Privacy Policy
Last updated: 2025-08-19
This Privacy Policy explains how Tabsy (“we”, “us”) collects, uses, and protects personal data when you use our website and services. We aim to comply with the EU GDPR (including France) and the UAE Personal Data Protection Law (PDPL).
1. Data Controller
The data controller is Tabsy. For privacy inquiries or rights requests, contact us at the address in the Contact page.
2. What We Collect
- Account data: name, email, company.
- Receipt data: receipt files (PDF/JPG) and metadata (totals, items, date, store).
- Device & usage data: IP address, logs, pages visited (security/analytics).
- Support data: messages you send us.
3. How We Use Data
- Provide and improve the service (store, index, and surface receipts).
- Authenticate users and ensure security.
- Respond to support requests and communicate service updates.
- Comply with legal obligations.
4. Legal Bases (GDPR)
- Contract — to provide Tabsy.
- Legitimate interests — security, product improvement, limited analytics.
- Consent — for non‑essential cookies/trackers.
5. International Transfers
We may process data outside your country. For GDPR, we rely on adequacy or SCCs. For UAE PDPL, we follow applicable cross‑border transfer safeguards.
6. Retention
We keep data as long as needed for these purposes or as required by law. Receipt files follow retailer agreements and end‑user accounts.
7. Your Rights
You can request access, correction, deletion, restriction, or portability of personal data. You can object to certain processing and withdraw consent. Contact us via Contact. You may also complain to your supervisory authority (e.g., CNIL in France).
8. Cookies
We use essential cookies to run the site and non‑essential cookies for analytics only with your consent. Manage preferences via the cookie banner.
9. Security
We use encryption at rest for receipt files, access controls, and monitoring.
10. Processors & Sharing
We share data with cloud/IT providers acting as processors bound by contractual obligations. We do not sell personal data.
11. Contact
To exercise rights or ask questions, see Contact.