Privacy Notice

This is an interim notice. A full UAE PDPL-compliant policy will replace it shortly.

What we collect

When you create an account we collect: email, name, and authentication metadata via Clerk. When you subscribe, billing details are handled entirely by Stripe — we do not store card data. We log basic request metadata (timestamp, route, anonymized IP) for security and abuse prevention.

How we use it

To authenticate you, deliver the subscribed service, communicate essential service messages, prevent abuse, and improve the product. We do not sell personal data and do not use it for cross-site advertising.

Sub-processors

Clerk (authentication), Stripe (billing), Neon (database hosting), Upstash (caching), DigitalOcean Spaces (asset CDN), Vercel (hosting).

Your rights

Data export: signed-in users can download a JSON export of their account record at GET /api/user/export. The export covers Underwrite's primary database. Authentication data is held by Clerk and billing records by Stripe — request export from those providers separately.

Erasure: signed-in users can delete their account by sending POST /api/user/delete with body {"confirm":"DELETE_MY_DATA"}. If you hold mandates, we will complete the manual portion of the erasure within 30 days.

For other requests (access in a different format, correction, objection) email privacy@underwrite.ae. We respond within 30 days.

Cookies

We use only essential cookies (Clerk session, Stripe checkout). No analytics or advertising trackers are set.