1. Data Collection Philosophy
At ecashbiz, we operate on a "Minimal Exposure" principle. We collect only the data necessary to provide a functional agency ledger. This includes business identity details (TRN, Name), user credentials for authentication, role and permission data for owner-manager-staff access control, and transactional data you choose to record for operational needs.
2. Encryption & Isolation
All sensitive records—including customer phone numbers, transaction profits, and government tracking IDs—are encrypted in transit via TLS 1.3 and stored in isolated database partitions. We utilize multi-tenant architecture to ensure one organization's data can never be accessed by another.
Our services run on high-performance cloud infrastructure with CDN delivery for assets and workspace files to keep data access fast and reliable.
3. Dropbox Cloud Backup
If you choose to enable the "Cloud Backup" feature (Enterprise plan), ecashbiz uploads your workspace data as a JSON file to the "ecashbiz-backups" folder in your connected Dropbox account. We only write and read files in that dedicated folder. This feature is designed to prevent data loss and gives you direct custody of your registry backups.
4. Role-Based Access & Audit Logs
Workspace access is protected by role-based permissions. Staff permissions are managed by managers, and managers are governed by workspace owners. We also maintain audit logs of key workspace actions so organizations can review activity history, strengthen accountability, and investigate misuse. ecashbiz personnel do not individually access customer login passwords and cannot arbitrarily change workspace business data outside authorized product controls.
5. Authentication & Payments
We support Google authentication for secure account access. Payments are processed through Ziina, and ecashbiz does not store full payment card information on its own systems.
6. Third-Party Disclosures
We strictly adhere to a No-Sale Policy. Your client databases and financial turnover metrics are your business intelligence and will never be shared, sold, or rented to third-party marketers or data aggregators. We only share data with essential service providers (e.g., Firebase for hosting) under strict confidentiality agreements.
7. Right to Erasure
Workspace Managers have the absolute right to purge their registry at any time. The "Registry Wipe" tool in the settings panel provides a permanent deletion of all invoices, transactions, and user profiles. Once confirmed, this action is irreversible and data is purged from our active systems within 24 hours.
8. Compliance with UAE Data Laws
Our privacy practices are designed to align with the UAE Federal Decree-Law No. 45 of 2021 regarding the Protection of Personal Data, ensuring that personal information is handled with the highest standards of integrity and transparency.
9. Branding Assets in Workspace Documents
Your configured branding assets (including logo, stamp, signature, and letter pad templates) are used only for generating your workspace documents and outputs, based on your settings and user permissions.
10. Service Operations
Our engineering and support teams continuously maintain and improve the platform using up-to-date technologies and security practices to resolve defects and keep services stable.