Privacy Policy
Learn how we collect, use, and protect your data.
Introduction
This Privacy Policy explains how BillsDeck collects, uses, discloses, and protects your information when you use our services. By accessing or using the platform, you agree to the practices described in this policy.
Information We Collect
We may collect the following types of information:
- Personal information such as name, email address, and company name
- Account credentials and authentication data
- Payment and billing information
- Documents and financial data you upload or sync (receipts, invoices, statements, and related metadata)
- Integration connection data when you connect third-party services (see Third-Party Integrations below)
- Usage data, logs, and device information
How We Use Your Information
- To provide, operate, and maintain our services
- To process documents, sync accounting data, and deliver integrations you authorize
- To process transactions and manage subscriptions
- To improve product performance and user experience
- To communicate updates, security alerts, and support messages
Third-Party Integrations & OAuth
BillsDeck lets you connect third-party services to import, export, or sync data. Connections are initiated by you and only access data you authorize.
Services you may connect
- QuickBooks / Intuit — Accounting data, company information, vendors, accounts, and related records needed to sync documents and financial workflows
- Google — Sign-in, Gmail, Google Drive, and Google Sheets when you enable those integrations
- Xero, Zoho Books, and other accounting providers — Data required for the integration features you choose
- Payment processors (e.g. Stripe) — Billing and subscription management
OAuth tokens and credentials
- When you authorize a connection, we receive OAuth tokens from the provider on your behalf. We use these tokens only to perform actions you request within the platform.
- Integration refresh tokens and related identifiers (such as QuickBooks company realm IDs) are encrypted at rest using industry-standard AES encryption before being stored in our database.
- We do not sell OAuth tokens or share them with unrelated third parties. Tokens are not exposed in the application interface or API responses.
- You can disconnect an integration at any time from your account settings. When disconnected, we revoke tokens with the provider where supported and remove or deactivate stored credentials.
Provider privacy policies
Connected services are governed by their own privacy policies and terms. We encourage you to review the policies of any provider you connect, including Intuit's Privacy Policy when using QuickBooks.
Data Sharing and Disclosure
We do not sell your personal data. We may share information only in the following circumstances:
- With trusted service providers acting on our behalf (hosting, infrastructure, email delivery, payment processing)
- With third-party services you explicitly connect through integrations, solely to provide the features you authorize
- To comply with legal obligations or lawful requests
- To protect the rights, safety, and security of our platform
Data Security
We follow industry-standard practices to protect your data across its lifecycle — from transmission to storage and access.
Secure Data Transmission
All data transmitted between your browser and our platform is encrypted using HTTPS (TLS 1.2/1.3). HTTP requests are redirected to HTTPS in production. This helps keep sensitive information protected while in transit.
Secure Data Storage
Your data is stored on secure servers with strict physical and technical access controls. Infrastructure is monitored, and access is limited to authorized personnel on a need-to-know basis.
Data Classification
- Public – Marketing and publicly available content
- Internal – Internal documents and operational data
- Sensitive – User data and financial records
- Highly Sensitive – Passwords, OAuth tokens, and API keys
Data Encryption
- Encryption in transit via HTTPS (TLS 1.2/1.3)
- Encryption at rest for databases and backups
- OAuth integration tokens (including QuickBooks refresh tokens and company identifiers) encrypted at rest with AES-256 before storage
- Session data protected via signed, HttpOnly cookies
Network & Infrastructure Security
- Firewalls and network isolation
- API authentication and authorization controls
- Secure HTTP headers (including HSTS, X-Content-Type-Options, and X-Frame-Options in production)
- Cache-control policies on authenticated pages and API routes
- DDoS protection through our hosting provider
Access Control & Authentication
- Role-Based Access Control (RBAC)
- Least privilege access principle
- Secure password hashing for account credentials
- Secure session management with HttpOnly cookies
- Signed OAuth state parameters for third-party authorization flows
Application Security
- Strict input validation and server-side file type checks on uploads
- Protection against SQL injection through parameterized database queries
- Protection against cross-site scripting (XSS)
- Protection against CSRF attacks on authenticated API and form actions
- Validated redirect URLs to prevent open redirect abuse
- Secure coding practices and regular security reviews
Employee Security Practices
- Strong password policies
- Device and endpoint security enforcement
- Immediate access revocation upon role change or exit
- Ongoing security awareness training
Data Processing & Handling
We process your data to deliver core functionality such as document extraction, financial analysis, categorization, and accounting sync.
- Data is securely ingested and processed within our systems
- Automated systems may categorize, analyze, or transform data
- AI-based processing may be used to generate insights and suggestions
- Data is exchanged with connected third-party services only when you authorize an integration and only as needed to provide that feature
Data Storage & Retention
- Data is stored on encrypted servers with strict access control
- Retention period depends on your selected plan (maximum 30 days)
- Users can request deletion of their data at any time
- All requested deletions are processed within 48 hours
Data Deletion & User Rights
- Right to access, update, or delete your personal data
- Request a copy (data export) of your stored information
- Request account deletion at any time
- Disconnect third-party integrations and revoke associated tokens
- Withdraw consent where applicable
Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated effective date. Material changes may also be communicated through the platform or by email where appropriate.
Contact Us
If you have any questions about this Privacy Policy, please contact our support team through the platform.