Privacy Policy
Last updated: August 10, 2026
This Privacy Policy explains how UniopX Singapore Pte. Ltd. ("UniopX", "we", "us") collects, uses, and protects information when you use INEX ("the Service"), our invoice and expense automation product accessible via Telegram and our website at inex.uniopx.com.
1. Information We Collect
Account information: When you subscribe, we collect your email address (via our payment processor, Stripe) and payment details (processed entirely by Stripe — we never see or store your full card number).
Telegram information: Your Telegram user ID, first name, and username, used solely to identify you as a user of the Service and route your messages to your business account.
Google account information: When you connect your Google account, we request access limited to files our application creates in your Google Drive (the drive.file scope). We cannot see, access, or modify any other files in your Google Drive. We store an encrypted authentication token to maintain this connection on your behalf.
Business and transaction data: Information you provide through the Service — client names, invoice details, expense records, vendor names, amounts, and related business data. This data is written directly to your own Google Drive and Google Sheets, which you own and control.
Usage data: We record which documents you create and when, for the purpose of enforcing subscription limits and providing customer support.
2. How We Use Information
We use the information described above solely to:
- Operate and provide the Service (generating invoices, logging expenses, storing documents in your Drive)
- Process your subscription payments
- Communicate with you about your account, including billing and service updates
- Provide customer support
- Improve the Service's reliability and accuracy
We do not sell your personal information or business data to third parties.
3. Third-Party Services
To operate the Service, we rely on a small number of trusted third-party providers for functions such as cloud storage, messaging, payment processing, and data processing. Each provider processes only the limited data necessary to perform its function on our behalf and is bound by its own privacy and security obligations. We do not sell your personal information or business data to any third party.
Cookies, analytics, and advertising. The Service uses cookies and similar technologies. Strictly necessary cookies — for example, the session cookie that keeps you signed in and secures the sign-in flow — are always active and are required for the site to function. On our public marketing pages we also use Google Ads and its Google tag (gtag.js) to measure whether an advertisement led to a sign-up and to improve our advertising; this may set cookies from Google and share a conversion event with Google. You can opt out of advertising and measurement cookies at any time using the cookie notice shown on your first visit, or by clearing your browser's cookies — opting out does not affect your ability to use the Service, and strictly necessary cookies cannot be disabled.
4. Data Storage and Security
- Google authentication tokens are encrypted at rest using AES-256-GCM. The encryption key is never stored in our database.
- Your business documents (invoices, receipts, spreadsheets) are stored in your own Google Drive and Google Sheets — not on our servers. You retain full ownership and control of these files at all times, including after cancellation.
- We maintain a record of transaction metadata (amounts, dates, categories) in our own database to power features like the ledger, tagging, and usage tracking.
5. Data Retention
- Your account and transaction metadata are retained for as long as your subscription is active, and for a reasonable period afterward for accounting, legal, and support purposes.
- Your business documents in Google Drive/Sheets are yours and are not deleted by us upon cancellation — they remain in your Google account indefinitely, under your control.
- You may request deletion of your account data by contacting us at javier@uniopx.com.
6. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, or request deletion of your personal data. To exercise these rights, contact us at javier@uniopx.com. We will respond in accordance with applicable law, including Singapore's Personal Data Protection Act (PDPA).
7. International Data Transfers
Our third-party service providers (listed above) may process data outside Singapore. By using the Service, you consent to this transfer, which is necessary for the Service to function.
8. Children's Privacy
The Service is intended for business use by adults and is not directed at individuals under 18. We do not knowingly collect data from children.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or through the Service. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
10. Contact Us
For questions about this Privacy Policy or your data, contact:
UniopX Singapore Pte. Ltd. javier@uniopx.com