Recoup Technologies, Inc. (“RecoupAR,” “we,” “us”) builds accounts-receivable tooling for accounting and bookkeeping firms and their clients. This policy explains what data we collect through our product and partner program, why we collect it, and what we do — and don't do — with it. We wrote it in plain language on purpose. If anything here is unclear, email us at hello@recoupar.com and we'll clarify or fix it.
When a firm or a business connects a QuickBooks Online or Xero account, we request read-only OAuth access scoped to invoices, customer contact details, and payment status. We do not request, and cannot obtain through this connection, the ability to create, edit, or delete anything in that ledger.
Data is encrypted with AES-256 at rest and TLS 1.2+ in transit. Each connected client's data is isolated at the row level in our database — one client's records are never queryable from another client's session, including across a partner firm's own team access.
Data connected under a partner firm's account is visible to that firm's authorized users and to RecoupAR staff who need it to operate or support the product. We do not sell customer or client data, and we do not share it with third parties for marketing purposes.
We are early — RecoupAR is not yet SOC 2 certified. We follow the security practices described above today, and a formal audit is on our roadmap as we bring on our first cohort of partner firms. We'll update this page and notify partners directly when that changes.
Any connected client can be disconnected instantly from the partner dashboard. Once disconnected, cached data for that client is purged from our systems within 30 days.
As the product and our practices evolve, we'll update this page and note the new effective date at the top.
Questions about this policy or your data: hello@recoupar.com.