Privacy Policy
HighTicket.io — BERH Stores & Consulting Inc. FZCO
Last Updated: July 10, 2026
This Privacy Policy explains how BERH Stores & Consulting Inc. FZCO, doing business as HighTicket.io and High Ticket (“Company,” “we,” “us,” “our”), collects, uses, shares, and protects personal data when you visit our websites, register for webinars or events, purchase or use our programs, software, coaching, and communities, or otherwise interact with us (collectively, the “Services”).
For the purposes of applicable data protection law — including UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the “PDPL”), the EU and UK General Data Protection Regulation (“GDPR”), and U.S. state privacy laws such as the California Consumer Privacy Act as amended (“CCPA”) — the Company is the controller of personal data processed under this Policy. Our contact details are at the end of this Policy.
1. Scope
This Policy applies to personal data we process in connection with the Services. It does not apply to third-party websites, platforms, or services that we link to or that you use in your own business (for example, advertising platforms, storefront software, or payment providers you contract with directly); those are governed by their own privacy policies. Where you sign a separate agreement with us containing data terms, that agreement controls to the extent of any conflict.
Whose personal data we process.
Most of this Policy addresses personal data collected from visitors to and users of our websites and platforms and from our customers. Like any company, we also process a limited amount of personal data about two other groups. For members of our workforce and job applicants, we collect and retain the professional and employment-related information you would expect an employer to hold, and we provide any legally required notices, and describe our use and sharing of that information, through internal human-resources documents and the workforce and applicant portals we (or third parties on our behalf) operate. For vendors and business partners, we collect the business contact and related information needed to manage, administer, and perform our contracts with them and to share information about our products, and we describe that processing in our contracts with those parties. The same person may fall into more than one group.
2. Personal Data We Collect
2.1 Data you provide to us.
Identity and contact data: name, email address, mailing address, and similar identifiers you submit through forms, registrations, checkout, applications, or support requests.Account data: login credentials, profile details, and preferences.
Purchase and billing data: products purchased, order history, billing address, and limited payment details. Full payment card numbers are collected and processed directly by our PCI-DSS compliant payment processors; we do not store full card numbers on our systems.
Program and community data: progress in courses, submissions, questions, posts, comments, and materials you share in our learning platforms and communities (which are visible to other members where posted in shared spaces).
Calls, sessions, and events: consultations, sales calls, coaching sessions, webinars, and events may be recorded (with notice, and consent where required by law) for delivery, quality assurance, training, and record-keeping. Chat messages and questions submitted during webinars and events may be retained.
Communications: the content of emails, messages, surveys, and support tickets you send us.
Testimonial and results data: results, screenshots, and stories you voluntarily share, used in marketing only under a signed release.
2.2 Data collected automatically.
When you use our websites and platforms, we and our service providers automatically collect device and usage data: IP address, device and browser type, operating system, referring pages and URLs, pages viewed, links clicked, video watch time, timestamps, approximate location derived from IP, and identifiers set by cookies, pixels, and similar technologies (see Section 5). The internet-activity information collected this way includes the domain name and IP address from which you accessed the Services; browser type and operating system; the date, time, and length of your visit; the specific pages visited, content viewed, and documents downloaded; and the links you followed to and from the Services. If you access the Services from a mobile device, we may also receive uniquely identifiable device information from your provider and, if location services are enabled on your device, device-based location information; you can disable this at any time through your device settings, and approximate location may still be derived from your IP address. Where you opt in to receive SMS, we record the opt-in details (including timestamp, IP address, and source page) to document consent. We use automatically collected and device information to compile aggregate reports about how the Services are used, to administer, secure, and improve them, and to make your use more convenient (for example, by remembering your information to save you time).
2.3 Data from other sources.
We may receive data from advertising and analytics partners (such as campaign, attribution, and engagement data), from event and webinar platforms, from payment processors (transaction status), and from publicly available sources.We do not intentionally collect sensitive or special categories of personal data (such as health data, government identification numbers, or precise geolocation), and we ask that you not submit them to us.
3. How We Use Personal Data
We use personal data to:
- Provide, operate, and deliver the Services, including account creation, course and community access, coaching, events, and customer support;
- process orders, payments, installments, subscriptions, and refunds, and maintain business records;
- communicate with you about your account, purchases, and the Services (transactional communications);
- send marketing communications — including email and, where you have separately opted in, SMS — about our products, services, events, and content, which you can opt out of at any time (Section 8);
- personalize content and measure, improve, and develop the Services;run, measure, and optimize advertising, including audience matching and campaign attribution (Section 5);
- monitor, secure, and protect the Services, prevent fraud and abuse, and enforce our Terms of Service and other agreements;
- comply with legal obligations, respond to lawful requests, and establish, exercise, or defend legal claims.
Legal bases. Where the GDPR applies, we rely on: performance of a contract (delivering what you purchased); our legitimate interests (securing and improving the Services, business administration, fraud prevention, and marketing to existing customers where permitted); your consent (marketing cookies, SMS marketing, and other uses where consent is required); and compliance with legal obligations. Where the PDPL applies, we process personal data on the basis of your consent or another lawful basis available under the PDPL, including processing necessary for a contract to which you are a party or for compliance with applicable law.
AI-assisted tools. We may use AI-enabled tools (for example, transcription, analytics, content, and support tools) to help provide and improve the Services. Providers of these tools are engaged as service providers under contractual restrictions limiting their use of personal data to providing services to us.No solely automated decisions. We do not use your personal data to make decisions that produce legal or similarly significant effects about you based solely on automated processing.
4. When and With Whom We Share Personal Data
We do not sell personal data for money. We share personal data only as follows:Service providers (processors): companies that host and operate parts of the Services on our behalf — for example, learning-management and community platforms (such as Kajabi), payment processors, email and SMS delivery providers, CRM and scheduling tools, video conferencing and webinar platforms, cloud hosting, analytics providers, and customer support tools. They are permitted to use personal data only to provide services to us.
Advertising partners: as described in Section 5, we share certain identifiers and event data with advertising platforms (such as Meta, Google, and TikTok) to measure and improve our advertising and to reach audiences likely to be interested in our Services.
Affiliated companies: entities under common ownership or control with the Company, for purposes consistent with this Policy.
Professional advisers: lawyers, accountants, auditors, and insurers, under duties of confidentiality.
Legal and safety: government authorities, courts, and other parties where required by law, subpoena, or court order, or where we believe disclosure is necessary to protect our rights, property, or the safety of any person, to enforce our agreements, or to detect and prevent fraud or abuse.
Business transfers: in connection with a merger, acquisition, financing, reorganization, or sale of assets, personal data may be transferred as part of the transaction, subject to this Policy or successor commitments.
Standards for our vendors and partners. We have adopted standards for vendors and business partners who receive personal data from us, and we bind them to those standards through written contracts wherever possible. Those contracts are designed to ensure that personal data we provide is used only to the extent necessary to carry out the business purpose for which it was provided; is not disclosed to anyone else without our consent or instruction; remains, as between us and the vendor, subject to our control; and is transferred across borders only in a lawful manner. We choose our vendors carefully, but we cannot guarantee that every vendor will agree to every requested term or, having agreed, will always fully comply; where we learn of non-compliance affecting your personal data, we act under the incident procedures described in
Section 9.5. Cookies, Pixels, and Advertising
We and our partners use cookies, pixels, tags, SDKs, and server-side event tools to operate the Services, remember preferences, analyze traffic, and measure and deliver advertising. This includes:
Analytics (for example, Google Analytics, a service of Google LLC) to understand how visitors use our websites. Information on how Google uses data from sites that use its services is available at google.com/policies/privacy/partners, and you can opt out of Google Analytics at tools.google.com/dlpage/gaoptout;
Advertising pixels and server-side events (for example, the Meta Pixel and Conversions API, and equivalent Google and TikTok technologies), which share event data — such as page views, registrations, and purchases — together with identifiers (which may include hashed email addresses) with those platforms for attribution, measurement, and audience building. Those platforms may match this data to their own user profiles and may use it as described in their own privacy policies;
Identity-resolution and remarketing partners: when you visit or log in to our websites, certain data partners may use cookies and similar technologies to associate your activity with contact information (such as an email or postal address) that they or others hold about you, so that we (or providers acting for us) can send marketing to that address. You can opt out of this form of advertising at app.retention.com/optout, and every marketing email we send includes an unsubscribe link (Section 8).
Your choices. You can control cookies through your browser settings and any cookie-consent tool presented on our websites; blocking some cookies may affect functionality. You can opt out of Google Analytics at tools.google.com/dlpage/gaoptout, and manage ad preferences directly with Meta, Google, and TikTok in their ad-settings tools. Under some U.S. state laws, sharing identifiers and activity data with advertising platforms for cross-context behavioral advertising may be considered a “sale” or “sharing” of personal information; Section 10 explains how to opt out. Where we are required to obtain consent for non-essential cookies (for example, for EEA/UK visitors), we do so through a consent banner, and you may withdraw consent at any time through the same tool.
We honor the Global Privacy Control (GPC) browser signal as an opt-out of sale/sharing where required by applicable law. Except as legally required, we do not respond to other “do not track” signals.
6. International Data Transfers
We are established in the United Arab Emirates, and our service providers process data in the United States, the European Union, and other countries. Where personal data is transferred across borders — including transfers subject to the PDPL’s cross-border rules or Chapter V of the GDPR — we take steps designed to ensure the transfer is lawful and the data remains protected, such as transferring to jurisdictions recognized as providing adequate protection, using appropriate contractual safeguards (including standard contractual clauses where applicable), or relying on your consent or another lawful transfer basis.
7. Data Retention
We retain personal data for as long as needed to fulfill the purposes described in this Policy: generally, for as long as you maintain an account or an active commercial relationship with us, and thereafter as necessary to comply with legal, tax, and accounting obligations, maintain business records, resolve disputes, enforce agreements, and document consents and compliance (for example, marketing opt-in records and signed releases). When personal data is no longer needed, we delete, anonymize, or securely archive it in accordance with our retention procedures.
8. Marketing Communications
You can opt out of marketing emails at any time using the unsubscribe link in any marketing email or by contacting [email protected]. If you have opted in to SMS, reply STOP (or a similar recognized keyword) to any message to opt out; message and data rates may apply per your carrier. Opt-outs are honored promptly and within the timeframes required by applicable law; because some communications are prepared in advance, you may receive messages already in progress for a short period after opting out, after which they will stop. Transactional and account-related communications (such as receipts, billing notices, and service announcements) are not marketing and will continue as needed to serve your account.
9. Security
We maintain a security program of technical, organizational, administrative, and physical safeguards designed to protect personal data against anticipated and actual threats, appropriate to the nature of the data and consistent with accepted industry standards and applicable law (our “Security Program”), and we require our service providers to do the same. Elements of our Security Program include: encryption of data in transit and at rest; restriction of staff access to personal data through role-based access control, so that access is limited to personnel whose job functions require it and is scoped to what each role needs; permissions structured to grant broader access only where responsibilities require it; regular audits and monitoring to verify compliance with our access-control policies and to detect unauthorized access attempts, with violations addressed promptly; and periodic review and updating of the Security Program, including as required by law.
No system is perfectly secure, and, except for our duty to maintain the Security Program under applicable law, we cannot guarantee that personal data will be free from unauthorized access, loss, misuse, alteration, or interception in transmission, storage, or otherwise. We maintain incident-response and management procedures that are activated whenever we become aware that personal data is likely to have been compromised, we require our vendors and business partners to notify us promptly if they have reason to believe an incident affecting personal data we provided to them has occurred, and we will notify affected individuals and regulators of personal data breaches where required by law.
10. Your Rights
Subject to applicable law and verification of your identity, you may request: access to the personal data we hold about you; correction of inaccurate data; deletion; a copy of your data in a portable format; restriction of, or objection to, certain processing (including direct marketing); and withdrawal of consent where processing is based on consent (without affecting prior processing). To exercise any right, email [email protected]. We will respond within the timeframes required by applicable law, and we will not discriminate against you for exercising your rights. You may designate an authorized agent to act for you where the law allows; we may require proof of authorization and verification of your identity.
10.1 United Arab Emirates (PDPL).
If the PDPL applies to our processing of your personal data, you have the rights described above as provided in the PDPL and its implementing regulations when in force, and you may lodge a complaint with the UAE Data Office.
10.2 EEA and United Kingdom (GDPR / UK GDPR).
You have the rights described above, including the right to object to processing based on legitimate interests and an absolute right to object to direct marketing. You also have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office), though we would appreciate the opportunity to address your concerns first.
10.3 California (CCPA/CPRA).
In the preceding 12 months we have collected the categories of personal information described in Section 2 (identifiers; customer records information; commercial information; internet and network activity; approximate geolocation; audio/visual information from recorded sessions; and inferences) from the sources and for the purposes described above, and disclosed them to the categories of recipients described in Section 4. We do not sell personal information for money and do not knowingly sell or share the personal information of anyone under 16; however, our use of advertising cookies, pixels, and audience-matching (Section 5) may constitute “sharing” (and in some cases a “sale”) under California law. You have the right to know, correct, delete, and opt out of sale/sharing, the right to limit use of sensitive personal information (which we do not use for purposes requiring that right), and the right to non-discrimination — we will not deny you services, charge different prices, or provide a different level of quality because you exercised your rights. You may make a right-to-know request up to twice in any 12-month period; we may ask you to complete a request form and to follow our identity-verification instructions, because the law only allows us to act on requests we can verify. To opt out of sale/sharing: email [email protected] with the subject line “Do Not Sell or Share My Personal Information,” use any “Your Privacy Choices” link or cookie controls on our websites, or enable the Global Privacy Control in your browser.
10.4 Other U.S. states.
Residents of Virginia, Colorado, Connecticut, Texas, and other states with comprehensive privacy laws may have similar rights of access, correction, deletion, portability, and opt-out of targeted advertising, and a right to appeal a refusal. To exercise these rights or appeal a decision, contact [email protected].
10.5 Canada.
We handle personal information of Canadian residents in accordance with applicable Canadian privacy law (including PIPEDA), and you may contact us to access or correct your information or to withdraw consent, subject to legal and contractual restrictions.
11. Children
The Services are intended for adults operating or intending to operate a business and are not directed to anyone under 18. We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has provided personal data to us, contact [email protected] and we will delete it.
12. Third-Party Links and Platforms
Our Services link to and interoperate with third-party websites, platforms, and social media (including Meta, Google, TikTok, YouTube, and others). We also maintain a presence on external social media platforms (such as Facebook/Meta, Instagram, YouTube, X, TikTok, and LinkedIn), and features of our Services may connect with or be viewable from those platforms; anything you post there is governed by the platform’s own terms and privacy policy, not this Policy. We are not responsible for the content or privacy practices of any external platform, site, or app. Review their privacy policies before providing them your data.
13. Changes to This Policy
We may update this Policy from time to time. The revised version will be posted with an updated “Last Updated” date, and material changes will be notified by email or prominent notice within the Services. All personal data we hold is governed by the version of this Policy in effect at the time of processing. This Policy was drafted in English, and the English-language version controls over any translation.
14. Contact Us
BERH Stores & Consulting Inc. FZCO (dba HighTicket.io) Attention: Legal / Privacy Dubai Silicon Oasis, DDP, Building A1 Dubai, United Arab Emirates Email: [email protected]
© 2026 BERH Stores & Consulting Inc. FZCO. All rights reserved.