Legal

Privacy policy

How IntelliRevenue handles personal information and the documents you send to intelliExtract.

Last updated 14 September 2026

Draft, pending legal review. This document has not been reviewed by a lawyer and contains details that still need to be confirmed. It is published here for review, not as a binding agreement.

In short

  • We collect the details you give us — your work email, optionally your company, and what you want to extract — plus the documents you submit for processing.
  • We use the documents to return extraction results to you. We are a service provider acting on your instructions, not an independent user of your data.
  • We do not sell or share personal information, and we do not run advertising cookies, tracking pixels or third-party analytics on this site.
  • We may use document content to improve intelliExtract. Section 5 explains exactly what that means and how to opt out.
  • You can ask us for a copy of your data, or ask us to delete it, at privacy@intellirevenue.com.

1. Who we are, and what this covers

IntelliRevenue, Inc. ("IntelliRevenue", "we", "us") provides intelliExtract, a service that classifies Consumer Packaged Goods trade documents — remittance advice, deduction backup packets, billbacks and supporting evidence — and returns the fields in them as structured data.

This policy covers the intelliextract.com website, the intelliExtract trial, and the classification and extraction API. It explains what we collect, why, how long we keep it, and what you can ask us to do about it.

Where you are a business customer submitting documents through the service, you are the controller of the personal information inside those documents and we act as your processor or service provider. Where we handle your own account and contact details, we act as the controller. Section 5 deals with the first case and sections 3 and 4 with the second.

2. What we collect

Details you give us

When you start a trial or ask for API access we collect your work email address, your company name if you choose to give it, a short description of your use case, and whether you opted in to product updates. If you contact us, we keep that correspondence.

Documents you submit

The files you upload or fetch by URL for processing, and the structured data we extract from them. These documents typically contain business information — vendor names, purchase orders, deduction numbers, UPC and SKU lines, amounts — and may contain personal information such as the names, signatures or contact details of the people who handled the shipment.

Verification and anti-abuse data

A one-time verification code sent to your email, a record of whether an address has already used its trial, and a token from Cloudflare Turnstile confirming the request came from a person. We also check that an email domain can receive mail and reject known disposable-address providers.

Technical data

Ordinary server logs: IP address, user agent, timestamps, the endpoint called and the response status. These exist to keep the service running, debug failures and detect abuse.

What we do not collect: this site runs no advertising cookies, no tracking pixels, no session recording and no third-party analytics. We do not buy personal information from data brokers, and we do not build advertising profiles.

3. How we use it

  • To run the service: classify and extract the documents you send, and deliver the result to you by email, webhook or API response.
  • To verify that an email address belongs to you, and to enforce one trial per person.
  • To protect the service against abuse, fraud, and automated scraping.
  • To answer your questions and provide support.
  • To send product updates, but only if you asked for them. Every such email carries an unsubscribe link, and the extraction results you requested are sent whether or not you opted in.
  • To meet legal, tax and accounting obligations.

Where the GDPR or UK GDPR applies, we rely on: performance of a contract, for running the service you asked for; our legitimate interests in securing the service, preventing abuse and improving our product; your consent, for product-update emails; and compliance with a legal obligation where one applies.

4. Your documents

Documents you submit are processed to produce the extraction result you asked for. We do not read them for any unrelated purpose, we do not disclose their contents to other customers, and we do not sell them.

Extraction results are delivered by email link, webhook or API response. Trial results are reachable through a link that expires 48 hours after it is sent; we do not attach extracted data to the email itself, so a forwarded message does not carry your data with it.

Please do not submit categories of data the service is not built for. intelliExtract is designed for trade documents. Do not upload health records, government identity documents, full payment card numbers, or the special categories of data described in Article 9 of the GDPR, unless we have agreed that in writing first.

5. Using content to improve the service

We may use content submitted to intelliExtract — including documents and the extraction results produced from them — to test, debug, evaluate and improve the classification and extraction models and the schemas behind them. A new retailer layout that the service handles badly today is the main reason it handles it well tomorrow.

When we do this we apply the following limits:

  • Access is restricted to personnel who need it for that purpose, under confidentiality obligations.
  • We de-identify or aggregate content wherever doing so still serves the purpose.
  • We do not disclose your documents or their contents to other customers, and nothing derived from them is made available in a form that identifies you or your trading partners.
  • We do not use your content to build a product that competes with you.

If you would rather we did not use your content this way, write to privacy@intellirevenue.com and we will exclude your account. Enterprise agreements may exclude it by default; where your signed agreement and this policy differ, your agreement governs.

6. Storage in your browser

This site sets no cookies. It does use your browser's local storage for two things: remembering whether you chose the light or dark theme, and remembering the state of the trial flow so a refresh does not lose your place.

Both stay on your device, are not transmitted to us, and are not used to track you across sites. Clearing site data in your browser removes them.

7. Who we share it with

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We disclose it only to:

Service providers

Vendors who run parts of the service under contract, bound to use the data only on our instructions. These currently cover cloud hosting and storage, transactional email delivery, and Cloudflare, whose Turnstile product confirms that a request came from a person. TODO: confirm and name the hosting and email providers before publishing.

Professional advisers

Lawyers, auditors and accountants, where they need the information to advise us.

Authorities

Where we are legally required to disclose it, or where disclosure is necessary to protect our rights, our users or the public. We will tell you about a request for your data unless we are legally barred from doing so.

A successor

If the business is merged, acquired or sold, your information may transfer as part of that transaction. This policy continues to apply until you are given notice of a replacement.

8. International transfers

We are established in the United States and our service providers may process data in other countries. Where we transfer personal information out of the European Economic Area, the United Kingdom or Switzerland, we do so under the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism. You can ask us for details of the mechanism that applies to you.

9. How long we keep it

Trial documents and results

TODO: state the actual retention period once the pipeline is built. The trial result link expires 48 hours after it is sent.

Customer documents under an API agreement

For the period set out in that agreement, and deleted on request or on termination, subject to backups expiring on their ordinary cycle.

Account and contact details

For as long as you have an account with us, and afterwards where we need them for legal, tax or dispute-resolution reasons.

Trial-eligibility records

We keep a record that an email address has used its trial for as long as that limit is enforced. This is a minimal record and does not include the document you submitted.

Server logs

TODO: state the log retention period. Typically a short rolling window.

10. Security

Traffic to the site and the API is encrypted in transit. API requests are authenticated with HMAC-signed credentials. Access to production systems and to customer content is limited to the people who need it, and email addresses are verified before a trial can be used.

No service can promise perfect security, and we do not claim a certification we have not been audited against. If you need documentation for a vendor security review, write to support@intellirevenue.com and tell us what your process requires.

11. Your rights

Wherever you are, you can ask us to give you a copy of the personal information we hold about you, correct it if it is wrong, or delete it. Write to privacy@intellirevenue.com. We will verify your request and respond within the period the applicable law allows. Exercising these rights costs nothing and we will not treat you differently for it.

If you are in California: under the CCPA as amended by the CPRA you have the right to know what we collect and why, to delete it, to correct it, to limit the use of sensitive personal information, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined, and we do not use or disclose sensitive personal information beyond the purposes permitted without a right to limit. You may use an authorised agent to make a request.

If you are in the European Economic Area or the United Kingdom: you additionally have the right to object to processing based on our legitimate interests, to ask us to restrict processing, to receive your data in a portable format, and to withdraw consent at any time without affecting processing already carried out. You may also complain to your local supervisory authority, though we would rather you came to us first.

If you submitted documents to us on behalf of a business customer, we will refer your request to that customer, who decides what happens to the data in their documents. We will help them respond.

12. Children

intelliExtract is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, write to privacy@intellirevenue.com and we will delete it.

13. Changes to this policy

We will update this policy as the service changes. The date at the top of the page shows when it was last revised. If a change materially affects how we handle your information, we will give notice — by email where we have your address, or by a notice on this site — before it takes effect.

14. Contact us

Questions, requests or complaints about privacy: privacy@intellirevenue.com. Postal mail: IntelliRevenue, Inc., [Registered address].