Third Party Index

Snapshot 73146

Document
Privacy policy
URL
https://kvitanco.com/privacy
Fetched
HTTP status
200
Content type
text/html
Fetch mode
static
Size
19783 bytes
SHA-256 (raw)
b41a46465c8458216ec5ba17765f0c8c386d0039a4a872978362015e93317543
SHA-256 (normalized text)
8a55eaad7d3ae311cdf4bef394fda25434e7aa453a54810b1b8abe0cafd0cda6

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Kvitanco
Language
1. Operator
Bonakodo Limited operates Kvitanco and is responsible for handling personal data in the service.
Registered address: Room 22B, 22/F, Kiu Yin Commercial Building, 361-363 Lockhart Road, Wanchai, Hong Kong
Contact address in Japan: 〒150-0043 東京都渋谷区道玄坂1丁目10番8号 渋谷道玄坂東急ビル2F−C
Responsible manager: Marat Uemachi
Privacy contact: [email protected]
When a user processes documents containing information about customers, suppliers, employees, or other people, the user may be the controller of that information and Kvitanco may act as a processor following the user’s instructions.
2. Information we collect
Email address, user ID, authentication data, sessions, and passkey registration data
Receipts, invoices, and other uploaded documents, including filenames, images, PDFs, and metadata
Extracted text, supplier names, dates, amounts, tax rates, registration numbers, categories, proposed journal entries, and other recognition results
Account categories, business settings, and integration details chosen by the user
AI usage, prepaid balance, payment correlation IDs, refund IDs, and the transaction ledger
IP address, device and browser data, access times, activity records, error records, and security audit records
Support requests and communications with us
Documents may contain personal data about people other than the user, such as suppliers or employees. The user must confirm that they have authority and a lawful purpose to send that information to Kvitanco.
3. How we use information
Create accounts, verify identity, authenticate users, and prevent misuse
Store, recognise, classify, search, review, export, and share documents
Connect to accounting services selected by the user
Measure usage, manage prepaid balances, handle payments and refunds, and prepare accounting records
Handle faults, maintain quality, secure and audit the service, and establish, exercise, or defend legal rights
Meet legal duties and respond to user requests and questions
If we state another purpose when we collect information, we will also use it for that purpose. If we change a purpose in a way the person could not reasonably expect, we will give any required notice or obtain consent.
4. AI document processing
On iPhone, you only capture or select a document and review it before sending. All document processing, including text recognition, classification, and field extraction, runs on Kvitanco's servers. The iPhone does not perform AI processing. Kvitanco does not upload a document until you confirm sending it.
Kvitanco sends documents and processing instructions to the Google Gemini API to extract text, amounts, dates, tax data, and similar fields. We do not use Google Search to add search results. For images, Gemini code execution may be used to inspect small text or perform calculations.
We use the Gemini API through a paid Cloud Billing project. We try to delete each file uploaded to Google for processing as soon as processing ends, whether recognition succeeds or fails. If deletion fails, the Google Files API retains the file for no more than 48 hours. Google may keep inputs and outputs for a limited period to maintain safety and prevent abuse.
Recognition results may contain errors. Kvitanco does not use recognition results alone to make automated decisions that have legal or similarly significant effects on a person. Users must compare results with the source document before using them for tax or accounting.
5. Service providers and recipients
Kvitanco uses the following providers only as needed for the stated purposes. We list our main providers, their roles, and processing regions in the Subprocessor List. We normally give notice of a material change on that page or by email at least 30 days in advance. An urgent security change may be announced promptly after it is made.
Amazon Web Services: application hosting in the Tokyo Region, document, database, backup, and log storage, and email delivery
Google: document recognition through the Gemini API
Cloudflare: traffic proxying, DNS, attack protection, and network records
Stripe: payments and refunds. Stripe processes card numbers directly.
When a user starts an integration, Kvitanco sends documents, recognition results, and transaction data to Money Forward Cloud Accounting or freee Accounting on the user’s instruction. Those providers handle the data under their own terms and privacy policies. Disconnecting an integration does not automatically delete data already sent to the provider.
We may also disclose information when law requires it, when needed to protect a person’s life, body, or property, or as part of a business transfer.
6. Processing outside Japan
The operator is a Hong Kong company. We store primary service data in an AWS Region in Japan, but Google, Cloudflare, Stripe, and other providers may process information in Japan, the United States, or other countries where they or their subprocessors operate facilities. We supervise providers through contracts, access controls, encryption, provider reviews, and other necessary measures.
If EEA, UK, or Swiss law applies and an international transfer needs added safeguards, we will use the applicable standard contractual clauses or another valid mechanism.
7. Document sharing
Documents are private by default. Kvitanco creates non-expiring share links only for receipts included in PTA exports. Anyone with a share link can view the corresponding receipt without signing in to Kvitanco. Check the recipient, receipt, and purpose, and send the link through a secure channel.
Re-exporting the same set of receipts uses the same links; a changed set gets different links. If a document is deleted and later restored, we do not restore the previous share and create different links.
Users can revoke each share link. A link stops working if it is revoked, its document is deleted, or the account is deleted. However, this cannot delete a copy the recipient has already saved. Revoke a link at once if you suspect misuse.
8. Retention and deletion
Account information: while the service is provided or until the account closes
Deleted documents: restorable for 30 days after deletion; permanent deletion of files and related active service data starts after 30 days
Authentication sessions: no more than 400 days from creation. We may invalidate them sooner on logout or for security.
Normal application and error logs: normally three months
Database backups: normally seven days of history. Deleted non-current versions expire within 30 days.
Tamper-resistant audit logs of document operations: ten years
Payment, refund, balance, and our tax and accounting records: normally seven years from the transaction or the applicable legal start date, or longer when required by law, a dispute, or a legal hold
Support records: two years after the matter closes, or longer when needed for a dispute or required by law
Deleting a document blocks ordinary and existing share-link access at once. Restoring it within 30 days does not add it back to prior share links. After the restore deadline, Kvitanco automatically attempts permanent deletion. The periods above still apply to backup expiry, records required by law, legal holds, and tamper-resistant audit logs. Old versions under a prior S3 Object Lock setting may remain until their retention date. Kvitanco keeps them inaccessible and retries deletion when the lock permits it.
You can request account deletion in the iOS app settings. When we receive the request, we revoke all authentication at once, stop normal account use, and start deleting or de-identifying documents and personal data. We usually complete this within 30 days. We keep legally required payment, refund, balance, tax, accounting, and audit records only for the periods stated above.
9. Cookies and device storage
Kvitanco uses cookies or device storage needed for sign-in, account switching, security, and language settings. We do not use advertising tracking cookies. Disabling required cookies will prevent features such as sign-in from working.
10. Security measures
Kvitanco uses security measures that include transport encryption, storage access controls, per-user authorisation checks, separation of secrets, audit logs, backups, provider reviews, and incident procedures. For non-expiring PTA share links, we encrypt and store the share secret so the same export can be created again, and manage the decryption key separately.
No internet service can guarantee absolute security. Keep authentication methods and share links secret, and revoke links you no longer need.
11. Age and prohibited uploads
Kvitanco is for business operators and business users aged 18 or older. Do not upload an Individual Number (My Number), an image of a My Number Card, passwords, authentication secrets, or sensitive data the service does not need. If you send such data by mistake, delete the document and contact us if needed.
12. Individual rights
To the extent provided by applicable law, a person may request notice of purpose, access to retained personal data, correction, addition, deletion, suspension or erasure, a stop to third-party disclosure, objection, restriction, or data portability. Consent-based processing can be withdrawn for the future. If we cannot grant a request, including because law requires a record, we will explain why.
Send requests to [email protected]. To prevent impersonation, we require re-authentication in the account or another reasonable identity check. We aim to respond within 30 days and will explain the reason and schedule if more time is needed. For third-party information controlled by a user, contact that user first.
If our response does not resolve a concern about handling personal data in Japan, you may consult Japan’s Personal Information Protection Commission or another authority with jurisdiction.
13. Access from the EEA, UK, and similar regions
Kvitanco is for businesses in Japan. We do not market the service to people in the EEA or UK and do not aim to monitor their behaviour. We therefore have not appointed an EEA or UK representative under the service’s current scope. If someone accesses Kvitanco from one of these regions while travelling or for another temporary reason, we still accept enquiries through the contact in this policy. Before changing our target regions, we will review the applicable law and whether a representative is required.
14. Changes and contact
When we change this policy, we update the effective date on this page. We give advance notice in the service or by registered email of a change that materially affects user rights or how information is used.
Send questions about personal data, providers, security measures, or this policy to [email protected]. Do not attach documents, authentication data, or share secrets to email.