Privacy policy
What Reconcible collects, why, where it is kept, who else handles it, and the rights you have.
Who we are
Reconcible (“Reconcible”, “we”, “us”) works out profit for WooCommerce stores and checks it against the money that arrived. This policy covers this website, www.reconcible.com, and the app at app.reconcible.com.
Questions about this policy or your data go to support@reconcible.com.
There are two kinds of data here, and our role differs:
- Your account: your email address, your organisation and your store’s settings. We decide how this is used, as this policy describes.
- Your store’s data, including your customers’ details inside your orders. You decide what happens to it. We handle it on your behalf, only to run Reconcible for you.
What we collect
Your early access request. When you request early access on this website, the form sends us your name, your email address, your store’s web address, roughly how many orders it takes a month, how your customers pay and any note you add. Netlify, which receives the form, also records when you sent it, your IP address, your browser and the page you came from.
Your account. Your email address, which is how you sign in. Whether we’ve approved that address for early access, when, and who approved it. The name of your organisation. For each store: its name, web address, base currency and whether you reconcile to your bank. Your light or dark theme choice.
From your WooCommerce store, read-only. Orders with their lines, refunds, discounts, taxes, shipping charges and status; products, variations and their cost fields; and the store’s currency and how it stores orders. We keep each order as WooCommerce sends it. That includes your customers’ details in the order: names, email addresses, phone numbers, billing and shipping addresses, any note they left, and the IP address and browser details WooCommerce recorded at checkout. Reconcible’s figures don’t use these details, but it keeps the whole order as the record each figure is traced back to.
From the optional Reconcible Connector plugin. If you install and pair it, the plugin sends each new or changed order, in the same form as above, within a minute of the change.
From payment gateways you connect. For WooPayments, its transactions, deposits and disputes, read through your store’s connection and kept as WooPayments returns them. For PayPal, transaction records from PayPal’s reporting service; we ask for transaction information only, not payer or cart details. For Stripe, we only check that the read-only key you give us works; no Stripe data is synced yet.
Bank statements you import. We read the file and keep its lines: dates, amounts, descriptions, references and balances, and the file’s name. We don’t keep the file itself. A description can include the name of a person or business that paid you, or that you paid.
What you enter. Suppliers, purchases with their freight, duty and handling, opening stock, fixed costs such as rent, and notes you write when you resolve an item. We record which account email imported, undid or removed a purchase or changed a cost.
Connection keys. The read-only key WooCommerce sends us when you approve access, a PayPal client ID and secret, a Stripe restricted key, and the plugin’s signing keys. They are stored encrypted and are never shown back to you.
Your progress through sign-up. When you ask for a sign-in link, create an organisation, add a store or connect it, we log the step, your email address, the organisation and store, the time and, if a step failed, why. We use this to email you if you get stuck and to let the founders know a store has connected. We keep a copy of each email we send you.
Security. To limit sign-in requests, we keep a one-way scrambled form (a hash) of your IP address and of your email address for up to 24 hours. We don’t store your IP address in our database.
This website. www.reconcible.com has one form, the early access request above, and sets no cookies. We count visits with Cloudflare Web Analytics, which is cookieless: it records the page, the referring site, the browser and the country from each page request, without identifying you or following you across other sites.
How we use it
- To answer your early access request: to decide whether Reconcible fits your store yet, to reply to you, and to set your store up with you if it does.
- To run Reconcible for you: sync your store, work out profit, margin and cost of goods, and reconcile orders, gateway transactions, payouts and, if you import statements, bank deposits.
- To sign you in. We email a link that works once and expires after 15 minutes. There are no passwords.
- To help you get set up: an email if a step doesn’t finish, a welcome when your first sync finishes, and an email if the first sync fails. You can unsubscribe from these at any time.
- To keep Reconcible working and safe: finding and fixing errors, limiting abuse, and helping you when you ask.
We don’t sell your data or your customers’ data, we don’t use either for advertising, and we don’t use them to train AI models. Reconcible uses no AI model today. The morning brief and Rico, its question-answering assistant, aren’t built yet; we will update this policy before they launch.
Where the law asks for a legal basis, ours are: providing the service you signed up for, and answering the early access request you sent us before you do; our legitimate interest in keeping it secure and helping you finish setting up; and your consent, where we need it.
Emails, and unsubscribing
Sign-in links come from login@mail.reconcible.com. Setup emails come from hello@reconcible.com. Every setup email has an unsubscribe link, and your email app’s own unsubscribe button works too. You don’t need to sign in to unsubscribe.
Unsubscribing stops the follow-up, welcome and first-sync emails to that address. Sign-in links still arrive whenever you ask for one, because that is how you sign in.
Who else handles it
We use a few service providers to run Reconcible. Each handles data only to provide its service to us.
| Provider | What it does for us | Where |
|---|---|---|
| Railway | Runs the app, its background jobs and its job queue | United States (Virginia) |
| Neon | The database that stores your data | United States (Ohio) |
| Resend | Sends sign-in and setup emails | United States |
| Sentry | Error reports when something in the app fails, with technical details of the request | United States |
| Google Workspace | Our own email, including support@ and hello@, the founders’ alerts about new sign-ups, and a copy of each early access request | United States and Google’s other locations |
| Netlify | Hosts this website; its servers see each visitor’s IP address to deliver the pages. Receives and stores early access requests, and checks each one for spam with Akismet, a service of Automattic | Global network for the pages; requests stored in the United States |
| Cloudflare | Cookieless visit counts for this website | Global network |
WooCommerce, WooPayments, PayPal and Stripe aren’t our service providers: they are services you run and connect, under their own terms and privacy policies.
Where it is stored
Your data is stored in the United States: the database in Ohio and the app that reads it in Virginia. Early access requests are stored by Netlify, also in the United States. If you are outside the United States, using Reconcible means your data, and your store’s customer data, is transferred there.
How long we keep it
- Early access requests are deleted from Netlify and from our inbox 6 months after we reply to them. If you join, the details we need to set your store up become part of your account.
- While your account is open, we keep your data. Nothing is deleted automatically. If you stop after early access, your data is locked but kept, as the pricing page says, unless you ask us to delete it.
- When you ask us to delete it, we delete your account, organisation and store data, including your customers’ details, within 30 days, and tell you when it’s done. Copies in our database provider’s backups are removed as those backups expire.
- When you disconnect a store or a gateway, we delete its stored key at once. Data already synced stays until you ask us to delete it. Delete Reconcible’s key in WooCommerce too, under WooCommerce → Settings → Advanced → REST API.
- Sign-in links expire after 15 minutes, and the scrambled sign-in limits after at most 24 hours.
- Your sign-up log and copies of our emails to you are kept with your account and deleted with it.
How we protect it
- Reconcible asks for read-only access to your store. It never writes to your store, and never changes an order, a product or a payment.
- Connection keys are encrypted with AES-256-GCM, using a key derived for your organisation and for each key separately, and are never shown back to you.
- Everything travels over HTTPS. Orders sent by the plugin are signed and checked, and Reconcible refuses orders sent from any other site.
- You sign in with a single-use link, so there’s no password to leak.
Your rights
You can ask us to:
- give you a copy of the personal data we hold about you;
- correct anything that is wrong;
- delete your account and your data;
- send you your data in a machine-readable format (CSV or JSON);
- stop or limit how we use your data, or object to a use.
Email support@reconcible.com from your account’s email address. We reply within 30 days. For now these requests are handled by a person, not a button in the app. You can also complain to the data protection authority where you live.
If one of your store’s customers asks you about their data, we will help you answer. If they write to us directly, we pass the request to you, because the data is yours to decide about.
Cookies
This website sets no cookies, so there is no cookie banner.
The app at app.reconcible.com uses cookies only to work: one keeps you signed in, one protects sign-in against forged requests, one remembers where to take you after you sign in, and one remembers whether you collapsed the sidebar. None is used for advertising or tracking.
Children
Reconcible is for businesses. It isn’t meant for anyone under 18, and we don’t knowingly collect data about children.
Changes to this policy
When we change this policy, we change the date at the top. If a change matters to how your data is used, we email each organisation’s owner before it takes effect.