Finloraq is an AI finance operating system — double-entry accounting, cash flow forecasting and an AI copilot for finance teams and business owners — built and operated by PAPPLE WORLD FZE LLC, a company registered in Ras Al Khaimah (RAK), United Arab Emirates.
This policy explains what we collect when you visit our marketing site, sign up for Finloraq, or use the product day to day, and what rights you have over that information. It covers finloraq.com and the authenticated application at app.finloraq.com.
When you register, we collect your name, email address and password (stored as a salted hash — we never store or can recover your plaintext password). If you set up two-factor authentication, we store the state needed to verify it, not your raw authenticator secret in reversible form. When you create or join a company workspace, we store the company's name, currency and the role each user holds within it.
Finloraq is an accounting system, so the core of what we store is the financial data you put into it: ledger entries, invoices, bills, expenses, purchases, sales, customer and supplier records, projects, cost centres, tax records and bank account records (account name, currency and balances you enter — Finloraq does not connect to your bank via a live feed; you create these records and their transactions directly). Documents you upload — receipts, invoices, bank statements, contracts — are stored so they can be attached to the records they support and, where you use AI extraction, processed to draft entries for your review.
If you connect optional integrations, we process what they send us: inbound emails to your dedicated Finloraq address (for document capture) and WhatsApp Business messages, each verified against a signed webhook so we only accept genuine messages from that channel.
Subscription payments are handled by Stripe. We do not store your card number or other full payment credentials — Stripe passes us the subscription status, plan and billing metadata needed to run your account, not your raw card data.
We keep an audit trail of security- and account-relevant actions (sign-ins, registrations, permission and record changes) tied to the user and company they belong to, so that activity in a shared workspace is traceable. We also process standard technical data — IP address, request headers, timestamps — for the limited purposes of rate-limiting abuse (e.g. repeated failed logins) and keeping the service running.
We do not sell your personal information, and we do not use your financial data to serve third-party advertising.
Features like AI-drafted journal entries, document extraction, the AI CFO copilot and voice commands work by sending the relevant text — for example, the content of a document you upload, or a transcript of a voice command — to a third-party AI provider (currently Anthropic and/or OpenAI, depending on configuration) for processing. That provider returns a proposed result, which is never applied to your books automatically: every AI-proposed entry or action is shown to you for review and requires your explicit confirmation before anything is posted.
We do not permit AI providers we use to train their general-purpose models on your data under our commercial terms with them. If you have specific questions about what a particular AI feature sends, ask us at hello@finloraq.com — we would rather answer directly than have you guess.
We keep your account and financial records for as long as your account is active, plus a reasonable period afterward to meet accounting, tax and legal record-keeping obligations that commonly apply to financial software (which can require retaining financial records for several years). If you close your account, contact support@finloraq.com to request deletion of your personal data beyond what we are required to retain for those legal purposes.
We apply security practices appropriate to handling financial data, including:
No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your data, we will notify affected users and relevant authorities as required by applicable law.
Depending on where you live, you may have rights to access, correct, export or delete your personal data, or to object to or restrict certain processing — for example under the UAE's Personal Data Protection Law, the EU/UK GDPR, or U.S. state privacy laws such as the CCPA/CPRA. To exercise any of these, email hello@finloraq.com; we will respond within the time required by the law that applies to you.
Within a company workspace, note that your company's administrators also control access to records within that workspace as part of its own accounting requirements — some requests may need to go through your company admin rather than us directly, if the data belongs to their business records rather than to you personally.
We are based in the UAE and use infrastructure and service providers located in other countries, so your information may be processed outside the country where you live. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for these transfers.
Finloraq is a business tool and is not directed at, or intended for use by, children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact us and we will delete it.
We may update this policy as Finloraq changes. If we make material changes, we will update the effective date above and, where appropriate, notify you directly (for example, by email or an in-app notice).
Questions about this policy or your data can be sent to hello@finloraq.com or support@finloraq.com.
PAPPLE WORLD FZE LLC — Ras Al Khaimah (RAK), United Arab Emirates.