Privacy Policy
Last updated: 10 March 2026
FreeReconcile is operated by [Your Company Name] ("we", "us", "our"), registered in England and Wales. For the purposes of UK GDPR and the Data Protection Act 2018, we are the data controller. Our registered address is [Your Registered Address].
This Privacy Policy, together with our Terms of Service, explains how we collect, use, and protect your personal data when you use FreeReconcile. By using our service, you accept the practices described here.
1.Information We Collect
1.1 Information you give us
When you register, subscribe, or contact us, you provide:
- Your name and email address
- Your company or business name
- Subscription and billing details (processed by our payment provider; we do not store card numbers)
1.2 Information from connected services
When you connect FreeReconcile to your email and FreeAgent account, we access:
- From your email: sender name, subject line, date, and PDF attachments only. We do not read or store email body content.
- From FreeAgent: bank account names (not account numbers or sort codes), unexplained bank transaction descriptions, amounts, and dates.
We import the minimum data necessary to operate the service. For example, we store your FreeAgent bank account name but never the account number or sort code.
1.3 Information from PDF processing
When we process a receipt or invoice PDF, we extract:
- Vendor name, invoice number, date
- Line items, amounts, VAT amounts
- Currency and payment terms
PDFs are sent to OpenAI for structured data extraction. We strip identifiable sensitive fields (credit card numbers, bank details) before transmission. OpenAI processes data under their API data usage policy and does not use API inputs for training.
1.4 Technical information
We automatically collect:
- IP address, browser type, and operating system
- Pages visited and features used
- Error logs for debugging
2.Lawful Basis for Processing
Under UK GDPR (Article 6), we process your data on the following bases:
- Contract (Art. 6(1)(b)): processing necessary to provide the FreeReconcile service you have signed up for, including scanning emails, matching receipts, and writing explanations to FreeAgent.
- Legitimate interest (Art. 6(1)(f)): improving the service, debugging, fraud prevention, and basic analytics. We only rely on legitimate interest where your rights do not override our interests.
- Legal obligation (Art. 6(1)(c)): retaining billing records as required by UK tax law.
- Consent (Art. 6(1)(a)): where we send you marketing communications (you can withdraw consent at any time).
3.How We Use Your Data
3.1 Providing the service
- Scanning your connected email accounts for PDF receipts and invoices
- Extracting structured data from PDFs
- Matching receipts to bank transactions in your FreeAgent account
- Suggesting VAT categories (standard rate, reverse charge, exempt, zero-rated)
- Applying matched explanations to FreeAgent when you approve them
3.2 Account and billing
- Authenticating you and managing your session
- Processing subscription payments
- Sending transactional emails (confirmations, receipts, password resets)
- Responding to support requests
3.3 Improving the service
- Analysing feature usage patterns (in aggregate, not individually identifiable)
- Debugging technical issues using error logs
- Improving matching accuracy
We will never sell or rent your personal data to anyone.
4.Data Storage and Security
4.1 Data in transit
All data transmitted between your browser and FreeReconcile, and between FreeReconcile and third-party services (FreeAgent, email providers, OpenAI), is sent over encrypted HTTPS connections.
4.2 Infrastructure
- Database and authentication: Supabase (EU data centre)
- Application hosting: Vercel (edge network)
- PDF processing: temporary storage, deleted within 7 days
4.3 Access controls
Access to production systems and customer data is restricted to authorised personnel only. API keys are stored as environment variables and are not committed to source code or logged.
4.4 Your responsibility
You are responsible for keeping your login credentials confidential. Do not share your password with anyone. Notify us immediately if you suspect unauthorised access to your account.
5.Data Retention
| Data type | Retention | Basis |
|---|---|---|
| User account and authentication | Until account is deleted | Contract |
| FreeAgent OAuth tokens | Until disconnected or account deleted | Contract |
| Email metadata (sender, subject, date) | 30 days | Legitimate interest |
| PDF attachments (temporary) | Deleted within 7 days of matching | Contract |
| Matching reports and logs | 2 years or until deleted by user | Contract |
| Server and error logs | 30 days | Legitimate interest |
| Billing and payment records | 6 years (UK tax requirements) | Legal obligation |
After you close your account or cease using FreeReconcile for 3 months, we delete your personal data unless we are legally required to retain it (e.g. billing records for UK tax purposes). De-personalised, aggregate data may be retained indefinitely.
6.Third-Party Services and Sub-Processors
We share data with the following services only as necessary to provide FreeReconcile:
| Service | Purpose | Location |
|---|---|---|
| FreeAgent | Accounting data (OAuth2) | UK |
| Google / Microsoft | Email access (OAuth2) | US / EU |
| OpenAI | PDF data extraction | US |
| Supabase | Database and authentication | EU |
| Vercel | Application hosting | Global edge |
| Resend | Transactional emails | US |
We do not sell your data to any third party. We only share the minimum data each service needs to fulfil its function.
7.International Data Transfers
Your data is primarily stored in the EU (Supabase). Where data is transferred outside the UK or EEA (for example, to OpenAI or Resend in the US), we rely on the UK International Data Transfer Agreement (IDTA) or Standard Contractual Clauses (SCCs) to ensure adequate protection under UK GDPR.
8.Cookies
8.1 What we use
We use strictly necessary cookies for authentication and session management only:
sb-access-token – session authentication
sb-refresh-token – session renewal
8.2 Analytics
We use Plausible Analytics, a privacy-friendly, cookie-free analytics tool. Plausible does not use cookies, does not collect personal data, and does not track users across sites. All data is aggregated and no individual visitor can be identified. Plausible is compliant with GDPR, PECR, and CCPA without requiring cookie consent.
8.3 What we do not use
We do not use advertising cookies, third-party tracking, Google Analytics, Meta Pixel, or similar services.
8.4 Consent
Since we only use strictly necessary cookies (as defined by the ICO) and cookie-free analytics, explicit cookie consent is not required under the Privacy and Electronic Communications Regulations 2003 (PECR). You can disable cookies in your browser settings, but authentication features will not work.
For more information about cookies, visit the ICO's guidance on cookies. For details on how Plausible handles data, see their data policy.
9.Your Rights
Under UK GDPR and the Data Protection Act 2018, you have the right to:
- Access your personal data (Subject Access Request)
- Rectify inaccurate or incomplete data
- Erase your data (right to be forgotten)
- Restrict processing in certain circumstances
- Data portability to receive your data in a machine-readable format
- Object to processing based on legitimate interest
- Withdraw consent at any time where processing is based on consent
To exercise any of these rights, email privacy@freereconcile.com. We will respond within one month. We may ask you to verify your identity before processing your request.
You also have the right to disconnect your email or FreeAgent account from FreeReconcile at any time through your account settings. Once disconnected, we can no longer access your data from those services.
10.Age Restriction
FreeReconcile is a business service and is not intended for anyone under the age of 16. We do not knowingly collect personal data from anyone under 16. If we become aware of such collection, we will delete the data and terminate the account.
11.Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on our website. The "Last updated" date at the top of this page indicates when the policy was last revised. Your continued use of FreeReconcile after any changes constitutes acceptance of the updated policy.
12.Complaints
If you believe we are processing your data unlawfully, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
13.Contact
Questions about this Privacy Policy should be addressed to: