Skip to main content
Legal

Privacy Policy

Learn how we collect, use, and protect your data.

Effective: January 1, 2026Last updated: June 15, 2026

Introduction

This Privacy Policy explains how BillsDeck collects, uses, discloses, and protects your information when you use our services. By accessing or using the platform, you agree to the practices described in this policy.

Information We Collect

We may collect the following types of information:

  • Personal information such as name, email address, and company name
  • Account credentials and authentication data
  • Payment and billing information
  • Documents and financial data you upload or sync (receipts, invoices, statements, and related metadata)
  • Integration connection data when you connect third-party services (see Third-Party Integrations below)
  • Usage data, logs, and device information

How We Use Your Information

  • To provide, operate, and maintain our services
  • To process documents, sync accounting data, and deliver integrations you authorize
  • To process transactions and manage subscriptions
  • To improve product performance and user experience
  • To communicate updates, security alerts, and support messages

Cookies & Similar Technologies

We use cookies and similar technologies to operate the platform securely and to keep you signed in. We do not use cookies for advertising or cross-site tracking.

Essential cookies

  • Session cookie — Keeps you signed in after authentication. HttpOnly, Secure (in production), SameSite=Lax. Expires after 24 hours or when you sign out.
  • CSRF cookie — Helps protect against cross-site request forgery on authenticated actions. HttpOnly, Secure (in production), SameSite=Strict.

OAuth security cookies

When you connect a third-party account (such as QuickBooks, Google, or Xero), short-lived cookies may be set during the authorization flow to validate the connection securely. These are HttpOnly, deleted after the flow completes, and are not used for tracking.

Managing cookies

Essential cookies are required for sign-in and core functionality. You can control cookies through your browser settings, but disabling them may prevent you from using parts of the service.

Third-Party Integrations & OAuth

BillsDeck lets you connect third-party services to import, export, or sync data. Connections are initiated by you and only access data you authorize.

Services you may connect

  • QuickBooks / Intuit — Accounting data, company information, vendors, accounts, and related records needed to sync documents and financial workflows
  • Google — Sign-in, Gmail, Google Drive, and Google Sheets when you enable those integrations
  • Xero, Zoho Books, and other accounting providers — Data required for the integration features you choose
  • Payment processors (e.g. Stripe) — Billing and subscription management

OAuth tokens and credentials

  • When you authorize a connection, we receive OAuth tokens from the provider on your behalf. We use these tokens only to perform actions you request within the platform.
  • Integration refresh tokens and related identifiers (such as QuickBooks company realm IDs) are encrypted at rest using industry-standard AES encryption before being stored in our database.
  • We do not sell OAuth tokens or share them with unrelated third parties. Tokens are not exposed in the application interface or API responses.
  • You can disconnect an integration at any time from your account settings. When disconnected, we revoke tokens with the provider where supported and remove or deactivate stored credentials.

Provider privacy policies

Connected services are governed by their own privacy policies and terms. We encourage you to review the policies of any provider you connect, including Intuit's Privacy Policy when using QuickBooks.

Data Sharing and Disclosure

We do not sell your personal data. We may share information only in the following circumstances:

  • With trusted service providers acting on our behalf (hosting, infrastructure, email delivery, payment processing)
  • With third-party services you explicitly connect through integrations, solely to provide the features you authorize
  • To comply with legal obligations or lawful requests
  • To protect the rights, safety, and security of our platform

Data Security

We follow industry-standard practices to protect your data across its lifecycle — from transmission to storage and access.

Secure Data Transmission

All data transmitted between your browser and our platform is encrypted using HTTPS (TLS 1.2/1.3). HTTP requests are redirected to HTTPS in production. This helps keep sensitive information protected while in transit.

Secure Data Storage

Your data is stored on secure servers with strict physical and technical access controls. Infrastructure is monitored, and access is limited to authorized personnel on a need-to-know basis.

Data Classification

  • Public – Marketing and publicly available content
  • Internal – Internal documents and operational data
  • Sensitive – User data and financial records
  • Highly Sensitive – Passwords, OAuth tokens, and API keys

Data Encryption

  • Encryption in transit via HTTPS (TLS 1.2/1.3)
  • Encryption at rest for databases and backups
  • OAuth integration tokens (including QuickBooks refresh tokens and company identifiers) encrypted at rest with AES-256 before storage
  • Session data protected via signed, HttpOnly cookies

Network & Infrastructure Security

  • Firewalls and network isolation
  • API authentication and authorization controls
  • Secure HTTP headers (including HSTS, X-Content-Type-Options, and X-Frame-Options in production)
  • Cache-control policies on authenticated pages and API routes
  • DDoS protection through our hosting provider

Access Control & Authentication

  • Role-Based Access Control (RBAC)
  • Least privilege access principle
  • Secure password hashing for account credentials
  • Secure session management with HttpOnly cookies
  • Signed OAuth state parameters for third-party authorization flows

Application Security

  • Strict input validation and server-side file type checks on uploads
  • Protection against SQL injection through parameterized database queries
  • Protection against cross-site scripting (XSS)
  • Protection against CSRF attacks on authenticated API and form actions
  • Validated redirect URLs to prevent open redirect abuse
  • Secure coding practices and regular security reviews

Employee Security Practices

  • Strong password policies
  • Device and endpoint security enforcement
  • Immediate access revocation upon role change or exit
  • Ongoing security awareness training

Data Processing & Handling

We process your data to deliver core functionality such as document extraction, financial analysis, categorization, and accounting sync.

  • Data is securely ingested and processed within our systems
  • Automated systems may categorize, analyze, or transform data
  • AI-based processing may be used to generate insights and suggestions
  • Data is exchanged with connected third-party services only when you authorize an integration and only as needed to provide that feature

Data Storage & Retention

  • Data is stored on encrypted servers with strict access control
  • Retention period depends on your selected plan (maximum 30 days)
  • Users can request deletion of their data at any time
  • All requested deletions are processed within 48 hours

Data Deletion & User Rights

  • Right to access, update, or delete your personal data
  • Request a copy (data export) of your stored information
  • Request account deletion at any time
  • Disconnect third-party integrations and revoke associated tokens
  • Withdraw consent where applicable

Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated effective date. Material changes may also be communicated through the platform or by email where appropriate.

Contact Us

If you have any questions about this Privacy Policy, please contact our support team through the platform.