Privacy Policy
Last updated: 4 August 2026
1. Who we are
Sandooq (“Sandooq”, “we”, “us”) is a petty-cash and expense-tracking service for businesses in the UAE and the wider GCC. Sandooq is provided by Xische FZ-LLC, a company registered in the Dubai Development Authority (DDA) free zone, United Arab Emirates, under commercial licence number 31335.
This Privacy Policy explains what personal data we collect through the Sandooq website and app, why we collect it, who we share it with, and the rights you and your business have over it.
2. Scope of this policy
This policy applies to the Sandooq marketing website, the Sandooq web/mobile application, and any related services (together, the “Service”). It applies to:
- Business customers: the company that signs up for Sandooq (acting as the data controller for its own business and staff data), and
- Staff users: owners, admins, accountants and drivers/field staff invited into a business account.
Where a business (“Customer”) uses Sandooq to manage its own staff and expense data, the Customer is generally the controller of that data and Sandooq acts as a processor on the Customer's behalf. See our Data Processing Addendum for how that split of responsibility works in more detail.
3. Information we collect
Account & identity data
- Name and email address (used for sign-in via one-time-passcode/OTP).
- Role within the business account (owner, admin, accountant, driver).
- Company/business information (business name and similar profile details).
Expense & cash-float data
- Cash float top-ups, balances, and expense entries logged by staff.
- Receipt photos and other documents that a user chooses to upload against an expense.
- Approval status, notes, and history attached to expense records.
Usage & device data
- Log data such as sign-in timestamps, IP address, device/browser type, and basic diagnostic/error information, used to keep the Service secure and working.
Payment data
Subscription payments are handled entirely by our payment processor, Stripe. Sandooq does not collect, see, or store your card number, expiry date, or CVV. Stripe processes and stores that data under its own PCI-DSS-compliant systems and privacy policy.
Communications
If you contact us for support, we keep a record of that correspondence (e.g. your email address and message) so we can respond and keep a history of the interaction.
4. How we use your information
We use personal data only to provide, maintain, and improve Sandooq, and for the following purposes:
| Purpose | Lawful basis |
|---|---|
| Creating and authenticating your account (email OTP sign-in) | Performance of contract with your business |
| Recording and displaying cash-float, expense and receipt data | Performance of contract; legitimate interest in operating the core service |
| Processing subscription payments via Stripe | Performance of contract; legal obligation (invoicing/tax) |
| Sending transactional emails (OTP codes, receipts, account notices) via Resend | Performance of contract; legitimate interest in operating the service securely |
| Keeping the Service secure, preventing abuse, and debugging issues | Legitimate interest in security and reliability |
| Responding to support requests | Performance of contract; legitimate interest |
| Complying with law (e.g. tax, accounting, law-enforcement requests) | Legal obligation |
We do not use your business or expense data to train third-party AI models, and we do not sell personal data.
5. Roles and access within your business account
Sandooq is designed around your business's own team structure. Access to a company's data is controlled by the roles your business assigns:
- Owner / Admin: full visibility into the company's floats, expenses, and staff.
- Accountant: access to records and exports needed for bookkeeping.
- Driver / field staff: access limited to logging expenses against floats they are assigned to.
It is the Customer's responsibility to assign roles appropriately and to remove staff access when someone leaves the business.
6. Who we share data with (sub-processors)
We do not sell personal data. We share it only with the service providers (“sub-processors”) that help us run Sandooq, each bound by contract to protect it and to use it only to provide their service to us:
| Provider | Role | What they process |
|---|---|---|
| Supabase | Database hosting & auth infrastructure | All application data (account, expense, receipt and log data), stored in Postgres |
| Vercel | Application & website hosting | Requests to the app/website; no persistent business data storage |
| Stripe | Subscription billing & payment processing | Billing contact details and payment card data (never touches Sandooq's own systems) |
| Resend | Transactional email delivery | Recipient email address and email content (e.g. OTP codes, notices) |
We may also disclose information where required by law, to enforce our Terms of Service, or in connection with a merger, acquisition, or sale of assets (with notice to affected customers where required).
The full sub-processor list and roles for business customers are also set out in our Data Processing Addendum.
7. Where your data is stored and international transfers
Application data is hosted with Supabase in the Mumbai (ap-south-1) region. This may change as we add regions, and we will update this policy if it does.
Because our infrastructure and sub-processors may be located outside the UAE, using Sandooq may involve transferring your data internationally (including to India, the United States, and/or the European Union, depending on the provider). Where we transfer personal data across borders, we rely on appropriate contractual safeguards with our sub-processors, including standard contractual clauses where applicable.
8. Data retention
We retain personal data for as long as your business account is active, so that you have continuous access to your expense history. After an account is closed:
- Account and expense records are kept for 30 days after an account is closed to allow recovery, then deleted or anonymized on request, except where we must keep records longer for accounting, tax, or legal reasons.
- We take periodic backups of production data and rotate them on a schedule; older backups are deleted as part of that rotation.
9. How we protect your data
Security is treated as core to the product, not an add-on:
- Encryption at rest: data is encrypted at rest using AES-256.
- Encryption in transit: all traffic to and from the Service is encrypted (TLS).
- Tenant isolation: every company's data is isolated at the database layer using row-level security (RLS), so one business cannot see another's data.
- No card data stored: payment card details are handled solely by Stripe; Sandooq never stores or has access to full card numbers.
- Access control: internal access to production data is restricted to authorized personnel on a need-to-know basis.
We are working toward independent security certifications (such as SOC 2 and ISO 27001) as the business matures; we do not currently hold these certifications and do not claim to.
10. Your rights
Depending on your location and applicable law (including the UAE Personal Data Protection Law and, where relevant, EU/UK data protection law), you may have the right to:
- Access the personal data we hold about you;
- Correct inaccurate or incomplete data;
- Request deletion of your personal data (“right to be forgotten”), subject to our legal retention obligations;
- Receive a copy of your data in a portable format (data export);
- Object to, or request restriction of, certain processing;
- Withdraw consent where processing is based on consent; and
- Lodge a complaint with the relevant data protection authority.
If you are a staff user, some of these requests may need to go through the business (Customer) that administers your account, since they control your account as between you and us. To exercise these rights, contact us at support@sandooq.ae.
11. Cookies and similar technologies
The Sandooq website and web app use strictly necessary cookies and local storage (for example to keep you signed in and remember language), plus Vercel Analytics — a privacy-oriented product analytics tool that helps us understand aggregate page views and performance on sandooq.ae and app.sandooq.ae. It does not use advertising cookies or sell personal data for ads.
12. Children's privacy
Sandooq is a business tool intended for use by adults acting on behalf of a company. It is not directed at, and is not intended for use by, individuals under the age of 18. We do not knowingly collect personal data from children. If we learn that we have inadvertently collected data from a child, we will delete it promptly.
13. Data breach notification
If we become aware of a security incident that compromises the confidentiality, integrity, or availability of personal data, we will investigate promptly and notify affected business customers and, where legally required, the relevant regulator and affected individuals, without undue delay and, where feasible, within 72 hours of becoming aware.
14. Changes to this policy
We may update this Privacy Policy from time to time as the Service, our sub-processors, or the law changes. We will update the “Last updated” date at the top of this page and, for material changes, provide additional notice by email or in-app notice.
15. Contact us
Questions about this Privacy Policy or how we handle your data can be sent to:
- Xische FZ-LLC (trading as Sandooq)
- Email: support@sandooq.ae
- Postal address available on request by emailing support@sandooq.ae.