Privacy Policy

Effective date: 6/16/2026

Smartify Expense ("Smartify", "we", "us") helps companies capture receipts, run approval workflows, and reimburse employees. This Privacy Policy explains what information we collect, why we collect it, and the choices you have.

1. Information we collect

  • Account data: name, work email, password hash, organization, role, department, manager.
  • Expense data: receipts, merchant, amount, tax, currency, category, mileage, per-diem, trips, advances, purchase orders, notes you upload.
  • Usage data: log events, IP address, browser, device, pages visited, feature actions, error reports.
  • Billing data: plan, billing email, and tokenised payment identifiers held by our payment processor.
  • Integrations: tokens and metadata you authorise (Slack, calendar, accounting, SSO).

2. How we use information

  • To provide and operate the Service (OCR, approvals, reporting, notifications).
  • To secure the platform, prevent fraud, and enforce our Acceptable Use Policy.
  • To support you, communicate service updates, and improve the product.
  • To comply with legal, accounting, and tax obligations.

3. Legal bases (GDPR/UAE PDPL)

We process personal data under contract, legitimate interest, consent, and legal obligation as appropriate. See our GDPR page for details.

4. Sharing

We do not sell personal data. We share data only with: (a) sub-processors that operate the Service (hosting, AI OCR, email, analytics) under contractual safeguards; (b) your own organisation's admins and approvers as required for the workflow; (c) authorities when legally compelled. A current sub-processor list is available on request.

5. Data retention

Expense records are retained for the duration of your subscription plus a statutory retention window required by tax authorities (typically 5–7 years). You may request deletion subject to these obligations.

6. Security

Encryption in transit (TLS 1.2+) and at rest, role-based access control, audit logs, and least-privilege backend access. See the Security page.

7. International transfers

Data may be processed in regions where our hosting providers operate. We rely on Standard Contractual Clauses or equivalent mechanisms for cross-border transfers.

8. Your rights

Access, correction, deletion, portability, and objection. Contact privacy@smartify.sbs.

9. Children

The Service is not directed to children under 16 and we do not knowingly collect their data.

10. Changes

We will notify customers of material changes by email or in-product notice.

11. Contact

Smartify Expense · privacy@smartify.sbs