LEGAL · PRIVACY POLICY

Privacy Policy

How BillRecon LLC("BillRecon", "we") handles personal data, for visitors to this site and for the MSPs who use the product. Last updated: June 26, 2026.

June 26, 2026last updated
BillRecon LLCoperator

Two roles, stated plainly

For your account and this website, we are the data controller. For the business data an MSP connects (which can include personal data about the MSP's own clients and their users), we are a processor acting on the MSP's instructions; that processing is governed by our Data Processing Addendum. If you are an employee of an MSP's client and have questions about data BillRecon processed about you, your MSP is the right first contact; we will support their requests.

What we collect

Account data. Name, email, and workspace membership, handled by our sign-in provider (Clerk).

Connection credentials. API keys, OAuth refresh tokens, and similar secrets you provide to connect your systems. These are envelope-encrypted (AES-256-GCM, with the key-encryption key held in a cloud key vault) before storage and are deleted when the connection or workspace is deleted.

Synced business data.What the connected systems return: client records, subscriptions and seat counts, billed agreement lines, product catalogs, and, where you enable those reads, per-user license assignments, sign-in recency, and device inventory records. This can include names and work email addresses of your clients' users. We read only what the connection discloses up front; each connection's exact API surface is shown in the product before you connect.

Usage data.First-party product events (for example "a workspace connected its PSA") used to improve onboarding. No third-party advertising trackers, no cross-site analytics.

Access requests. When you ask for beta access through our request form, we store what you submit (name, work email, company, and any optional details you add) along with the network address (IP) the request came from. The IP is used only to prevent abuse and to run the human-verification check (Cloudflare Turnstile). We keep these request records for up to 180 days, then delete them.

Free Drift Scan data. When you run a Free Drift Scan, the PSA credentials you connect and the billing data we sync are held in an isolated scan workspace, encrypted at rest, and hard-deleted on a 14-day timer unless you convert it into a full workspace. To prevent abuse, starting a scan also records the network address (IP) and email domain it came from; we use that only to rate-limit scans and we delete it within 14 days.

Correspondence. Emails you send us.

What we use it for

To provide and secure the service (reconciliation itself, alerts you configure, the emails the product sends such as the monthly digest and connection-expiry notices), to understand and improve onboarding, to provide support, and to meet legal obligations. We do not sell personal data, and we do not use your business data to train models or to benchmark you against other MSPs.

Sub-processors

We use a small set of infrastructure providers to run the service: hosting and compute (Vercel), the database (Neon, Postgres), authentication (Clerk), key management (Microsoft Azure Key Vault), encrypted file storage for uploads (Cloudflare R2), background-job orchestration (Inngest), transactional email (Resend), error monitoring (Sentry), bot protection on our public forms (Cloudflare Turnstile), and payments when billing is enabled (Stripe). Billing is off during the beta, so Stripe does not process any data until paid plans go live. We also relay new beta-access requests to a private Discord channel we monitor so we notice them quickly; that channel receives the contact details you submit (your name, work email, and company). The current list with purposes is maintained on /trust and in the DPA; we will update it before adding a provider that touches customer data.

Retention and deletion

Workspace data is retained while the workspace is active. Deleting a connection deletes its stored credentials; deleting a workspace hard-deletes the tenant's data, including uploaded files and secrets. In-product notifications are pruned after 90 days. Scan workspaces, once the scan opens, expire on the 14-day timer above. The append-only audit log (who did what in your workspace) is retained for the life of the workspace and deleted with it. Beta-access request records, including the submission IP, are deleted after 180 days. The Drift Scan abuse-throttle log, which records a scan's submission IP and email domain, is deleted after 14 days. On cancellation, stored connection credentials are purged immediately and the remaining workspace data is retained read-only for a 30-day grace window before permanent deletion. Deletion takes effect in the live service on this schedule; encrypted backups kept for disaster recovery can retain a copy until they age out of our backup retention window, after which it is unrecoverable, and we restore from them only to recover from an incident, not to revive deleted workspaces.

Security

Tenant isolation is enforced at the database with row-level security, secrets are envelope-encrypted, uploads are encrypted before they reach object storage, and access is least-privilege by design. The full posture, including how to report a vulnerability, is at /trust. Security contact: security@billrecon.com.

Cookies

We use the cookies needed to keep you signed in (set by Clerk) and no advertising or cross-site tracking cookies. Because we only use essential cookies, there is no cookie banner to click through.

Your rights

Depending on where you live (including under the GDPR and CCPA/CPRA), you may have rights to access, correct, export, restrict, or delete personal data we hold about you, and to object to certain processing. Email privacy@billrecon.com and we will respond within the legally required time. For data we process on an MSP's behalf, we will refer the request to that MSP. You will not be discriminated against for exercising your rights.

International transfers

The service is hosted in the United States. Where personal data subject to the EU or UK GDPR or the Swiss FADP is transferred to us, the transfer is covered by the EU Standard Contractual Clauses (with the UK International Data Transfer Addendum for UK transfers, and the FDPIC-required adjustments for Swiss transfers), incorporated through the DPA.

Children

The service is for businesses and is not directed to children. We do not knowingly collect personal data from anyone under 16.

Changes and contact

We will post changes here and, for material changes, notify workspaces by email or in-product before they take effect. Questions: privacy@billrecon.com.