Back to Interchange

Legal Ledger

Interchange Privacy Policy

Effective date: August 2, 2026Last updated: August 2, 2026

Interchange ("we," "our," or "us") respects your privacy. This Privacy Policy explains how we collect, use, store, and protect your information when you use the Interchange mobile application (iOS and Android), our web application, and related services (collectively, the "Services").

1. Information We Collect and How We Handle It

We collect and process personal data strictly to provide automated mileage tracking, receipt management, and approval workflows. We do not sell your personal data to third parties.

A. Location Data

Data Collected: Precise GPS coordinates, start/end locations, and saved location profiles (e.g., home, office, client sites).

Handling & Control: Location data is collected only when auto-detection is enabled by you. You can turn auto-detection off at any time in the app Settings and opt to log trips manually.

B. Motion & Sensor Data

Data Collected: Accelerometer and motion coprocessor activity.

Handling & Control: Used strictly to detect when a drive begins and ends without unnecessarily draining your battery. This collection is active only when auto-detection is toggled ON (disabled by default toggle).

C. Trip Data

Data Collected: Start/end locations, distance, duration, timestamp, business purpose description, and assigned category (e.g., business, commuting, personal).

Handling & Isolation: Stored per-user in encrypted databases isolated via Row-Level Security (RLS). Trip data is visible only to you and your explicitly designated reviewers (e.g., your accountant, manager, or employer).

D. Receipt Data & Images

Data Collected: Vendor name, transaction amount, date, expense category, and receipt photo uploads.

Handling & Isolation: Stored per-user with images transmitted via secure file storage. Designated reviewers can view receipt images only for items you explicitly submit for reimbursement, review, or tax preparation.

E. Personal & Account Information

Data Collected: Full name, email address, phone number, and company name.

Handling: Used solely to manage account identity, secure sign-ins, and populate your user profile.

F. Payment Data

Data Collected: Subscription tier selection, billing plan details, and transaction history.

Handling: All payment processing is handled entirely by Stripe. Your full payment card details (credit/debit card numbers, CVVs) never touch or pass through our servers.

G. Category & Merchant Suggestions

Data Collected: Merchant names and category assignment history.

Handling: Private by default to your individual account. If you participate in community auto-categorization features, only fully anonymized and aggregated data is used.

2. Data Sharing and Third-Party Access

We keep your data strictly within the Interchange ecosystem except in the following necessary operational cases:

  • Designated Reviewers & Administrators: When you submit trips or receipts for approval or tax prep, your chosen reviewer (e.g., CPA, accountant, employer, or manager) gains read-only access to those submitted items via the Interchange Reviewer Portal. Organization administrators can access organization-level records for audit purposes.
  • Stripe (Payment Processor): Subscription billing data is transmitted directly to Stripe to process your payments safely.
  • Legal Compliance: We may disclose records if required by law or to respond to valid legal processes.

We do not sell, rent, or trade your data or user records to advertisers or data brokers.

3. Data Security Measures

We enforce rigorous administrative and technical security controls to protect your data across all stored records:

  • Authentication Required: Access to all account data requires secure authentication tokens.
  • Row-Level Security (RLS): Database records are isolated at the database level so users cannot query or access data outside their authorized permission scope.
  • Encryption: Data transmitted between the app and our backend is encrypted using TLS/HTTPS, and files/database records are encrypted at rest.

4. Your Data Control & Deletion Rights

You retain total ownership and control over your data:

  • Granular Data Deletion: You can delete individual receipts, trip logs, or specific data types at any time directly in the app without deleting your entire account.
  • Full Account Deletion: You have the right to delete your entire account and all associated historical records at any time via the in-app settings menu or by submitting a deletion request to our support team.

5. Summary for App Store Privacy Declarations

For transparency with the Apple App Store and Google Play Store Data Safety disclosures:

Data TypeCollected?Linked to Identity?Used for Tracking/Ads?Purpose
Precise LocationYesYesNoApp Functionality (Drive Tracking)
Financial InfoYes (Receipts)YesNoApp Functionality (Expense Logging)
IdentifiersYes (Name/Email)YesNoAccount Management
Sensors/MotionYesNoNoApp Functionality (Battery-Optimized Drive Detection)
User ContentYes (Photos/Notes)YesNoApp Functionality & CPA Sharing

6. Contact Us

If you have questions regarding this Privacy Policy, your data rights, or account deletion, please contact us at: contact@contorta.dev