Privacy Policy
How Xrero collects, uses, and protects your information - in plain language.
Last updated: 2 June 2026The short version
We collect only what we need to run your account, we never sell your data, and your card details go straight to our payment providers - we never store them.
1Who we are
Xrero ("Xrero", "we", "us") provides cloud business-management (ERP) software at xrero.com to customers in the UAE and the wider region. This Privacy Policy explains what personal data we collect, how we use it, and your rights. Xrero is operated from Dubai, United Arab Emirates.
2Information we collect
- Account and contact data: name, business name, email, phone, and login credentials.
- Billing data: billing name, address, and the plan you purchase. We do not store full card numbers - card payments are handled directly by our payment providers.
- Usage data: pages visited, features used, device and browser, IP address, and approximate location.
- Content you provide: data you enter into your Xrero workspace, and messages you send us.
- Cookies to run the site and understand how it is used.
3How we use your data
To create and operate your account; provide and improve the service; process payments and prevent fraud; provide customer support; send service and (with your consent) marketing messages; and comply with legal obligations.
4Legal bases
We process personal data to perform our contract with you, with your consent, for our legitimate business interests (security and improvement), and to meet legal obligations.
5Cookies and analytics
We use essential cookies to operate the site and analytics cookies to understand usage. You can control cookies through your browser settings.
6Sharing your data
We share data only with payment providers (to process payments), infrastructure and email providers that run the service on our behalf, and authorities where required by law. We do not sell your personal data.
7Storage and security
Data is stored on secured servers and protected with encryption in transit (HTTPS), access controls, and regular backups. No method is 100% secure, but we take reasonable measures to protect your data.
8Data retention
We keep account data for as long as your account is active and as needed for legal, tax, and accounting requirements, after which it is deleted or anonymised.
9International transfers
Where data is processed outside the UAE, we ensure appropriate safeguards are in place.
10Your rights
You may request access to, correction of, or deletion of your personal data, and may object to or restrict certain processing. Contact us at info@xrero.com.
11Children
Xrero is intended for businesses and is not directed at anyone under 18.
12Changes to this policy
We may update this policy and will post the revised version here with a new date.
13Contact us
Xrero - Dubai, United Arab Emirates - info@xrero.com