MICO360

Privacy Policy

MICO360 Finance

Version 1.2 Effective date: 22 September 2026 · Contact: info@mico360.com

This policy explains what MICO360 Finance records, why, and the choices you have. It is a professional template; confirm the specifics with your legal/data-protection adviser before relying on it.

This Privacy Policy explains how MICO360-Softwares ("MICO360", "we", "us") collects, uses, stores and protects personal data in the MICO360 Finance service (the "Service"), a multi tenant finance-operations platform whose modules include petty cash and employee expense management. It applies to every user of the Service: employees, managers, finance staff, company administrators and platform administrators.

1. Roles and responsibilities

2. Data we collect

CategoryDetailsSource
Account and profileFirst and last name, username, work email, employee ID, national or resident ID card number, contact number, role and department per company. Passwords are stored only as one way hashes (BCrypt); we cannot read them.Entered by your administrator at invitation and editable by administrators.
Financial recordsExpense lines (date, project, category, amount, tax, description), petty cash ledgers, top ups, transfers, payment vouchers (including the reason a receipt is missing and your declaration), reconciliations and monthly sheets.Entered by you and processed through the approval workflow.
Cheque records (eCheques module)Cheques your Company prepares: payee name, amount, date, bank, reference and status; cheque books and their leaf ranges; print profiles; a permanent history of every print and reprint with who performed it.Entered by authorised members of your Company.
Documents and signatures (eSign module)Documents uploaded for approval or signature, their references and versions; the approval trail (who approved, rejected or signed, when, and any comments); signature groups and company stamps configured by your administrators. The original file is preserved unaltered.Uploaded and acted on by participants of each document.
Vendors and recruitment (Procurement & Jobs modules, where enabled)Procurement: vendor registration, prequalification and RFQ records. Jobs: recruitment postings, candidate profiles and applications. These modules are rolled out per Company; where they are not enabled, no such data is collected.Entered by authorised Company members, applying vendors and candidates.
Bills and receiptsImages and PDF files you upload as proof of expenses, plus automatically generated thumbnails. Images are converted to WEBP; photo metadata (EXIF) is removed by default after orientation is applied. The untouched original is kept only when your Company enables that option.Uploaded by you.
Activity and auditAn audit trail of actions (who did what and when: edits, submissions, approvals, rejections, configuration changes), notification records and email delivery logs.Generated by the Service.
TechnicalSign in timestamps and the IP address used for rate limiting and abuse prevention; standard server logs.Generated by the Service.
Stored on your deviceLocal storage items: your session token, chosen theme, active company and cached identity details. See section 8.Your browser.

3. How we use data

We do not sell personal data, we do not use it for advertising, and we do not profile users.

4. Company data isolation

The Service is multi tenant. Every record belongs to exactly one Company, and every request is checked against your membership of the active company. No Company can see another Company's users, expenses, files or balances. Within a Company, visibility follows your assigned modules and per-action permissions: you only see the modules you are given, and within them what your permissions allow — typically employees see their own records, managers their team, and finance/administrators the whole Company. eSign documents are narrower still: only a document's own participants (requester, approvers and eSign administrators) can see it.

5. Sharing and processors

6. Security

7. Retention

8. Cookies and local storage

The Service does not use advertising or third party tracking cookies. It stores the following in your browser's local storage, strictly to make the Service work:

KeyPurpose
mico-jwtYour session token, so you stay signed in.
mico-user, mico-companiesYour name, role and company memberships, to render the interface.
mico-company-id, mico-moduleThe company and module you are currently working in.
mico-themeYour light or dark theme choice.
mico-last-id, mico-help-seenThe sign-in name you asked us to remember (when you tick "keep me signed in"), and whether you have already seen the help tour.

Signing out removes the session entries. You can clear all of them at any time from your browser settings.

9. Your rights

10. Children

The Service is a workplace tool for adults and is not directed at children. We do not knowingly collect data about minors.

11. International use

The Service is operated from and primarily intended for use in the Sultanate of Oman. If your Company deploys or accesses it elsewhere, your Company is responsible for ensuring local law permits recording its staff's data in the Service.

12. Changes to this policy

We may update this policy as the Service evolves. The effective date above always reflects the current version, and material changes are announced in the portal.

13. Contact

MICO360-Softwares · info@mico360.com