PRIVACY POLICY

This Privacy Policy explains how Email Receipts (“emailreceipts.io,” “we,” “us,” or “our”) collects, uses, shares, and protects personal information when you access or use our website and services that automate payment receipt processing and order workflows by analyzing transaction confirmations that you forward to your unique @emrcpts.com email address. By using our services, you agree to this Policy.

Email Receipts is owned and operated by The African Boss LLC, incorporated in Texas, USA. References to “emailreceipts.io,” “we,” “us,” or “our” mean The African Boss LLC. References to “you” or “your” mean the individual or entity using the service.

Last Updated: Sep 1, 2025. For questions, contact contact@emailreceipts.io

Your continued use of the service after the Last Updated date of this Policy constitutes your acceptance of this Policy.

Scope and Roles

This Policy applies to our website, web application, APIs, and related services offered under the emailreceipts.io domain and brand. It covers information about our merchant users and, to the extent that merchant users connect mailboxes that contain customer receipts, information about those end customers that appears on payment or order confirmations.

For most processing of receipt and payment-related data, the merchant is the data controller and Email Receipts acts as a data processor or service provider, processing data on the merchant’s behalf to deliver our services. For our own account administration, billing, security, product improvement, and compliance needs, we act as an independent controller. References to “you” in this Policy include both merchants and any individual whose information is processed in connection with our services.

Information We Collect

Account and profile information includes your name, company details, billing information, email address, phone number, login credentials, and preferences you provide when you register, authenticate, or contact support.

Connected email account data includes access tokens or credentials necessary to retrieve emails, message metadata, sender and recipient information, timestamps, subject lines, message bodies, and attachments to the extent needed to detect and process payment receipts and related order confirmations. We take steps to limit processing to emails relevant to the financial accounts or receipts you want us to track.

Receipt and transaction content includes payment confirmations, order details, payer and payee names, transaction dates and times, amounts, currencies, reference or transaction IDs, shipping addresses, and any other information included in receipts or confirmations. We retain the original receipt email as a source of truth for processed transactions as described in the Data Retention section.

Derived and operational data includes information extracted by our systems and artificial intelligence from emails such as normalized merchant names, line items, totals, tax and fee details, and status of order processing or fulfillment steps triggered by a receipt.

Usage, device, and log data includes IP address, browser type, operating system, access times, pages viewed, referring pages, error logs, and similar information collected when you use our website or app. We use this to secure, operate, and improve the service.

Cookies and authentication data includes session tokens and cookies used to keep you signed in and secure your account. We set a login cookie to keep you signed in for approximately seven days unless you sign out or clear cookies.

Communications and support data includes information you send to us via email, forms, or in-app messages, including feedback and attachments.

How We Use Information

We use information to provide the service you requested, including connecting to your email, detecting payment receipts, extracting relevant details, and triggering merchant-configured actions such as confirming and processing orders.

We use information to operate, maintain, secure, and improve our services, including developing new features, training and evaluating our extraction logic, and improving accuracy and reliability.

We use information to communicate with you about your account, service updates, security alerts, and administrative messages, and to provide customer support.

We use information to comply with law, enforce our terms, prevent fraud and abuse, protect our rights, and ensure the safety and integrity of our services.

We do not use your data for third-party advertising, and we do not sell personal information.

Information Sharing and Disclosure

Service providers receive information only as necessary to provide services to us and are bound by confidentiality and data protection obligations. We rely on Amazon Web Services for hosting, storage, and email-related infrastructure, and on OpenAI’s API to process email content and extract structured receipt and transaction details. These are the only third parties we use for processing, hosting, and storage in connection with our core service as of the date of this Policy.

Legal and safety disclosures may occur when we believe disclosure is necessary to comply with law or legal process, respond to lawful requests from public authorities, enforce our terms, protect our rights, privacy, safety or property, or protect users or the public.

Business transfers may involve sharing or transferring information in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets. We will continue to protect your information consistent with this Policy and will notify you of any material changes as required by law.

We do not sell personal information, and we do not share personal information with third parties for cross-context behavioral advertising.

AI Policy

Our service uses artificial intelligence to analyze emails and receipts to extract payment and order details and to automate merchant-configured actions. We use OpenAI’s API for this purpose. We transmit only the portions of email content and related fields necessary to perform the requested extraction, and we store the resulting structured data to operate the service.

We configure OpenAI’s API so that customer content submitted via the API is not used to train OpenAI’s models. Outputs generated from AI processing are used only to provide and improve our service for you. We do not permit OpenAI to use your content for advertising or unrelated purposes.

The core functionality of Email Receipts relies on AI-based extraction. If you do not want your email content to be processed by AI, you should not connect a mailbox or use features that require email processing.

Cookie Policy

We use essential cookies and similar technologies to authenticate users, maintain sessions, and protect accounts. Our login cookie is designed to keep you signed in for approximately seven days to provide a fast and secure experience.

You can control cookies through your browser settings. Blocking essential cookies may impair the website’s functionality, including your ability to sign in and use the service. We do not use third-party advertising cookies.

Data Retention

Emails that are linked to a processed receipt are retained and not deleted so that there is an auditable source of truth for your transaction and order history. We retain the original message and relevant extracted fields for as long as your account remains active or as needed for compliance, dispute handling, and accounting purposes.

Emails and messages that are not linked to a financial account or a processed receipt are either stored temporarily until automated cleanup or are destroyed when processing determines they are not relevant.

Account records, configuration settings, logs, and support communications are retained for as long as necessary to provide the service, resolve disputes, maintain security, and comply with legal obligations. Backup copies may persist for a limited time as part of our standard disaster recovery procedures.

For full account deletion, please contact us at contact@emailreceipts.io. After verifying your identity and applicable authorization, we will delete or de-identify your personal information, subject to retention required by law or legitimate business needs such as fraud prevention and recordkeeping.

Security

We implement administrative, technical, and physical safeguards designed to protect personal information. These include encryption in transit, encryption at rest where supported, access controls based on least privilege, audit logging, and secure key and secret management. We host our services on Amazon Web Services and leverage their security capabilities and data center protections.

No method of transmission or storage is completely secure. If we become aware of a security incident that affects your personal information, we will notify you and the relevant authorities as required by applicable law.

International Data Transfers

We may process and store information in the United States and other countries where we and our service providers, including Amazon Web Services and OpenAI, operate. These locations may have data protection laws different from those in your jurisdiction. Where required, we use appropriate safeguards, such as standard contractual clauses, to protect personal data transferred internationally.

By using the service, you understand that your information may be transferred to and processed in jurisdictions with different data protection standards than your home country.

Your Rights and Choices

You can access and update certain account information directly in your account settings. You may disconnect connected email accounts at any time, which will stop new processing. Previously processed receipts and related records may be retained as described in this Policy.

Depending on your location, you may have rights to request access to your personal information, correction, deletion, restriction of processing, objection to processing, and data portability. Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing before withdrawal.

To exercise your rights, contact us at contact@emailreceipts.io. We may ask you to verify your identity and, if you are an end customer of a merchant, we may direct your request to the appropriate merchant controller. You also have the right to lodge a complaint with your local data protection authority.

California Privacy Notice

If you are a California resident, the California Consumer Privacy Act gives you the right to know what personal information we collect, use, disclose, and retain, to request deletion of personal information, to correct inaccurate information, and to receive equal service without retaliation for exercising your rights.

We collect identifiers such as names, email addresses, and account identifiers; commercial information such as transaction details included in receipts; internet or other electronic network activity information from your interactions with our site; and professional information such as company affiliation. We collect this directly from you, from your connected email accounts, and from your use of our services. We use it to provide and secure the service, support accounts, and comply with law.

We do not sell or share personal information for cross-context behavioral advertising. You may submit rights requests by contacting contact@emailreceipts.io. We will verify your request as required by law. You may designate an authorized agent to make requests on your behalf subject to verification requirements.

Children’s Privacy

Our services are intended for businesses and individuals aged 18 and over. We do not knowingly collect personal information from children under 18. If you believe a child has provided us with personal information, please contact us and we will take appropriate steps to delete such information.

Merchant Responsibilities

If you connect a mailbox that contains your customers’ information, you are responsible for ensuring you have a lawful basis and appropriate notices and permissions to allow us to process that information on your behalf. You should ensure that your own privacy notices inform your customers that you use Email Receipts to process receipts and automate order workflows and that emails linked to processed receipts may be retained as a source of truth.

Scope and Roles

This Policy applies to our website, web application, APIs, and related services offered under the emailreceipts.io domain and brand. It covers information about our merchant users and, to the extent merchant users forward receipt emails that contain end-customer details, information about those end customers included in payment or order confirmations.

We do not connect to your mailbox. Instead, you configure auto-forwarding rules with your email provider so that specific receipt emails are forwarded to your unique @emrcpts.com address. We process only the emails we receive at that address.

For most processing of receipt and payment-related data, the merchant is the data controller and Email Receipts acts as a data processor or service provider, processing data on the merchant’s behalf to deliver our services. For account administration, billing, security, product improvement, and compliance, we act as an independent controller. References to “you” include both merchants and any individual whose information is processed in connection with our services.

Information We Collect

Account and profile information includes your name, company details, billing information, email address, phone number, login credentials, and preferences you provide when you register, authenticate, or contact support.

Forwarded email data includes messages that you or your email provider forward to your @emrcpts.com address. This may include headers, sender and recipient information, timestamps, subject lines, message bodies, inline content, and attachments to the extent needed to detect and process payment receipts and related order confirmations.

Receipt and transaction content includes payment confirmations, order details, payer and payee names, transaction dates and times, amounts, currencies, reference or transaction IDs, shipping addresses, and other details present on receipts or confirmations. We retain the original receipt email as a source of truth for processed transactions as described in the Data Retention section.

Derived and operational data includes information extracted by our systems and artificial intelligence from emails such as normalized merchant names, line items, totals, taxes, fees, and the status of order processing or fulfillment steps triggered by a receipt.

Usage, device, and log data includes IP address, browser type, operating system, access times, pages viewed, referring pages, error logs, and similar information collected when you use our website or app. We use this to secure, operate, and improve the service.

Cookies and authentication data includes session tokens and cookies used to keep you signed in and secure your account. We set a login cookie to keep you signed in for approximately seven days unless you sign out or clear cookies.

Communications and support data includes information you send to us via email, forms, or in-app messages, including feedback and attachments.

How We Use Information

We use information to provide the service you requested, including receiving your forwarded emails, detecting payment receipts, extracting relevant details, and triggering merchant-configured actions such as confirming and processing orders.

We use information to operate, maintain, secure, and improve our services, including developing new features, training and evaluating our extraction logic, and improving accuracy and reliability.

We use information to communicate with you about your account, service updates, security alerts, and administrative messages, and to provide customer support.

We use information to comply with law, enforce our terms, prevent fraud and abuse, protect our rights, and ensure the safety and integrity of our services.

We do not use your data for third-party advertising, and we do not sell personal information.

Information Sharing and Disclosure

Service providers receive information only as necessary to provide services to us and are bound by confidentiality and data protection obligations. We rely on Amazon Web Services for hosting, storage, and email-related infrastructure, and on OpenAI’s API to process email content and extract structured receipt and transaction details. These are the only third parties we use for processing, hosting, and storage in connection with our core service as of the date of this Policy.

Legal and safety disclosures may occur when we believe disclosure is necessary to comply with law or legal process, respond to lawful requests from public authorities, enforce our terms, protect our rights, privacy, safety or property, or protect users or the public.

Business transfers may involve sharing or transferring information in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets. We will continue to protect your information consistent with this Policy and will notify you of any material changes as required by law.

We do not sell personal information, and we do not share personal information with third parties for cross-context behavioral advertising.

AI Policy

Our service uses artificial intelligence to analyze forwarded emails and receipts to extract payment and order details and to automate merchant-configured actions. We use OpenAI’s API for this purpose. We transmit only the portions of email content and related fields necessary to perform the requested extraction, and we store the resulting structured data to operate the service.

We configure OpenAI’s API so that customer content submitted via the API is not used to train OpenAI’s models. Outputs generated from AI processing are used only to provide and improve our service for you. We do not permit OpenAI to use your content for advertising or unrelated purposes.

The core functionality of Email Receipts relies on AI-based extraction. If you do not want your email content to be processed by AI, do not forward emails to your @emrcpts.com address and do not enable auto-forwarding rules.

Data Retention Policy

Emails that are linked to a processed receipt are retained and not deleted so that there is an auditable source of truth for your transaction and order history. We retain the original forwarded message and relevant extracted fields for as long as your account remains active or as needed for compliance, dispute handling, and accounting purposes.

Emails and messages that are not linked to a financial account or a processed receipt are either stored temporarily until automated cleanup or are destroyed when processing determines they are not relevant.

Account records, configuration settings, logs, and support communications are retained for as long as necessary to provide the service, resolve disputes, maintain security, and comply with legal obligations. Backup copies may persist for a limited time as part of our standard disaster recovery procedures.

For full account deletions, please contact us at contact@emailreceipts.io. After verifying your identity and applicable authorization, we will delete or de-identify your personal information, subject to retention required by law or legitimate business needs such as fraud prevention and recordkeeping.

Security

We implement administrative, technical, and physical safeguards designed to protect personal information. These include encryption in transit, encryption at rest where supported, access controls based on least privilege, audit logging, and secure key and secret management. We host our services on Amazon Web Services and leverage their security capabilities and data center protections.

Your unique @emrcpts.com address should be kept confidential. Only forward emails that you intend for us to process. You can modify or disable auto-forwarding rules at any time within your own email provider to stop new emails from reaching us.

No method of transmission or storage is completely secure. If we become aware of a security incident that affects your personal information, we will notify you and the relevant authorities as required by applicable law.

International Data Transfers

We may process and store information in the United States and other countries where we and our service providers, including Amazon Web Services and OpenAI, operate. These locations may have data protection laws different from those in your jurisdiction. Where required, we use appropriate safeguards, such as standard contractual clauses, to protect personal data transferred internationally.

By using the service, you understand that your information may be transferred to and processed in jurisdictions with different data protection standards than your home country.

Your Rights and Choices

You can access and update certain account information directly in your account settings. You may modify or disable email auto-forwarding at any time, which will stop new processing. Previously processed receipts and related records may be retained as described in this Policy.

Depending on your location, you may have rights to request access to your personal information, correction, deletion, restriction of processing, objection to processing, and data portability. Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing before withdrawal.

To exercise your rights, contact us at contact@emailreceipts.io. We may ask you to verify your identity and, if you are an end customer of a merchant, we may direct your request to the appropriate merchant controller. You also have the right to lodge a complaint with your local data protection authority.

California Privacy Notice

If you are a California resident, the California Consumer Privacy Act gives you the right to know what personal information we collect, use, disclose, and retain, to request deletion of personal information, to correct inaccurate information, and to receive equal service without retaliation for exercising your rights.

We collect identifiers such as names, email addresses, and account identifiers; commercial information such as transaction details included in receipts; internet or other electronic network activity information from your interactions with our site; and professional information such as company affiliation. We collect this directly from you, from emails you forward to your @emrcpts.com address, and from your use of our services. We use it to provide and secure the service, support accounts, and comply with law.

We do not sell or share personal information for cross-context behavioral advertising. You may submit rights requests by contacting contact@emailreceipts.io. We will verify your request as required by law. You may designate an authorized agent to make requests on your behalf subject to verification requirements.

Children’s Privacy

Our services are intended for businesses and individuals aged 18 and over. We do not knowingly collect personal information from children under 18. If you believe a child has provided us with personal information, please contact us and we will take appropriate steps to delete such information.

Merchant Responsibilities

If you forward emails that contain your customers’ information, you are responsible for ensuring you have a lawful basis and appropriate notices and permissions to allow us to process that information on your behalf. Your own privacy notice should inform your customers that you use Email Receipts to process receipts and automate order workflows and that emails linked to processed receipts may be retained as a source of truth.

You are responsible for configuring your email provider’s auto-forwarding rules. To minimize unnecessary data processing, forward only receipt and transaction-related emails from financial institutions or services you intend us to track. Review your rules periodically to ensure they forward only relevant emails.

Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will provide notice by posting the updated Policy on the site or by emailing you, and will update the “Last updated” date at the top of this Policy. Your continued use of the service after the Last Updated date of this Policy constitutes your acceptance of the changes.

Contact Us

If you have any questions about this Policy, You can contact us: