cooperation and 24-hour incident reporting; and give Qembara investigation, access-control, suspension and termination rights. Hosts must delete or anonymise the information when no longer permitted and cooperate with rights, incident and deletion requests. Users may report suspected Host misuse to Qembara; Qembara will preserve relevant evidence, investigate, enforce its terms and direct or refer the complaint appropriately.

6.2 Providers and other recipients

Cloud, security, support, communications, analytics, mapping, localisation and document-management providers.

Payment processors, payout providers, banks, card networks, fraud-prevention and identity-verification providers under their confirmed roles and notices.

Professional advisers, auditors, insurers and claims administrators.

Referral or campaign partners where you use their channel, limited to attribution or fulfilment.

Authorities where required by lawful process or reasonably necessary to protect rights and safety, investigate wrongdoing, enforce terms or meet tax duties.

A genuine buyer, investor, lender, merger partner or successor, subject to confidentiality and continuity safeguards.

Providers processing on Qembara’s behalf must follow documented instructions, protect the data, support rights requests and delete or return data at the end of the service unless lawful retention is required. Binding Host and provider agreements require notification to Qembara within 24 hours after awareness of a suspected breach affecting Qembara-sourced data, with the facts then available and prompt rolling updates.

7. Payments, Identity Checks and Automated Processing

Before payment or verification begins, the interface will identify the contracting payment entity and provide a concise notice linked to Qembara’s versioned Provider Register. The Register will identify payment, payout and identity-verification providers, each party’s role, principal processing locations, whether Qembara receives raw identity documents and the relevant provider notice. Some providers independently determine processing required by payment networks, anti-money-laundering, sanctions, fraud, tax or regulatory rules.

Qembara may use automated tools separately for security and fraud detection, identity verification, account or Booking restrictions, search ranking, recommendations and marketing personalisation. The data used, purpose and possible consequence will be explained where it is not reasonably apparent. Qembara does not use solely automated processing to make a decision producing legal or similarly significant effects unless permitted by law and protected by suitable safeguards.

Where an automated or assisted decision materially affects verification, an account, a transaction or a Booking, you may request review by a competent person who will consider additional evidence and has authority to change Qembara’s outcome. If a regulated or independent provider controls the final decision, Qembara will explain that limitation and provide or facilitate the provider’s available review or appeal route. Qembara will explain the main reason for the outcome where lawful and safe. This commitment does not require manual review of every search ranking or recommendation.

8. Cookies, Analytics and Advertising

Essential technologies support login, security, booking, payment, language and preferences. Optional technologies may measure performance, personalise content or support advertising. Non-essential technologies will not activate before consent where consent is required.

The preference centre will identify vendors, purposes, data categories and lifetimes; offer purpose-level choices without pre-selected optional settings; and make withdrawal as easy as consent. Qembara will describe any advertising audiences, matching or inferred-interest profiles and provide the applicable opt-out. Browser controls may affect Platform functionality.

9. Communications and Marketing

Qembara sends transactional messages needed for accounts and Bookings, such as confirmations, changes, safety alerts, payment notices, support responses and policy updates. These are not optional marketing.

Promotional email, telephone, text message, push notification and targeted campaigns are sent only with the consent or other permission required by law. For covered telephone or text marketing, Qembara will obtain and retain clear and unambiguous consent in evidential form or check the applicable do-not-contact register, as required. It will retain the consent wording and version, date, time, channel, scope, withdrawal record and register-check evidence where applicable. You may unsubscribe in the message, change account preferences or contact Qembara. Opting out of marketing does not stop essential service communications.

10. International Access and Transfers

Approved Hosts, providers and support personnel may access personal data from locations outside the place where it was collected. Before permitting a restricted transfer or access, Qembara will assess the recipient, purpose, data categories, necessity, onward transfers and security; use a lawful transfer mechanism; and take steps to ensure a standard of protection comparable to that required by the law governing Qembara.

Safeguards may include binding contractual clauses, group rules, recognised adequacy mechanisms, provider assessments, encryption, access restrictions, data minimisation or a legally permitted exception. Consent will not be used to replace appropriate safeguards where it is not a valid or proportionate transfer basis. You may request information about the applicable safeguard, subject to lawful confidentiality limits.

11. Data Retention

Data categoryStandard retention rule
Active account and profileFor the account’s life. Core account and security records: up to 24 months after closure, unless a longer legal or claims period applies.
Unsuccessful booking requestUp to 12 months after the request ends; Participant and sensitive information is removed earlier when no longer needed, unless a complaint, fraud review or legal hold applies.
Financial, tax and payment recordsSeven years after the end of the relevant financial year, or longer where law, payment rules or an active claim requires. This period does not automatically apply to Participant data, sensitive information or routine messages.
Identity verificationRaw identity documents are not retained where a provider’s verification result is sufficient. If Qembara receives a raw document, it is deleted within 30 days after verification unless a documented legal need requires longer. Verification results follow an approved risk-based period stated at collection.
Routine messages and supportGeneral enquiries: up to 12 months after closure. Booking communications: up to 24 months after the Booking or case closes. Sensitive, Participant, identity-document, safety, fraud or dispute content within a message follows the shorter or case-specific rule applicable to that content, including across exports and backups.
Safety incidents and disputesMinor matters follow a shorter, case-specific period. Serious incident, fraud and claim evidence is retained through final resolution and the documented claims period, subject to legal hold, restricted access and six-monthly review.
Marketing consent and suppressionConsent evidence while used and for 24 months after withdrawal; minimal suppression data as long as needed to respect the opt-out.
Cookies and analyticsAs stated in the preference centre, with non-essential identifiers ordinarily no longer than 13 months unless renewed consent or a shorter period applies.
Participant, accessibility and health informationDelete or anonymise within 30 days after the Experience, unless an unresolved accommodation, safety incident, complaint, consent record or legal hold requires a documented longer period.

Qembara will delete, anonymise or securely isolate information when the applicable period expires. Deletion follows the content and sensitivity of the data across messages, support tickets, logs, exports, backups and Host-accessible copies; it does not depend only on the system in which the information appears. Qembara will contractually require Hosts to delete or anonymise Qembara-sourced copies when instructed or when the permitted period ends. Legal holds are documented, limited to the affected data and reviewed at least every six months. Approved periods will be reviewed at least annually.

12. Security and Personal-Data Breaches

Qembara uses risk-appropriate administrative, technical and physical safeguards, including access control, authentication, encryption where appropriate, secure development, logging, backups, vendor review, staff confidentiality and incident response. No online service can guarantee absolute security.

If a breach occurs, Qembara will contain and assess it, preserve evidence, mitigate harm and notify affected individuals and the competent authority where required. Qembara will begin its assessment immediately and complete the notifiability assessment within 30 calendar days after it first has credible grounds to believe a breach occurred, or sooner where applicable law requires. Any delay risk will be escalated to the Data Protection Officer and executive incident team. Where authority notification is required, it will be made as soon as practicable and no later than three calendar days after that determination. Affected individuals will be notified as soon as practicable where required, with clear protective steps.

Under their binding agreements, Hosts and providers must notify Qembara within 24 hours after becoming aware of a suspected breach affecting Qembara-sourced data. The first notice must contain the information then available and be supplemented promptly as the investigation develops. Qembara remains responsible for its statutory assessment and notification.

13. Your Privacy Rights

Ask whether Qembara holds personal data about you and request access to it, including information about use and disclosure where required.

Correct inaccurate or incomplete data.

Withdraw consent for future processing based on consent.

Object to direct marketing and use available communication preferences.

Use any statutory right to deletion, restriction, anonymisation, portability or human review that applies to the relevant processing, and any additional service option Qembara expressly makes available through the Privacy Centre.

Complain to Qembara or the competent privacy authority.

Submit a request through section 18. The Privacy Centre distinguishes statutory rights from voluntary service options and states the applicable limits and target response time. Qembara may request proportionate identity verification and clarification. An authorised representative must prove authority. Qembara will respond as soon as reasonably possible. If it cannot complete an access or correction request within 30 days, it will tell you in writing when it expects to respond. Qembara will explain any lawful refusal, limitation, fee or extension.

Rights are not absolute. Qembara may retain or withhold information where necessary to protect another person, preserve legal privilege, prevent fraud, comply with law or establish, exercise or defend claims. Qembara will not disadvantage you for exercising a privacy right.

14. Children and Participants

You must be at least 21 to create an account or make a Booking. A minor may participate only where the listing permits and the Booking Guest or lawful guardian has authority. Qembara does not knowingly permit a minor to create an independent account.

Information about a minor Participant must be limited to what is genuinely needed for eligibility, safeguarding, accessibility, safety or law. Where consent is required, Qembara or the Host will obtain it from the appropriate parent, guardian or authorised person and verify authority proportionately. Qembara will not use a minor’s data for behavioural advertising or direct marketing. Suspected improper collection may be reported for prompt review and deletion where appropriate.

15. Reviews, Photos and Public Content

Profiles, listings, reviews, ratings and content you choose to publish may be visible to others. Qembara will indicate the intended audience where it is not obvious. Do not post another person’s personal data, image or sensitive information without authority.

Participation in an Experience does not itself authorise promotional recording. Consent to promotional use of an identifiable image must be specific and recorded and may be withdrawn for future use where applicable. Qembara may moderate content and retain a restricted copy where needed for evidence, legal compliance or enforcement.

16. Account Closure

You may request closure through account settings or the privacy contact. Closure does not require immediate deletion of data retained for Bookings, payments, safety, fraud prevention, disputes, tax, legal duties or others’ rights. Qembara will explain material continuing retention where appropriate.

17. Changes to This Policy

Qembara may update this Policy for legal, technical or service changes. The current version and effective date will be published on the Platform, and earlier versions will be archived. If a change materially affects how personal data is used, Qembara will provide prominent advance notice and obtain consent where required. Confirmed Bookings retain their recorded contractual terms, while this Policy governs ongoing processing from its effective date to the extent permitted by law.

Qembara

Qembara Experiences Pte Ltd operates the Qembara Platform and provides marketplace, booking, payment-facilitation and support services. Except where a listing expressly identifies Qembara as the supplier, Qembara is not the host and is not a party to the experience contract.

Legal entity
Qembara Experiences Pte Ltd
Company registration number (UEN)
—
Registered address
—
Support
support@qembara.com
Legal contact
—
Privacy contact
—