FinPulse
Terms Sign in

Privacy Policy

Last updated 24 August 2026

FinPulse connects to your accounting software and shows your finances back to you. To do that we hold your account details and a copy of figures read from your books. We do not sell your data, we do not advertise to you, and we run no analytics or tracking software of any kind on this site.

1. Who we are 2. What we collect 3. Why we use it 4. Your accounting data 5. Cookies 6. Who we share with 7. Where it is stored 8. How long we keep it 9. Security 10. Your rights 11. Disconnecting and deletion 12. Children 13. Changes 14. Contact

1. Who we are

FinPulse is a product of Finalytics Centre of Financial Excellence - FZCO, a free zone company registered with the Dubai Integrated Economic Zones Authority in Dubai, United Arab Emirates, trade licence number 45380, with its registered office at DSO-IFZA, IFZA Properties, Dubai Silicon Oasis, Dubai ("FinPulse", "we", "us").

We are the data controller for the information described in this policy. For anything to do with privacy, write to finpulse@finalytics.ae.

2. What we collect

Everything below is either given to us by you, or read from an accounting system you connect.

Information you give us

WhatWhen
Your name, work email address, company name and job titleWhen you create an account
Your phone numberOptional, at sign-up
Your organisation's name, and the email addresses of people you inviteWhen you set up your organisation and invite colleagues
Anything you write to usWhen you contact support

We record the same contact details as a sales enquiry when you first ask to see FinPulse, even if you do not go on to finish creating an account.

Information created by using FinPulse

  • Sign-in codes. We store a one-way hash of each six-digit code, never the code itself. Codes expire after ten minutes.
  • Sessions. We store a one-way hash of your session token, never the token itself.
  • An activity log of significant actions, such as connecting an accounting system, inviting a colleague or changing someone's role, with who did it and when.
  • Billing references. Our customer and subscription identifiers at Stripe, and your plan status. We never see or store your card details. Those go directly to Stripe.

Information handled automatically

Our hosting provider, Cloudflare, processes standard technical request data, including your IP address, in order to serve the site and protect it from abuse. We do not use this to build a profile of you and we do not run any analytics product.

3. Why we use it

PurposeBasis
Creating your account and signing you inTo perform our contract with you
Reading your accounting data and showing it back to youTo perform our contract with you, on your explicit instruction
Taking payment and managing your subscriptionTo perform our contract with you
Keeping the service secure, and investigating misuseOur legitimate interest in a safe service
Replying to your enquiry about FinPulseYour consent, and our legitimate interest in responding
Meeting tax, accounting and other legal obligationsLegal obligation

We do not sell your personal information, we do not share it with advertisers, and we do not use it to train machine learning models.

4. Your accounting data

This is the part that matters most, so we want to be exact about it.

When you connect Xero, QuickBooks Online, Zoho Books, Odoo or Wafeq, you authorise FinPulse to read from that system. We then store what we need to render your dashboard, which includes bank and cash account names and balances, outstanding customer invoices and supplier bills together with the counterparty name, amount, currency, issue date and due date, your chart of accounts, and profit and loss and balance sheet figures by month.

Two commitments about that access:

  • FinPulse only ever reads. It never creates, edits or deletes anything in your accounting system.
  • FinPulse never moves money. It has no payment feature of any kind. It cannot transfer funds or pay a bill.

Where a provider offers a read-only permission, we ask for nothing more: our Xero and Zoho Books connections are restricted to read access at the provider itself. QuickBooks Online, Odoo and Wafeq do not offer a read-only option, so the credential those issue technically allows more than we use. We only ever read, and you can revoke the connection at any time from inside that provider.

We also store the access credentials for that connection, which for Xero, QuickBooks and Zoho Books means OAuth tokens issued by the provider, and for Odoo and Wafeq means the instance details and API key you enter. These are held so that we can refresh your figures on a schedule without asking you to reconnect each time.

Your accounting data is visible only to members of your own organisation, according to the role its administrator gives them. It is never shown to another customer.

5. Cookies

FinPulse sets one cookie, fp_session. It keeps you signed in, lasts up to 30 days, and is marked HttpOnly, Secure and SameSite=Lax. It is strictly necessary, so there is nothing to opt out of and no cookie banner to click.

We set no advertising cookies, no analytics cookies and no third-party tracking pixels.

One thing to note for completeness: our pages load the Inter typeface from Google Fonts, which means your browser makes a request to Google and Google receives your IP address as part of that request.

6. Who we share with

We use a small number of service providers. Each is bound to protect your data and to use it only to provide their service to us.

ProviderWhat they doWhat they receive
CloudflareHosting, database, network securityAll application data, technical request data
StripeSubscription paymentsYour name, email and payment details, which you give to Stripe directly
ResendSending sign-in code emailsYour email address and the code
Google FontsDelivering the site typefaceYour IP address, when your browser loads the font

We also exchange data with the accounting provider you choose to connect, in order to read your books. That provider's own privacy policy governs what they do with your information.

We may disclose information if we are legally required to, or to establish or defend legal claims. If our business is ever sold or restructured, information may transfer to the buyer, who would remain bound by this policy.

7. Where it is stored

FinPulse runs on Cloudflare's global network, and our providers operate infrastructure outside the United Arab Emirates. Your information will therefore be processed and stored outside the UAE, including in the United States and the European Union. We rely on our providers' contractual safeguards for those transfers.

8. How long we keep it

DataKept for
Your account and organisationWhile your account is open
Accounting data and connection credentialsUntil you disconnect, which deletes them straight away
Everything, after you close your accountDeleted within 30 days, except as below
Sign-in codes and sessionsMinutes to 30 days, then expired
Sales enquiry contact details24 months from your last contact with us
Activity log and billing recordsUp to 7 years, where tax and company law require it

9. Security

  • All traffic runs over HTTPS.
  • There are no passwords to steal. Signing in uses a one-time code sent to your email.
  • Sign-in codes and session tokens are stored only as one-way hashes, and codes are rate limited and expire.
  • Accounting credentials are held server-side and are never exposed to the browser.
  • Access within an organisation is limited by role, and every organisation's data is separated from every other.

No system is perfectly secure. If we discover a breach affecting your personal data, we will tell you and the relevant authority without undue delay.

10. Your rights

Subject to the law that applies to you, you can ask us to:

  • give you a copy of the personal data we hold about you;
  • correct anything that is wrong;
  • delete your data, where we are not required to keep it;
  • restrict or object to how we use it;
  • provide it in a portable format;
  • withdraw consent, where we relied on consent.

Email finpulse@finalytics.ae and we will respond within 30 days. You can also complain to your local data protection authority.

11. Disconnecting and deletion

An administrator can disconnect at any time from the Connections screen in FinPulse. Disconnecting revokes our access at the provider, deletes the credentials we hold, and deletes the financial data we derived from your books. Nothing in your own accounting system changes.

You can also revoke our access from inside your accounting provider, under its connected apps or authorised applications settings. Either route stops further data being read immediately.

To close your account entirely, email finpulse@finalytics.ae from the address on your account. We will confirm and complete the deletion within 30 days.

12. Children

FinPulse is a business product and is not intended for anyone under 18. We do not knowingly collect information from children. If you believe a child has given us information, contact us and we will delete it.

13. Changes to this policy

If we change this policy we will update the date at the top. If a change materially affects how we handle your information, we will email account administrators at least 30 days before it takes effect.

14. Contact

Finalytics Centre of Financial Excellence - FZCO
DSO-IFZA, IFZA Properties
Dubai Silicon Oasis, Dubai
United Arab Emirates
finpulse@finalytics.ae

FinPulse · a Finalytics product · Privacy · Terms · finpulse@finalytics.ae