Privacy Policy
What Mohaseb 365 collects, why, where it is kept, for how long — and what you can do about it.
Who we are
Mohaseb 365 is a business platform (ERP and storefront) used by companies to run their accounting, inventory, sales and staff. The platform domain is mohaseb365.com.
This policy covers two groups: panel users (employees of a business that uses Mohaseb 365) and visitors to the public landing page.
Business data (customers, invoices, stock) belongs to the business that entered it, not to us. We are the custodian. If you are a customer of one of those businesses, that business's own privacy policy governs your relationship with them.
What we collect
For panel users, only what the system needs to work:
- Work identity: name, username, organisational role, and — if entered by an administrator — national ID, staff number, hire date.
- Contact details: mobile number and email. The number is required to send the one-time login code.
- Google account email, only if your administrator enabled "Sign in with Google" for you. See the dedicated section below.
- Login and session records: login time, IP address, browser and device type, and security events such as failed attempts. These exist to protect your account, not to profile you.
- Whatever you enter into the system: invoices, products, ledger entries — the day-to-day work of the business.
What we do not collect: location, phone contacts, personal email content, or anything from your device beyond the browser itself. The public landing page carries no analytics and no advertising cookies.
Sign in with Google — exactly what is exchanged
If your administrator has enabled it, you may sign in with a Google account instead of a username and password. In that case:
- We receive three things from Google: account identifier, email address, and profile name and picture (scopes:
openid email profile). - We have no access to your Gmail, Drive, Contacts, Calendar or any other Google service, and we do not want any.
- No refresh token is stored. The short-lived token is used at the moment of sign-in and then discarded.
- Only the account identifier and email are kept in our database, so we can recognise you next time.
- Google sign-in does not replace the second factor: the SMS code still applies unless your device is already marked as trusted.
- You may revoke our access at any time from your Google Account settings. Password sign-in keeps working.
Mohaseb 365's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Cookies
Every cookie here is functional. None of them track you:
- Session cookie — keeps you signed in.
- CSRF cookie — proves a submitted form came from our own pages.
- "Remember this device" cookie — only if you tick the box; suppresses the SMS code for a period.
- Language cookie on the landing page — remembers the language you chose.
There are no advertising cookies, no pixels and no third-party trackers. That is why there is no cookie banner.
Where data is kept
Mohaseb 365 servers are located in Iran and data does not leave the country. The single exception is the moment of Google sign-in, where your own browser talks to Google — as it does whenever you open Gmail.
Each business has its own separate database. One connection cannot see two businesses' data; the separation is enforced at the database level, not only in application code.
Who we share it with
Nobody. Your data is not sold, rented, or handed to advertisers. Three narrow exceptions:
- The SMS provider — to deliver your login code; the mobile number and the code text only.
- Google — only if you press "Sign in with Google", and only for that authentication.
- Legal obligation — on a valid, formal request from a competent authority.
How long we keep it
- Your account: for as long as you work for that business. After you leave, the account is deactivated, but the work record (who entered which invoice) remains, because the books must stay correct.
- Security and login records: retained so incidents can be investigated.
- Business data: for as long as the business keeps it. That is their decision, not ours.
- Backups: encrypted backups are kept on the same server and on the administrator's computer.
Your choices
- You may ask to see or correct your data — address the request to your business's system administrator.
- You may disconnect Google sign-in; password sign-in is unaffected.
- You may view your open sessions on the "My Devices" page and end them remotely.
- You may leave "remember this device" unticked so that a code is sent every time.
Security
All traffic is over HTTPS. Passwords are never stored in readable form. Two-step sign-in with an SMS code is on by default. Server secrets live outside the web root with restricted permissions.
No system is perfectly secure. If a breach occurs that puts your data at risk, we will inform your business.
Children
This is a workplace tool and is not designed for anyone under 18. We do not knowingly collect data from children.
Changes to this policy
If this document changes in a meaningful way, its version is incremented and panel users are shown the text again and asked to accept it at their next sign-in. The version and date appear at the top of this page.