Last updated:
Privacy Policy
3 October 2026
1. Introduction
This Privacy Policy explains how TrustBill LLC ("TrustBill", "we", "us") collects, uses, discloses and safeguards personal data when you use our e-invoicing platform, mobile and desktop applications, website, and related services (together, the "Services"). It applies to Consultancies, SMEs, and any individual user acting for either. TrustBill acts as a Data Controller for its own account, billing and platform data, and as a Data Processor for Customer Data submitted by Consultancies and SMEs (see Section 10). This Policy is issued under and read in accordance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("PDPL") and its implementing regulations, together with all other applicable UAE laws and Federal Tax Authority ("FTA") e-invoicing regulations.
2. Definitions
Capitalised terms have the meanings given in the PDPL. In particular:
- "Personal Data" — any information relating to an identified or identifiable natural person.
- "Sensitive Personal Data" — data that reveals family, ethnic, religious, political, criminal, biometric, genetic, health or financial-identifier information as defined in Article 1 of the PDPL.
- "Data Subject" — the natural person to whom Personal Data relates.
- "Data Controller" — the person or entity that determines the purpose and means of processing.
- "Data Processor" — the person or entity that processes Personal Data on behalf of a Controller.
- "Customer Data" — invoice content, buyer/seller records, line items, tax data and files submitted to the Services by or on behalf of a Consultancy or SME.
3. Personal Data We Collect
We collect the following categories of Personal Data:
- Identity data: name, job title, national ID or passport number (only where required for KYB or FTA registration), Emirates ID, date of birth.
- Contact data: business email address, phone number, business address, WhatsApp number if provided.
- Business data: company legal name, trade licence number and expiry, Tax Registration Number (TRN), corporate group information, bank account details for payouts.
- Account data: username, hashed password (Argon2id), authentication tokens, role assignments, multi-factor authentication settings.
- Financial data: invoice line items, buyer/seller TRNs, VAT amounts, credit balances, subscription and payout records. Payment card data is processed directly by Stripe under its own privacy policy — we do not receive or store full card numbers.
- Technical data: IP address, device identifiers, browser type and version, operating system, referrer URL, session duration, feature-usage telemetry, error diagnostics.
- Communications data: support tickets, email correspondence, in-app messages, call recordings where lawfully made and disclosed.
- Sensitive Personal Data: we do not intentionally process Sensitive Personal Data. If it appears in Customer Data (for example, on an uploaded invoice or receipt), you are responsible for ensuring you have the legal basis to process it.
4. How We Collect Personal Data
Personal Data reaches us in three ways:
- Directly from you — when you sign up, subscribe, submit invoices, upload documents, or contact us.
- Automatically — through cookies, log files, error monitors, and usage analytics when you interact with the Services (see Section 15).
- From third parties — from your Consultancy when they invite you, from your ERP when you connect it, from Stripe for payment confirmations, from Accredited Service Providers ("ASPs") for invoice-delivery receipts, and from public registers (trade-licence and TRN verification via the UAE Federal Tax Authority public lookup).
5. Purposes and Legal Basis for Processing
We process Personal Data for the purposes below, on the legal bases set out in Article 5 of the PDPL:
- To provide the Services (basis: performance of contract with the Consultancy or SME) — creating accounts, delivering invoices to ASPs and the FTA, managing subscriptions, providing customer support.
- To meet legal obligations (basis: legal obligation) — retaining invoicing and tax records under Federal Decree-Law No. 8 of 2017 on VAT and applicable FTA rules; complying with UAE Anti-Money Laundering (Federal Decree-Law No. 20 of 2018) and Cybercrime laws.
- To operate and secure the platform (basis: legitimate interest) — fraud detection, abuse prevention, capacity planning, error monitoring, and product improvement.
- To communicate with you (basis: performance of contract for transactional messages; consent for marketing) — service notices, security alerts, feature updates, and, only with your consent, marketing communications.
- With your explicit consent — for optional analytics cookies, product research invitations, and any processing that requires consent under the PDPL.
6. Sharing and Disclosure
We share Personal Data only where necessary and only with the categories of recipient set out below. We do not sell Personal Data.
- Sub-processors acting on our behalf: Stripe Payments Europe Ltd (payment processing), our infrastructure hosting provider (compute, storage, database), Sentry (error monitoring), Resend or an equivalent transactional email provider, IndexNow-participating search services (for public marketing URLs only, no user data).
- Accredited Service Providers (ASPs): Microvista, Tron-Stride, Storecove, Complyance or an equivalent FTA-accredited partner nominated by the SME's Consultancy. Invoice data is transmitted to the ASP so it can be delivered to the FTA under Cabinet Decision No. 106 of 2025.
- The Federal Tax Authority: invoice content, buyer/seller TRNs and status metadata are transmitted through the ASP to the FTA e-invoicing network as required by UAE law.
- The Consultancy that invited you (if you are an SME): your Consultancy sees your account status, invoice counts, subscription state and any data you elect to share for support purposes. If you sign up directly without a Consultancy, this does not apply.
- Professional advisers: legal, accounting and audit firms bound by confidentiality, engaged by us and only to the extent they need Personal Data to advise us.
- Authorities: regulators, courts and law-enforcement authorities where compelled by law, court order, or a valid regulatory request.
- A successor entity: in the event of a merger, acquisition, or asset sale, on notice to you and subject to the acquirer accepting obligations no less protective than this Policy.
A current list of our material sub-processors is available on request to info@trustbill.ae. We contract each sub-processor to apply security and confidentiality standards consistent with the PDPL.
7. Data Residency and Storage Location
TrustBill's production databases and object storage are located inside the United Arab Emirates so that Customer Data — invoice content, buyer/seller records, tax data — remains subject to UAE jurisdiction. Certain limited operational data (error diagnostics stripped of Customer Data, payment metadata processed by Stripe, email delivery metadata) may be processed outside the UAE by the sub-processors listed in Section 6, subject to the safeguards described in Section 8.
8. International Data Transfers
Where a sub-processor operates outside the UAE and receives Personal Data, we rely on one of the transfer mechanisms permitted by Articles 22 and 23 of the PDPL: an adequacy assessment of the destination country, an appropriate contractual safeguard (typically the sub-processor's standard data-processing agreement plus, where applicable, standard contractual clauses aligned with UAE Data Office guidance), or your explicit consent for a specific transfer. We transfer only the minimum data required for the sub-processor's stated purpose.
9. Retention
We retain Personal Data only for as long as necessary for the purpose it was collected and to comply with applicable law. Specific retention periods:
- Invoice content and tax records: retained for at least five (5) years from the end of the tax period to which they relate, per the record-keeping requirements of Federal Decree-Law No. 8 of 2017 on VAT and Federal Decree-Law No. 47 of 2022 on Corporate Tax. Real-estate related invoices may be retained for fifteen (15) years where the FTA requires.
- Account and authentication data: retained while the account is active and for twelve (12) months after account closure to allow reactivation and comply with anti-fraud obligations, then deleted or anonymised.
- Support tickets and correspondence: three (3) years after resolution.
- Payment and billing records: seven (7) years from the transaction date, consistent with UAE commercial-record-keeping practice.
- Marketing consent records: retained while consent remains valid plus two (2) years after withdrawal to evidence the withdrawal.
- Aggregated or anonymised data derived from your usage may be retained indefinitely.
10. Our Role: Controller vs. Processor
TrustBill's role depends on the data:
- For account, billing, security and platform-usage data belonging to Consultancies and their operators, we act as Data Controller.
- For Customer Data submitted through the Services by a Consultancy or SME (invoice content, buyer/seller records, uploaded documents), we act as Data Processor for that Consultancy or SME, who is the Controller for that data.
- Consultancies who use TrustBill to service their SME clients act as Controller for the SME data they hold on the platform and are responsible for having the necessary legal basis to process it. An SME that signs up directly is Controller for its own data.
A Data Processing Agreement (DPA) suitable for enterprise customers is available on request to info@trustbill.ae.
11. Security
We implement technical and organisational measures appropriate to the risks of processing, including:
- Encryption in transit (TLS 1.3) and at rest (AES-256-GCM envelope encryption for sensitive fields).
- Argon2id password hashing and secure session-token issuance (RS256-signed JWTs with short lifetimes).
- Row-level security in the database so tenant data is isolated by design.
- Least-privilege operator access, IP allowlisting for administrative surfaces, and full audit logging of administrative actions in a hash-chained tenant_actions ledger.
- Automated daily database backups.
- Continuous vulnerability monitoring, patch management, and periodic security review of the codebase.
No system is completely secure. If we become aware of a personal data breach, we will notify affected Data Subjects and the UAE Data Office within the time limits set by the PDPL implementing regulations (typically within 72 hours of becoming aware of the breach).
12. Your Rights Under the PDPL
Subject to the conditions and exceptions in Articles 13-19 of the PDPL, you have the right to:
- Access — obtain confirmation of whether we process your Personal Data and receive a copy.
- Rectification — correct inaccurate or incomplete Personal Data.
- Erasure — request deletion of your Personal Data, subject to legal retention obligations (in particular FTA record-keeping under Section 9).
- Restriction — ask us to limit processing while a rectification, deletion or objection request is being handled.
- Portability — receive your Personal Data in a structured, commonly used, machine-readable format and have it transmitted to another controller where technically feasible.
- Objection — object to processing based on legitimate interests, direct marketing, or automated decision-making.
- Withdrawal of consent — withdraw any consent you previously gave, without affecting the lawfulness of processing carried out before the withdrawal.
- Human review of automated decisions — where a decision that significantly affects you is based solely on automated processing (we do not currently make such decisions).
13. How to Exercise Your Rights
You may exercise any of the rights in Section 12 by emailing info@trustbill.ae or info@trustbill.ae. We will:
- Verify your identity before acting on the request.
- Respond within thirty (30) days of a valid request. Complex or repeated requests may be extended by a further thirty (30) days on notice.
- Fulfil the request free of charge unless it is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse.
- For SME data held on behalf of a Consultancy, we may direct you to your Consultancy to action the request, since they are the Controller.
14. Automated Decision-Making and Profiling
We do not currently make decisions that produce legal or similarly significant effects on you based solely on automated processing. Where we introduce such processing in future, we will update this Policy, seek any consent required, and offer you the right to obtain human intervention, express your point of view, and contest the decision.
15. Cookies and Similar Technologies
The Services use cookies and similar technologies (local storage, session storage, analytics tags) for the following purposes. On your first visit we present a consent banner where you can accept or reject non-essential categories.
- Strictly necessary — session, authentication, CSRF protection, load balancing, consent state. These cannot be disabled.
- Preference — locale (English/Arabic), theme, and UI state.
- Analytics — aggregated product-usage measurement (loaded only after you consent).
- Marketing — attribution to referring campaigns (loaded only after you consent).
You can withdraw consent at any time from the cookie preferences link in the site footer, or by clearing cookies in your browser settings.
16. Children
The Services are intended for use by natural persons aged eighteen (18) or over acting on behalf of a business. We do not knowingly collect Personal Data from anyone under 18. If we learn we have inadvertently collected such data we will delete it promptly. If you believe a minor has provided us Personal Data, please contact info@trustbill.ae.
17. Marketing Communications
We send transactional messages (service notices, security alerts, invoice-status updates) without needing separate marketing consent because they are necessary to perform our contract with you. We only send marketing messages if you opt in. Every marketing email includes an unsubscribe link; SMS/WhatsApp marketing (if any) includes a STOP keyword. Withdrawing marketing consent does not affect transactional messages.
18. Third-Party Links and Integrations
The Services may link to or integrate with third-party sites and platforms (ERP systems such as QuickBooks, Xero, Odoo, Tally, Zoho; the FTA e-invoicing network; the App Store, Google Play and Microsoft Store; payment processors). We do not control those third parties and are not responsible for their privacy practices. Their privacy policies apply to the data they collect. Review them before connecting or providing data.
19. Changes to This Policy
We may update this Policy from time to time. If we make material changes we will notify you by email, by an in-app notice, or by a prominent banner on the site at least thirty (30) days before the change takes effect. The "Last updated" date at the top of the page always reflects the most recent revision. Continued use of the Services after the effective date constitutes acceptance of the updated Policy.
20. Complaints
If you believe we have handled your Personal Data in a way that breaches the PDPL, please contact us first at info@trustbill.ae so we can investigate and respond. You also have the right to lodge a complaint with the UAE Data Office at https://www.dataoffice.gov.ae/.
21. Contact Us
For any question about this Policy, to exercise a right, or to request the Data Processing Agreement:
Email: info@trustbill.ae
Registered address: TrustBill LLC, Media City, Sharjah, United Arab Emirates