Last updated: 11 September 2026
Privacy Policy
Kontroma Private Limited (“Reimbilly”, “we”, “us”) is committed to protecting your personal data. This policy explains what we collect, why, and how you can control it.
1. Who we are
Kontroma Private Limited, incorporated in India on 18 July 2026 (CIN U62011MH2026PTC473706), operates the Reimbilly platform at reimbilly.com and app.reimbilly.com (“the Service”). Grievance Officer: Sachin Zore — grievance@reimbilly.com.
Registered office:
Floor 7, Skyline Icon, Marol Chimatpada,
J.B. Nagar, Andheri East, Mumbai 400059,
Maharashtra, India
2. Data we collect
- Account data: Name, email address, phone number (optional), profile photo.
- Expense data: Receipt images, vendor names, amounts, dates, categories, notes, GST details.
- Organisation data: Company name, team memberships, roles, spending policies.
- Usage data: App events and feature usage (via PostHog, hosted in the EU), crash reports (via Sentry), device type, OS version.
- Accounting data: If your workspace connects QuickBooks or Xero, we read your chart of accounts and supplier list, and write approved expense lines. See §5a.
- Payment data: We do not store card numbers. Card payments in India are processed by Razorpay, and subscriptions are sold through Paddle, which acts as merchant of record; we store only payment references and status.
- Direct messages: End-to-end encrypted. Stored as ciphertext only — we cannot read them.
- Channel messages: Encrypted in transit and at rest, but not end-to-end encrypted. Your workspace admins can read them, and so can we if compelled by law. Use a direct message for anything you would not put in a work channel.
3. How we use your data
- Providing and improving the Service.
- Processing expense reports and approvals.
- Sending transactional emails (approval notifications, invitations).
- Analytics to improve features (aggregated, not sold to advertisers).
- Compliance with legal obligations.
4. Legal basis (DPDP Act 2023 / GDPR)
Under the GDPR, we process personal data on the following bases: (a) consent — for marketing; (b) contract — to provide the Service you signed up for; (c) legitimate interests — for security monitoring and fraud prevention; and (d) legal obligation — for tax and regulatory purposes.
Under India's DPDP Act 2023, we do not rely on legitimate interest. That basis is not available to private entities under the Act. For users in India we process personal data on the basis of your consent, or for the limited legitimate uses and legal obligations the Act itself recognises. You may withdraw your consent at any time in Settings → Privacy, and withdrawing it is as easy as giving it.
5. Data sharing
We share personal data with third parties that operate parts of the Service on our behalf — hosting, email, crash reporting, payments, and analytics. The complete, current list, including what each one receives and where it is located, is published at reimbilly.com/subprocessors and updated whenever it changes.
We do not sell your data. We do not use your data for advertising.
5a. Accounting integrations (QuickBooks and Xero)
If a workspace administrator connects an accounting system, Reimbilly exchanges data with that provider strictly to keep your books in step with your approved expenses. Connecting is optional, is initiated by your workspace, and can be undone at any time.
- What we send: lines from approved expense reports only — vendor name, amount, currency, date, description, and the expense category. Nothing is sent for draft, submitted, or rejected reports.
- What we read: your chart of accounts and supplier list, so each expense can be booked against the right account rather than guessed.
- What we never send: receipt images, chat messages, your Reimbilly password, or any expense that has not been approved.
- Authorisation: we never see your QuickBooks or Xero login. You sign in on the provider's own site and the resulting access token is stored encrypted on our servers — never on your device.
- Disconnecting: using Disconnect in Reimbilly revokes our access at the provider and deletes the stored tokens. Anything already written to your accounting system stays there — it is your record, and we do not delete your books.
Data sent to QuickBooks is processed by Intuit Inc. under its own privacy policy; data sent to Xero is processed by Xero Limited under its own. Your relationship with those providers is governed by your agreement with them.
5b. How Reimbilly uses AI
Reimbilly uses AI in one place: reading the receipts you upload. When you add a receipt, the image is passed to an optical character recognition (OCR) service that extracts the text, and we then pattern-match that text to guess the merchant, amount, date and payment reference. The current OCR provider is listed on our sub-processors page.
- Every extracted field is a suggestion you can edit. Nothing is submitted or approved on the strength of an extraction alone.
- No automated decisions are made about people. Expense approvals, rejections and reimbursements are decided by a human approver in your organisation, never by a model.
- We do not generate synthetic content. Reimbilly does not produce AI-written text, images, audio, video or avatars for you to read or publish, so there is no AI-generated output to label.
- We do not train models on your data. Your receipts and expense records are not used to train or fine-tune any model, by us or on our behalf.
- You are never talking to a bot. Team chat and support replies are from people.
If we ever add a feature that generates content or interacts with you conversationally, we will say so clearly in the product and update this section before it ships.
6. International transfers
Your data may be processed in countries other than your own. The primary data store is in India (Supabase, ap-south-1); product analytics are hosted in the European Union (PostHog); and some processors operate from the United States. Which processor sits where is listed on our sub-processors page.
Where we transfer personal data out of the EEA or the UK, we rely on the Standard Contractual Clauses approved by the European Commission, together with the UK International Data Transfer Addendum where the UK GDPR applies.
Under India's DPDP Act 2023, transfers abroad are permitted except to territories the Central Government has restricted by notification. We monitor those notifications and will move or replace a processor if one of ours becomes restricted.
7. Data retention
- Free plan: 3 months of expense data after account deletion.
- Pro plan: 2 years.
- Business / Enterprise: 5 years or as contractually agreed.
- Deleted accounts: All personal data purged within 30 days, except where legally required.
8. Your rights
Under the DPDP Act 2023 and GDPR, you have the right to:
- Access and export your personal data (Settings → Data Export).
- Correct inaccurate data.
- Delete your account and data.
- Restrict processing in certain circumstances, and object to it.
- Withdraw consent for marketing.
- Nominate someone (India, DPDP Act 2023 §14). You may appoint another individual to exercise your rights on your behalf in the event of your death or incapacity. Write to our Grievance Officer to register a nominee.
- Lodge a complaint with a supervisory authority, or with the Data Protection Board of India.
To exercise your rights, email privacy@reimbilly.com. We respond within 30 days.
9. Children's privacy
Reimbilly is an expense-management tool for working professionals. It is not directed to children, and we do not market it to them.
Under India's DPDP Act 2023, which defines a child as anyone under 18, the Service is intended only for users aged 18 and over, and we do not knowingly process a child's personal data without verifiable consent from a parent or lawful guardian. A self-declaration checkbox is not treated as verifiable consent. Under the United States' COPPA, we do not knowingly collect personal data from children under 13.
If we learn that we hold a child's personal data without the consent the law requires, we delete it promptly. If you believe a child has given us data, contact our Grievance Officer at grievance@reimbilly.com.
11. Security
See our Security page for a full description of our technical and organisational measures.
12. Changes to this policy
We will notify you by email and in-app notification at least 14 days before material changes take effect. Continued use of the Service constitutes acceptance.
13. Contact and data controller
The data controller is Kontroma Private Limited (CIN U62011MH2026PTC473706), Floor 7, Skyline Icon, Marol Chimatpada, J.B. Nagar, Andheri East, Mumbai 400059, Maharashtra, India.
Privacy and data-rights requests: privacy@reimbilly.com
General support: support@reimbilly.com
Grievance Officer (India, DPDP Act 2023): Sachin Zore, Director — grievance@reimbilly.com. We acknowledge grievances on receipt and respond within 30 days, as the Act requires. You also have the right to complain to the Data Protection Board of India.