Privacy Policy

Last Updated: October 14, 2025

Effective Date: October 14, 2025

Important Notice: This Privacy Policy applies to all users of TiCloud Receipt Management System ("TiCloud", "we", "us", or "our") worldwide. It is designed to comply with the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), California Privacy Rights Act (CPRA), Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), Utah Consumer Privacy Act (UCPA), UK Data Protection Act 2018, Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and other applicable privacy laws.

Table of Contents

1. Introduction

Welcome to TiCloud Receipt Management System. We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, process, and protect your data when you use our mobile application, web application, and related services (collectively, the "Services").

By using TiCloud, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your personal information as described herein. If you do not agree with this Privacy Policy, please do not use our Services.

2. Data Controller Information

Service Name: TiCloud Receipt Management System

Legal Entity: [Your Company Legal Name]

Registration Number: [Company Registration Number]

Registered Address: [Complete Business Address]

Email: privacy@ticloud.app

Data Protection Officer: dpo@ticloud.app

For EU/EEA residents, we act as the Data Controller for your personal information. For California residents, we are a Business under CCPA/CPRA.

3. Information We Collect

3.1 Information You Provide Directly

3.2 Information Collected Automatically

3.3 Information from Third Parties

4. How We Use Your Information

We process your personal information for the following purposes:

4.1 Service Provision

4.2 Service Improvement

4.3 Communication

4.4 Security and Fraud Prevention

4.5 Legal Compliance

5. AI Model Training and Data Analytics

Important Disclosure: Your receipt data may be used to train and improve our AI models. This section explains how we process your data for AI training purposes.

5.1 Purpose of AI Training

We use receipt data to:

5.2 Pseudoanonymization Process

Before any data is used for AI training, we apply strict pseudoanonymization:

5.3 Third-Party AI Services

We currently use the following AI services:

5.4 Your Control Over AI Training

You can opt out of AI training:

5.5 AI Training Data Retention

6. Commercial Use and Metadata Sales

Metadata Commercialization: We may sell aggregated, anonymized metadata derived from receipt data for commercial purposes. This section explains our commercial data practices.

6.1 Types of Metadata We May Sell

Aggregate, anonymized insights only (never individual data):

6.2 What We Never Sell

We do NOT sell:

6.3 Aggregation and Anonymization Standards

Before any metadata is sold, we ensure:

6.4 Opt-Out of Commercial Data Use

You have the right to opt out:

6.5 Metadata Purchasers

We may provide anonymized metadata to:

All purchasers must sign agreements prohibiting re-identification attempts and ensuring compliance with applicable privacy laws.

8. Data Sharing and Third Parties

8.1 Service Providers

We share personal information with third-party service providers who perform services on our behalf:

All service providers are contractually bound to:

8.2 Merchants

When you scan a QR code at a merchant:

8.3 Legal Requirements

We may disclose personal information if required by law:

We will notify you of legal requests unless prohibited by law.

8.4 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets:

8.5 Metadata Purchasers (See Section 6)

Anonymized, aggregated metadata only - never personal information.

9. International Data Transfers

TiCloud operates globally. Your data may be transferred to and processed in countries outside your country of residence, including the United States, European Union member states, and other jurisdictions.

9.1 Transfers from EU/EEA/UK

For transfers outside the EU/EEA/UK, we ensure adequate protection through:

9.2 Transfers from Canada

For Canadian users (PIPEDA compliance):

9.3 US-Based Processing

Some data processing occurs in the United States. We comply with:

9.4 Your Rights Regarding Transfers

You have the right to:

10. Data Retention

10.1 Active Accounts

10.2 Deleted Accounts

10.3 Inactive Accounts

10.4 AI Training Data (Pseudoanonymized)

11. Your Rights (All Jurisdictions)

Regardless of your location, you have the following rights:

11.1 Right to Access

11.2 Right to Rectification

11.3 Right to Erasure ("Right to be Forgotten")

11.4 Right to Restriction of Processing

11.5 Right to Data Portability

11.6 Right to Object

11.7 Right to Withdraw Consent

11.8 Right to Lodge a Complaint

11.9 How to Exercise Your Rights

Contact us at:

We will respond within:

12. Additional Rights for US Residents

12.1 California Residents (CCPA/CPRA)

You have the right to:

Categories of Personal Information Collected (CCPA):

Do Not Sell My Personal Information:

We do not "sell" personal information as traditionally understood. However, sharing anonymized metadata may be considered a "sale" under broad CCPA definitions. To opt-out: donotsell@ticloud.app

Shine the Light Law (California Civil Code § 1798.83): California residents may request information about disclosure of personal information to third parties for direct marketing purposes. Contact: cashine@ticloud.app

12.2 Virginia (VCDPA)

Virginia residents have rights similar to CCPA, including:

12.3 Colorado (CPA)

Colorado residents have the right to:

12.4 Connecticut (CTDPA)

Connecticut residents have similar rights to Virginia and Colorado residents.

12.5 Utah (UCPA)

Utah residents have the right to:

12.6 Other US States

As additional states enact privacy laws, we will comply with their requirements and update this policy accordingly.

13. Additional Rights for Canadian Residents (PIPEDA)

Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), you have the right to:

Quebec Residents (Law 25)

For Quebec residents, additional rights under Bill 64/Law 25:

Contact for PIPEDA Requests: pipeda@ticloud.app

14. Additional Rights for UK Residents

Under the UK Data Protection Act 2018 and UK GDPR, you have rights equivalent to EU GDPR (Section 11), plus:

UK Supervisory Authority: Information Commissioner's Office (ICO)

Website: https://ico.org.uk

You have the right to lodge a complaint with the ICO.

UK Representative: [If you have UK operations, list UK representative contact]

15. Data Security

We implement industry-standard security measures to protect your personal information:

15.1 Technical Safeguards

15.2 Organizational Safeguards

15.3 Data Breach Notification

In the event of a data breach affecting personal information:

15.4 Third-Party Security

16. Children's Privacy

Age Restrictions: TiCloud is not intended for children under 16 years of age (or 13 in jurisdictions where applicable).

If you are a parent/guardian: Contact childrenprivacy@ticloud.app to request deletion of a child's data.

17. Cookies and Tracking Technologies

17.1 Types of Cookies We Use

Cookie Type Purpose Duration
Essential Cookies Authentication, session management, security Session / 30 days
Functional Cookies Remember preferences, language settings 1 year
Analytics Cookies Understand usage patterns, improve service 2 years
Security Cookies Detect fraud, prevent abuse Session / 24 hours

17.2 Mobile App Local Storage

17.3 Third-Party Tracking

17.4 Your Cookie Choices

18. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

Notice of Changes:

Version History: Previous versions available at: https://ticloud.app/privacy-history

19. Contact Information

General Privacy Inquiries

Email: privacy@ticloud.app

Response Time: Within 5 business days

Data Subject Rights Requests

Email: rights@ticloud.app

Mail: 199 rue Hélène Boucher 34710 Castelnau le Lez, France

Specific Request Types

  • Opt-Out of AI Training: ai-optout@ticloud.app
  • Opt-Out of Metadata Sales: metadata-optout@ticloud.app
  • Do Not Sell (California): donotsell@ticloud.app
  • PIPEDA Requests (Canada): pipeda@ticloud.app
  • Children's Privacy: childrenprivacy@ticloud.app
  • Data Breach Reports: security@ticloud.app

Mail Address

TiCloud Privacy Team
199 rue Hélène Boucher
34710 Castelnau le Lez
France

20. Data Protection Officer

We have appointed a Data Protection Officer (DPO) as required by GDPR Article 37:

Name: Thomas Wyskiel

Email: dpo@ticloud.app

Responsibilities:

21. Supervisory Authorities

You have the right to lodge a complaint with a supervisory authority, particularly in your country of residence, workplace, or where an alleged infringement occurred.

21.1 European Union

Find your local Data Protection Authority: https://edpb.europa.eu/about-edpb/board/members_en

21.2 United Kingdom

Information Commissioner's Office (ICO)

Website: https://ico.org.uk

Phone: 0303 123 1113

21.3 Canada

Office of the Privacy Commissioner of Canada

Website: https://www.priv.gc.ca

Phone: 1-800-282-1376

21.4 United States

Federal Trade Commission (FTC)

Website: https://www.ftc.gov

California Attorney General (CCPA/CPRA)

Website: https://oag.ca.gov/privacy

State-Specific Authorities: Contact your state Attorney General's office for privacy complaints.

Additional Legal Information

Automated Decision-Making and Profiling

We use automated processing for:

These automated processes do not produce legal effects or significantly affect you. You have the right to request human review of any automated decision.

Data Protection Impact Assessments (DPIA)

We have conducted DPIAs for:

Data Minimization

We collect only data necessary for stated purposes:

User Data Segregation

Anonymization vs. Pseudonymization

Pseudonymized Data: Data with identifiers replaced by pseudonyms; linkage table destroyed after 90 days

Anonymized Data: Aggregated data representing 100+ users, impossible to re-identify

Only truly anonymized data is sold commercially (Section 6).

Transparency and Accountability

Records of Processing Activities

We maintain comprehensive records of all processing activities as required by GDPR Article 30.

Privacy by Design and Default

Third-Party Audits

We engage independent third parties to:

Certifications and Frameworks

We strive to obtain and maintain:

Special Categories of Data

We do not intentionally collect sensitive personal information such as:

Incidental Sensitive Data on Receipts:

Receipts may inadvertently contain sensitive information (e.g., pharmacy purchases revealing health conditions). If you upload such receipts:

Biometric Data:

Your California Privacy Rights - Detailed

CCPA/CPRA Information Requirements

Personal Information Collected (Last 12 Months):

Category Examples Collected? Sold/Shared?
Identifiers Name, email, IP address, device ID Yes No
Commercial Information Receipt data, purchase history Yes Anonymized aggregate only
Biometric Information Face ID/Touch ID (device only) Device local only No
Internet Activity Usage data, interactions Yes Anonymized aggregate only
Geolocation City/region from IP Yes (approximate) Anonymized aggregate only
Visual Information Receipt photos Yes No (pseudoanonymized for AI training)
Inferences Spending patterns, preferences Yes Anonymized aggregate only
Sensitive Personal Info Precise geolocation, health data No No

Business Purposes for Collection

  1. Providing receipt management services
  2. Processing and analyzing receipts
  3. Customer support
  4. Security and fraud prevention
  5. Quality assurance and service improvement
  6. Legal compliance

Right to Limit Use of Sensitive Personal Information

If we use or disclose sensitive personal information beyond service provision, you have the right to limit such use. Contact: sensitivelimit@ticloud.app

Authorized Agent Requests

To designate an authorized agent:

Accessibility

This Privacy Policy is designed to be accessible to all users:

Request Alternative Format: accessibility@ticloud.app

Data Processing Addendum for Business Users

For merchant accounts processing customer data:

Definitions

Personal Information/Data: Any information relating to an identified or identifiable natural person.

Processing: Any operation performed on personal data, including collection, storage, use, disclosure, and deletion.

Pseudoanonymization: Processing personal data so it can no longer be attributed to a specific individual without additional information, which is kept separately.

Anonymization: Irreversibly transforming data so individuals cannot be identified, directly or indirectly.

Controller: Entity that determines purposes and means of processing personal data.

Processor: Entity that processes personal data on behalf of the Controller.

Data Subject: Individual whose personal data is processed.

Consent: Freely given, specific, informed, and unambiguous indication of agreement to processing.

Dispute Resolution

Informal Resolution

We encourage you to contact us first with any privacy concerns: privacy@ticloud.app

We will investigate and respond within 30 days.

Formal Complaints

If informal resolution fails:

Arbitration (US Users)

For US users, disputes may be subject to binding arbitration as outlined in our Terms of Service, except where prohibited by law or for CCPA/CPRA rights requests.

Consent for Specific Purposes

By using TiCloud and accepting this Privacy Policy, you specifically consent to:

  1. Receipt Image Processing: Upload and processing of receipt images using AI/OCR technology
  2. Cloud Storage: Storage of your data on cloud servers (which may be located internationally)
  3. OpenAI Processing: Transmission of receipt images to OpenAI for text extraction
  4. Pseudoanonymized AI Training: Use of your pseudoanonymized receipt data for AI model training (subject to opt-out)
  5. Anonymized Metadata Sales: Inclusion of your data in anonymized aggregate metadata sold commercially (subject to opt-out)
  6. Email Communications: Receiving service-related emails

You may withdraw consent at any time by:

Compliance Certifications

TiCloud is committed to maintaining the following compliance standards:

Questions and Concerns

If you have any questions, concerns, or complaints about this Privacy Policy or our data practices, please contact us:

Primary Contact: privacy@ticloud.app

Response Time: We aim to respond to all privacy inquiries within 5 business days

We take all privacy concerns seriously and will work diligently to address your questions and resolve any issues.


© 2025 TiCloud Receipt Management System. All rights reserved.
Home | Terms of Service | Privacy Policy | Data Processing Agreement | Contact Privacy Team