v1.6.0SOC 2 Remediation, Theme Contrast & Mobile Navigation now live across Mints ERP.
Home/Legal/Privacy Policy

Privacy Policy

Product: Mints ERP — a product of Mints GlobalCompliance: UAE PDPL, UK GDPR, EU GDPR, DPDP 2023Effective September 2026

1. Introduction

Mints Global (“we,” “us,” “our”) operates Mints ERP, a cloud-based enterprise resource planning platform. This Privacy Policy explains how we collect, use, store, and protect personal data in connection with the Service, and describes your rights regarding that data.

We operate across the UAE, United Kingdom, India, and the European Union, and this Policy is written to address relevant obligations under the UAE Personal Data Protection Law (PDPL), the UK GDPR, the EU General Data Protection Regulation (GDPR), and India's Digital Personal Data Protection Act (DPDP Act) 2023, as applicable to you.


2. Who This Policy Applies To

  • Customers: Organizations that subscribe to Mints ERP and their authorized users (employees, managers, administrators).
  • End Users of Customer Data: Individuals whose data a Customer inputs into the Service (e.g., a Customer's employees via the HR Hub, or a Customer's clients via the External Client Portal). For this category, the Customer is generally the data controller and Mints Global acts as a data processor (see Section 8).
  • Visitors: Individuals visiting our marketing site (erp.mintsglobal.ae).

3. Data We Collect

3.1 Account & Usage Data

  • Name, email address, role/department, and login credentials (or SSO identity via Google Workspace)
  • Usage logs: pages visited within the Service, feature interactions, and session timestamps
  • Device and browser information, IP address, and security telemetry

3.2 Data You Input Into the Service (Customer Data)

As an enterprise ERP platform, the Service processes operational data your organization inputs, including:

  • HR data: Employee records, department assignments, subroles, and org-chart hierarchy
  • Attendance data: Clock-in/out timestamps and, where enabled, geolocation telemetry for attendance verification
  • CRM data: Lead and client records, pipeline stages, and communications logged in-platform
  • Project & timesheet data: Task assignments, hours logged, and Gantt milestone dependencies
  • Financial data: Invoices, tax items, and revenue records generated through the platform
  • Files: Documents uploaded to the Secure Company Cloud Vault
  • Chat data: Messages transmitted through Corporate Chat channels

3.3 Cookies & Similar Technologies

We use essential cookies for authentication and session state management, and optional marketing site cookies (see Section 10).


4. How We Use Data

We use collected data to:

  • Provide, maintain, and secure the Service
  • Authenticate users and enforce 5-tier role-based access control (RBAC)
  • Generate platform features (attendance reporting, CRM pipelines, invoices, analytics dashboards)
  • Send transactional notifications (leave approvals, workflow triggers, and optional Discord webhooks)
  • Improve the Service and diagnose technical performance
  • Comply with statutory obligations, including UAE FTA VAT invoicing, UK MTD, and Indian GST rules
  • Communicate with you regarding your account, billing, and security alerts
We do not sell personal data to third parties.

5. Legal Basis for Processing (GDPR / UK GDPR)

  • Contract: Processing necessary to deliver the subscribed Service
  • Legitimate Interests: Securing the Service, preventing fraud, and optimizing features
  • Legal Obligation: Tax, statutory invoicing, and audit record-keeping compliance
  • Consent: Where explicitly given, e.g. for certain analytics cookies

6. Where Data Is Stored & International Transfers

Customer Data is stored using Google Cloud Firestore (Firebase), hosted on Google Cloud enterprise infrastructure, and deployed globally via Vercel.

Where data is transferred internationally (e.g. between our UAE engineering hubs and EU/UK/India Customers), we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) and equivalent cross-border data transfer mechanisms recognized under GDPR, UK GDPR, and UAE PDPL.


7. Data Sharing & Subprocessors

We share data only as strictly necessary to operate the Service:

SubprocessorPurposeData Location
Google Cloud / FirebaseDatabase hosting, Firestore real-time sync, and token authenticationGlobal / Multi-Region
VercelServerless edge network application hosting and CDN distributionGlobal Edge
DiscordOptional customer-configured webhook notifications (only data the Customer explicitly routes)United States / Global

We do not share Customer Data with third parties for their own marketing. An updated subprocessor list is available on request at info@mintsglobal.ae.


8. Controller vs. Processor Roles

For data your organization inputs about your own employees or clients (Section 3.2), your organization is the data controller and Mints Global acts as a data processor, processing that data solely on your instructions and as necessary to provide the Service. Where required, we enter into a Data Processing Agreement (DPA) with Customers upon request.

For account and usage telemetry collected directly about you as a user of the Service (Section 3.1) and marketing-site visitor data, Mints Global acts as the data controller.


9. Data Retention

  • Active account data is retained for as long as your subscription remains active.
  • Upon termination, Customer Data is retained for 30 days to facilitate complete export, after which it is permanently purged, except where longer retention is required for legal, tax, or statutory audit purposes (e.g., UAE VAT, UK MTD, or Indian GST records).
  • Security audit logs are retained separately per our internal security guidelines to support incident investigations and regulatory compliance.

10. Cookies & Tracking

CategoryPurposeConfigurable?
EssentialAuthentication token validation, CSRF protection, and session state persistenceNo — required for the Service to operate
AnalyticsAggregate anonymized visitor telemetry to understand marketing site usageYes — configurable via browser cookie preferences

11. Your Data Protection Rights

Depending on your jurisdiction, you may have statutory rights to:

  • Access: Request copies of the personal data we hold about you
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion (“right to be forgotten”), subject to statutory tax retention rules
  • Portability: Request machine-readable export of your data
  • Restriction/Objection: Restrict or object to certain forms of data processing
  • Consent Withdrawal: Withdraw previously granted consent at any time

These rights apply under UK/EU GDPR, India's DPDP Act, and the UAE PDPL. To exercise these rights, contact info@mintsglobal.ae.


12. Data Security

We maintain enterprise security safeguards aligned with our ISO 27001-aligned information security management system, including document-level Firestore security rules, AES-256 encryption at rest, TLS 1.3 encryption in transit, administrative audit logging, and automated vulnerability management.


13. Children's Privacy

The Service is intended strictly for business use by authorized adult personnel acting on behalf of an enterprise organization. We do not knowingly collect personal data from individuals under 16 years of age.


14. Changes to This Policy

We may update this Privacy Policy from time to time. Material modifications will be communicated via in-app notification or email at least 15 days before taking effect.


15. Contact

Privacy inquiries and Data Protection Officer requests can be sent to:

Mints Global — Data Protection

Office #315, 3rd Floor, Bank Street Building

Bur Dubai, Dubai, UAE

info@mintsglobal.ae