This Privacy Policy describes how Walker Capital Management LLC ("ExCap," "we," "us," or "our") collects, uses, and shares information about you when you use the ExCap mobile-web application and related services (collectively, the "Service"). By using the Service, you agree to the collection and use of information in accordance with this Policy.
1. Information We Collect
1.1 Information You Provide Directly
- Account information. Your email address and a password hash when you create an account.
- Receipt content. The images of receipts you upload and the structured data extracted from them, including merchant name, transaction date, total, tax, line items, and the last four digits of any payment card visible on the receipt.
- Project and category labels. Names of projects you create and any edits you make to extracted data, categories, or notes.
- Card metadata. Nicknames, brand, and bank you assign to a card's last four digits in Settings. We do not collect or store full card numbers.
- Support communications. If you email us for support, we retain that correspondence.
1.2 Payment Information
Subscription payments are processed by Stripe, Inc. ("Stripe"). When you subscribe, you provide payment information directly to Stripe. We do not see, receive, or store your full credit-card number, CVC, or other sensitive payment credentials. We do receive and store an opaque Stripe customer identifier and subscription identifier so that we can recognize your subscription status and surface the Stripe billing portal to you. Stripe's use of your information is governed by Stripe's Privacy Policy.
1.3 Information Collected Automatically
- Usage data. Server logs may record IP address, device type, operating system, browser type, the pages or endpoints you accessed, and timestamps. We use this for security, fraud prevention, abuse monitoring, and to operate and improve the Service.
- Cookies and local storage. We use first-party authentication cookies set by our authentication provider so that your session persists. We do not use third-party advertising cookies.
2. How We Use Information
- To provide, maintain, and operate the Service.
- To extract structured data from receipt images and auto-categorize expenses using third-party machine-learning providers (see "Service Providers" below).
- To process subscriptions, billing, and refunds.
- To communicate with you about your account, billing, security, changes to the Service, and support.
- To detect, prevent, and respond to fraud, abuse, or violations of our Terms of Service.
- To comply with legal obligations and enforce our agreements.
3. Service Providers and Sharing
We share information with the following categories of service providers strictly to operate the Service:
- Hosting and database. Vercel Inc. (application hosting) and Supabase Inc. (authentication, database, and file storage) host the Service and your data on our behalf.
- Receipt OCR and categorization. Receipt images are transmitted to OpenAI, OpCo, LLC for the purpose of extracting structured data and proposing a tax category. OpenAI's use of this information is subject to its API data-usage terms; OpenAI does not use API content to train its models by default.
- Payments. Stripe, Inc. processes subscription payments and provides the hosted billing portal.
We do not sell your personal information. We do not share personal information with third parties for their own marketing purposes.
We may disclose information when required by law, subpoena, or to protect the rights, property, or safety of ExCap, our users, or others; in connection with a corporate transaction (merger, acquisition, financing, or sale of assets), in which case the recipient will be bound by terms substantially similar to this Policy.
4. Data Retention
We retain your account, receipt images, and extracted data for as long as your account is active. If you delete an expense, the associated receipt image is removed from our storage. If you delete your account or request deletion, we will delete or anonymize your personal information within thirty (30) days, except where retention is required by law (e.g., tax records, fraud prevention).
5. Security
We use commercially reasonable administrative, technical, and physical safeguards designed to protect your information, including encryption in transit (TLS), encryption at rest for databases and storage maintained by our service providers, role-based access controls, and per-user row-level security. No method of electronic transmission or storage is one hundred percent secure, and we cannot guarantee absolute security.
6. Your Rights and Choices
Subject to applicable law, you have the following rights:
- Access. You can view and edit your receipts, categories, projects, and cards inside the Service. You can export your data at any time as a CSV file or, on a Pro subscription, as a self-contained ZIP archive containing your CSV and every original receipt image.
- Correction. You can edit extracted receipt data, categories, projects, and card information at any time.
- Deletion. You can delete individual expenses, or email support@walkercapitalmanagement.com to request deletion of your account and all associated data.
- Portability. The CSV and Pro ZIP exports satisfy standard data-portability requirements.
7. California Residents (CCPA/CPRA)
California residents have the rights described in Section 6 above. California residents also have the right to request the categories and specific pieces of personal information we have collected, the sources of that information, the purposes for collection, and the categories of third parties with whom it has been shared, all of which are described in this Policy. We do not sell or share personal information for cross-context behavioral advertising. To exercise your rights, email support@walkercapitalmanagement.com. We will not discriminate against you for exercising your rights.
8. Residents of the EEA, UK, and Switzerland
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the right to access, correct, delete, restrict processing of, and port your personal data, and to object to certain processing. Our legal basis for processing is performance of the contract you enter into when you create an account, your consent where applicable, and our legitimate interests in operating and securing the Service. To exercise your rights, email support@walkercapitalmanagement.com. You also have the right to lodge a complaint with your local supervisory authority.
9. International Data Transfers
ExCap is operated from the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, where data-protection laws may differ from those of your jurisdiction.
10. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, email us and we will delete it.
11. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will notify you by email or through the Service before the changes take effect. Your continued use of the Service after the effective date constitutes your acceptance of the updated Policy.
12. Contact
Walker Capital Management LLC
Email: support@walkercapitalmanagement.com