Legal

Privacy Policy

Effective date: 27 June 2026  ·  Last updated: 27 June 2026  ·  receift.com

Your personal data is secure with us. We never sell, rent, or share your information with advertisers or data brokers — ever. Your receipt data belongs to you.

Contents

  1. Information we collect
  2. How we use it
  3. Local processing commitment
  4. Sharing & disclosure
  5. Security
  6. Data retention
  7. Your rights
  8. Children
  9. International transfers
  10. Cookies
  11. Changes
  12. Contact

1. Information we collect

Account information

When you register, we collect your name, email address, and a hashed password (plaintext passwords are never stored). We also record account creation date and your preferences.

Receipt data

When you scan or upload a receipt, we collect and store:

Important: Do not upload receipts that display a full payment card number. If one is visible, redact it before uploading. We only retain the last four digits where they appear on a receipt.

Technical data

We automatically collect IP address (for security only, not stored long-term), device type, browser version, session tokens, error logs, and aggregated/anonymised feature usage data.

What we do not collect

2. How we use your information

We use your data solely to provide and improve Receift:

We do not use your data for advertising, profiling for marketing, or any purpose beyond delivering the service described above.

3. Local processing commitment

All OCR processing runs on our own servers in the EU. Your receipt images are never sent to third-party AI providers, advertising networks, or any external service for processing.

We use PaddleOCR running on infrastructure we control. No receipt image or its contents leaves our systems except as described in Section 4 below.

4. Sharing & disclosure

We do not sell, rent, or trade your personal information. The only circumstances in which we share data are:

Infrastructure providers

We use secure cloud infrastructure for database storage and authentication. These providers act solely as data processors under our instruction and are contractually prohibited from using your data for any other purpose.

Legal requirements

We may disclose your information if required by law, court order, or governmental request. Where permitted, we will notify you before complying to allow you to seek protective relief.

Business transfers

In the event of a merger or acquisition, your data may transfer to the new entity. We will notify you at least 30 days in advance and you will have the opportunity to delete your account beforehand.

Aggregated data

We may publish aggregate statistics (e.g. total receipts processed across all users) that cannot identify any individual.

5. Security

We implement the following measures to protect your data:

MeasureDetail
Encryption in transitTLS 1.2+ for all communications
Encryption at restAll receipt images and database contents
Password storageHashed and salted — never plaintext
Access controlRow-level security; users can only access their own data
Rate limitingBrute-force protection on all authentication endpoints
Session securityAutomatic expiry and token rotation

No internet service can guarantee 100% security. You accept this inherent risk when using any online service.

6. Data retention

We retain your data for as long as your account is active. Upon account deletion:

Some data may be retained longer where required by law or to resolve disputes.

7. Your rights

Regardless of your location, you have the following rights:

RightHow to exercise
Access your dataView in the app, or email codingkansvce@gmail.com
Correct your dataEdit receipts directly in the app
Delete your dataDelete receipts in the app, or email us for full account deletion
Export your dataEmail codingkansvce@gmail.com — we respond within 30 days
Withdraw consentClose your account or email us
Object to processingEmail codingkansvce@gmail.com

8. Children

Receift is not intended for users under 18. We do not knowingly collect data from children. If you believe a child has created an account, contact codingkansvce@gmail.com and we will delete it promptly.

9. International transfers

The Service is operated from New Zealand. If you access it from outside New Zealand, your data may be processed in New Zealand or in the jurisdictions where our infrastructure providers operate. By using the Service you consent to these transfers. We take appropriate safeguards to ensure adequate protection in all jurisdictions.

10. Cookies

We use only essential cookies:

No advertising cookies, tracking pixels, or third-party analytics. Blocking essential cookies will prevent the Service from functioning.

11. Changes to this policy

We will notify you of material changes by email at least 14 days before they take effect. Continued use of the Service after that date constitutes acceptance. If you disagree, you may delete your account before the changes apply.

12. Contact & complaints

Questions or concerns? Email codingkansvce@gmail.com — we respond within 30 days.

If you are unsatisfied with our response, you may lodge a complaint with the Office of the Privacy Commissioner of New Zealand (privacy.org.nz) or with the data protection authority in your country of residence.