This Privacy Policy explains how [COMPANY_LEGAL_NAME] (company number [COMPANY_NUMBER], registered office [REGISTERED_OFFICE]) ("we", "us") collects and uses personal data when you use ReceiptTidy (the "Service"). We are the data controller for the personal data of our account holders, and a data processor for the receipt/invoice data you upload about third parties (see our Data Processing Agreement).
We are registered with the UK Information Commissioner's Office (ICO) under reference [ICO_REGISTRATION].
1. Personal data we collect
- Account data: name, email address, password (stored hashed), organisation name, role.
- Billing data: plan, subscription status, and limited payment metadata. Card details are handled by Stripe — we do not store full card numbers.
- Content you upload: receipts and invoices (images/PDFs) and the data extracted from them, which may include supplier/customer names, amounts, dates and tax details.
- Connection data: OAuth tokens for accounting platforms you connect (encrypted at rest).
- Usage & technical data: log data, device/browser information, and IP address (truncated/sanitised where used in security logs).
2. How and why we use it (purposes & lawful bases)
| Purpose | Lawful basis |
|---|---|
| Provide and operate the Service (capture, extract, review, publish) | Performance of a contract |
| OCR & AI extraction of uploaded documents | Performance of a contract |
| Billing and fraud prevention | Contract / legitimate interests |
| Security, abuse prevention, audit logging | Legitimate interests / legal obligation |
| Service emails (e.g. verification, digests, important notices) | Contract / legitimate interests |
| Product analytics and improvement | Legitimate interests |
| Compliance with law (e.g. tax, accounting records) | Legal obligation |
3. Automated processing
We use automated OCR and AI to extract data from your documents. This supports your bookkeeping; it does not produce legal or similarly significant decisions about individuals. You always review and approve extracted data before it is published.
4. Who we share it with (processors & recipients)
We use trusted sub-processors strictly to provide the Service, including: Google Cloud Vision (OCR), our LLM provider(s) (data extraction), Cloudflare R2 (encrypted document storage), Stripe (payments), our email provider, and our hosting provider. We share data with the accounting platforms you choose to connect, at your direction. We do not sell personal data. We may disclose data where required by law.
5. International transfers
Where data is transferred outside the UK/EEA, we rely on appropriate safeguards such as UK adequacy regulations or the International Data Transfer Agreement / Standard Contractual Clauses.
6. Retention
We keep personal data only as long as needed for the purposes above or as required by law. Retention periods and how to request erasure are described in our Data Deletion & Retention policy.
7. Your rights
Under UK GDPR you have the right to: access; rectification; erasure; restriction; objection; data portability; and to withdraw consent where processing is based on consent. To exercise any right, contact [PRIVACY_EMAIL]. We will respond within one month. You also have the right to complain to the ICO (ico.org.uk).
8. Security
We use technical and organisational measures including encryption in transit and at rest, per-tenant data isolation (row-level security), access controls and audit logging. No system is perfectly secure; we will notify affected users and the ICO of qualifying personal data breaches as required.
9. Children
The Service is not intended for anyone under 18 and we do not knowingly collect their data.
10. Cookies
See our Cookie Policy.
11. Changes & contact
We may update this Policy; material changes will be notified in-app or by email. For privacy questions or to exercise your rights, contact [PRIVACY_EMAIL] or write to [COMPANY_LEGAL_NAME], [REGISTERED_OFFICE].
Last updated: [LAST_UPDATED].