
Privacy Policy
This Privacy Policy explains how MICO360-Softwares ("MICO360", "we", "us") collects, uses, stores and protects personal data in the MICO360 Finance service (the "Service"), a multi tenant finance-operations platform whose modules include petty cash and employee expense management. It applies to every user of the Service: employees, managers, finance staff, company administrators and platform administrators.
1. Roles and responsibilities
- Each customer company (a "Company") decides which of its staff use the Service and what financial information they record. For that content, the Company acts as the data controller and MICO360 processes the data on its behalf.
- MICO360 controls the platform account data needed to operate the Service (sign in identities, security logs, service email delivery).
2. Data we collect
| Category | Details | Source |
|---|---|---|
| Account and profile | First and last name, username, work email, employee ID, national or resident ID card number, contact number, role and department per company. Passwords are stored only as one way hashes (BCrypt); we cannot read them. | Entered by your administrator at invitation and editable by administrators. |
| Financial records | Expense lines (date, project, category, amount, tax, description), petty cash ledgers, top ups, transfers, payment vouchers (including the reason a receipt is missing and your declaration), reconciliations and monthly sheets. | Entered by you and processed through the approval workflow. |
| Cheque records (eCheques module) | Cheques your Company prepares: payee name, amount, date, bank, reference and status; cheque books and their leaf ranges; print profiles; a permanent history of every print and reprint with who performed it. | Entered by authorised members of your Company. |
| Documents and signatures (eSign module) | Documents uploaded for approval or signature, their references and versions; the approval trail (who approved, rejected or signed, when, and any comments); signature groups and company stamps configured by your administrators. The original file is preserved unaltered. | Uploaded and acted on by participants of each document. |
| Vendors and recruitment (Procurement & Jobs modules, where enabled) | Procurement: vendor registration, prequalification and RFQ records. Jobs: recruitment postings, candidate profiles and applications. These modules are rolled out per Company; where they are not enabled, no such data is collected. | Entered by authorised Company members, applying vendors and candidates. |
| Bills and receipts | Images and PDF files you upload as proof of expenses, plus automatically generated thumbnails. Images are converted to WEBP; photo metadata (EXIF) is removed by default after orientation is applied. The untouched original is kept only when your Company enables that option. | Uploaded by you. |
| Activity and audit | An audit trail of actions (who did what and when: edits, submissions, approvals, rejections, configuration changes), notification records and email delivery logs. | Generated by the Service. |
| Technical | Sign in timestamps and the IP address used for rate limiting and abuse prevention; standard server logs. | Generated by the Service. |
| Stored on your device | Local storage items: your session token, chosen theme, active company and cached identity details. See section 8. | Your browser. |
3. How we use data
- To operate the Service: recording expenses, calculating balances, routing approvals, producing monthly sheets, reconciliations, reports and exports; preparing, printing and tracking cheques; and routing documents for approval and signature.
- To secure the Service: authentication, role based access control, tenant isolation, rate limiting, audit trails and abuse prevention.
- To notify you: in app notifications and transactional emails about submissions, approvals, rejections, transfers, vouchers, reminders and account changes.
- To support you: investigating problems you report.
We do not sell personal data, we do not use it for advertising, and we do not profile users.
4. Company data isolation
The Service is multi tenant. Every record belongs to exactly one Company, and every request is checked against your membership of the active company. No Company can see another Company's users, expenses, files or balances. Within a Company, visibility follows your assigned modules and per-action permissions: you only see the modules you are given, and within them what your permissions allow — typically employees see their own records, managers their team, and finance/administrators the whole Company. eSign documents are narrower still: only a document's own participants (requester, approvers and eSign administrators) can see it.
5. Sharing and processors
- Within your Company: your expense data is visible to the approvers, finance staff and administrators of that Company as required by the workflow.
- Email delivery: transactional emails are delivered through Mailjet (Sinch group). Mailjet receives the recipient address, name and the message content. Sender address: info@mico360.com.
- Hosting: the application and database run on infrastructure operated by or for MICO360 or the deploying organization.
- Legal: we disclose data when a law, regulation or competent authority validly requires it.
6. Security
- Passwords hashed with BCrypt; sessions use signed tokens with a 12 hour lifetime on the web and a shorter 3 hour lifetime in the mobile app, so a lost or unattended phone stops working sooner.
- Role based authorization and per company membership checks on every request.
- Sign in rate limiting, security response headers, and validation of every uploaded file by actually decoding it on the server.
- Uploaded files are stored under server generated names and served only to authorized members of the owning Company; employees can open only their own bills.
- Every change to financial records is written to an immutable audit trail.
- Production deployments must be served over HTTPS; database and file storage are included in the operator's backup routine.
7. Retention
- Financial records (expenses, ledgers, vouchers, reconciliations, audit trail) are business records of your Company and are retained for as long as the Company requires, typically to satisfy accounting and tax law.
- User accounts are deactivated, not deleted, when someone leaves, because their name is part of the Company's financial history. Deactivated accounts cannot sign in.
- Cheque registers, print histories, and eSign documents with their approval and signature trails are likewise business records, retained unaltered for as long as the Company requires.
- Projects and categories with history are archived, never deleted.
- Email delivery logs and notifications are kept for operational troubleshooting.
8. Cookies and local storage
The Service does not use advertising or third party tracking cookies. It stores the following in your browser's local storage, strictly to make the Service work:
| Key | Purpose |
|---|---|
| mico-jwt | Your session token, so you stay signed in. |
| mico-user, mico-companies | Your name, role and company memberships, to render the interface. |
| mico-company-id, mico-module | The company and module you are currently working in. |
| mico-theme | Your light or dark theme choice. |
| mico-last-id, mico-help-seen | The sign-in name you asked us to remember (when you tick "keep me signed in"), and whether you have already seen the help tour. |
Signing out removes the session entries. You can clear all of them at any time from your browser settings.
9. Your rights
- Access and correction: you can see your own records throughout the portal. Profile corrections (name, contact number, ID card number, employee ID) are made by your Company administrator.
- Objection and complaints: raise privacy questions with your Company administrator or with us at info@mico360.com. We answer within a reasonable time.
- Deletion: because expense records are statutory business records, deletion requests are satisfied by deactivation and, where lawful, removal of profile details that are no longer required.
10. Children
The Service is a workplace tool for adults and is not directed at children. We do not knowingly collect data about minors.
11. International use
The Service is operated from and primarily intended for use in the Sultanate of Oman. If your Company deploys or accesses it elsewhere, your Company is responsible for ensuring local law permits recording its staff's data in the Service.
12. Changes to this policy
We may update this policy as the Service evolves. The effective date above always reflects the current version, and material changes are announced in the portal.
13. Contact
MICO360-Softwares · info@mico360.com