Privacy Policy
Effective 6 October 2026
This policy explains what information ReceiptsPls (“we”, “us”), operated by Gander Ecommerce Solutions Private Limited, collects when you use https://app.receiptspls.com and the ReceiptsPls browser extension, how we use it, and the choices you have.
What we collect
- Account details: your name, email address and a one-way hash of your password, plus the workspaces you belong to and your role in each.
- Documents you give us: invoices, receipts and bank statements you upload, forward to your workspace address, or capture with the browser extension, and the data we extract from them (for example vendor, amounts, dates, line items, tax IDs and billing addresses).
- Mailbox data: if you connect Gmail, Microsoft 365 or an IMAP mailbox, we search it for invoices and receipts and read the matching messages and attachments. We keep the documents we find and the sender address they came from. We do not keep other email.
- Accounting data: if you connect QuickBooks Online, Xero or Zoho Books, we read your company name and the accounts and vendors needed to file bills, and we create vendors, bills and receipt attachments when you export.
- Connection credentials: OAuth tokens for the services you connect, and IMAP passwords if you use IMAP. These are encrypted at rest.
- Activity records: an audit log of actions in your workspace (for example sign-ups, connections, exports and edits) and diagnostic information when something goes wrong.
- Cookies: only the cookies needed to keep you signed in, remember your selected workspace and protect sign-in flows. We do not use advertising or analytics cookies.
How we use it
- To provide the service: collect, read and organise your invoices and receipts, reconcile them, and export them to the accounting system you choose.
- To keep the service secure, investigate errors and provide support.
- To contact you about your account and important changes to the service.
We do not sell your information, use it for advertising, or use your documents to train AI models.
Google user data
ReceiptsPls’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request read-only Gmail access, use it only to find and import invoices and receipts into your workspace, and do not let people read your email except with your permission, for security purposes, or as required by law.
Intuit (QuickBooks) data
Data we receive from QuickBooks Online is used only to provide the export features you turn on, is shown only to members of your workspace, and is not shared with anyone else. When you disconnect QuickBooks we revoke our access at Intuit.
Service providers
We share information only with providers that help us run the service, and only as needed for that purpose:
- Railway: application hosting, database and file storage (Singapore region).
- Google (Gemini API): reads the documents you import so their details can be extracted. Google does not use this data to train its models.
- Resend: receives email sent to your workspace address and delivers our emails.
- Sentry: error monitoring. Session replays used to debug errors have all text and media masked.
- Google, Microsoft, Intuit, Xero and Zoho: only when you connect them, to exchange the data described above.
We may also disclose information if required by law, or to protect the rights and safety of our users or the service. If the business is transferred, this policy will continue to apply to your information.
Where your data is stored
Your data is stored in Singapore. If you use the service from another country, your information is transferred to and processed in Singapore and in the countries where our service providers operate.
Security
All traffic to the service uses HTTPS. Passwords are stored as salted PBKDF2 hashes. Mailbox and accounting connection credentials are encrypted at rest with AES-256-GCM. Each workspace’s data is isolated from every other workspace, and actions are recorded in an audit log. No system is perfectly secure; if a breach affects your information we will notify you as required by law.
How long we keep it
We keep your information while your account is active. When you disconnect a mailbox or accounting system we delete its credentials, and you can choose to delete the documents imported from it. If you ask us to delete your account, we delete your account and workspace data within 30 days, except where we must keep something to meet a legal obligation.
Your choices and rights
- Disconnect any connected service at any time from the Integrations page, or revoke access from your Google, Microsoft, Intuit, Xero or Zoho account settings.
- Export your invoices and receipts at any time.
- Ask us for a copy of your information, to correct it, or to delete it, by emailing [email protected]. We respond within 30 days.
These include your rights under India’s Digital Personal Data Protection Act, 2023. Depending on where you live (for example in California or the European Economic Area), you may have additional rights under local law. We honour those rights for all users.
Children
The service is for businesses and is not directed to anyone under 16.
Changes
If we make material changes to this policy we will notify you by email or in the app before they take effect. The effective date above shows when it last changed.
Contact and grievances
ReceiptsPls is operated by Gander Ecommerce Solutions Private Limited (CIN U72900KA2022PTC166618), registered office: Unit No. A307, Brigade Omega, Sy No. 23/1, Banashankari 6th Stage, Thurahalli Village, Bangalore South, Bengaluru, Karnataka 560061, India. For questions, requests or complaints about your information, contact our Grievance Officer at [email protected]. We resolve grievances within 30 days.