- Last updated
- 1 August 2026
- Governing law
- United Arab Emirates
01
This site, and the product
Two different things are covered here. This marketing site sets no analytics or advertising cookies and asks for nothing except what you type into a form. The only value it stores in your browser is your light or dark appearance choice, held locally and never transmitted.
The product at app.myinvoice.ae is where account data lives. The sections below describe both, and say which is which.
02
What the product collects
Account data — name, email, organisation, role, and the second-factor secret needed to verify sign-in.
Business records — the customers, suppliers, products, documents, payments, stock movements and journal entries you create. This is your data; we process it to run the service.
Operational records — audit entries capturing what changed, who changed it and when, plus security logs needed to detect abuse.
03
Why we process it
To provide the service you have asked for: issuing documents, computing VAT, posting to the ledger, sending the emails you trigger, and taking payment for a plan.
To meet legal obligations: retaining financial records for the statutory period and producing them if lawfully required.
To keep the platform secure and to support you when you ask us to.
04
How long it is kept
Financial documents are soft-deleted rather than destroyed and are retained for at least five years, as UAE record-keeping rules require. This is deliberate: deleting a document removes it from your views, not from the record.
Account and operational data is kept while your account is active and for the retention period after closure, then deleted.
05
Who else sees it
Only the processors needed to run the service: infrastructure and database hosting, email delivery, and payment processing. Each receives only what its function requires, under contract, and none may use your data for their own purposes.
Where you connect an external system yourself through the Connected Apps API, that system receives what its scopes allow. You control those scopes.
We do not sell data, and we do not share it for advertising.
06
Isolation and security
Every query is scoped to your organisation before it reaches the database, and a direct record lookup is re-validated after the fetch. Two-factor authentication is mandatory. Access inside your organisation is governed by five role tiers.
Passwords are stored hashed, never in a recoverable form. Session tokens are signed and short-lived, with cookie flags set centrally.
07
Your rights
You can access and export your data at any time from inside the product, correct it directly, and ask us to delete what is not subject to statutory retention.
To make a request, or to raise a concern about how data is handled, write to support@myinvoice.ae. We reply within one business day.
08
Changes
If this policy changes materially, the change will be notified in the application before it takes effect, and the date at the top of this page will be updated.