Privacy Policy
Last updated 10 August 2026
This policy explains how Infinite Barakah Ventures (“we”), the provider of Cashflow OS, collects, uses, stores and protects personal data. It is written to meet Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the UAE PDPL).
1. Who we are
Infinite Barakah Ventures, Dubai, United Arab Emirates, is the data controller for account and billing data. For the financial records a customer loads into Cashflow OS, the customer is the controller and we act as their processor.
Privacy contact: privacy@infinitebarakah.com.
2. What we collect
- Account data — name, work email, organization, role, and authentication identifiers. Collected from you or from your administrator.
- Customer content — the payables, receivables, cheques, facilities, projects and related records you upload or sync. This may contain personal data about your own counterparties.
- Usage and audit data — a record of who changed which row and when, plus security events such as sign-ins. This exists because finance software needs an audit trail; it is not used for profiling or advertising.
- Billing data — subscription status and invoices. Card details are handled by Stripe and never reach our systems.
3. Why we process it, and on what basis
| Purpose | Lawful basis (PDPL Art. 4) |
|---|---|
| Providing the service to your organization | Necessary for performance of a contract |
| Maintaining the audit trail and security logs | Legitimate interest in security and record integrity; legal obligation where accounting rules apply |
| Billing, invoicing and tax records | Legal obligation (UAE VAT and e-invoicing rules) |
| Service email such as the daily cash summary | Consent — opt-in, withdrawable at any time from Settings or the unsubscribe link in every message |
4. Who we share it with
We do not sell personal data. We use a small number of processors:
- Supabase — database, authentication and file storage.
- Vercel — application hosting and delivery.
- Stripe — subscription billing and payment processing.
- Resend — transactional and summary email delivery.
- Zoho — only where you connect Zoho Books yourself. That link is read-only and one-way into Cashflow OS; we never write back to your accounting system.
5. Where the data lives
Customer data is stored in AWS ap-southeast-2 (Sydney, Australia), via Supabase. The UAE PDPL does not require data localisation, and no transfer restriction applies to this arrangement; the region is disclosed so customers can assess it. Customers with a contractual or regulatory need for a different region should contact us before onboarding.
6. How long we keep it
Customer content is retained for as long as the organization's account is active, and deleted within 90 days of account closure unless a longer period is required by law. Audit and billing records are retained for the statutory retention period. You can export a full copy of your organization's data at any time from Settings, in Excel format.
7. Your rights
Under the PDPL you may request:
- access to the personal data we hold about you;
- correction of inaccurate or incomplete data;
- deletion of your data, subject to our legal retention duties;
- a portable copy of your data (the Excel export satisfies this directly);
- restriction of, or objection to, certain processing;
- withdrawal of consent where consent is the basis, such as summary emails.
Write to privacy@infinitebarakah.com. We respond within 30 days. If you are an employee of a customer organization, we may need to route your request through that organization, since they control the record.
8. Security
Data is encrypted in transit (TLS 1.2+) and at rest. Every tenant table is protected by database-level row-level security keyed on organization, so one customer's query cannot return another's rows. Access inside a customer organization is role-based, and every write is recorded in an append-only audit trail. A security summary is available on request.
9. Breach notification
If a personal data breach occurs that is likely to prejudice the privacy, confidentiality or security of data subjects, we notify the UAE Data Office and affected customers without undue delay, and in any case within 72 hours of becoming aware of it. Notification describes what happened, the data involved, the likely consequences, and the steps taken.
10. Changes
We will post any change here and update the date above. Material changes are also emailed to organization administrators.