This Privacy Policy explains how the receipt.garden service ("we", "us", "our") collects, uses, and protects your information when you use our receipt scanning and expense tracking service (the "Service").
[LEGAL ENTITY NAME], [legal form, e.g. sole trader / Lda], registered address: [REGISTERED ADDRESS], [tax/registration number if applicable]. You can reach us at support@receipt.garden.
[Note: replace the bracketed details above with your actual registered business name, address, and registration number before publishing.]
Account information: email address, and optionally a Telegram ID, when you register.
Uploaded content: photos of receipts and invoices, and the data we extract from them (amount, date, vendor, category, and similar fields).
Usage data: basic technical information such as log-in times and device/browser type, used for security and troubleshooting.
For users in the EU/EEA and UK, we rely on the following legal bases (GDPR Article 6) for each purpose:
We do not use your uploaded content to train or improve any AI model. Receipt data extraction runs on infrastructure we operate ourselves, not on a third-party AI service — see Section 4.
By default, we delete the original photo of a receipt once we have finished extracting its data — we keep the extracted information (amount, date, vendor, category, line items), not the image itself.
If you would like us to keep a copy of the original photo instead — for example, so you have it on hand if a tax authority asks for supporting documentation — you can turn this on in your profile settings (or at signup). This is off by default. If you turn it on, the original photo is retained under the same conditions as your other account data (Section 5) until you delete it, delete your account, or turn the setting back off.
Whether or not you choose to keep original photos with us, you remain responsible for retaining any documents required by your local tax or accounting rules — see also Section 9 of our Terms of Service.
Some receipts can incidentally reveal sensitive information — for example, a pharmacy receipt may reveal something about your health, or a donation receipt may reveal a religious or political affiliation. Under GDPR this is called "special category data," and it requires a stronger legal basis than ordinary personal data.
We only process this kind of information with your explicit, separate consent, given when you create your account (this consent is kept separate from your acceptance of these policies, and you can withdraw it at any time by contacting us — see Section 6). We do not analyze receipt content for the purpose of identifying such information; it is simply stored and processed as part of the normal receipt-scanning flow, to the extent it appears on a document you chose to upload.
We do not sell your personal or financial data, and we do not share it for advertising purposes. We share information only:
If you use the Service as part of a group with other people, receipts assigned to a shared group are visible to the other members and administrator of that group — see Section 5 of our Terms of Service for details.
We keep the following for as long as your account is active:
You can delete individual receipts at any time from your dashboard. When you delete your account, we delete your account data and any retained receipt photos within [30] days, except where we're required to keep certain records for longer to comply with a legal obligation.
If you are in the EU/EEA or UK, you have the following rights over your personal data:
You can exercise most of these rights directly from your dashboard. For anything else, contact us at support@receipt.garden — we will respond within one month.
We use the following measures to protect your data:
No method of storage or transmission is completely secure, so we cannot guarantee absolute security — but we do not describe this with a generic disclaimer alone, and we review these measures periodically.
In the unlikely event of a data breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours where required, and we will notify you directly without undue delay where the breach is likely to result in a high risk to your rights and freedoms.
We use a small number of strictly necessary cookies to keep the Service working: cookies that store your login (access and refresh) tokens so you stay signed in, a cookie that remembers your chosen language, and a cookie that remembers you've seen our cookie notice. We do not use cookies for advertising or third-party tracking.
If you believe we have not handled your personal data properly, you can contact us first at support@receipt.garden and we will do our best to resolve it — we aim to respond to any complaint within [14] days.
You also have the right to lodge a complaint directly with a data protection supervisory authority. If you are based in Portugal, this is the Comissão Nacional de Proteção de Dados (CNPD); if you are based elsewhere in the EU/EEA, you may also contact your own country's supervisory authority. [Confirm this is the correct lead authority once your business registration is finalized.]
The Service is not directed at individuals under 16, and we ask you to confirm you are at least 16 years old when you create an account. We do not knowingly collect personal data from children under this age; if we learn that we have, we will delete it.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Service or by email before they take effect.
Questions about this Privacy Policy or your data can be sent to support@receipt.garden.
See also our Terms of Service.