Privacy Policy
1. Introduction
This Privacy Policy explains how TRO Invoice Matcher collects, uses, and protects your personal information when you use our AI-powered invoice comparison platform.
Our Privacy Commitment
- Your data is never sold — we do not sell your information to third parties
- No tracking cookies — we use only essential cookies for authentication
- You own your data — export or delete your data anytime from Settings
- AI does not train on your invoices — your data stays yours
TRO Invoice Matcher ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use our invoice processing platform at tro-matcher.com (the "Service").
Built for Small and Medium Businesses: We designed our privacy practices with SMBs in mind. Unlike enterprise solutions that often require extensive data sharing across their ecosystems, TRO Matcher operates on a data-minimization principle. We collect only what is necessary to provide our Service, and you should not need a legal team to understand how we handle your data.
Quick Summary:
- We collect only data necessary to provide our Service
- Your invoice data is processed by AI and is not sold to third parties. We share data only with service providers necessary to deliver the Service as described in this Privacy Policy
- You have the ability to access, export, and request deletion of your personal data, subject to applicable legal requirements
- We comply with GDPR, CCPA, PIPEDA, and Australian Privacy Act
Please read this Privacy Policy carefully. By using the Service, you agree to the collection and use of information in accordance with this policy.
2. Data Controller
The data controller responsible for your personal data is:
TRO Matcher
Location: Georgia
Email: support@tro-matcher.com
For any privacy-related inquiries or to exercise your data rights, please contact us at support@tro-matcher.com.
3. Categories of Personal Data We Collect
We collect several types of information to provide and improve our Service.
We collect the following categories of personal data:
Your Responsibility for Uploaded Data: You represent and warrant that you have all necessary rights, consents, and authorizations to upload and process any invoices and documents through the Service, including any personal data of third parties contained therein. You agree to indemnify and hold us harmless from any claims arising from your upload of content that you do not have the right to process.
| Category | Data Types | Source |
|---|---|---|
| Account Data | Email address, name, password (hashed) | Provided by you at registration |
| Invoice Data | Uploaded invoice files, extracted text and data (vendor names, amounts, dates, line items) | Uploaded by you |
| Comparison Data | Comparison results, AI recommendations, export files | Generated from your uploaded invoices |
| Billing Data | Subscription plan, payment status (via Paddle) | Provided during subscription |
| Usage Data | Features used, timestamps, error logs | Collected automatically |
| Support Data | Chat messages, support ticket content | Provided when contacting support |
4. Purposes of Processing
We process your personal data for specific, legitimate purposes.
We process your personal data for the following purposes:
- Service Delivery: To extract data from your invoices using AI, compare invoices, and generate recommendations
- Account Management: To create and manage your account, authenticate access, and provide customer support
- Subscription Management: To process payments, manage your subscription, and send billing notifications
- Service Improvement: To analyze usage patterns and improve our AI extraction accuracy and user experience
- Communication: To send service-related emails (password resets, security alerts, subscription updates)
- Legal Compliance: To comply with applicable laws and respond to legal requests
- Security: To detect, prevent, and address technical issues and security threats
5. Legal Bases for Processing
We process your data only with a valid legal basis under GDPR.
Under GDPR Article 6, we rely on the following legal bases for processing:
| Processing Activity | Legal Basis | GDPR Article |
|---|---|---|
| Invoice extraction and comparison | Contract performance | Art. 6(1)(b) |
| Account creation and authentication | Contract performance | Art. 6(1)(b) |
| Payment processing | Contract performance | Art. 6(1)(b) |
| Service-related communications | Contract performance | Art. 6(1)(b) |
| Error monitoring and security | Legitimate interest | Art. 6(1)(f) |
| Usage analytics (aggregated) | Legitimate interest | Art. 6(1)(f) |
| Legal compliance | Legal obligation | Art. 6(1)(c) |
6. Third-Party Service Providers
We use trusted third-party services to help deliver our Service. We do not sell your data.
We share your data with the following third-party processors who help us operate our Service:
| Provider | Purpose | Data Shared | Location | Safeguards |
|---|---|---|---|---|
| Google (Gemini AI) | AI invoice data extraction | Invoice files, extracted text | United States | Google Cloud DPA, SOC 2 |
| Paddle | Payment processing | Email, billing info, user ID | UK/US | Merchant of Record (covers DPA) |
| Brevo | Transactional email | Email address, name | France (EU) | GDPR compliant, DPA |
| Supabase | File storage | Invoice files, exports | United States | Supabase DPA, SOC 2 Type II |
| Sentry | Error monitoring | Error context, user ID, email | United States | Sentry DPA |
| Telegram | Support chat (optional) | Chat messages, name | UAE/UK | End-to-end encryption |
| PostHog | Product analytics (optional) | Usage events, page views, device info (anonymized) | EU (Frankfurt) / US | PostHog DPA, SOC 2 Type II |
| Google Analytics 4 | Website analytics | Aggregated usage metrics | United States | Google DPA |
| Google Search Console | Search analytics | Website performance data | United States | Google DPA |
| Exa AI | Search analytics | Aggregated search data | United States | Exa DPA |
7. International Data Transfers
Some of our service providers are located outside the European Economic Area (EEA). When we transfer your data internationally, we ensure adequate protection through:
- Standard Contractual Clauses (SCCs): EU-approved contractual terms that provide adequate data protection
- Data Processing Agreements: Binding agreements with all processors specifying their data protection obligations
- Adequacy Decisions: Where applicable, we rely on EU adequacy decisions for specific countries
For transfers to the United States, we ensure our providers maintain appropriate certifications and implement supplementary measures as required by the Schrems II decision.
8. Data Retention
We retain your data only as long as necessary to provide our Service and comply with legal obligations.
We retain different categories of data for different periods based on legal requirements and business needs:
| Data Type | Retention Period | Basis |
|---|---|---|
| Account data | Until account deletion request; data may be retained in backups for up to 90 days | Contract performance |
| Invoice and comparison data | User-controlled (until you delete) | Contract performance |
| Email logs | 90 days | Legitimate interest (troubleshooting) |
| Support chat messages | 365 days | Legitimate interest (support continuity) |
| Export files (PDF/CSV) | 90 days | Contract performance |
| Error logs (Sentry) | 90 days | Legitimate interest (debugging) |
| Password reset tokens | 1 hour | Security |
| Email verification tokens | 24 hours | Security |
| Refresh tokens | 30 days | Security/Contract |
9. Your Privacy Rights
You have comprehensive rights over your personal data under GDPR and other privacy laws.
Depending on your location, you may have the following rights regarding your personal data:
- Right of Access (Art. 15): Request a copy of your personal data
- Right to Rectification (Art. 16): Correct inaccurate personal data
- Right to Erasure (Art. 17): Request deletion of your personal data ("right to be forgotten")
- Right to Restriction (Art. 18): Limit how we process your data
- Right to Data Portability (Art. 20): Receive your data in a machine-readable format
- Right to Object (Art. 21): Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
How to Exercise Your Rights: You can exercise most rights directly through your account settings. For data export or deletion, go to Settings > Privacy. For other requests, email support@tro-matcher.com. We aim to respond within 30 days. For complex requests or high volumes of requests, we may extend this period by up to 60 additional days as permitted by applicable law, in which case we will inform you of the extension and the reasons for the delay.
Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated.
11. AI Processing and Automated Decision-Making
We use AI to extract data from invoices. This section explains how it works and your rights.
Our Service uses Google Gemini AI to extract structured data from invoice images and documents. Here's what you need to know:
- What AI Does: When you upload an invoice, AI extracts text, identifies vendor names, amounts, dates, and line items, and structures this data for comparison
- No Profiling: We do not use your data to profile you or make automated decisions that affect you legally
- Human Review Available: You can always review, edit, or delete extracted data before using it
- No Training: Your invoice data is not used to train our AI models or Google's models
- Accuracy Disclaimer: AI extraction is provided as a convenience and may contain errors. You are solely responsible for verifying the accuracy of all extracted data before relying on it for any purpose. We make no representations or warranties regarding the accuracy, completeness, or reliability of AI-extracted data.
GDPR Article 22: Our AI processing does not constitute automated individual decision-making under Art. 22 because the extracted data is always subject to your review and does not produce legal effects on you.
Your Rights Under GDPR Article 22:
- Review all AI-extracted data before using it
- Modify or correct any extracted information
- Request manual processing by contacting support@tro-matcher.com
- Obtain human intervention for concerns about AI output
To request human review, email support@tro-matcher.com with "Human Review Request" in the subject line. Response within 30 days.
12. Security Measures
We employ commercially reasonable safeguards designed to protect your data.
We employ commercially reasonable administrative, technical, and physical safeguards designed to protect your personal data. The following describes our current security practices, which may be updated from time to time to address evolving security threats:
| Measure | Details |
|---|---|
| Encryption at Rest | Industry-standard encryption for all stored data |
| Encryption in Transit | Secure HTTPS connections for all data transmission |
| Password Security | Secure one-way hashing with password history protection |
| Authentication | Secure token-based authentication with automatic expiration |
| Brute Force Protection | Account lockout after multiple failed login attempts |
| File Security | Time-limited secure URLs with file size restrictions |
| Access Controls | Role-based access with principle of least privilege |
| Monitoring | Real-time error tracking and security event logging |
13. Children's Privacy
Our Service is not intended for users under the age of 13 (or 16 in the EEA). We do not knowingly collect personal data from children.
If you are a parent or guardian and believe your child has provided us with personal data, please contact us at support@tro-matcher.com. If we become aware that we have collected personal data from a child without parental consent, we will take steps to delete that information.
14. California Privacy Rights (CCPA/CPRA)
Additional rights for California residents under the California Consumer Privacy Act.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: Request information about what personal data we collect, use, and share
- Right to Delete: Request deletion of your personal data
- Right to Correct: Request correction of inaccurate personal data
- Right to Opt-Out: Opt out of the sale or sharing of personal data
- Right to Non-Discrimination: Not be discriminated against for exercising your rights
We Do Not Sell Your Data: We do not sell your personal information to third parties as defined by CCPA. We do not share your data for cross-context behavioral advertising.
To exercise your California rights, email support@tro-matcher.com with subject "CCPA Request" or use the in-app privacy controls.
15. Information for UK Users
If you are located in the United Kingdom, you are protected by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Your rights under UK GDPR are substantially similar to those under EU GDPR as described in Section 9. You have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF
Website: ico.org.uk
16. Information for Canadian Users (PIPEDA)
If you are located in Canada, your personal information is protected under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws.
Under PIPEDA, you have the right to:
- Access your personal information held by us
- Challenge the accuracy and completeness of your information
- Request correction of inaccurate information
- Know how your information is being used
- Withdraw consent (subject to legal or contractual restrictions)
You may file a complaint with the Office of the Privacy Commissioner of Canada if you believe your privacy rights have been violated.
17. Information for Australian Users
If you are located in Australia, your personal information is protected under the Privacy Act 1988 and the Australian Privacy Principles (APPs).
Under Australian privacy law, you have the right to:
- Know what personal information we hold about you
- Access your personal information
- Request correction of inaccurate information
- Complain about a breach of the APPs
You may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the Privacy Act:
18. Contact Us and Policy Changes
Contact Information:
For any questions about this Privacy Policy or to exercise your privacy rights, please contact us:
Email: support@tro-matcher.com
Subject Line: "Privacy Inquiry" or "Data Request"
Response Time: Within 30 days (may be extended for complex requests as permitted by law)
Changes to This Policy:
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the updated policy on this page with a new "Last Updated" date
- Sending an email notification for significant changes that affect your rights
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after any changes constitutes acceptance of the updated policy.
19. Disclaimer and Limitation of Liability
SERVICE PROVIDED "AS IS": The Service and all data processing activities described in this Privacy Policy are provided on an "AS IS" and "AS AVAILABLE" basis. To the maximum extent permitted by applicable law, we disclaim all warranties, express or implied, including but not limited to implied warranties of merchantability, fitness for a particular purpose, and non-infringement.
NO GUARANTEE OF SECURITY: While we implement commercially reasonable security measures as described in Section 12, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee the absolute security of your data and make no warranty, express or implied, regarding the security of data transmitted to or from the Service.
LIMITATION OF LIABILITY: To the maximum extent permitted by applicable law, we shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including but not limited to loss of profits, data, use, or goodwill, arising out of or related to any data breach, unauthorized access, or failure of security measures, regardless of the theory of liability. Our total liability for any claims arising under this Privacy Policy shall not exceed the greater of (a) the amount you paid to us in the twelve (12) months preceding the claim, or (b) fifty US dollars ($50).
THIRD-PARTY SERVICES: Our Service relies on third-party providers as described in Section 6. We are not responsible for the acts or omissions of these third parties, including any security incidents, service disruptions, or changes to their data practices. Your use of the Service constitutes acknowledgment of these dependencies.
JURISDICTIONAL LIMITATIONS: Some jurisdictions do not allow the exclusion of certain warranties or the limitation of liability for certain damages. In such jurisdictions, our liability shall be limited to the maximum extent permitted by law. Nothing in this Privacy Policy excludes or limits our liability for death or personal injury caused by our negligence, fraud, or fraudulent misrepresentation, or any other liability that cannot be excluded by law.
20. Governing Law and Dispute Resolution
This Privacy Policy shall be governed by and construed in accordance with the laws of Georgia, without regard to its conflict of law provisions, except where mandatory local data protection laws apply (such as GDPR for EU residents or CCPA for California residents).
Any disputes arising from or relating to this Privacy Policy shall be resolved through good-faith negotiation. If negotiation fails, disputes shall be submitted to the competent courts of Georgia, except where applicable law grants you the right to bring proceedings in your local courts.
Nothing in this section shall limit your right to lodge a complaint with your local data protection supervisory authority.