Security & Trust

How We Protect Your Data

Last updated: July 2026

Your receipts are your business records. Here is exactly how we keep them safe — in plain language, with no fine print.

We Never Ask for Your Bank Login

RecSync works from receipt photos — not bank connections. We never ask for your online banking credentials, and we never connect to your bank account. If we do not collect it, it cannot be leaked.

Most expense apps require a live bank feed. That means your banking credentials sit with a third party. Ours don't, because we never have them.

Encryption

  • In transit: All connections use TLS 1.2 or higher. Nothing travels unencrypted.
  • At rest: Data is stored with AES-256 encryption.
  • Receipt images: Stored in private object storage. Images are not publicly accessible by URL alone.

Access Control

  • Every request is authenticated. You can only see your own data.
  • Agency accounts are scoped: an agency can only access data for clients under its own account.
  • We do not sell your data, and we do not use your receipts to train AI models.

Where Your Data Lives

RecSync runs on infrastructure operated by established providers — including Wix (Base44), Cloudflare, and Stripe — that maintain their own SOC 2 and ISO 27001 certifications and PCI DSS compliance. Data is hosted in Canada or the United States.

Payments are handled entirely by Stripe, a PCI DSS Level 1 certified processor. Your card details never touch our servers.

Is RecSync SOC 2 Certified?

Not yet — and we would rather tell you that directly than hide it.

RecSync is a bootstrapped Canadian company. A SOC 2 audit is on our roadmap as we grow. In the meantime: your data is encrypted in transit and at rest, hosted on SOC 2 and ISO 27001 certified infrastructure, we comply with PIPEDA (Canada's federal privacy law), and we never touch your bank login.

If your organization requires specific security documentation, email us at support@recsync.ai and we will answer your questionnaire directly.

Privacy Law Compliance (PIPEDA)

We operate under PIPEDA, Canada's Personal Information Protection and Electronic Documents Act. That means: we collect only what we need, you can access or delete your data at any time, and we have a designated privacy officer who responds to requests within 10 business days.

  • Export your data: One-click CSV export, anytime. Settings → Data & Privacy.
  • Delete your data: Request permanent deletion anytime. Processed within 30 days.
  • Full details: See our Privacy Policy.

Sub-Processors

We use a small number of vendors to run the service:

  • AI extraction provider — reads receipt images for OCR. Images are not retained or used for model training.
  • Stripe — payment processing (PCI DSS Level 1).
  • Cloud infrastructure — database and file storage in Canada or the US.
  • Email provider — transactional emails only.

If Something Goes Wrong

We maintain an internal breach response plan. If a security incident creates real risk of harm to your data, we will notify affected users and the Office of the Privacy Commissioner of Canada, as required by PIPEDA.

Report a Security Issue

security@recsync.ai

Found a vulnerability? Email us. We read every report and respond within 5 business days. We ask that you give us reasonable time to fix an issue before disclosing it publicly.

RecSync AI · support@recsync.ai

Questions about anything on this page? Email us. A real person answers.