Effective date: 17 June 2026 · Last updated: 11 September 2026 · Kontroma Private Limited
Kontroma Private Limited ("we", "us", "our") operates the Reimbilly application. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use Reimbilly. We comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), India's Digital Personal Data Protection Act (DPDPA), and other applicable data protection laws.
Organisation data: company name, team memberships, roles, spending policies.
Accounting data: if your workspace connects QuickBooks or Xero, we read your chart of accounts and supplier list, and write approved expense lines. See Section 6a.
Payment information: billing address, transaction history. We do not store card numbers: card payments in India are processed by Razorpay, and subscriptions are sold through Paddle, which acts as merchant of record.
Session data: IP address, country, approximate city for security anomaly detection.
Direct messages: end-to-end encrypted. Stored as ciphertext only — we cannot read them.
Channel messages: encrypted in transit and at rest, but not end-to-end encrypted. Your workspace admins can read them, and so can we if compelled by law. Use a direct message for anything you would not put in a work channel.
2. How We Use Your Information
Provide, operate, and improve the Service;
Process payments and send billing receipts;
Send transactional and service emails (account, security, billing);
Detect and prevent fraud, abuse, and security incidents;
Comply with legal obligations (including tax and financial record-keeping);
Respond to your support requests.
We do not sell your personal data to third parties. We do not use your expense data to train AI models without your explicit consent.
3. Legal Basis for Processing (GDPR)
Contract performance: processing necessary to provide the Service you signed up for.
Legal obligation: financial record retention required by law.
Consent: marketing communications (you can withdraw at any time).
India (DPDP Act 2023): For users in India, we do not rely on "legitimate interest" — a basis the DPDP Act does not provide to private entities. We process your personal data on the basis of your consent, or, where applicable, for the limited legitimate uses and legal obligations recognised under the Act. You may withdraw consent at any time in Settings → Privacy; withdrawal is as easy as giving it.
4. Data Retention
We retain your personal data for as long as your account is active. After an account is deleted, expense data is retained according to your plan:
Free: 3 months.
Pro: 2 years.
Business / Enterprise: 5 years, or as contractually agreed.
All other personal data is purged within 30 days of account deletion, except where the law requires otherwise. Financial and transaction records are retained for 7 years to comply with applicable accounting laws (Indian Companies Act and equivalent). When you request erasure, we pseudonymise your profile data while retaining those financial records as required by law.
5. Your Rights
Depending on your jurisdiction, you have the right to:
Access the personal data we hold about you;
Portability — receive a copy of your data in a machine-readable format;
Correction of inaccurate data;
Erasure ("right to be forgotten"), subject to legal retention requirements;
Restriction of processing in certain circumstances;
Opt out of marketing communications at any time.
Nominate (India, DPDP Act 2023) — appoint another individual to exercise your rights in the event of your death or incapacity. Contact our Grievance Officer (Section 13) to register a nominee.
You can exercise these rights directly within the app (Settings → Privacy) or by writing to privacy@reimbilly.com. We will respond within 30 days.
6. Data Sharing & Sub-Processors
We do not sell your personal data. We share it only with the sub-processors below, each engaged under a data processing agreement (or equivalent contractual terms) that requires them to protect it and process it only on our instructions:
Supabase — cloud database, authentication, file storage, and serverless functions; the primary data store, hosted in the ap-south-1 (India) region;
Razorpay — payment collection and processing for Indian transactions;
Paddle — merchant of record and payment processing for subscriptions;
Vercel — hosting for our website and web app (IP address and request metadata);
Sentry — application error and crash diagnostics (may include device context and request identifiers);
Postmark — transactional email such as approvals, invitations and security alerts; it also receives bank transaction alerts you choose to forward to your Reimbilly alert address, from which we store only the transaction we extract (amount, merchant, date, and the last four digits of the card) and never the message itself;
Brevo — marketing email, only where you have opted in (name and email address);
Cloudflare — bot and abuse protection on our sign-in and sign-up forms;
OCR.space — optional receipt text extraction (the receipt image, where the cloud OCR provider is in use);
QuickBooks Online (Intuit) & Xero — accounting export, only where your workspace connects them (approved expense lines: vendor, amount, currency, date, description, category);
Google & Microsoft — optional OAuth sign-in (we receive your name, email, and profile photo only if you choose social login);
Expo, Apple Push Notification service & Firebase Cloud Messaging — delivery of push notifications (device push token only);
SMS / OTP gateway — phone-number one-time-password delivery, where that feature is enabled (phone number and OTP);
Law enforcement — only when required by a valid legal order.
We maintain a current Record of Processing Activities and review this sub-processor list periodically. Each sub-processor's own sub-processors are contractually bound to equivalent protections. We will notify you of material changes to this list per Section 11.
The authoritative, continuously updated list — including what each sub-processor receives and where it is located — is published at reimbilly.com/subprocessors. Where that page and the list above differ, that page governs.
6a. Accounting Integrations (QuickBooks and Xero)
If a workspace administrator connects an accounting system, Reimbilly exchanges data with that provider strictly to keep your books in step with your approved expenses. Connecting is optional, is initiated by your workspace, and can be undone at any time.
What we send: lines from approved expense reports only — vendor name, amount, currency, date, description, and the expense category. Nothing is sent for draft, submitted, or rejected reports.
What we read: your chart of accounts and supplier list, so each expense can be booked against the right account rather than guessed.
What we never send: receipt images, chat messages, your Reimbilly password, or any expense that has not been approved.
Authorisation: we never see your QuickBooks or Xero login. You sign in on the provider's own site and the resulting access token is stored encrypted on our servers — never on your device.
Disconnecting: using Disconnect in Reimbilly revokes our access at the provider and deletes the stored tokens. Anything already written to your accounting system stays there — it is your record, and we do not delete your books.
Data sent to QuickBooks is processed by Intuit Inc. under its own privacy policy; data sent to Xero is processed by Xero Limited under its own. Your relationship with those providers is governed by your agreement with them.
6b. How Reimbilly Uses AI
Reimbilly uses AI in one place: reading the receipts you upload. When you add a receipt, the image is passed to an optical character recognition (OCR) service that extracts the text, and we then pattern-match that text to guess the merchant, amount, date and payment reference. The current OCR provider is listed among the sub-processors above.
Every extracted field is a suggestion you can edit. Nothing is submitted or approved on the strength of an extraction alone.
No automated decisions are made about people. Expense approvals, rejections and reimbursements are decided by a human approver in your organisation, never by a model.
We do not generate synthetic content. Reimbilly does not produce AI-written text, images, audio, video or avatars for you to read or publish, so there is no AI-generated output to label.
We do not train models on your data. Your receipts and expense records are not used to train or fine-tune any model, by us or on our behalf.
You are never talking to a bot. Team chat and support replies are from people.
If we ever add a feature that generates content or interacts with you conversationally, we will say so clearly in the product and update this section before it ships.
7. International Transfers
Your data may be processed in countries outside your own. Where we transfer data from the EEA or UK, we rely on Standard Contractual Clauses approved by the European Commission to ensure adequate protection.
Categories of recipients are located in India (Supabase ap-south-1, Razorpay) and the United States (Sentry, Paddle, Google, Microsoft, Expo / Firebase Cloud Messaging). Under India's DPDP Act 2023, cross-border transfers are permitted except to jurisdictions specifically restricted by the Central Government; we monitor those notifications and adjust our processors accordingly.
8. Security
We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, role-based access control, rate limiting, geo-anomaly detection, and regular security reviews. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.
9. Children's Privacy
Reimbilly is an expense-management tool intended for working professionals and is not directed to children. Under the U.S. COPPA, we do not knowingly collect personal data from children under 13. Under India's DPDP Act 2023 — which defines a "child" as anyone under 18 — the Service is intended only for users aged 18 and over, and we do not knowingly process a child's personal data without verifiable parental or guardian consent. A self-declaration checkbox is not treated as such consent. If we become aware that we have collected a child's data without the required consent, we will delete it promptly. If you believe a child has provided us data, contact our Grievance Officer (Section 13).
10. Cookies
The mobile app does not use browser cookies. Any web interfaces may use strictly necessary cookies for authentication sessions; no tracking or advertising cookies are used without your consent.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notice at least 14 days before they take effect.
In accordance with the Digital Personal Data Protection Act 2023, you may address any question or complaint about how we handle your personal data to our Grievance Officer:
We acknowledge grievances on receipt and aim to resolve them within 30 days. You also have the right to lodge a complaint with the Data Protection Board of India.