Privacy Policy
Last updated September 10, 2026
ReconLoopPro (“we,” “us”) provides a reconciliation tool that matches your Stripe payouts and charges against a bank statement you upload. This page explains what data we collect, why, and how you can control it. It applies to reconlooppro.com and the ReconLoopPro iOS and Android apps, which are the same product.
What we collect
- Account information: the email address and password you sign up with, or your name, email, and profile photo if you sign up with Google.
- Stripe connection: when you connect your own Stripe account, we store its Stripe account ID. We authenticate to it via Stripe’s own OAuth flow using our platform credentials — we never see or store your Stripe password or API secret keys.
- Xero connection (optional): if you connect a Xero organisation, we store an encrypted OAuth access and refresh token so we can read your accounting data on your behalf. These are encrypted at rest and only decrypted server-side when a request needs them.
- Transaction data: Stripe charges/payouts you sync, and the contents of any bank statement CSV you upload (date, amount, description) — this is the data the reconciliation engine compares.
- Billing information: your subscription tier and status. Payment card details are collected and stored by Stripe directly, on Stripe’s own checkout page — we never see or store your card number.
- Support messages: anything you submit through the Help/contact form, including your name and email if provided.
- Usage analytics: page views and feature-usage events (e.g. that a sync happened, not what was synced) via Plausible Analytics, a privacy-focused analytics provider that does not use cookies and does not track you across other sites.
What we don’t do
- We don’t sell your data, to anyone, ever.
- We don’t use your data to serve you ads, on this app or anywhere else.
- We don’t share your financial data with other users, or with anyone outside the service providers listed below.
Who we share data with
We use a small number of service providers to run ReconLoopPro. Each only receives what it needs to do its job:
- Supabase — hosts our database and handles authentication. Your account data and transaction data live here, access-controlled per account.
- Vercel — hosts the application itself.
- Stripe — processes ReconLoopPro’s own subscription billing, and is the source of the payouts and charges data you choose to sync from your connected account.
- Xero — if you connect it, the source of the accounting data you choose to sync.
- Resend — sends transactional email on our behalf: sign-up confirmation, password reset, the onboarding email sequence, and replies to support requests.
- Plausible Analytics — aggregate, non-cookie usage analytics, described above.
Your controls
- Disconnect Stripe or Xero at any time from the Integrations page — this deletes the stored connection immediately (and, for Stripe, revokes the authorization on Stripe’s side too).
- Unsubscribe from onboarding/product emails via the link in any of those emails. Transactional emails you can’t opt out of (like password resets) are triggered by your own actions.
- Request deletion of your account and all associated data by contacting support through the in-app Help page. Deleting your account removes your profile, uploaded transaction data, and integration connections.
Data retention
We keep your data for as long as your account is active, so the reconciliation history stays useful. If you delete your account, associated transaction and connection data is deleted along with it.
Children’s privacy
ReconLoopPro is a business tool and isn’t directed at, or knowingly used by, children under 16.
Changes to this policy
If this policy changes materially, we’ll update the date at the top of this page. Continued use of ReconLoopPro after a change means you accept the updated policy.
Contact
Questions about this policy or your data: reach us through the Help page, or at support@reconlooppro.com.