Privacy Policy
What Drystamp collects, why, who else sees it, and how to get it back or have it deleted.
Last updated 20 September 2026. Datamart Inc. is the controller of the personal data described here.
The short version: we collect what the product needs to work, we process receipts with AI to read them, we never sell your data, we never use it to train third-party models, and we never see your card number.
1. What we collect
Information you give us
- Account details — your name, email address, organisation name and a password, which is stored only as a hash and never in readable form.
- Your records — receipt images and PDFs you upload, and the expense details attached to them: vendor, date, amount, category, business purpose, attendees, business relationship, destination, mileage and similar.
- Conversations — the questions you ask the assistant and its answers, kept so a thread makes sense when you come back to it.
- Remembered context — facts about your business you tell it to remember. These are visible and editable, and you can delete them.
- Anything you send us — support email and feedback.
Information collected automatically
- Session and security data — a session cookie, sign-in times, IP address and user agent, used to keep you signed in and to rate-limit sign-in attempts.
- Operational logs — errors and request records needed to run and secure the service.
We do not use advertising trackers, and we do not run third-party analytics that profile you across other websites.
2. Why we use it, and on what basis
We process your data to provide the service you asked for (performance of a contract), to keep it secure and prevent abuse, to take payment, to reply to you, and to meet legal obligations. Where you are in a jurisdiction that requires a lawful basis, those are contract, legitimate interests and legal obligation as applicable.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
3. AI processing
To read a receipt and to answer questions, the relevant content is sent to Amazon Bedrock, which runs the models inside our AWS account in the United States. Under the AWS Bedrock terms, prompts and outputs are not stored by AWS and are not used to train the underlying models.
We do not use your content to train any model of our own.
Answers are generated with AI assistance. They can be wrong, and the product tells you when it has no source for something rather than guessing.
4. Who else processes your data
We use a small number of processors, each under a contract that limits them to acting on our instructions.
- Amazon Web Services (United States) — hosting, storage of receipt images, and AI processing through Bedrock.
- Stripe — payments, invoices and the customer portal. Your card details go to Stripe directly. We receive only the last four digits, the card brand and the status of the subscription, and we never see or store a full card number.
- Resend — transactional email such as invitations, password resets and billing notices.
We may also disclose data where we are legally required to, or to protect our rights, and to a successor if the business is sold. We will tell you before your data becomes subject to a different privacy policy.
5. Where your data is held
Drystamp runs in the United States (AWS, us-east-1). If you use it from outside the United States your data is transferred there. Where required, such transfers rely on the European Commission's Standard Contractual Clauses or an equivalent mechanism.
6. How long we keep it
- Receipt images and expense records — kept while your account is active. They are documentary evidence for a tax position, and the period in which a return can be examined runs to six years for a substantial understatement, so we do not expire them on a shorter schedule.
- After cancellation — retained for 30 days so you can reactivate or export, then deleted.
- Billing records — kept as long as tax and accounting law requires, typically seven years.
- Security logs — kept for a limited period for abuse prevention.
Deleting a record in the application also deletes its stored image.
7. Security
Passwords are hashed with Argon2. Traffic is encrypted in transit with TLS. Receipt images are stored in private, encrypted object storage that is not publicly reachable, and every request for one is authorised against the account it belongs to. Businesses inside an account are separated, and invited users only reach the businesses they were granted.
No system is perfectly secure. If a breach affects your personal data we will notify you and any regulator as the law requires.
8. Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, object to or restrict processing, receive a portable copy, and withdraw consent. California residents have rights under the CCPA and CPRA, including the right to know, to delete, to correct, and to opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of. We will not discriminate against you for exercising any right.
You can export your records yourself from the application at any time. For anything else, write to info@drystamp.com with “Privacy request” in the subject. We will respond within 30 days, and will ask you to confirm control of the account first.
9. Cookies
We use one essential cookie to keep you signed in, and short-lived browser storage for interface preferences. We do not use advertising or cross-site tracking cookies, so there is no consent banner to dismiss.
10. Children
Drystamp is a business tool and is not intended for anybody under 18. We do not knowingly collect data from children. If you believe a child has given us data, write to us and we will delete it.
11. Changes
We may update this policy. Material changes will be notified by email or in the application, and the date at the top will change.
12. Contact
Datamart Inc., California, United States. info@drystamp.com.