Skip to content

Privacy policy

Last updated: October 1, 2026

This policy explains what information GenIT Expenses collects, how receipts are processed, who can see your data and the choices you have. GenIT Solutions Inc. operates GenIT Expenses. Questions or requests: Patrick@genitsolutions.us.

1. Who we are

GenIT Expenses is an expense-tracking service operated by GenIT Solutions Inc. ("we", "us"). Companies sign up to record and report their expenses; the people they invite use it with their own accounts.

For the expense data a company records, that company decides what is recorded and why, and we process it on its behalf to provide the service. For account and security information, we decide how it is handled, as described here.

Contact for anything about privacy: Patrick@genitsolutions.us.

2. Information we collect

We collect only what the service needs:

  • Account: your name, username, email address and language. Your password is never stored, only a one-way hash of it (Argon2). Two-factor settings: authenticator secrets are encrypted, backup codes and email codes are stored only as hashes.
  • Company: company name, base currency, language, time zone and settings; members, their roles and invitations; the credit balance and its history.
  • Receipts and expenses: the receipt images and PDFs you upload, the text read from them, and the expense details (merchant, date, amounts, taxes, currency, category, payment method, description), plus who created or changed them and when.
  • Security and usage: sign-in times, the IP address and browser of each session, security notices, rate-limit records that protect against password guessing, and an audit log of sign-ins and changes.

We do not collect payment card numbers, and we do not use analytics, advertising or tracking tools.

3. How receipts are processed

When you upload a receipt, we process it to read its content (merchant, date, amounts, taxes) and to clean up and organize the results. Depending on how the service is set up, this is done on our servers or by trusted third-party providers that process receipts on our behalf, using the receipt file or the text read from it. These providers may process data in other countries, under their own terms and safeguards. A receipt can contain personal information printed on it, such as a name or the last digits of a card.

A company's Managers can turn the optional AI cleanup step off in Company settings.

Exchange rates. To convert foreign currencies we ask a public exchange-rate service for the rates of a given date. Only currency codes and dates are sent, never personal information or receipt content.

4. How we use information

We use information to:

  • provide the service: store receipts, read and categorize them, convert currencies, build reports and exports, send the emails you need (invitations, verification, security notices, exports ready);
  • keep accounts and data secure: two-factor sign-in, new-device notices, limits on repeated sign-in attempts, the audit log;
  • support you when you ask for help, and meet legal obligations.

We do not sell your information, we do not use it for advertising, and we do not use your receipts to train AI models.

5. Who can see your data

  • Inside a company: Managers can see all of the company’s expenses, receipts, reports, users and audit log. Employees see only their own expenses and receipts.
  • Several companies: if your account belongs to more than one company, each company sees only its own data and your name, email and role in that company.
  • Platform administrators: our staff who run the service can see the list of companies and accounts (names, email addresses, roles, credit balances and usage) to operate it and manage credits. They do not see a company’s expenses or receipts unless they are members of that company.
  • Service providers: only as described in "Service providers" below.
  • Legal requests: we disclose information only when required by law, and only what is required.

6. Service providers

We rely on a small number of providers to run the service. Each receives only what it needs:

  • Hosting and storage: the servers that run the application and its database, and the place where receipt files are kept.
  • Email delivery: the email service that sends invitations, verification links, sign-in codes and notices (it receives the recipient's address, name and the email's content).
  • Receipt processing: third-party services that read, clean up and organize receipts (they receive the receipt file or the text read from it).
  • Exchange rates: a public rate service (currency codes and dates only).

7. Cookies

We use only cookies that are strictly necessary for the service to work. We do not use analytics, advertising or third-party tracking cookies, so there is nothing to opt out of. The cookies are:

CookiePurposeDuration
__Host-sessionKeeps you signed in. Only a hashed copy of its value is stored on our side.Up to 30 days; ends after 12 hours without activity or when you sign out
__Host-pending-loginLinks your password step to your two-factor step while you sign in.5 minutes
__Host-invite-returnBrings you back to an invitation after you sign in.30 minutes
NEXT_LOCALERemembers your language (English or French).1 year

Your browser also keeps two small preferences in its local storage (not cookies): that you have seen this cookie notice, and whether you dismissed the "install the app" prompt. They never leave your device.

8. How long we keep data

  • Expenses and receipts are kept for as long as the company keeps them. Deleted expenses can be restored for 30 days and are then permanently deleted with their receipt files.
  • Deleting a company: everyone loses access immediately; after a 30-day grace period the company’s expenses, receipts, memberships and audit log are permanently deleted. Accounts that also belong to other companies are kept.
  • Exports are available for 7 days, then deleted.
  • Sessions end after 30 days at most. Records used to limit repeated sign-in attempts are deleted after 24 hours; sign-in and verification codes expire within minutes to days.
  • The audit log is kept for as long as the company exists.
  • Backups are kept for 14 days, so deleted data may remain in backups for up to that long before disappearing.

9. How we protect data

We take reasonable technical and organizational measures to protect your information, including:

  • encrypted connections (HTTPS) between your browser and the service;
  • passwords stored only as Argon2 hashes, two-factor sign-in, and encrypted authenticator secrets;
  • database-level separation of each company’s data, and permission checks on every action;
  • receipt files that are never public and are only served to people allowed to see them;
  • an audit log, limits on repeated sign-in attempts and notices of new sign-ins.

No method of transmission over the internet or of electronic storage is completely secure. We work hard to protect your data, but we cannot guarantee its absolute security.

10. Limitation of liability

We take the protection of your data seriously, as described in this policy. However, to the fullest extent permitted by applicable law, GenIT Solutions Inc. is not liable for any unauthorized access to, or loss, disclosure, alteration or leakage of, information that results from events beyond our reasonable control, including:

  • incidents at third-party providers, such as receipt processing, email delivery, storage or hosting providers;
  • how you or your company use, share or protect accounts, passwords, devices, exports or downloaded files;
  • attacks or failures that occur despite the reasonable measures we take.

You are responsible for the content you upload, including making sure you are allowed to upload it. Nothing in this policy excludes or limits any liability that cannot be excluded or limited by law.

11. Your choices and rights

Depending on where you live, you may have the right to access, correct, export or delete your personal information, and to object to or restrict some processing. In the service:

  • you can update your name, email, language, password and two-factor settings in your profile and security settings;
  • your company’s Managers can export all of the company’s data, turn AI cleanup off, and delete the company;
  • to close your account, or for any other request, write to Patrick@genitsolutions.us. We may need to confirm your identity first. For expense data, we may refer your request to your company, which decides what it records.

You may also complain to your local data protection authority.

12. Children

GenIT Expenses is a business tool and is not intended for children. We do not knowingly collect information from anyone under 16.

13. Changes to this policy

We may update this policy as the service evolves. The date at the top shows when it last changed. If a change is significant, we will let you know in the app or by email before it takes effect.