1. Information We Collect
We collect information necessary to provide automated receipt parsing, categorisation, accounting sync, and user account management:
- Account Registration Information: Your name, email address, password hashes, company/organisation name, and subscription tier.
- Receipt & Financial Data: Uploaded images or PDFs of receipts, invoices, and expense documents, including extracted merchant names, dates, currency, line items, net/VAT breakdowns, and payment method indicators.
- Integration Tokens: Authentication tokens for linked services such as Xero, Google Drive, WhatsApp, or email webhooks.
- Usage & Technical Logs: IP address, browser type, device information, access timestamps, and error diagnostic logs.
2. Legal Bases for Processing (UK GDPR)
We process your personal data under the following legal bases:
- Contractual Necessity: To fulfil our obligation to provide receipt extraction, storage, and accounting integration services under our Terms & Conditions.
- Legitimate Interests: To improve machine learning accuracy, maintain system security, prevent fraud, and optimise application performance.
- Legal Compliance: To satisfy tax, accounting, and financial reporting duties under UK law.
3. How We Use Information
We use collected information for the following specific purposes:
- Extracting, processing, and storing receipt transaction data for your financial dashboard.
- Synchronising receipt metrics and attachments with third-party accounting providers (e.g. Xero).
- Sending system notifications, password resets, and customer support communications.
- Monitoring system health, debugging operational failures, and defending against cyber threats.
- Conducting normalised, anonymised research on receipt structures for Free Tier accounts.
4. Free Account Data Normalisation & Research
As detailed in our Terms & Conditions, users on Free Tier Accounts consent to the use of receipt metadata for technological research and model development.
The Normalisation Process:
Before any data from a Free Account is admitted into research or benchmarking workflows, it passes through an automated Data Normalisation Protocol:
- PII Removal: Names, personal email addresses, billing addresses, phone numbers, and payment details are permanently stripped.
- Schema Standardisation: Vendor names, item names, and line amounts are converted into standardised, category-level vectors (e.g. `MERCHANT_CATEGORY: OFFICE_SUPPLIES`, `TAX_RATE: 20%`).
- Anonymisation & Aggregation: Extracted data is pooled into anonymised datasets disassociated from specific user accounts.
Note: Paid Accounts (Standard, Pro, Business) are completely excluded from research data pipelines.
5. Data Security & Storage
We implement industry-standard technical and organisational security measures to safeguard your personal data:
- TLS/SSL encryption for all data in transit.
- AES-256 encryption at rest for file uploads and stored credentials.
- Role-based access controls (RBAC) and row-level security (RLS) policies.
- Regular automated backups and isolated database instances.
6. Third-Party Sub-processors
We work with carefully vetted third-party service providers to deliver our core capabilities:
- Cloud Infrastructure & Database: Supabase / Cloud SQL for secure hosted database and authentication storage.
- OCR & Document Analysis: Optical character recognition providers (e.g. OCR.space, Google Cloud Vision, Gemini API) for line-item text extraction.
- Payment Processing: Stripe for PCI-DSS compliant payment processing.
- Transactional Email: Resend / SendGrid for delivering system notifications and reports.
7. Your Data Subject Rights
Under UK GDPR and the Data Protection Act 2018, you have the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten"): Request full deletion of your account and associated receipt data.
- Right to Restrict or Object: Object to specific processing activities or request restriction of data processing.
- Right to Data Portability: Export your receipt data in structured format (CSV/JSON).
- Right to Opt Out of Research: Upgrade your account to any Paid Subscription Plan to immediately exclude all data from research processing.
8. Data Retention & Deletion
We retain your personal data and uploaded receipt documents for as long as your account remains active or as required by law for tax and audit compliance. When an account is closed or deletion is requested, all personal data, file attachments, and database records are permanently deleted within 30 days.
9. Cookies Policy
Receipts Keeper uses essential session cookies to authenticate users, prevent CSRF attacks, and remember basic user preferences. We do not use third-party cross-site tracking cookies for advertising purposes.
10. Contact Us
If you wish to exercise your data protection rights, ask questions about our data normalisation procedures, or submit a inquiry, please contact our Data Protection Team via our Contact Form or email us at privacy@receiptskeeper.co.uk.