Last updated: 10 August 2026
Privacy Policy
Kontroma Private Limited (“Reimbilly”, “we”, “us”) is committed to protecting your personal data. This policy explains what we collect, why, and how you can control it.
1. Who we are
Kontroma Private Limited, incorporated in India (CIN placeholder), operates the Reimbilly platform at reimbilly.com and app.reimbilly.com (“the Service”). Grievance Officer: Sachin Zore — grievance@reimbilly.com.
2. Data we collect
- Account data: Name, email address, phone number (optional), profile photo.
- Expense data: Receipt images, vendor names, amounts, dates, categories, notes, GST details.
- Organisation data: Company name, team memberships, roles, spending policies.
- Usage data: App events and feature usage (via PostHog, hosted in the EU), crash reports (via Sentry), device type, OS version.
- Accounting data: If your workspace connects QuickBooks or Xero, we read your chart of accounts and supplier list, and write approved expense lines. See §5a.
- Payment data: We do not store card numbers. Payment is processed by Razorpay; we store only payment references and status.
- Chat messages: Stored as ciphertext only. We cannot read message content.
3. How we use your data
- Providing and improving the Service.
- Processing expense reports and approvals.
- Sending transactional emails (approval notifications, invitations).
- Analytics to improve features (aggregated, not sold to advertisers).
- Compliance with legal obligations.
4. Legal basis (DPDP Act 2023 / GDPR)
We process personal data on the following bases: (a) consent — for marketing; (b) contract — to provide the Service you signed up for; (c) legitimate interest — for security and fraud prevention; (d) legal obligation — for tax and regulatory purposes.
5. Data sharing
We share personal data with third parties that operate parts of the Service on our behalf — hosting, email, crash reporting, payments, and analytics. The complete, current list, including what each one receives and where it is located, is published at reimbilly.com/subprocessors and updated whenever it changes.
We do not sell your data. We do not use your data for advertising.
5a. Accounting integrations (QuickBooks and Xero)
If a workspace administrator connects an accounting system, Reimbilly exchanges data with that provider strictly to keep your books in step with your approved expenses. Connecting is optional, is initiated by your workspace, and can be undone at any time.
- What we send: lines from approved expense reports only — vendor name, amount, currency, date, description, and the expense category. Nothing is sent for draft, submitted, or rejected reports.
- What we read: your chart of accounts and supplier list, so each expense can be booked against the right account rather than guessed.
- What we never send: receipt images, chat messages, your Reimbilly password, or any expense that has not been approved.
- Authorisation: we never see your QuickBooks or Xero login. You sign in on the provider's own site and the resulting access token is stored encrypted on our servers — never on your device.
- Disconnecting: using Disconnect in Reimbilly revokes our access at the provider and deletes the stored tokens. Anything already written to your accounting system stays there — it is your record, and we do not delete your books.
Data sent to QuickBooks is processed by Intuit Inc. under its own privacy policy; data sent to Xero is processed by Xero Limited under its own. Your relationship with those providers is governed by your agreement with them.
5b. How Reimbilly uses AI
Reimbilly uses AI in one place: reading the receipts you upload. When you add a receipt, the image is passed to an optical character recognition (OCR) service that extracts the text, and we then pattern-match that text to guess the merchant, amount, date and payment reference. The current OCR provider is listed on our sub-processors page.
- Every extracted field is a suggestion you can edit. Nothing is submitted or approved on the strength of an extraction alone.
- No automated decisions are made about people. Expense approvals, rejections and reimbursements are decided by a human approver in your organisation, never by a model.
- We do not generate synthetic content. Reimbilly does not produce AI-written text, images, audio, video or avatars for you to read or publish, so there is no AI-generated output to label.
- We do not train models on your data. Your receipts and expense records are not used to train or fine-tune any model, by us or on our behalf.
- You are never talking to a bot. Team chat and support replies are from people.
If we ever add a feature that generates content or interacts with you conversationally, we will say so clearly in the product and update this section before it ships.
6. Data retention
- Free plan: 3 months of expense data after account deletion.
- Pro plan: 2 years.
- Business / Enterprise: 5 years or as contractually agreed.
- Deleted accounts: All personal data purged within 30 days, except where legally required.
7. Your rights
Under the DPDP Act 2023 and GDPR, you have the right to:
- Access and export your personal data (Settings → Data Export).
- Correct inaccurate data.
- Delete your account and data.
- Withdraw consent for marketing.
- Lodge a complaint with a supervisory authority.
To exercise your rights, email privacy@reimbilly.com.
9. Security
See our Security page for a full description of our technical and organisational measures.
10. Changes to this policy
We will notify you by email and in-app notification at least 14 days before material changes take effect. Continued use of the Service constitutes acceptance.
11. Contact
Grievance Officer: Sachin Zore
Email: grievance@reimbilly.com
Response time: Within 30 days (DPDP Act 2023 requirement).