Privacy Policy
Effective date: May 13, 2026
Fox Receipts ("Fox Receipts", "we", "us") is a product of Allpath Enterprises LLC. This Privacy Policy explains what information we collect when you use foxreceipts.com or the Fox Receipts SMS service (collectively, the "Service"), how we use it, who we share it with, and the rights you have over it.
SMS opt-in summary (TCPA/CASL): When you sign up, you explicitly consent to receive SMS messages from Fox Receipts for receipt confirmations, account verification, and service notifications. Message frequency: up to 30 messages per month. Message and data rates may apply. Reply STOP to opt out anytime; reply HELP for help. We do not sell or share your mobile phone number with third parties for marketing purposes.
1. Information we collect
Information you provide
- Account information: your email address, name, phone number, and authentication credentials (managed by our auth provider, Clerk).
- Tax & geographic context: country (US or Canada), state or province, preferred language, filing status (optional), GST/HST registration status (Canada only).
- Receipts: photographs of receipts you submit via SMS, MMS, email forwarding, or web upload, and any audit notes you provide.
- Payment information: handled and stored exclusively by Stripe, our payment processor. We never see or store your card details; we only store a Stripe-issued customer identifier and subscription status.
Information collected automatically
- Service usage data: timestamps and metadata for messages, syncs, and dashboard activity, used to operate the service.
- Device and connection data: IP address, user agent, and referrer when you visit the website (used for security, abuse prevention, and basic analytics).
2. How we use your information
- To provide the receipt-capture, categorization, and tax-pack services you signed up for.
- To send SMS confirmations, verification codes, and account-related notifications.
- To process subscription payments via Stripe.
- To sync receipts to your selected accounting platform (QuickBooks, Wave, FreshBooks, Xero, Zoho Books) when you authorize it.
- To improve service quality, including categorization accuracy. Aggregated, de-identified usage data may be used for product improvement.
- To comply with legal obligations, prevent fraud, and enforce our Terms of Service.
3. SMS messaging program (10DLC)
Fox Receipts uses a registered A2P 10DLC messaging program operated through Twilio. By verifying your phone number during signup, you agree to receive SMS and MMS from Fox Receipts. Specifically:
- Frequency: up to 30 messages per month, depending on how often you submit receipts.
- Cost: standard message and data rates from your wireless carrier may apply.
- Opt-out: reply
STOP(orUNSUBSCRIBE,CANCEL,END,QUIT,STOPALL) at any time to stop all messages. - Help: reply
HELP(orINFO,SUPPORT) for assistance, or email [email protected]. - Resubscribe: reply
STARTto opt back in after you've opted out. - Mobile carriers are not liable for delayed or undelivered messages.
We do not sell, rent, or share your mobile phone number with any third party for marketing or promotional purposes. Your phone number is used solely to deliver the Service and to verify your identity at signup.
4. How we share your information
We share information only with the service providers necessary to operate Fox Receipts:
- Stripe — payment processing
- Twilio — SMS/MMS delivery
- Clerk — authentication
- Supabase — database hosting (US-based)
- Railway — application hosting (US-based)
- Cloudflare — content delivery and DDoS protection
- Cloudflare R2 — encrypted storage of receipt images
- Anthropic — AI-based receipt parsing (text and image data sent for OCR; not retained by Anthropic for training)
- Postmark and Resend — inbound and outbound email
- QuickBooks Online, Wave, FreshBooks, Xero, Zoho Books — only when you explicitly authorize sync
- Sentry — error monitoring (PII-free; emails are hashed in logs)
We may also disclose information if required by law, in response to valid legal process, or to protect the rights, safety, or property of Fox Receipts, our users, or others.
If Fox Receipts is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
5. Data retention
- Active subscribers: data is retained for the life of your account.
- Cancelled paying subscribers: read-only dashboard access continues indefinitely ("Lifetime Archive"); receipt images are retained so you can access your records for tax purposes. You can request full deletion at any time.
- Users who never paid (e.g., abandoned signups): account and any uploaded data are deleted within 60 days.
- Logs: system logs are retained for up to 90 days for security and debugging; emails appearing in logs are SHA-256 hashed.
6. Your rights
Depending on where you live, you may have the following rights:
- Access: request a copy of the personal data we hold about you.
- Correction: request that we correct inaccurate or incomplete data.
- Deletion: request that we delete your data (GDPR Article 17, CCPA § 1798.105, PIPEDA, Quebec Law 25). We process deletion requests within 30 days.
- Portability: export your receipts and account data via CSV or ZIP download from the dashboard.
- Opt-out of SMS: reply
STOPat any time. - Quebec Law 25: residents of Quebec are asked to provide explicit consent at signup and may revoke it at any time.
To exercise any of these rights, email [email protected]. We may need to verify your identity before fulfilling certain requests.
7. Security
We use industry-standard security measures: TLS for data in transit, encryption at rest for receipt images (Cloudflare R2), AES-256 (Fernet) encryption for OAuth tokens in the database, signed-URL access for receipt photos, and bcrypt-hashed credentials via Clerk. SOC 2 Type II is in progress for Q3 2026.
No system is perfectly secure. We will notify affected users within 72 hours if we learn of a personal-data breach that creates risk to your rights or freedoms.
8. Children's privacy
Fox Receipts is intended for users 18 years of age and older. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal data from a minor, we will delete it.
9. International users
Fox Receipts is operated in the United States. If you access the Service from outside the US, you understand that your information will be transferred to, stored, and processed in the US. We rely on Standard Contractual Clauses or equivalent transfer mechanisms where required.
10. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be announced by email or in-app notice at least 30 days before they take effect. The "Effective date" at the top of this page reflects the latest version.
11. Contact
Questions about this policy? Email [email protected]. We respond to privacy and data-rights requests within 30 days.