Legal
Privacy Policy
Last updated: 7 October 2026
In short: We collect the details we need to run your account, bill you and support you, plus basic technical data that keeps the site secure. We don’t sell personal data, we don’t use advertising or tracking cookies, and we only share data with the companies that help us run OLODESK. You can ask us to see, correct or delete your data at any time by emailing [email protected].
1. About this policy
This policy explains how OLODESK collects, uses, shares and protects personal data when you visit olodesk.org, contact us, subscribe, or use your OLODESK dashboard and services. It applies to our customers, the people who work for them, and visitors to our website.
It does not cover the data our customers put into their own apps and automations on OLODESK (for example, their own customers’ orders or contact details). We handle that data on our customers’ behalf, and they decide how it is used; see section 4.
2. Who we are
OLODESK is a trade name of OLODESK INFORMATION TECHNOLOGY CONSULTANCY, a sole proprietorship licensed in the Emirate of Abu Dhabi, United Arab Emirates. We are responsible (the “controller”) for the personal data described in this policy. For anything about your personal data, contact us at [email protected].
3. What we collect
Information you give us
- Account and business details: when you subscribe, your first and last name, email address, phone number and password (which we store only in a scrambled, one-way form), and your business’s legal and trading name, country, tax or VAT ID, and company registration number or UTR.
- Billing details: your billing address, the plan you choose, your invoices and your payment history. Card payments are taken by Stripe; we never see or store your full card number.
- Messages: what you send us through our support form, support tickets or by email, including your email address and the content of your message.
- Settings and requests: the choices you make in your dashboard, such as connected apps, sender names and phone numbers for texts, and requests to change your account details.
Information collected automatically
- Technical data: your IP address, browser and device type, the approximate country your connection comes from (which we use to show prices in the right currency), and your time zone (to show dates in your local time).
- Security and usage data: sign-in times, actions taken in your dashboard, API requests and error logs, which we use to keep accounts secure, measure usage and fix problems.
- Bot checks: our forms use Cloudflare Turnstile, which checks the browser for signs of automated abuse.
Information from others
- Stripe tells us whether a payment succeeded and, where we ask it to, whether a tax ID is valid.
- Apps you connect (such as Shopify, Microsoft, Google or Xero) send us the account name and the access permissions you approve when you connect them.
- If someone else (for example, a colleague, agency or consultant) sets up an account for your business, they may give us your details.
4. Data in your apps and connected services
When you use OLODESK to run apps, automations and integrations, those services handle data that belongs to you, which can include personal data about your own customers, staff or contacts. For example, an automation might read an order from your shop and send a text to the buyer.
For that data, you are the controller and we are your processor. We process it only to provide the services you have set up and on your instructions, as described in our Terms and Conditions. We don’t use it for our own purposes, and we never sell it. If you are a person whose data one of our customers handles on OLODESK, please contact that business directly; we will help them respond to your request.
The access keys and sign-in tokens for apps you connect are stored encrypted and are used only to run the services you set up. You can disconnect any app at any time from your dashboard.
5. Why we use it, and our legal bases
We use personal data only where we have a lawful reason to. Under data protection laws such as the UAE Personal Data Protection Law and, where they apply, the EU and UK General Data Protection Regulations, our reasons are:
| What we do | Legal basis |
|---|---|
| Create and run your account, provide the services you subscribed to, and give you support | Performing our contract with you |
| Take payments, issue invoices, apply the right tax and keep financial records | Performing our contract; complying with tax and accounting laws |
| Send you service messages, such as sign-in emails, password resets, receipts, payment problems, security alerts and changes to our terms | Performing our contract; our legitimate interest in keeping you informed |
| Answer messages sent through our website or by email | Our legitimate interest in responding to enquiries; taking steps you ask for before a contract |
| Keep the services, accounts and forms secure, and prevent fraud, spam and abuse | Our legitimate interest in protecting our customers and our business |
| Measure usage, fix problems and improve the services | Our legitimate interest in running a reliable service |
| Meet legal obligations, respond to lawful requests from authorities, and establish or defend legal claims | Complying with the law; our legitimate interests |
We don’t send marketing emails. If we ever want to, we will ask for your consent first where the law requires it, and you can withdraw it at any time. We don’t make decisions about you based solely on automated processing that have legal or similarly significant effects.
7. Where it is stored
We are based in the United Arab Emirates. Our servers and databases are in the United States, our database backups are stored in Western Europe, and our website is delivered through Cloudflare’s worldwide network. This means your personal data is transferred outside the country where you are.
When we transfer personal data internationally, we use safeguards that the applicable law accepts, such as contracts with our service providers that include standard contractual clauses or similar protections, and we choose providers with strong security and privacy commitments.
8. How long we keep it
- Account and business details: for as long as your account is open and after your subscription ends, until you ask us to delete them.
- Billing and tax records: for as long as tax and accounting laws require, which is generally at least five years.
- Support messages: until you ask us to delete them, so we can follow up on earlier issues.
- Technical logs: usually up to 90 days, unless needed longer to investigate a security issue.
- Account activity records (such as changes to your account details and who made them): kept with your account details, until you ask us to delete them.
- Backups: deleted data disappears from our backups as they expire, within about 30 days.
We may keep data for longer where the law requires it or to establish or defend a legal claim. When we no longer need it, we delete it or make it anonymous.
9. How we protect it
We use technical and organisational measures appropriate to the risk, including encryption in transit (HTTPS) and of stored access keys and backups, scrambled one-way storage of passwords, strict access controls on our servers and databases, private networks between our servers, regular backups, and monitoring. Only people who need access to provide the services have it.
No system is completely secure. If a breach affects your personal data, we will tell you and the relevant authorities where the law requires us to.
11. Your rights
Depending on where you are, you have some or all of these rights over your personal data:
- Access: ask for a copy of the personal data we hold about you.
- Correction: ask us to correct data that is wrong or incomplete. You can also update many details yourself in your dashboard under Settings.
- Deletion: ask us to delete your data, unless we need to keep it for a legal reason.
- Restriction and objection: ask us to limit how we use your data, or object to uses based on our legitimate interests.
- Portability: ask for data you gave us in a common, machine-readable format.
- Withdraw consent: where we rely on your consent, withdraw it at any time.
- Complain: raise a concern with the data protection authority where you live or work, such as the UAE Data Office, a data protection authority in the EU, or the Information Commissioner’s Office in the UK. We would appreciate the chance to sort it out with you first.
To use any of these rights, email [email protected]. We may need to confirm your identity first. We will reply within one month, and won’t charge you unless a request is clearly unfounded or excessive. We will never treat you differently for using your rights.
12. Children
OLODESK is a service for businesses and is not meant for children. We don’t knowingly collect personal data from anyone under 18. If you think a child has given us personal data, please contact us and we will delete it.
13. Changes to this policy
We may update this policy at any time, without notice, when our services or the law change. The date at the top shows when it last changed, so please check this page from time to time.
14. Contact us
OLODESK INFORMATION TECHNOLOGY CONSULTANCY
Abu Dhabi, United Arab Emirates
Email: [email protected]