Sandooqصندوق

Privacy Policy

Last updated: 4 August 2026

1. Who we are

Sandooq (“Sandooq”, “we”, “us”) is a petty-cash and expense-tracking service for businesses in the UAE and the wider GCC. Sandooq is provided by Xische FZ-LLC, a company registered in the Dubai Development Authority (DDA) free zone, United Arab Emirates, under commercial licence number 31335.

This Privacy Policy explains what personal data we collect through the Sandooq website and app, why we collect it, who we share it with, and the rights you and your business have over it.

Simply put:We built Sandooq to track cash, not to harvest data. We collect what we need to run the service for your business and nothing more.

2. Scope of this policy

This policy applies to the Sandooq marketing website, the Sandooq web/mobile application, and any related services (together, the “Service”). It applies to:

  • Business customers: the company that signs up for Sandooq (acting as the data controller for its own business and staff data), and
  • Staff users: owners, admins, accountants and drivers/field staff invited into a business account.

Where a business (“Customer”) uses Sandooq to manage its own staff and expense data, the Customer is generally the controller of that data and Sandooq acts as a processor on the Customer's behalf. See our Data Processing Addendum for how that split of responsibility works in more detail.

3. Information we collect

Account & identity data

  • Name and email address (used for sign-in via one-time-passcode/OTP).
  • Role within the business account (owner, admin, accountant, driver).
  • Company/business information (business name and similar profile details).

Expense & cash-float data

  • Cash float top-ups, balances, and expense entries logged by staff.
  • Receipt photos and other documents that a user chooses to upload against an expense.
  • Approval status, notes, and history attached to expense records.

Usage & device data

  • Log data such as sign-in timestamps, IP address, device/browser type, and basic diagnostic/error information, used to keep the Service secure and working.

Payment data

Subscription payments are handled entirely by our payment processor, Stripe. Sandooq does not collect, see, or store your card number, expiry date, or CVV. Stripe processes and stores that data under its own PCI-DSS-compliant systems and privacy policy.

Communications

If you contact us for support, we keep a record of that correspondence (e.g. your email address and message) so we can respond and keep a history of the interaction.

4. How we use your information

We use personal data only to provide, maintain, and improve Sandooq, and for the following purposes:

PurposeLawful basis
Creating and authenticating your account (email OTP sign-in)Performance of contract with your business
Recording and displaying cash-float, expense and receipt dataPerformance of contract; legitimate interest in operating the core service
Processing subscription payments via StripePerformance of contract; legal obligation (invoicing/tax)
Sending transactional emails (OTP codes, receipts, account notices) via ResendPerformance of contract; legitimate interest in operating the service securely
Keeping the Service secure, preventing abuse, and debugging issuesLegitimate interest in security and reliability
Responding to support requestsPerformance of contract; legitimate interest
Complying with law (e.g. tax, accounting, law-enforcement requests)Legal obligation

We do not use your business or expense data to train third-party AI models, and we do not sell personal data.

5. Roles and access within your business account

Sandooq is designed around your business's own team structure. Access to a company's data is controlled by the roles your business assigns:

  • Owner / Admin: full visibility into the company's floats, expenses, and staff.
  • Accountant: access to records and exports needed for bookkeeping.
  • Driver / field staff: access limited to logging expenses against floats they are assigned to.

It is the Customer's responsibility to assign roles appropriately and to remove staff access when someone leaves the business.

6. Who we share data with (sub-processors)

We do not sell personal data. We share it only with the service providers (“sub-processors”) that help us run Sandooq, each bound by contract to protect it and to use it only to provide their service to us:

ProviderRoleWhat they process
SupabaseDatabase hosting & auth infrastructureAll application data (account, expense, receipt and log data), stored in Postgres
VercelApplication & website hostingRequests to the app/website; no persistent business data storage
StripeSubscription billing & payment processingBilling contact details and payment card data (never touches Sandooq's own systems)
ResendTransactional email deliveryRecipient email address and email content (e.g. OTP codes, notices)

We may also disclose information where required by law, to enforce our Terms of Service, or in connection with a merger, acquisition, or sale of assets (with notice to affected customers where required).

The full sub-processor list and roles for business customers are also set out in our Data Processing Addendum.

7. Where your data is stored and international transfers

Application data is hosted with Supabase in the Mumbai (ap-south-1) region. This may change as we add regions, and we will update this policy if it does.

Because our infrastructure and sub-processors may be located outside the UAE, using Sandooq may involve transferring your data internationally (including to India, the United States, and/or the European Union, depending on the provider). Where we transfer personal data across borders, we rely on appropriate contractual safeguards with our sub-processors, including standard contractual clauses where applicable.

8. Data retention

We retain personal data for as long as your business account is active, so that you have continuous access to your expense history. After an account is closed:

  • Account and expense records are kept for 30 days after an account is closed to allow recovery, then deleted or anonymized on request, except where we must keep records longer for accounting, tax, or legal reasons.
  • We take periodic backups of production data and rotate them on a schedule; older backups are deleted as part of that rotation.

9. How we protect your data

Security is treated as core to the product, not an add-on:

  • Encryption at rest: data is encrypted at rest using AES-256.
  • Encryption in transit: all traffic to and from the Service is encrypted (TLS).
  • Tenant isolation: every company's data is isolated at the database layer using row-level security (RLS), so one business cannot see another's data.
  • No card data stored: payment card details are handled solely by Stripe; Sandooq never stores or has access to full card numbers.
  • Access control: internal access to production data is restricted to authorized personnel on a need-to-know basis.

We are working toward independent security certifications (such as SOC 2 and ISO 27001) as the business matures; we do not currently hold these certifications and do not claim to.

10. Your rights

Depending on your location and applicable law (including the UAE Personal Data Protection Law and, where relevant, EU/UK data protection law), you may have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate or incomplete data;
  • Request deletion of your personal data (“right to be forgotten”), subject to our legal retention obligations;
  • Receive a copy of your data in a portable format (data export);
  • Object to, or request restriction of, certain processing;
  • Withdraw consent where processing is based on consent; and
  • Lodge a complaint with the relevant data protection authority.

If you are a staff user, some of these requests may need to go through the business (Customer) that administers your account, since they control your account as between you and us. To exercise these rights, contact us at support@sandooq.ae.

11. Cookies and similar technologies

The Sandooq website and web app use strictly necessary cookies and local storage (for example to keep you signed in and remember language), plus Vercel Analytics — a privacy-oriented product analytics tool that helps us understand aggregate page views and performance on sandooq.ae and app.sandooq.ae. It does not use advertising cookies or sell personal data for ads.

Simply put:No ad trackers and no advertising pixels. Native iOS and Android apps do not use Vercel Analytics; crash and basic usage signals on Android may use Google Firebase Analytics where the Play build includes it.

12. Children's privacy

Sandooq is a business tool intended for use by adults acting on behalf of a company. It is not directed at, and is not intended for use by, individuals under the age of 18. We do not knowingly collect personal data from children. If we learn that we have inadvertently collected data from a child, we will delete it promptly.

13. Data breach notification

If we become aware of a security incident that compromises the confidentiality, integrity, or availability of personal data, we will investigate promptly and notify affected business customers and, where legally required, the relevant regulator and affected individuals, without undue delay and, where feasible, within 72 hours of becoming aware.

14. Changes to this policy

We may update this Privacy Policy from time to time as the Service, our sub-processors, or the law changes. We will update the “Last updated” date at the top of this page and, for material changes, provide additional notice by email or in-app notice.

15. Contact us

Questions about this Privacy Policy or how we handle your data can be sent to: