Founding member pricing: the first 10 customers get 50% off for life. Use code FOUNDING50 at checkout.

Privacy Policy

Last updated: August 25, 2026

1. Introduction

ReceivAR is operated by Bosque Tech LLC, a New Mexico limited liability company ("we", "us", "our"). We operate an accounts-receivable collections platform for professional services firms. This policy describes what data we collect, how we use it, and the third parties we share it with so that you can make informed choices about your firm's use of the service.

Our two roles. For the account, billing, and usage information you give us directly as a subscriber, we act as the data controller: we decide how it is used, as described in this policy. For the AR data you upload about your clients and debtors, we act solely as a data processor (service provider) on your instructions: we process it only to operate the service for you. You, as the subscriber, remain the controller of that data and are responsible for maintaining a valid legal basis for uploading it and for providing any privacy notices owed to the individuals and organizations it describes.

2. Information we collect

Account information: name, email, firm name, password (stored hashed), mailing address, and tone/escalation preferences you set in Settings.

AR data you upload: client names, contact details (when imported), invoice numbers, balances, due dates, and aging buckets, derived from the aged-receivables files you upload.

Activity you log: contact-log entries, payment records, promises, broken-promise flags, and the letters you generate or send.

Session data: a session cookie used to keep you signed in; basic server access logs (IP, timestamp, route).

Billing information: your subscription plan, subscription status, and a Stripe customer identifier. Payment-card details are collected and stored by Stripe, our payment processor. Your card number never touches our servers.

Free tools: if you use our free letter generator, we collect the email address you provide (to deliver your letter and, only if you opt in, to send occasional product tips you can unsubscribe from at any time). The letter details you enter are used to produce your letter and are not saved.

What we do not collect: the raw AR files you upload are parsed in your browser, and we do not retain the original spreadsheet on our servers.

3. How we use your data

To operate the service: authentication, displaying your AR portfolio, generating collection letters, tracking your contacts and promises, and producing your cash-flow forecast.

To communicate with you about account events (password resets, security notifications).

To manage your subscription: processing payments, applying trials, and keeping your plan status current via Stripe.

We do not sell your data, share it with advertisers, or use it to train AI models on your behalf or anyone else's.

4. Third-party processors

We rely on the following service providers to operate ReceivAR. Each has its own data-handling practices, which we've linked below.

  • Anthropic (Claude API): when you generate an AI letter, the prompt we send to Anthropic includes the client name, invoice numbers and amounts, aging bucket totals, prior contact log entries, broken-promise details, and your sender info. This data is processed by Anthropic to produce the letter and is governed by Anthropic's Commercial Terms and Privacy Policy. If you prefer to keep client data out of any third-party AI, choose the template-letter mode instead; it makes no external calls.
  • Stripe: processes subscription payments. When you subscribe, your card details go directly to Stripe; we receive only your subscription status, plan, and a customer identifier. Stripe's handling of your data is governed by Stripe's Privacy Policy.
  • Resend: delivers email on our behalf, including account email to you (such as password resets), and the collection letters you choose to send to your clients, which include the client's email address and the letter content (client name, invoice numbers, and amounts). When a client replies to a collection letter, the reply is received and processed by Resend so it can appear in your contact log.
  • Vercel: hosts the application and edge functions. Routine HTTP request metadata flows through Vercel infrastructure.
  • Neon: hosts our PostgreSQL database where your account and AR data are stored.

We process data with each of these providers under their commercial terms and data processing agreements. If we add or replace a subprocessor that handles your AR data, we will update this list and notify active subscribers by email before the change takes effect.

5. Data retention

We retain your account and AR data for as long as your account is active. If you delete your account or ask us to delete your data, we will remove it from our active systems within 30 days. Some records may persist in encrypted backups for up to 90 days before they are overwritten. Billing records are retained by Stripe as required for tax and accounting purposes.

These deletion commitments do not apply where retention is required or permitted by applicable law, including for tax, accounting, or regulatory compliance, to resolve an active dispute, to enforce our agreements, or to comply with a legal obligation or lawful request. Any data retained under these exceptions remains protected by this policy and is deleted when the basis for retention ends.

6. Your rights

You can update your account information from Settings inside the app. To request a copy of your data or its deletion, email us at support@receiv-ar.com. Depending on your jurisdiction (including, e.g., GDPR or CCPA), you may have additional rights such as access, correction, portability, or objection.

If you are a client or debtor of one of our subscribers: we process your information only as a service provider acting on that subscriber's instructions. If you contact us directly with a request to access, correct, or delete your information, we will refer your request to the subscriber whose account contains it, and we will assist them in fulfilling it. The subscriber, as the controller of that data, is responsible for responding to your request.

7. Cookies

We use a single session cookie (receivar_session) to keep you signed in. It is HTTP-only, same-site lax, and marked Secure in production. We do not use advertising cookies or cross-site tracking. We measure aggregate page traffic with Vercel Web Analytics, which is cookieless and does not identify individual visitors.

8. Security

Passwords are hashed with scrypt and a random salt. Session tokens are stored as hashes server-side. Communication is over HTTPS in production. No system is perfectly secure; please use a strong, unique password and report anything suspicious to support@receiv-ar.com.

9. Changes to this policy

If we make material changes we will notify active users by email and update the "Last updated" date above.

10. Contact

Questions about this policy? support@receiv-ar.com