Legal

Privacy Policy

How InvoiceReconcile collects, uses, shares, retains, and protects personal information.

Effective August 23, 2026

This Privacy Policy explains how ND SOFT LLC ("InvoiceReconcile," "we," "us," or "our") handles personal information through invoicereconcile.com, the InvoiceReconcile application, and related services.

It also explains the choices and privacy rights available to individuals. This policy does not apply to third-party services that have their own privacy policies.

1. Our privacy roles

For account registration, billing, website analytics, security, support, and our own business operations, InvoiceReconcile determines why and how personal information is processed. In those contexts, we act as a controller or business under applicable privacy law.

For personal information contained in invoices, payment files, bank descriptions, customer records, and other Customer Content submitted by a customer, the customer generally determines why the information is processed. In those contexts, the customer acts as the controller or business, and InvoiceReconcile acts as its processor, service provider, or contractor. Requests about Customer Content should normally be directed to the organization that uploaded it. We will assist that organization as required by contract and law.

2. Information we collect

Please do not submit passwords, authentication secrets, complete payment-card numbers, Social Security numbers, government identifiers, health data, or other highly sensitive information unless a specific secure feature expressly requests it.

CategoryExamplesPrimary sources
Account and identity informationName, business email, authentication identifier, organization, workspace membership, role, timezone, and preferences.You, your workspace administrator, and authentication providers you choose.
Customer Content and financial workflow dataInvoices, customer and payer names or contact details, payment amounts and dates, balances, transaction references, bank descriptions, account labels, memos, source values, and imported files.You, your organization, files you upload, and integrations you direct us to connect.
Reconciliation and derived dataNormalized values, duplicate indicators, match candidates, confidence categories, reasons, discrepancies, approvals, rejections, notes, and exports.Generated from Customer Content and your actions in the Service.
Billing and commercial informationPlan, subscription status, billing interval, transaction status, tax-related details, payment-processor customer identifiers, and limited payment-method details such as brand and last four digits.You and our payment processor. We do not receive or store complete payment-card numbers.
Device and usage informationIP address, device and browser type, operating system, pages or features used, referral source, approximate region, timestamps, session events, and error diagnostics.Collected automatically from your browser, device, cookies, and similar technologies.
Support and communicationsSupport requests, feedback, survey responses, attachments, and communications with us.You and your organization.
Security and audit informationSign-in events, access changes, import and export events, reconciliation actions, administrative actions, suspected fraud signals, and security logs.Your use of the Service, administrators, and our security systems.

3. How and why we use information

Where we rely on legitimate interests, we consider the impact on individuals and do not use that basis where their rights and interests outweigh ours. Where we rely on consent, you may withdraw it at any time without affecting earlier processing.

PurposeExamplesEEA and UK legal basis when applicable
Provide the ServiceCreate accounts, import and normalize data, suggest matches, support review, preserve decisions, create audit history, and generate exports.Perform our contract with you. For Customer Content, follow the customer's documented instructions as its processor.
Operate and support accountsAuthenticate users, manage workspaces and roles, provide support, and send service messages.Perform our contract and pursue our legitimate interest in operating and supporting the Service.
BillingProcess subscriptions, payments, invoices, taxes, cancellations, and account status.Perform our contract and comply with legal obligations.
Security and abuse preventionProtect accounts, enforce access controls, investigate suspicious activity, prevent fraud, and maintain audit records.Our legitimate interests in protecting the Service and users, and compliance with legal obligations.
Improve the ServiceDiagnose errors, measure feature performance, understand aggregate usage, and improve workflows without using Customer Content to train general-purpose AI models.Our legitimate interests in maintaining and improving the Service. Consent where law requires it for analytics technologies.
CommunicateSend requested support responses, operational notices, optional product updates, and optional summaries.Perform our contract, pursue legitimate interests, or obtain consent, depending on the communication.
Comply and protectMeet legal obligations, respond to lawful process, exercise or defend legal claims, and protect people, rights, and property.Compliance with legal obligations and our legitimate interests in protecting rights and resolving disputes.

4. Reconciliation suggestions and automated processing

The Service uses rules and software-assisted analysis to generate match candidates, confidence categories, duplicate indicators, and explanations. These outputs are recommendations for review. The Service is designed to require user confirmation before a reconciliation is finalized or exported.

We do not use these suggestions to make solely automated decisions about individuals that produce legal or similarly significant effects. Customers remain responsible for their own decisions and for responding to requests about their use of Customer Content.

5. How we disclose information

We may disclose personal information to the following recipients for the stated purposes:

  • Infrastructure and service providers that support hosting, storage, authentication, email, analytics, customer support, security, error monitoring, and similar operations. They may process information only for contracted purposes.
  • Payment processors and billing providers that process subscriptions and related transactions.
  • Third-party integrations when you direct us to connect, import, or export data.
  • Other users and administrators in the same organization or workspace according to configured permissions.
  • Professional advisers, auditors, insurers, and financial institutions where reasonably necessary for business operations and subject to appropriate duties of confidentiality.
  • Government authorities or other parties when we reasonably believe disclosure is required by law, lawful process, or necessary to protect rights, safety, security, or the integrity of the Service.
  • A buyer, investor, successor, or other participant in a merger, financing, reorganization, bankruptcy, or sale of all or part of the business, subject to appropriate confidentiality protections.
  • Other recipients when you request or consent to the disclosure.

We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising. We do not use or disclose sensitive personal information to infer characteristics about individuals.

We may use and disclose aggregated or de-identified information where we take reasonable measures to prevent it from being associated with an individual and do not attempt to re-identify it.

6. Retention and deletion

We keep personal information only as long as reasonably necessary for the purposes described in this policy, including providing and securing the Service, meeting legal obligations, resolving disputes, and enforcing agreements. The criteria below describe how retention is determined. We do not publish a fixed deletion period that our current systems cannot verify.

DataRetention approach
Original invoice and payment file bytesFiles of up to 2 MiB that use the synchronous request path are processed in request memory without a deliberate application-storage copy. The background path stores source bytes temporarily in a private bucket so work can continue safely after you leave the page. A signed upload capability may remain valid for about two hours, so deletion stays pending until that capability has expired. After processing, permanent preview failure, or a user deletion request, removal is scheduled as soon as the capability-safe time is reached. The 24-hour lifecycle schedules cleanup for every remaining source, and provider failures are retried until deletion is confirmed. Structured values created from a file remain Customer Content under the retention approach below.
Structured Customer Content, reconciliation records, configured rules where enabled, and audit historyRetained while the workspace is active and afterward only as needed to complete a verified deletion request, preserve customer-requested records, meet legal or contractual duties, resolve disputes, prevent fraud, or protect the Service.
Account profile and workspace membershipRetained while the account or workspace relationship is active and afterward only for account recovery, security, legal compliance, dispute resolution, or another documented operational need.
Security, access, and application logsRetained for the shortest period reasonably needed to operate and secure the Service, investigate incidents, prevent abuse, and satisfy applicable legal obligations. Provider-specific log lifecycles may apply.
Support recordsRetained while a request is open and afterward as reasonably needed to document the response, improve support, resolve disputes, or meet legal obligations.
Billing, tax, and contract recordsRetained for the period required by tax, accounting, payment, contract, and automatic-renewal laws and for related dispute or fraud-prevention needs.
BackupsDeleted information may remain in restricted backups until the applicable provider backup cycle expires. Backups are not restored for ordinary use and may be isolated longer when required for security, legal hold, or disaster recovery.

A workspace or organization cannot be deleted while a private source object is awaiting confirmed removal. You can request source removal from Imports, then delete the workspace after the deletion status is confirmed. To request deletion of an account, workspace, or other personal information, contact support@invoicereconcile.com. We verify the requester and scope before acting. Deletion may also be delayed where information must be preserved for security, fraud prevention, legal claims, financial recordkeeping, or a valid legal hold. Information retained for those reasons will be limited and isolated where practical.

7. International data transfers

InvoiceReconcile and its providers may process information in the United States and other countries where they operate. Those countries may have privacy laws different from the laws where you live.

When applicable law requires a transfer safeguard, we use a legally recognized mechanism appropriate to the transfer, such as an adequacy decision, the European Commission's Standard Contractual Clauses with supplementary measures where needed, or the UK International Data Transfer Agreement or UK Addendum. Contact support@invoicereconcile.com to request information about the safeguard relevant to your data.

8. Security

We use administrative, technical, and organizational safeguards designed to protect personal information. These include access controls, private file handling, encryption in transit and at rest through our infrastructure providers, environment-based secret management, audit logging, file validation, rate limiting, and signed verification for supported webhooks.

No system is completely secure. You are responsible for protecting your credentials, devices, exports, integration access, and workspace permissions. If you believe an account or data may have been compromised, contact support@invoicereconcile.com promptly.

9. Your privacy rights and choices

Depending on where you live and subject to legal exceptions, you may have the right to request access to personal information, correction, deletion, a portable copy, restriction of processing, or information about disclosures. You may also have the right to object to certain processing, withdraw consent, appeal a denied request, or complain to a privacy regulator.

You can update certain account details in the Service. To make another privacy request, email support@invoicereconcile.com. Describe the right you want to exercise and the account or organization involved. We may need to verify your identity and authority using information reasonably related to the request. Authorized agents may submit requests where applicable law permits, subject to verification of their authority.

We will not discriminate against you for exercising a privacy right. If we process your information only for a customer, we may direct your request to that customer or help the customer respond.

EEA and UK residents may complain to the data protection authority where they live or work, or where they believe a violation occurred. We encourage you to contact us first so we can address the concern.

10. California privacy notice

This section supplements the rest of the policy for California residents. The categories of personal information collected in the preceding 12 months are described in Section 2. Depending on the data, they may correspond to CCPA categories including identifiers, customer records, commercial information, internet or electronic activity, professional information, sensitive personal information, and inferences used for reconciliation.

We collect and use those categories for the business and commercial purposes in Section 3, retain them as described in Section 6, and disclose them to the recipient categories in Section 5. We do not sell personal information, share it for cross-context behavioral advertising, or use sensitive personal information to infer characteristics. As a result, we do not offer a separate right-to-limit link. If these practices change, we will update this notice and provide required choices, including honoring applicable opt-out preference signals such as Global Privacy Control.

Subject to applicability and exceptions, California residents may request to know, access, correct, or delete personal information and may receive information about categories of collection, sources, purposes, and disclosures. Requests may be sent to support@invoicereconcile.com. InvoiceReconcile operates exclusively online and uses this email address as its request method. We will verify requests as required and will not discriminate for exercising CCPA rights.

11. Cookies and analytics choices

We use cookies and similar technologies that are necessary to sign users in, protect sessions, remember settings, and operate the Service. We may also use limited analytics technologies to understand website traffic and product usage. Analytics events must not contain invoice amounts, customer names, payment references, bank descriptions, or other Customer Content.

Optional website and product-usage analytics providers do not start until you choose Accept analytics. The analytics notice provides equally accessible accept and reject choices. You can revisit your decision at any time through the Privacy choices control. Browser settings may also block or delete storage, but blocking necessary cookies can prevent sign-in or other features from working.

Rejecting optional analytics does not disable records that are necessary to provide and secure the Service. We still record limited account creation, authentication, billing state, saved reconciliation completion, workspace actions, and audit decisions where needed to perform the contract, enforce plan limits, preserve financial workflow history, prevent abuse, or meet legal obligations. These operational records are not used for cross-context advertising and exclude bank memos, payer names, payment references, and invoice values from growth reporting.

Because we do not sell personal information or share it for cross-context behavioral advertising, an opt-out preference signal does not change those practices. We will treat recognized signals as required if our practices change.

12. Communications

We send transactional messages needed to operate your account, such as verification, password reset, billing, security, and subscription notices. You can disable background-import ready and failed emails in Settings; in-app progress and notifications remain available. You may not be able to opt out of other messages that are necessary to provide the Service.

You may opt out of optional product updates and summary emails by using the unsubscribe link or account settings. We may still send non-promotional messages about your account or a request you made.

13. Children

The Service is intended for business users age 18 and older. It is not directed to children, and we do not knowingly collect personal information directly from children under 13. If you believe a child submitted personal information to us, contact support@invoicereconcile.com so we can investigate and delete it where appropriate.

14. Changes to this policy

We may update this policy as the Service, law, or our practices change. We will post the updated policy and revise the effective date. If a change materially affects how we use personal information, we will provide additional notice or seek consent when required by law.

15. Contact us

The controller for account and website information is ND SOFT LLC, at 2942 E 24th St Tucson AZ 85713. Contact us about privacy questions or requests at support@invoicereconcile.com.