Security & Privacy Policy

Your Ledger Data Remains Secure and Under Your Control

At recoupAR, we prioritize B2B relationship integrity, compliance, and data protections. Here is exactly how we safeguard your financials.

Read-Only Scopes

RecoupAR only retrieves invoice metadata. We never request permission to move funds or modify accounts.

SOC 2 Type I Standard

Undergone independent compliance audit verification. Every audit log event is stored in an immutable, read-only datastore.

Zero Model Training

We strictly guarantee your customer, invoice, and contact database values are never used to train public AI models.


1. QuickBooks and Xero OAuth Scopes

When you click “Connect Ledger”, you authenticate directly with Intuit (QuickBooks) or Xero. RecoupAR requests the following specific, minimal scopes:

read:invoices

Retrieves overdue amounts, invoice dates, customer names, and contact emails to construct context drafts.

read:company_info

Verifies company configuration options to align custom SMTP setup and default currency displays.

write:payments

Writes reconciliation entries back to your ledger when a payment settles via RecoupAR, eliminating manual bookkeeping entries.

Note: We explicitly DO NOT have access to, nor will we ever request, login credentials, passwords, direct bank transfers, or invoice modification/creation capabilities.

2. Access Revocation & Purge Protocols

You maintain complete ownership of your ledger connections. If you ever choose to disconnect recoupAR:

  • You can revoke OAuth permissions with a single click directly from your QuickBooks App Settings or Xero Connected Apps directory.
  • Upon connection revocation, recoupAR instantly suspends all database syncing and outreach queue updates.
  • We enforce a strict 30-day data purge protocol. All imported metadata logs, client contact cards, and draft records are completely wiped from our databases.

3. Encryption & Infrastructure Protection

RecoupAR implements enterprise standards to ensure data remains secure:

Data in Transit

All communications between recoupAR, QuickBooks, Xero, Stripe, and your browsers are encrypted using TLS 1.3.

Data at Rest

Customer information database rows, billing data, and OAuth access tokens are encrypted using AES-256 with rotation keys.

4. Safety Controls & Manual Approvals

RecoupAR is built to safeguard your client relationships. We prevent robotic outreaches and ensure complete human oversight:

  • Strict Review Queue: recoupAR never sends notifications automatically. You must review and click “Approve” for every single message.
  • Billing Dispute Pauses: If a client flags a billing discrepancy, reminders are instantly snoozed and assigned to your support team for review.
  • Manual Veto: You can exclude or snooze specific customers, invoices, or projects with a single click.

Ready to test in a secure sandbox?

Connect in read-only mode to find your outstanding capital exposure with zero setup fees.

Start Free Trial