PurchasomaticPurchasomatic

Privacy Policy

Effective date: June 7, 2026

1. Who We Are

Purchasomatic is a software service operated by Heather Dillon (“we,” “us,” or “our”). Purchasomatic automates vendor invoice capture, data extraction, and QuickBooks synchronization for contractors and small businesses.

If you have questions about this policy, contact us at privacy@purchasomatic.com.

2. Information We Collect

Account information

When you create an account we collect your name, email address, and company name.

Invoice and purchase order data

When vendor invoices or purchase orders are forwarded to your Purchasomatic capture address, we receive and process the email content including attachments. We extract structured data from those documents — vendor names, invoice numbers, dates, line item descriptions, quantities, and amounts — using optical character recognition (OCR) and AI-assisted extraction.

QuickBooks data

When you connect Purchasomatic to QuickBooks Online or QuickBooks Desktop, we sync and cache a subset of your QuickBooks data to enable matching and bill creation. This includes vendor names, chart of accounts, job and customer names, and payment terms. We access only the data necessary to provide the service and do not read or store your QuickBooks payroll, employee, or personal financial data.

Usage and activity data

We log actions taken within the application — invoices processed, bills published, credits used — to power the activity log, support troubleshooting, and maintain accurate credit balances.

Technical data

We collect standard web server logs including IP addresses, browser type, and pages visited for security monitoring and debugging purposes. We do not use third-party analytics tracking.

3. How We Use Your Information

  • To provide and operate the Purchasomatic service — extracting invoice data, matching to QuickBooks records, and pushing approved bills to QuickBooks
  • To send transactional notifications — processing confirmations, sync errors, and credit balance alerts
  • To maintain your account, process billing, and provide customer support
  • To improve extraction accuracy over time using anonymized document format patterns (vendor format knowledge is shared across customers to improve accuracy for all)
  • To detect and prevent fraud, abuse, or violations of our Terms of Service

We do not sell your data. We do not use your invoice or business data for advertising.

4. How We Share Your Information

We share your information only in the following circumstances:

Service providers

We use the following sub-processors to deliver the service:

  • Supabase — database and file storage (United States)
  • Vercel — application hosting (United States)
  • Anthropic — AI-powered text and document extraction (United States)
  • Resend — transactional email delivery (United States)
  • Stripe — payment processing (United States)
  • Intuit — QuickBooks API integration (United States)

Each provider is bound by data processing agreements and may not use your data for their own purposes.

Legal requirements

We may disclose your information if required by law, court order, or to protect the rights, property, or safety of Heather Dillon, our customers, or the public.

Business transfers

If Heather Dillon is acquired or merges with another entity, your information may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.

5. QuickBooks Integration and Data Access

Purchasomatic integrates with Intuit QuickBooks Online via the Intuit QuickBooks API, operating under Intuit’s developer platform terms. When you connect your QuickBooks account, you authorize Purchasomatic to read and write data on your behalf within the scopes you approve. This section describes exactly what data we access and why.

Data we read from QuickBooks

  • Vendors — vendor names, default expense accounts, and payment terms, used to match incoming invoices to the correct QuickBooks vendor record
  • Chart of accounts — expense and cost-of-goods-sold account names and IDs, used to populate the GL account selection on bill line items
  • Customers and jobs — customer and sub-customer (job) names and IDs, used to match invoices and purchase orders to the correct job for cost coding
  • Classes — class names and IDs (if class tracking is enabled in your QuickBooks company), used for bill line item classification
  • Payment terms — vendor payment terms, used to pre-populate bill due dates

Data we write to QuickBooks

  • Bills (Accounts Payable) — we create vendor bill records in QuickBooks from processed invoices, including vendor reference, line items, GL account coding, job coding, and attached PDF
  • Purchase orders — we create purchase order records in QuickBooks from captured PO confirmations
  • Bill payments — when the “Mark as Paid” feature is enabled, we create a linked bill payment record against the designated payment account
  • Vendors — with your explicit confirmation, we can create new vendor records in QuickBooks for vendors that do not yet exist
  • Customers / Jobs — with your explicit confirmation, we can create new customer or job (sub-customer) records in QuickBooks

Data we do not access

Purchasomatic does not access, read, or store your QuickBooks payroll data, employee records, banking credentials, bank transaction data, sales invoices, customer payment data, or any personal financial information beyond what is listed above. We request only the minimum OAuth scopes required to deliver the service.

How your QuickBooks data is stored

We maintain a local cache of vendor names, account names, and job names to enable fast matching without making a live API call for every action. This cached data is stored in our database and refreshed periodically from QuickBooks. Your QuickBooks OAuth access tokens are stored encrypted in our database and are never transmitted to any party other than Intuit’s API servers.

Revoking access

You can disconnect Purchasomatic from your QuickBooks account at any time from the Settings page within Purchasomatic. This immediately revokes our access token with Intuit and clears all stored credentials. You can also revoke access directly from your Intuit account at accounts.intuit.com. After disconnection, we retain cached QuickBooks reference data (vendor names, account names, job names) for up to 90 days to preserve your bill history, after which it is deleted. We do not retain any QuickBooks credentials or tokens after disconnection.

6. Data Retention

We retain your account and business data for as long as your account is active. If you close your account, we delete your personal information and business data within 90 days, except where we are required to retain it for legal or financial compliance purposes.

Invoice PDFs are stored in encrypted cloud storage and are deleted with your account or upon request. Processed invoice records (extracted data) are retained to support your activity history and audit trail.

7. Security

We protect your data using industry-standard measures including encryption in transit (TLS) and at rest, row-level security on our database, and server-side-only handling of API credentials. Access tokens for QuickBooks and other integrations are never exposed to client-side code.

Despite our efforts, no method of transmission over the internet is 100% secure. If you discover a security vulnerability, please report it to privacy@purchasomatic.com.

8. Your Rights

Depending on your location, you may have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate information
  • Request deletion of your personal information
  • Export your data in a portable format
  • Opt out of certain processing activities

To exercise any of these rights, contact us at privacy@purchasomatic.com. We will respond within 30 days.

9. Cookies

Purchasomatic uses cookies strictly for session management and security. We set an authentication cookie when you log in (required for the service to function) and short-lived cookies during the QuickBooks OAuth connection flow. We do not use tracking, advertising, or analytics cookies.

10. Children's Privacy

Purchasomatic is a business-to-business service not directed at children under 13. We do not knowingly collect personal information from children.

11. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of material changes by email or by posting a notice in the application at least 14 days before the change takes effect. Continued use of the service after that date constitutes acceptance of the updated policy.

12. Contact

For privacy questions, data requests, or concerns:

Heather Dillon

privacy@purchasomatic.com

© 2026 Heather Dillon · Terms of Service · purchasomatic.com