Privacy Policy
Last updated: 24 July 2026 · Effective date: 24 July 2026
Summary: eInvoicey collects only the data needed to provide invoicing services. We do not sell your data. You can delete your account and all data at any time.
1. Who We Are
eInvoicey ("we", "us", "our") is an online invoicing and accounting platform designed for UAE businesses. We are operated by eInvoicey (contact: privacy@einvoicey.com).
This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our website at einvoicey.com and our accounting application at accounting.einvoicey.com (together, the "Service").
2. Information We Collect
2.1 Information You Provide
- Account information: Name, email address, company name, Tax Registration Number (TRN), business address.
- Invoice data: Customer names, addresses, TRNs, invoice line items, amounts, payment records.
- Payment information: Billing details processed through Stripe. We do not store full card numbers — Stripe handles all payment processing.
- Communications: Messages you send to our support team.
- Settings: Company logo, bank details you choose to display on invoices, email preferences.
2.2 Information Collected Automatically
- Usage data: Pages visited, features used, timestamps of actions.
- Device data: Browser type, operating system, IP address, language settings.
- Cookies: Session cookies for authentication. We do not use advertising or tracking cookies.
2.3 Information from Third Parties
- Stripe: Subscription status, payment confirmation (not card details).
- Supabase: Authentication provider storing encrypted credentials.
3. How We Use Your Information
- Provide, operate, and improve the Service
- Process payments and manage subscriptions
- Send transactional emails (invoices, payment receipts, password resets)
- Comply with UAE Federal Tax Authority (FTA) record-keeping requirements
- Detect and prevent fraud and abuse
- Respond to your support requests
- Send product updates and announcements (you may unsubscribe at any time)
We do not use your data to train AI models or sell it to third parties.
4. Legal Basis for Processing
We process your data under the following legal bases:
- Contract performance: To provide the Service you signed up for.
- Legal obligation: To comply with UAE VAT laws and FTA requirements (Federal Decree-Law No. 8 of 2017).
- Legitimate interest: To improve the Service, prevent fraud, and ensure security.
- Consent: For marketing communications — you can withdraw consent at any time.
5. Data Sharing and Disclosure
We share your data only with:
- Supabase (USA): Database hosting and authentication
- Stripe (USA): Payment processing
- Railway (USA): Backend API hosting
- Netlify (USA): Frontend hosting
- SendGrid / SMTP provider: Transactional email delivery
All sub-processors operate under appropriate data processing agreements. We do not sell, rent, or trade your personal information to any third party for their marketing purposes.
We may disclose information if required by law, court order, or government authority, including UAE regulatory bodies.
6. Data Retention
- Account data: Retained while your account is active and for 7 years after closure (UAE VAT record-keeping requirement).
- Invoice records: Minimum 5 years from the tax period (FTA requirement — Article 78, Federal Decree-Law No. 8 of 2017).
- Deleted accounts: Personal data removed within 30 days of deletion request, except where legal retention applies.
7. Your Rights
You have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Delete your account and personal data (subject to legal retention obligations)
- Portability: Export your data in CSV/JSON format from within the app
- Objection: Object to processing based on legitimate interest
- Withdrawal of consent: Unsubscribe from marketing emails at any time
To exercise any right, email us at privacy@einvoicey.com. We will respond within 30 days.
8. Security
- All data in transit encrypted with TLS 1.2+
- Passwords hashed using bcrypt (cost factor 12)
- Database encrypted at rest (AES-256)
- Access tokens expire after 15 minutes; refresh tokens after 30 days
- Row-level security enforced: you can only access your own data
- Regular automated backups retained for 7 days
No system is 100% secure. If you suspect a security breach, notify us immediately at security@einvoicey.com.
9. Cookies
We use strictly necessary cookies only:
- Session cookie: Keeps you logged in during your session
- CSRF token: Protects against cross-site request forgery
We do not use advertising cookies, analytics cookies (Google Analytics, etc.), or fingerprinting. No cookie consent banner is required for strictly necessary cookies.
10. Children's Privacy
The Service is intended for business use only. We do not knowingly collect personal information from individuals under 18. If you believe a minor has provided us with personal data, contact us immediately.
11. International Data Transfers
Our servers are located in the United States and European Union. By using the Service, you consent to your data being transferred to and processed in these locations. All transfers comply with applicable data protection laws through standard contractual clauses.
12. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes via email or a prominent notice in the app at least 14 days before the change takes effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
13. Contact Us
For privacy questions or to exercise your rights: