Terms of Service & Privacy Policy
1. Introduction and acceptance
These Terms of Service and this Privacy Policy (together, the "Terms") govern access to and use of iMonetary, a private, invitation-only financial intelligence platform available at imonetary.ir and its subdomains (the "Service"), designed, developed, and operated by Dara Hosh Tehran (داراهوش تهران), reachable at darahoshtehran.ir [registration number and registered address to be added] ("iMonetary", "we", "us", or "our").
The Service is not open to public registration. Access is by invitation only, following a request submitted through the Service and a decision made by us at our discretion. By requesting an invitation, accepting one, or otherwise accessing the Service, you agree to these Terms on your own behalf and, where you act for an organisation, on behalf of that organisation, which you confirm you are authorised to bind.
If you do not agree to these Terms, do not request an invitation, do not accept one, and do not use the Service.
2. Definitions
| Term | Meaning |
|---|---|
| Member | An individual granted access to the Service following an approved invitation, or a secondary user granted access by a Member's primary account. |
| Primary Account | The account belonging to the chief executive or financial manager in whose name membership was granted. The Primary Account holder controls what secondary users on that account can see and do. |
| Secondary User | An individual given access to a Primary Account's data by that Primary Account holder, with permissions the Primary Account holder defines and may revoke at any time. |
| Financial Data | Any financial information, transaction record, document, or figure a Member enters into, uploads to, or connects to the Service. |
| Membership Tier | The specific plan (for example Trial, Annual, or Diamond) under which a Member is invited, as described to that Member at the time of invitation or renewal. |
3. Eligibility and invitation-only access
- The Service is intended for chief executives, financial managers, and individuals they designate as Secondary Users, acting on behalf of a business.
- An invitation is personal to the individual and organisation it is issued to and may not be transferred, resold, or shared outside the organisation without our written consent.
- We may decline any invitation request, and may decline to renew or may suspend any membership, at our discretion, including where we reasonably believe the Service is being used in a way that is unlawful, fraudulent, or harmful to us, to other Members, or to third parties.
4. Accounts, security, and your responsibilities
- You are responsible for maintaining the confidentiality of your password and any additional authentication method you enable (such as an authenticator app), and for all activity that occurs under your account.
- You must notify us promptly of any suspected unauthorised access to your account.
- A Primary Account holder is responsible for the actions of Secondary Users they add to their account, and for setting permissions that reflect who should actually see what.
- We reserve the right to suspend an account where we have a reasonable, good-faith concern about its security, without that suspension constituting a breach of these Terms.
5. Membership, fees, and tiers
- Membership is offered at one of four levels: Bronze, Silver, Diamond, and VIP. A level applies to a Member's whole company account, is set by us when the account is approved or when we invite a company directly, and may be changed by us afterwards; we tell the company when it changes. The specific features, support level, and price applicable to each level are as communicated to that Member directly, and these Terms do not themselves guarantee any particular feature not yet part of the live Service.
- VIP Members correspond with us through a dedicated address, vip@imonetary.ir, from which they also receive our emails.
- Fees, once paid, are non-refundable except where required by applicable law or expressly stated at the time of invitation.
- We may change the fees applicable to future membership periods with reasonable advance notice; changes do not apply retroactively to a period already paid for.
6. Acceptable use
You agree not to use the Service to:
- upload or submit data you do not have the right to hold or share;
- attempt to access another Member's account or data without authorisation;
- probe, scan, or attempt to bypass the Service's access controls or security measures;
- use the Service for money laundering, terrorist financing, sanctions evasion, or any other unlawful financial activity; or
- reverse-engineer, resell, or provide third-party access to the Service other than through Secondary User accounts you control.
7. Your Financial Data — ownership and licence
- As between you and us, you (or your organisation) own the Financial Data you submit to the Service. We do not claim ownership of it.
- You grant us a limited licence to host, process, analyse, and display your Financial Data solely to provide the Service to you, and to the extent necessary to maintain backups, ensure security, and comply with our legal obligations.
- We do not sell Financial Data, and we do not use it to train products for the benefit of anyone other than the account it belongs to.
8. Privacy and data protection
8.1 What we collect
- Account and profile data — name, work email, phone number, password (stored as a salted hash, never in plain text), and the permissions assigned to you.
- Financial Data — transactions, categories, vendors, amounts, currencies, and documents you or your organisation enter or upload, and any petty-cash or sales records connected to your account.
- Uploaded documents — files you upload (receipts, statements, exports), stored with a record of who uploaded them and when.
- Security and audit data — each sign-in and the session it opens (its time, IP address, browser and the steps used to sign in), and an append-only log of account actions (such as a changed password or second sign-in step, a permission change, a document sent or downloaded), kept to protect your account and investigate misuse.
- Invitation-request data — if you request an invitation, the name, company, role, email, and any message you submit, until a decision is made and, if declined, for a limited period after.
- Visitor and traffic records (first-party only) — for security and to understand how
our sites are used, our servers record each request made to imonetary.ir and its subdomains: the time,
your IP address, the page requested (never its query string), our response, and your browser's
user-agent and language settings. On our public pages we also set a first-party cookie
(
vid, kept up to one year) to recognise a returning browser and a session cookie (vsid) for the current visit, and once per visit your browser reports its timezone and a rough screen-size class (small, medium or large). From your IP address we derive an approximate location and the kind of network it belongs to (for example a home connection, a mobile carrier, a data centre, a VPN or Tor), using databases kept on our own servers: your address is never sent to a third party for this. If your browser sends a Do Not Track or Global Privacy Control signal, it is not asked for its timezone or screen size. We do not use third-party advertising or analytics trackers.
8.2 How we use it
We use the data above to: provide and operate the Service; authenticate you and protect your account; review invitation requests; respond to messages sent through our Contact form; understand how our public pages are used, in aggregate; investigate suspected misuse or security incidents; and meet our legal and accounting obligations. We process the visitor and traffic records described in 8.1 on the basis of our legitimate interest in keeping the Service, its members and our other sites secure, and in preventing fraud and abuse.
8.3 Security measures
We describe our current security posture accurately rather than aspirationally:
- All connections to the Service are encrypted in transit (TLS/HTTPS).
- Passwords are hashed with bcrypt and are never stored, logged, or emailed in plain text.
- Access to Financial Data is governed by the permissions a Primary Account holder sets for each Secondary User, enforced on our servers, not only in the visual layout of the dashboard.
- Our database is not currently encrypted at the disk/storage level. Full end-to-end encryption, so that not even iMonetary can read a Member's ledger, is on our roadmap and not yet built; we will update this Policy and our marketing pages together when it is.
- No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
8.4 Cookies
Beyond the visitor-analytics cookies described in 8.1, the Service uses a small number of strictly functional cookies (for example, to remember your selected language and to keep you signed in during a session). We do not use cookies for third-party advertising.
8.5 Data retention
We retain account and Financial Data for as long as your membership is active, and for a reasonable period afterward to comply with legal, tax, and accounting obligations and to resolve disputes, after which it is deleted or anonymised. Declined or expired invitation requests are retained only briefly before deletion.
Security and audit data (8.1) is kept for one year and then deleted. When an account is erased, a copy of its security and audit data is kept apart, for the security of the Service only, until that year is over, and then deleted.
Visitor and traffic records (8.1) are kept in full for 90 days; the server's raw log files, for 14 days. After 90 days we keep only daily totals, with IP addresses shortened to their network (the first three parts of an IPv4 address, the first 48 bits of an IPv6 address), which no longer point to one connection. The records of an address involved in a security incident, or one we are watching because of earlier misuse, are kept for up to one year, for that investigation only, and then deleted.
8.6 Your rights
Subject to applicable law, you may ask us to access, correct, export, or delete personal data we hold about you, or to explain how it is used, by contacting us at the address in Section 15. We will respond within a reasonable time. Some requests may be limited where retention is required by law or necessary to protect the rights of others (for example, another Member whose data is intertwined with yours in a shared company account).
8.7 Where your data is hosted
The Service is hosted on servers located in Iran. If you or your organisation are based outside Iran, your data will be transferred to and processed in Iran by using the Service.
8.8 Who we share data with
We do not sell personal data or Financial Data. We share data only: with service providers who process it on our behalf under confidentiality obligations (for example, our email delivery provider, solely to send transactional messages such as sign-in codes and account notices); where required by law or a valid legal process; or with your consent.
9. Intellectual property
The Service, including its software, design, and branding, is owned by us or our licensors and is protected by applicable intellectual property laws. These Terms do not grant you any right to our trademarks, logos, or brand assets.
10. Disclaimers
- The Service provides analysis, reporting, and tools based on the data you provide. It is not a substitute for professional financial, accounting, tax, investment, or legal advice, and nothing on the Service constitutes such advice.
- Where the Service includes an analytical or advisory feature (however described — for example as an "assistant"), its output is informational, based on the data available to it, and should be independently verified before being relied upon for a material decision.
- The Service is provided "as is" and "as available." We do not warrant that it will be uninterrupted, error-free, or that any forecast, fraud flag, or analysis it produces will be accurate or complete.
11. Limitation of liability
To the maximum extent permitted by applicable law, we are not liable for indirect, incidental, special, or consequential damages, or for loss of profits, revenue, or data, arising from your use of the Service. Our total liability arising out of or relating to the Service will not exceed the fees you paid us for the membership period in which the event giving rise to the claim occurred. Nothing in these Terms limits liability that cannot be limited under applicable law.
12. Term, suspension, and termination
- Membership runs for the period stated at invitation or renewal and may be terminated by either party at the end of that period, or earlier as these Terms allow.
- We may suspend or terminate access immediately for a material breach of these Terms, non-payment, or conduct we reasonably believe is unlawful or harmful to the Service or other Members.
- On termination, we will retain your Financial Data for the period described in Section 8.5, during which you may request an export, after which it will be deleted or anonymised.
13. Changes to the Service or these Terms
We may update these Terms from time to time. Where a change is material, we will make reasonable efforts to notify current Members before it takes effect. Continued use of the Service after a change takes effect constitutes acceptance of the updated Terms.
14. Governing law and dispute resolution
These Terms are governed by the laws of the Islamic Republic of Iran, without regard to conflict-of-law principles. Any dispute arising out of or relating to these Terms or the Service will be subject to the exclusive jurisdiction of the competent courts of [city — e.g. Tehran], Iran.
15. Contact
Questions about these Terms, or requests relating to your data, can be sent to email@imonetary.ir or through the Contact form on our site.
Dara Hosh Tehran (داراهوش تهران) ·
darahoshtehran.ir
[registration number and registered address to be inserted here once
provided, before publication.]