Last updated: 16 July 2026 · Effective: 16 July 2026
This Privacy Policy explains how Novara Horizon Group FZE LLC (“we”, “us”), operator of Qarran (“the Service”), collects, uses, stores and protects information. We are based in Ajman, United Arab Emirates. Contact: legal@qarran.com. We process personal data in line with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, “PDPL”) and, for users in other regions, applicable laws such as the GDPR.
Qarran is a business tool for contractors and SMEs to manage projects, sales, purchasing and accounting. It is not directed to children and is not intended for anyone under 18. We do not knowingly collect data from children.
| Category | Examples | Why |
|---|---|---|
| Account data | Your name, email, password (hashed by our auth provider), company name, role | Create and secure your account; multi-user access |
| Business records you enter | Clients, suppliers and subcontractors (names, contacts, phone, email, address, TRN/VAT no.); projects; quotations, sales orders, invoices, LPOs, delivery notes, credit notes, payments; expenses; products & rates | To provide the core service you signed up for |
| Uploaded documents | Project drawings/PDFs, company files, and compliance documents you choose to upload — which may include trade licences, establishment cards, employee visas, Emirates ID, labour cards, passports, insurance and vehicle registrations, plus your company logo/stamp | Document storage and expiry reminders you request |
| Technical data | A session token stored in your browser’s local storage; basic error information | Keep you logged in; diagnose faults |
Card payments are handled by Stripe; we do not store or see your card details — Stripe processes them directly. We do not run advertising trackers, and we do not use AI to process your data. Optional privacy-friendly analytics are described in section 10 (off by default).
Device access. If you choose to upload a document or photo, your browser or device may ask permission to use your camera or files. We use this only to attach the file you select — we do not otherwise access your camera, photos or files.
Only to operate, secure and support the Service, and to comply with law (including UAE tax record-keeping). We do not sell or share your personal data for advertising.
We rely on these bases under the UAE PDPL (and the equivalent bases under the GDPR for EU/UK users):
Where we rely on consent, it is requested in clear, specific terms, and you may withdraw it at any time — by contacting us or closing your account. Withdrawing consent does not affect processing already carried out.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage (encrypted in transit & at rest) | Cloud data centre — Southeast Asia (Singapore) |
| Cloudflare | Website hosting (Cloudflare Pages) + content delivery / security | Global CDN |
| CDN providers (jsDelivr, unpkg, Google Fonts) | Serving app libraries and fonts | Global CDN |
| Stripe | Subscription payment processing (PCI-DSS) | Global |
Your data is stored on Supabase infrastructure located in Singapore. As you may be based in the UAE or elsewhere, some processing occurs outside your country. Under the UAE PDPL, such cross-border transfers are made only where the destination provides an adequate level of protection, appropriate safeguards are in place (e.g. contractual clauses), you have consented, or the transfer is necessary to provide the Service.
Each provider processes personal data only on our instructions and under its own data-processing terms, and is bound to keep it confidential and secure.
We keep your business records while your account is active. Financial/tax records may be retained to meet UAE FTA requirements (generally 5 years, longer for real-estate). On account closure we delete or anonymise personal data within 90 days, except where law requires retention.
Deleting your account & data. You can permanently delete your account and your company’s data at any time — inside the app under Settings → Data, or via our account-deletion page. This erases your stored business data from our systems; any legally-required financial records are kept only for the minimum period and then deleted. You can export a backup first (Settings → Data → Export).
Under the UAE PDPL you have the right to: access your personal data and information about how it is processed (including the purposes, the parties it is shared with, and any automated decisions); request portability — to receive your data in a structured, machine-readable format; correct inaccurate data; request erasure (“the right to be forgotten”); restrict processing; stop / object to processing; object to automated decision-making, including profiling, made solely by automated processing of your data; and withdraw consent. We aim to respond within 30 days. To exercise any right, contact legal@qarran.com. If you are not satisfied, you may lodge a complaint with the UAE Data Office (the national data-protection regulator).
Automated decisions. We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing or profiling. Qarran does not use your data to train AI models.
GDPR (EU/UK) & CCPA/CPRA (California): equivalent rights apply — access, rectification, erasure, restriction, portability and objection, and (California) the right to opt out of “sale”/“sharing”. We do not sell or share your personal information, and you may complain to your local data-protection authority.
Note on multi-user companies: the company administrator controls the company’s data and its members; data you enter as an employee belongs to the company account.
Data is encrypted in transit (HTTPS/TLS) and at rest, access is restricted per company via database row-level security, and access is role-based. No method is 100% secure. For security concerns, contact legal@qarran.com.
If a personal-data breach occurs that would affect the privacy, confidentiality or security of your data, we will, in line with Article 9 of the UAE PDPL: notify the UAE Data Office and, where the breach is likely to prejudice your rights, notify you — in each case without undue delay and within any period and procedure set by the PDPL and its Executive Regulation, together with the measures we have taken. Where a service provider (processor) becomes aware of a breach, it is required to notify us immediately so we can act.
We use only a strictly-necessary session token in your browser’s local storage to keep you signed in — this needs no consent. We do not use advertising cookies or third-party trackers. We show a consent banner offering optional, privacy-friendly, cookie-less analytics (Plausible) to help us improve Qarran; this is off by default and currently not enabled at all — nothing loads or is sent unless you click “Accept”, and you can decline. Your choice is stored on your device and you can change it at any time.
Our designated contact for privacy and data-protection matters is legal@qarran.com. We are a small business and are not currently required to appoint a formal Data Protection Officer (DPO); should the nature or scale of our processing require one under the PDPL, we will appoint a DPO and update this policy.
We will post changes here and update the “Last updated” date; material changes will be notified in-app or by email.