Privacy Notice
1. Controller
SITUS FZ L.L.C., Expo City Dubai Authority Service Licence No. 00134, Dubai, United Arab Emirates, is the controller of personal data it processes for website, account, billing and service-administration purposes, unless a different role is expressly stated for a feature.
2. Data we process
- Account data: name, business email, authentication identifiers and account status.
- Subscription and billing data: plan, entitlement, payment/customer identifiers, billing status and transaction metadata. Payment card details are handled by the payment processor rather than stored directly by SITUS.
- Technical data: browser/device information, security events, timestamps, error diagnostics and aggregate usage counts and opaque record identifiers used to coordinate plan limits across companies and operate the Service.
- Checkout consent: Stripe records acceptance of the required terms checkbox with checkout information. The app does not currently provide an independently archived copy of the exact terms text accepted at each checkout.
- Customer Content: vendor/supplier data, invoices, evidence, explanations and other compliance records entered by the customer. In the encrypted-vault architecture, this content is encrypted client-side. The current build supports encrypted browser storage, selected-folder workspace files with retained revisions, and manual encrypted backup export and restore.
- Support communications: messages and files voluntarily sent to SITUS for support.
3. Why we process data
We process data to provide and secure VAT Guard, authenticate users, administer subscriptions, enforce plan entitlements, provide encrypted backup-file export/recovery, deliver transactional communications, detect abuse, maintain legal/security records, comply with law and improve reliability.
Early-bird email offers
If you request an offer, we store your email, selected plan, verification and consent timestamps, offer status, delivery records and subscription identifiers. For instant offers, we also store the original five-minute deadline and an opaque checkout-session reference. Your browser stores a signed offer reference so refreshing does not restart the timer; it does not grant access to your account. We do not send a confirmation email before instant checkout. An optional, unchecked choice lets you request up to three promotional reminders over seven days after your request. The first two do not renew an expired five-minute discount; the final reminder may contain a separate first-month-free offer. Earlier confirmation-email offers retain their original reminder schedule after confirmation. The discount is available without this marketing choice. You can withdraw consent using the unsubscribe link in each message; this stops offer reminders but does not cancel a subscription or necessary billing notices.
We check Stripe subscription status before sending reminders and stop the sequence on purchase, withdrawal, a bounce or complaint. Email and IP hashes help limit abuse and are deleted after seven days. Campaign lead, offer-session and delivery records are deleted after 90 days from the request, once any free trial has ended. Billing and legally required records follow their separate retention rules. Email-provider delivery logs may follow that provider’s retention settings. Campaign emails do not use open or click tracking. Contact consult@thevatguide.ae to exercise your rights.
4. Customer-side encrypted content
Customer Content in the local vault is encrypted in the browser. Where the customer exports a .vgbackup file, the exported content remains encrypted. The current build does not automatically upload that backup to SITUS, Google Drive or iCloud. SITUS does not need the customer’s vault passphrase or recovery key to administer subscriptions. Customers must protect their recovery credentials. If the encryption architecture makes recovery technically impossible without the key, SITUS may be unable to restore readable content when the key is lost.
5. Service providers
VAT Guard may use service providers for website hosting, application hosting/CDN, authentication, subscription payments, transactional email, monitoring and security. The current service uses Tilda for marketing pages, Cloudflare Pages for app and demo hosting, Supabase for authentication and account/subscription metadata, Stripe for payments, and Resend for transactional email and consented offer reminders. The Supabase project is hosted in Frankfurt. Other providers operate internationally; their processing locations and contractual terms apply. Supplier documents are processed locally for PDF reading and OCR, rather than sent to an external document-analysis service. Your organisation selects and controls any provider used to sync its workspace folder.
6. International processing
Service providers may process data in jurisdictions outside the UAE. SITUS will use contractual, technical and organisational safeguards required by applicable UAE data-protection law where cross-border transfers occur.
7. Retention
Account, subscription, security, tax-invoice and legal records are retained for periods reasonably necessary for their purposes and applicable legal obligations. Customer Content kept in the local encrypted vault remains under the customer’s browser/device storage controls. Customers are responsible for maintaining exported encrypted backups where needed. Account/control-plane records are retained according to the Service’s subscription, termination and legal-retention settings.
8. Security
SITUS uses reasonable technical and organisational measures appropriate to the Service. No internet, browser, encryption or cloud system is absolutely secure. Customers are responsible for authorised-user management, endpoint security, strong credentials and recovery-key custody.
9. Rights
Individuals may have rights under applicable UAE data-protection law, including rights relating to access, correction, deletion or other processing controls, subject to legal limitations and verification of identity. Requests should be sent through the privacy/contact channel published on the VAT Guard website.
10. Cookies and local storage
The application may use strictly necessary browser storage for authentication and the encrypted working vault. With your permission, Google Ads measures visits and completed paid purchases using advertising click identifiers, first-party cookies, the amount paid, currency and an opaque transaction identifier. This helps us understand which ads lead to subscriptions. Free trial sign-ups are not reported as paid purchases. Google receives technical request information such as IP address and browser details. We do not send passwords, verification links, email addresses, supplier records, invoices or document contents to Google Ads. Automatic enhanced conversions and personalised advertising are disabled in this implementation. Measurement runs in a dedicated page with a clean URL, rather than sending your account-access URL. Your choice is shared across thevatguide.ae and its app subdomain for 180 days; advertising attribution and duplicate-prevention records are retained for up to 90 days. A pending purchase measurement can retry for up to 30 days. Choosing No thanks leaves Google Ads measurement off and does not affect purchase or app access. . You can also clear your browser cookies and site data. Google processes measurement data under its Privacy Policy. Tilda supplies the marketing-page hosting and its necessary technical services.
11. Changes
This Notice may be updated as the product architecture or law changes. Material changes will be identified by a new version/effective date and notified where appropriate.
12. Contact
Privacy questions and requests can be sent to consult@thevatguide.ae. Do not send your workspace passphrase or recovery key.