Privacy Policy
Last Updated: March 13, 2026
1. Introduction
RuBiWo ("we", "our", or "us") respects your privacy and is committed to protecting your personal data.
This privacy policy explains how we collect, use, and protect your information when you use our
expense management application.
2. Information We Collect
2.1 Information You Provide
- Account information (name, email address, phone number)
- Business information (business name, GST/QST numbers)
- Financial information (expense details, receipt images)
- Payment information for subscription management
2.2 Information We Collect Automatically
- Device information (device type, operating system)
- Usage data (features used, time spent in app)
- Log data (IP address, access times, errors)
2.3 Gmail Integration Data
Important: Gmail Access Scope
When you connect your Gmail account, we:
- Only access emails with attachments that may contain receipts or invoices
- Do not read your personal emails or messages
- Do not access your contacts or other Gmail data
- Use Gmail APIs in compliance with Google's Limited Use Requirements
3. How We Use Your Information
We use your information to:
- Provide and improve our expense management services
- Process and categorize your expenses automatically
- Generate CRA-compliant reports and exports
- Verify GST/QST numbers for compliance
- Send notifications about your account and expenses
- Provide customer support
- Detect and prevent fraud or unauthorized access
4. Data Security
We implement industry-standard security measures:
- All data is encrypted in transit using SSL/TLS
- All stored data is encrypted at rest
- Receipt images are stored securely on AWS S3 with encryption
- Access to your data is restricted to authorized personnel only
- We regularly audit our security practices
5. Data Sharing and Disclosure
We do not sell your personal data. We may share your information only in these limited circumstances:
- With your accountant: If you grant them access to your account
- Service providers: AWS (hosting), payment processors (Stripe/Apple/Google)
- AI services: OpenAI, Anthropic, or Google for expense categorization (anonymized)
- Legal requirements: If required by law or to protect our rights
6. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and data
- Export your data
- Revoke Gmail access at any time
- Opt-out of marketing communications
7. Data Retention
We retain your data for as long as your account is active or as needed to provide services.
For CRA compliance, we recommend retaining expense records for 7 years, but you can delete
your data at any time. Deleted data is permanently removed within 30 days.
8. Children's Privacy
Our service is not intended for children under 18. We do not knowingly collect information
from children under 18.
9. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of significant changes
via email or in-app notification.
10. Contact Us
If you have questions about this privacy policy or our data practices, please contact us:
- Email: privacy@rubiwosem.com
- Support: support@rubiwosem.com