Privacy Policy
Last updated: 20 September 2026 · Operated by Soufiane Mehdi Project Management Services LLC, Office 205-426, Al Bahar Building, Plot 0-546, Al Khabeesi, Dubai, United Arab Emirates
This policy explains what personal data Soufiane Mehdi Project Management Services LLC ("Rowvert", "we") collects when you use rowvert.com and our API, why we collect it, who we share it with and the rights you have. It is written to meet the UK and EU GDPR, the California Consumer Privacy Act (CCPA/CPRA) and other US state privacy laws, Canada's PIPEDA, the Australian Privacy Act 1988 and the UAE Personal Data Protection Law. We are the data controller for account and billing data, and your data processor for the contents of the statements you upload.
1. What we collect
Documents you upload. PDF bank statements and the transaction data extracted from them (dates, descriptions, amounts, balances, account numbers, bank names). These often contain financial information about you or, if you are an accountant or bookkeeper, about your clients.
Account data. Name, email address, a salted hash of your password (never the password itself) or, if you sign in with Google, your Google account identifier and email. Email-verification and password-reset tokens (hashed, short-lived).
Billing data. Plan, billing period, Stripe customer and subscription identifiers, invoice history and the country used for tax purposes. Card numbers are entered directly on Stripe's pages and never reach our servers.
Usage and technical data. Pages converted, timestamps, file names and page counts, error messages, IP address, browser type and the pages you visit. Anonymous visitors are identified only by a salted, one-way hash of their IP address, used solely to enforce the free daily limit.
Support messages. Anything you send us through the contact form or by email.
We do not knowingly collect data from children under 18 and the Service is not directed at them.
2. How and why we use it
We use personal data to: (a) provide the Service — read your PDF, build the spreadsheet, store it for your retention period and let you download it (legal basis: performance of a contract); (b) create and secure your account, verify your email and reset passwords (contract); (c) take payment, issue invoices, prevent fraud and comply with tax and accounting obligations (contract and legal obligation); (d) enforce usage limits and protect the Service from abuse (legitimate interests); (e) answer support requests (contract / legitimate interests); (f) send service emails such as receipts, renewal reminders and material changes to these terms (contract / legal obligation); and (g) send occasional product news if you opt in — you can unsubscribe at any time (consent).
We never sell personal data, never share it with data brokers or advertisers, and never use the contents of your statements to train machine-learning models. We do not make decisions about you with legal or similarly significant effects by automated means.
3. How long we keep it
Uploaded PDFs are processed in memory and discarded as soon as extraction completes; they are not written to disk. Extracted spreadsheets and transaction data are kept for the retention period of your plan — 1 day for anonymous visitors, 7 days on the free plan, 90 days on Starter, 365 days on Professional and for the life of the account on Business — and are then permanently deleted by an automated job. You can delete any conversion sooner from your dashboard.
Account data is kept while your account is open and deleted within 30 days of closure, except for invoices and payment records that we must keep for up to 7 years under tax law. Technical logs are kept for 90 days. Anonymous usage hashes expire after 24 hours.
5. International transfers
We are based in the United Arab Emirates and our providers operate in the EU and the United States, so your data is transferred internationally. For data from the UK, EEA and Switzerland we rely on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses (and, for US providers certified under it, the EU-US Data Privacy Framework). Transfers from Canada and Australia are made under comparable contractual safeguards, and we remain accountable for the data under PIPEDA and APP 8. You can request a copy of the relevant safeguards at privacy@rowvert.com.
6. Security
All traffic is encrypted with TLS. Data is encrypted at rest. Passwords are hashed with bcrypt. Access to production systems is limited to named staff with multi-factor authentication. Converted files are only accessible to the account (or anonymous session) that created them and are purged automatically. If we become aware of a breach affecting your data we will notify you and the relevant supervisory authority without undue delay and, where the law requires, within 72 hours.
8. Your rights
Depending on where you live you have the right to: access the personal data we hold about you and receive a copy in a portable format; correct inaccurate data; delete your data ("right to be forgotten"); restrict or object to processing; withdraw consent at any time; and lodge a complaint with a supervisory authority. We honour these rights for everyone, regardless of location.
You can export your conversions and delete your account and all associated data yourself from Dashboard → Settings. For anything else, email privacy@rowvert.com; we respond within 30 days (45 days for CCPA requests) and will not discriminate against you for exercising your rights. We may ask you to verify your identity first.
UK / EEA: you may complain to the UK Information Commissioner's Office (ico.org.uk) or your national data-protection authority. California and other US states: we do not "sell" or "share" personal information as defined by the CCPA/CPRA and have not done so in the preceding 12 months; you may designate an authorised agent to make requests on your behalf. Canada: you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca). Australia: you may complain to the Office of the Australian Information Commissioner (oaic.gov.au). UAE: you may complain to the UAE Data Office.
9. Data-processing terms for business users
If you upload statements containing personal data of third parties (for example as an accountant, bookkeeper, lender or property manager), you are the controller and Soufiane Mehdi Project Management Services LLC is your processor. In that capacity we: process personal data only to provide the Service and on your documented instructions; ensure staff are bound by confidentiality; implement the security measures described above; engage only the sub-processors listed in section 4 and remain liable for them; assist you with data-subject requests and impact assessments as reasonably needed; delete or return the data at the end of the retention period or on account closure; and make available the information needed to demonstrate compliance. These terms constitute the data-processing agreement required by Article 28 UK/EU GDPR. A signed copy is available on request from privacy@rowvert.com.
10. Changes to this policy
We will post any changes on this page and update the date at the top. For material changes we will email account holders in advance. The previous version is available on request.
11. Contact
Soufiane Mehdi Project Management Services LLC
Office 205-426, Al Bahar Building, Plot 0-546, Al Khabeesi, Dubai, United Arab Emirates
Privacy requests: privacy@rowvert.com · General support: support@rowvert.com
Related: Terms of Service · Privacy Policy · Refund & Cancellation Policy · Cookie Policy · Legal notice