Security note

How we handle card details

A short, plain-English summary of the pieces that matter when you pay for a Hafilat recharge on this site. No jargon, no compliance theatre.

Transport in transit

Every page on abudhabidesk.org is served over HTTPS with a modern TLS configuration. Older ciphers are turned off. HTTP requests are redirected to HTTPS, and the certificate is renewed automatically well ahead of expiry.

Where the card details go

Card fields — cardholder name, card number, expiry and CVV — are entered on our billing page, which is served over HTTPS and posts straight to our payment processor. Card details are not stored on our servers: the processor returns a payment reference, and that reference is all our order record holds.

If your bank asks for a 3-D Secure step, the confirmation happens on the bank's own page. That is a decision by your issuer, not by us — and it's the layer that verifies the payment is really you.

What we do keep

An order record is kept for support and accounting. It contains:

  • the order number
  • your email address for the receipt
  • your Hafilat card number, so support can trace a failed load
  • the amount in AED and a timestamp

We do not keep the full card number, the CVV, or any 3-D Secure code. The last four digits of the payment card may appear on the receipt because the bank sends them back — nothing more.

Accounts and passwords

There is no user account on this site, and no password to lose. Every recharge is a one-shot form with three fields. Fewer secrets to protect is a design choice.

What we do not claim

We do not publish PCI compliance levels or badges. Card handling is delegated to the billing processor, which runs its own certified environment; the security of the card form is inherited from them, not from us. Anything you read here is a description, not a certification.