Legal

Privacy Policy

Effective date: 26 June 2026Last updated: 26 June 2026Applies to: uregisto.com
Summary: We collect the minimum data needed to run the service. Your uploaded files are stored directly in your own Google Drive or Dropbox — we do not keep copies on our servers. We do not sell your data.

§ 01 Who we are

Uregisto (“we”, “us”, “our”) is an online accounting and document management service available at uregisto.com. We help sole traders and small businesses organise financial documents and generate invoices.

For questions about this policy, contact us at privacy@uregisto.com.

§ 02 What data we collect

We collect only what is necessary to provide the service:

CategoryExamplesWhy we collect it
Account dataEmail address, name, password (hashed)To create and secure your account
Company dataCompany name, NIF, country, currencyTo generate invoices and organise documents
Document metadataFilename, size, type, upload dateTo index and display your documents
OAuth tokensGoogle Drive / Dropbox access & refresh tokensStored encrypted; used only to write files to your cloud on your behalf
Usage dataIP address, browser type, pages visited, timestampsSecurity, fraud prevention, and service improvement
Your files: Documents and invoice PDFs are written directly to your connected Google Drive or Dropbox account. We store only the file path and metadata (name, size, type) — never the file content itself.

§ 03 How we use your data

  • Providing the service — account management, document organisation, invoice generation, and PDF storage.
  • Authentication — verifying your identity when you sign in.
  • Cloud storage integration — writing files to your Google Drive or Dropbox using your authorised OAuth tokens.
  • Service communications — transactional emails (password reset, account alerts). We do not send marketing emails unless you opt in.
  • Security and abuse prevention — detecting and stopping fraudulent or harmful activity.
  • Legal compliance — meeting applicable legal obligations.

We do not use your data for advertising, and we do not sell or rent it to third parties.

§ 04 Third-party services

  • Google LLC (Google Drive API) — When you connect Google Drive, we request the drive.filescope, which allows us to create and manage only the files our app creates. Your OAuth tokens are stored encrypted. Google's privacy policy: policies.google.com/privacy.
  • Dropbox, Inc. — When you connect Dropbox, we request access limited to the /uregistofolder we create. Dropbox's privacy policy: dropbox.com/privacy.

Our application is hosted on infrastructure in the European Union. Servers, logs, and encrypted database backups reside within the EU.

§ 05 Data retention

  • Account data — retained while your account is active. Deleted within 30 days of account deletion.
  • Document metadata — deleted with your account. Files remain in your Google Drive or Dropbox under your control.
  • OAuth tokens — revoked and deleted when you disconnect an integration or delete your account.
  • Usage logs — retained for 90 days for security purposes.

§ 06 Your rights (GDPR)

If you are in the European Economic Area, you have the following rights regarding your personal data:

  • Access — request a copy of the data we hold about you.
  • Rectification — request correction of inaccurate data.
  • Erasure — request deletion of your account and associated data.
  • Portability — receive your data in a machine-readable format.
  • Restriction — request that we limit processing of your data.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — disconnect cloud integrations at any time from your account settings.

To exercise any of these rights, email privacy@uregisto.com. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority.

§ 07 Cookies

  • Session cookie — stores your authentication state. Strictly necessary; no consent required.
  • CSRF token — protects against cross-site request forgery. Strictly necessary.

We do not use tracking, advertising, or analytics cookies.

§ 08 Security

We protect your data using TLS encryption in transit, AES-256 encryption at rest for OAuth tokens, bcrypt password hashing, and role-based access controls. If you discover a vulnerability, please disclose it responsibly to security@uregisto.com.

§ 09 Changes to this policy

We may update this policy from time to time. When we do, we will update the “Last updated” date above and notify you by email if the changes are material.

§ 10 Contact

For privacy-related questions or requests:

Uregisto

Email: privacy@uregisto.com

We aim to respond to all requests within 5 business days.