Legal

Privacy policy

Effective date:

This Privacy Policy explains how OverpayAlert handles personal data when you visit overpayalert.com, use the web application at app.overpayalert.com, use our API, or connect integrations such as Slack or Microsoft Teams (together, the “Service”).

OverpayAlert is a product of PrinceAI. PrinceAI is the trading name of Khalid Albalawi, a sole proprietor (“OverpayAlert”, “we”, “us”). For any privacy question or request, email support@overpayalert.com.

1. Our two roles

  • Account and website data. For information about the people who sign up, sign in, pay, contact us, or visit our website, we decide how the data is used. We are the “controller” of that data.
  • Customer Data. For the invoices, documents, emails, and vendor information our business customers send to the Service, and the results we generate from them, we act on the customer’s behalf and on its instructions. We are a “processor” (or “service provider”). The customer is responsible for its own notices to the people in that data. If you are a vendor contact or an employee of one of our customers and have a question about that data, please contact that customer first; we will help them respond.

2. What we collect

Information you give us

  • Account details: name, work email, company name, job role, and password (stored only in hashed form).
  • Onboarding answers, such as your role, approximate invoice volume, accounting tools, and preferred alert channels.
  • Team information: the email addresses of people you invite, and their roles.
  • Messages to us: support emails, product feedback you send from the app (including the page you were on), and answers to our optional cancellation or downgrade survey.

Customer Data

  • Invoice files you upload or submit through the API.
  • Emails forwarded to your workspace address: we keep the attachments as invoices and record the sender address, subject, message ID, and file details. If an email fails authentication checks, or does not meet your workspace’s sender rules, we may hold the full message for review for up to 14 days.
  • Information extracted from invoices, such as vendor names and tax IDs, invoice numbers, dates, line items, amounts, and payment details printed on the invoice, plus the alerts, comments, and decisions your team records.
  • Numeric representations of invoice details (such as vendor, tax ID, and amounts) that we create to find duplicates and similar invoices.

Information collected automatically

  • Sign-in and security data: IP address, browser user agent, session identifiers, and sign-in times, used to keep accounts secure and to apply your organization’s security settings.
  • Workspace activity log: a record of important account events, such as sign-ins, invitations, role and settings changes, data exports, and connected integrations. Your workspace owners and admins can view and export this log to see who changed what.
  • Service monitoring: error reports, logs, traces, and performance metrics that we use to keep the Service running and fix problems. We configure these to exclude personal data where possible. We do not record your screen, keystrokes, or browsing sessions.
  • Device storage: the app stores your sign-in session and preferences (for example theme and active workspace) in your browser’s local storage.
  • Bot protection: our sign-up, sign-in, and password reset forms use a bot-protection check, which evaluates technical signals from your browser.
  • Website analytics: we measure visits to our marketing website using a privacy-focused analytics service that does not use cookies to track you across sites. We do not use advertising cookies.

Information from others

  • If you sign in with Google or Microsoft, we receive your name and email address from that provider.
  • If you connect Slack or Microsoft Teams, we receive access tokens and the list of channels or teams you can choose from.
  • Paddle, our payment reseller, tells us about your subscription status, plan, billing period, and invoices. We do not receive or store your card details.

3. How we use it

Purpose Legal basis (where GDPR or similar laws apply)
Create and run your account and workspaces, and provide the Service Performance of our contract with you
Tailor setup using your onboarding answers Performance of contract
Process Customer Data: extract invoice details and detect duplicates, price changes, and other issues On our customer’s instructions (as processor)
CrowdShield on the Scale plan (section 5) On our customer’s instructions (as processor)
Send service emails: alerts, digests, invitations, usage and billing notices, trial and plan notices, and security and deletion notices Performance of contract; legitimate interests
Keep the Service and accounts secure: bot protection, session and access controls, activity logs, fraud and abuse prevention Legitimate interests; legal obligations
Monitor the Service and find and fix errors Legitimate interests
Measure website visits Legitimate interests
Manage subscriptions and refunds with Paddle Performance of contract
Answer support requests and product feedback, and improve the Service Legitimate interests
Comply with law and enforce our Terms Legal obligations; legitimate interests

We do not sell personal data, we do not share it for cross-context behavioral advertising, and we do not send marketing emails without your consent.

4. Artificial intelligence

To read invoices, the Service processes documents and related text with AI models, which may be run by us or by service providers acting on our behalf. We send this data only to AI providers whose terms prohibit them from retaining it or using it to train their models. We never use Customer Data to train AI models, and we do not share it with other customers.

AI results can be wrong. Alerts are a review aid, and a person at the customer decides what to do with each invoice.

5. CrowdShield

On the Scale plan, CrowdShield compares alerts across companies. When a duplicate invoice or a price increase is flagged, the Service creates a cryptographic fingerprint (hash) derived from the vendor’s tax ID or, if there is none, its normalized name, together with the type of issue. We keep a record of which workspace contributed each fingerprint so we can count companies and honor opt-outs. Other Scale customers see only a count of how many other companies flagged the same pattern. We never share invoice numbers, amounts, dates, documents, your company’s name, or any person’s details. Sharing and receiving are on by default on the Scale plan, and a workspace admin can switch either off in Settings.

6. Who we share it with

We share personal data only as needed to run the Service:

  • Service providers that host and operate the Service on our behalf: cloud hosting, database, and file storage; authentication; email delivery and inbound email routing; AI document processing; service monitoring; bot protection; and website analytics. They process the data under their contracts with us. We can provide a current list of these providers on request.
  • Paddle, our online reseller and Merchant of Record, which processes payments, taxes, refunds, and billing support as an independent controller under its own privacy policy.
  • Integrations you turn on, such as Slack, Microsoft Teams, or your own webhook endpoints. Alert messages sent there include the alert title, vendor name, invoice number, amount, and a link to the app.
  • Sign-in providers such as Google or Microsoft, if you choose to use them.
  • People in your workspace, according to the roles your owners and admins assign.
  • Authorities or others when required by law, or to protect the rights, safety, or security of our customers, the Service, or others.
  • A successor, such as a company we form to operate the Service or a buyer of the business, which would be bound by this policy.

7. International transfers

We operate from the Kingdom of Saudi Arabia, and our service providers may store and process data in the United States and other countries. When the law requires a safeguard for a transfer, we use the European Commission’s Standard Contractual Clauses (and the UK Addendum), or another transfer mechanism the law allows, and we follow the conditions for transfers under Saudi Arabia’s Personal Data Protection Law.

8. How long we keep it

Data How long
Account and workspace data, including Customer Data While the workspace is active. When an owner deletes a workspace, it can be restored for 7 days and is then permanently deleted from the live Service.
Emails held for review Up to 14 days
Documents identified as not being invoices The file is deleted after 7 days
Invoices held over your plan’s allowance Until processed or the workspace is deleted
Alert and email delivery logs While the workspace is active
Workspace activity logs Up to 2 years
Session records Sessions unused for 30 days are removed the next time you sign in
Invitations Expire after 7 days
User login accounts Until you ask us to delete them
Support and feedback messages As long as needed to handle them and improve the Service
Billing records As long as needed for tax and accounting purposes

Deleting a workspace does not delete the user accounts of its members, because a person can belong to more than one workspace. To delete your user account, email support@overpayalert.com. Backups kept by our hosting providers are overwritten on their normal schedule.

9. Security

We protect data with encryption in transit, encryption at rest provided by our hosting and storage providers, separation of each customer’s data, role-based access, optional or required multi-factor authentication, session controls, optional IP allowlists, and activity logging. No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify affected customers without undue delay and, where required, the authorities within the time the law requires.

10. Your rights

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data; to object to or restrict certain uses; and to withdraw consent where we rely on it. You can also complain to your local data protection authority.

  • You can download a copy of your personal data from your account settings, and workspace owners and admins can export workspace data.
  • For any other request, email support@overpayalert.com. We will reply within the time the applicable law requires, and may need to verify your identity first.
  • If your request is about Customer Data held for one of our customers, we will pass it to that customer and help them respond.

We will not treat you differently for exercising your rights.

US residents. We do not sell or share personal information as those terms are defined in US state privacy laws, and we use the personal information we collect only for the purposes in this policy.

11. Children

The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect personal data from children.

12. Changes

We may update this policy. If a change is material, we will notify workspace owners by email or in the app at least 30 days before it takes effect. The effective date at the top shows when this version started.

13. Contact

PrinceAI (trading name of Khalid Albalawi)
Operator of OverpayAlert
Email: support@overpayalert.com