Legal
Privacy Policy
Learn how ReceiptCue collects, uses, shares, and protects account, receipt, billing, connected mailbox, and support data.
Last updated: March 30, 2026
Overview
This Privacy Policy explains how ReceiptCue collects, uses, discloses, and protects personal information when you access the ReceiptCue website, create an account, upload receipts, connect supported mailboxes, use billing features, or contact us for support.
When this Privacy Policy refers to 'ReceiptCue', 'we', 'us', or 'our', it means the operators of the ReceiptCue service. When we refer to 'you', we mean the person using the service or, if applicable, the organization on whose behalf that person is acting.
Information We Collect
The information we collect depends on how you use the service.
- Account and profile information, such as your name, email address, authentication details, password reset requests, language preferences, and account status.
- Workspace and collaboration information, such as workspace membership, roles, invitations, ownership, and settings for company or personal workspaces.
- Receipt and spending information that you upload or create in the service, including receipt files, extracted OCR fields, line items, merchant information, amounts, notes, recommendations, card details, and related workspace activity.
- Connected mailbox information for supported Gmail / Google Workspace and Outlook / Microsoft 365 integrations, including connected mailbox identifiers, mailbox health and sync state, sender settings, message metadata, and receipt-like email content or attachments that you authorize us to review or import.
- Billing and subscription information processed through Stripe, such as customer, checkout, portal, subscription, plan, invoice, payment status, and billing timeline data.
- Support, compliance, and communications data, including feedback submissions, customer support messages, data export requests, deletion requests, and optional marketing consent records.
- Guest product update subscription information, such as the name, email address, optional phone number, subscription source, channel preferences, subscription timestamps, unsubscribe timestamps, and preference-management tokens associated with public product update signups.
- Technical and security information, such as session and preference cookies, request identifiers, browser or device signals, service logs, error events, and operational diagnostics generated when you use the service.
How We Use Information
We use personal information to operate, secure, support, and improve ReceiptCue, and to provide the features you request.
- Authenticate users, maintain accounts, and keep workspaces available to authorized members.
- Store receipt files and process uploaded content to extract receipt fields, line items, and related workflow data.
- Generate recommendations, insights, and advisor outputs based on the information available in your account or workspace, including model-assisted features when configured.
- Connect and sync supported Gmail or Outlook mailboxes and import receipt-like email bodies, HTML receipts, or attachments into the receipt-processing workflow.
- Provide billing, checkout, subscription management, invoicing, and account recovery flows.
- Send operational communications such as password reset emails, billing notices, product support responses, and compliance-related messages.
- Send guest product update communications that you request, including product update emails and, if you provide a phone number for that purpose, future product update SMS notifications when that channel becomes available.
- Protect the service, detect misuse, troubleshoot failures, audit changes, and enforce our terms and internal controls.
- Analyze product performance, improve import accuracy, and maintain service quality.
- Comply with legal obligations, resolve disputes, and exercise or defend legal claims.
Connected Mailboxes And Imported Content
If you connect Gmail / Google Workspace or Outlook / Microsoft 365, you authorize ReceiptCue to access the mailbox data needed to identify, sync, and process receipt-like messages for your workspace. Depending on the integration and message format, that may include sender data, message metadata, message bodies, HTML receipts, and file attachments.
Mailbox connections can bootstrap recent history, including the last 30 days where that workflow is available, and can continue to sync new receipt-like messages over time. Imported content may be stored with the rest of your workspace receipt records and may be reviewed by authorized workspace members according to their roles.
You are responsible for connecting only mailboxes you are authorized to access and for ensuring that your use of these integrations is permitted under your internal policies and applicable law.
Cookies, Sessions, And Diagnostics
ReceiptCue uses essential session and security cookies to keep users signed in, protect authenticated routes, and maintain service integrity. We also use preference cookies, such as language settings, so the public and signed-in experience can respect your chosen locale.
We may generate logs and diagnostic records that include request identifiers, timing data, browser or user-agent signals, and failure details. We use that information to secure the service, investigate incidents, and troubleshoot reliability problems.
How We Share Information
We do not sell your personal information or receipt content. We disclose information only as needed to operate ReceiptCue, comply with law, or complete a transaction or workflow you request.
- Service providers and infrastructure vendors that help us host the application, run databases, store files, send email, process OCR, support AI-assisted features, and operate development or production systems.
- Payment and billing providers, including Stripe, to process subscriptions, manage billing, and support customer portal flows.
- Google or Microsoft, when you choose to connect supported mailbox integrations that rely on Google APIs or Microsoft APIs.
- Configured OCR or model providers, including OpenAI-powered advisor features and OCR processing services, when those features are used to process your content.
- Other users in your workspace, to the extent your role, workspace configuration, and product behavior make shared data visible to owners, admins, employees, accountants, or other authorized collaborators.
- Courts, regulators, law enforcement, advisors, or transaction counterparties when disclosure is reasonably necessary to comply with law, enforce our agreements, protect rights and safety, or complete a reorganization, financing, or sale of the service.
Retention, Export, And Deletion
We retain personal information for as long as reasonably necessary to provide the service, maintain billing and security records, support account recovery, resolve disputes, and comply with legal obligations.
ReceiptCue currently provides account export tooling for eligible signed-in users. Export downloads are protected by signed access controls and are intended to help you retrieve a copy of account data made available by the product at the time of export.
ReceiptCue also supports account deletion requests. Under the current product flow, a deletion request places the account into a pending state and keeps it recoverable for 30 days before final deletion processing begins. During that recoverable period, parts of the account may remain read-only. Some records may remain after deletion where retention is required for security, billing, abuse prevention, backup integrity, or legal compliance.
If you own a company workspace, the product may require you to transfer ownership or resolve workspace responsibilities before a deletion request can proceed.
Security And International Processing
We use administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, or disclosure. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
ReceiptCue and its service providers may process or store information in jurisdictions outside the one where you live. By using the service, you understand that your information may be processed by providers in other regions, subject to their laws and our contractual or operational controls.
Your Choices And Rights
Depending on applicable law, including private-sector privacy law that may apply in British Columbia, you may have rights to request access to, correction of, export of, or deletion of your personal information.
You can exercise some of these choices directly through the product, including account export requests, deletion requests, connected mailbox controls, billing self-service, and optional marketing consent settings. For other privacy requests or questions, contact us and we will review the request in light of applicable law and the functionality available in the service.
If you subscribe to guest product updates without creating an account, you can use the preference-management and unsubscribe links we send by email to update or cancel email and SMS product update notifications. Providing a phone number in that signup flow means you are asking us to retain it for future product update SMS notifications until you change that preference or unsubscribe.
Children's Privacy
ReceiptCue is not intended for anyone under 18 years old, and we do not knowingly collect personal information from children under 18. If you believe someone under 18 has provided personal information to the service, please contact us so we can review and address it.
Contact
If you have privacy questions, requests, or complaints, contact support@receiptcue.com.