Payments are currently processed in simulated demo mode; no real charge is made until a live payment provider is connected.
1. Who we are
Controller: Libardo Valladares, operating ReceiptSpark. Contact for privacy matters: hello@receiptspark.com.
2. Information we collect
2.1. Account data
- Email address.
- Password, always stored hashed (using a one-way function); never in readable form.
- Plan, remaining document allowance and renewal date.
- Usage history (date and action, e.g. "document processed").
2.2. Documents you upload
When you upload a receipt or invoice, the file is sent to our server and from there to the AI provider that performs the extraction. The temporary file is deleted from our server as soon as processing finishes. We do not store the original documents unless you explicitly enable the original-file history feature available on the Firm plan; in that case they are kept while the feature is on and until you delete them.
The extracted data (the resulting table) is processed in your browser and only saved if you choose to download it. We keep no copy of the table.
2.3. Technical data
- IP address, to apply usage limits and prevent abuse.
- Server logs (errors, response times) with no content from your documents.
- One technical session cookie to keep you signed in (see the cookie policy).
3. How we use it
| Purpose | Basis |
|---|---|
| Provide the service (create your account, process documents, manage credits) | Performance of the contract |
| Charge the subscription (in the production version) | Performance of the contract |
| Usage limits, security and abuse prevention | Legitimate interest |
| Respond to support requests | Performance of the contract / legitimate interest |
| Comply with legal obligations (e.g. tax and accounting) | Legal obligation |
| Service-related communications | Legitimate interest; marketing, consent |
We do not sell your personal information, and we do not use your documents for advertising.
4. Service providers
To provide the service we rely on providers that process data on our behalf:
- Web hosting provider (servers where the application runs).
- AI provider that performs the data extraction. In the production version we use a plan that does not use submitted content to train its models.
- Payment platform (production version only), which handles billing and payment data under its own safeguards.
5. How long we keep data
- Account data: while the account is active. If you delete it or it stays inactive for a long period, it is deleted or anonymized.
- Uploaded documents: deleted after processing (unless original-file history is enabled).
- Billing data: the period required by tax and accounting rules.
- Technical logs: a maximum of 12 months.
6. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, and to opt out of certain uses. California residents have specific rights under the CCPA/CPRA, including the right to know, delete and correct, and the right not to be discriminated against for exercising them. To make a request, email hello@receiptspark.com. You can also request full export or deletion of your account.
7. Security
We apply reasonable technical and organizational measures: encryption in transit (HTTPS), hashed passwords, restricted access to data, keeping provider API keys out of any public code, and deleting temporary files after use.
8. Children
The service is intended for professionals and businesses. It is not directed to children under 13, and we do not knowingly collect their information.
9. Changes
We may update this policy to reflect legal or service changes. We will post the current version on this page with its date and, if the change is significant, notify you by email.