Privacy Policy
This policy explains what SpendRegister collects, why, who we share it with, and the choices you have. We tried to write it to match what the software actually does — not a generic template.
SpendRegister is operated by Skhoolar EdTech Solutions Private Limited (“Skhoolar”), a company registered in India at EG-27, First Floor, Inderpuri, New Delhi – 110012 — the data controller for the purposes of this policy. It is a B2B product for companies and their staff; it is not directed at consumers or children.
- Your company's data is yours. We store it to run the service, we never sell it, and we never train AI on the items you track.
- We collect only what the product needs — your account, the items you track, and basic technical logs. One essential sign-in cookie; aggregate, cookieless analytics; no cross-site tracking.
- Your register and account data are hosted in Singapore.
- Passwords are hashed, sensitive secrets are encrypted, and department-level visibility is enforced on the server.
- You can export everything yourself from Settings, and ask us to delete it.
1Who we are and how to reach us
The service at spendregister.com is provided by Skhoolar. For any privacy request — access, correction, export, deletion, or a question about this policy — contact anshu@spendregister.com.
Because SpendRegister is used by organisations, your employer (the company whose account you belong to) is often the controller of the business data inside their workspace, and Skhoolar acts as their processor for that data. For account-level and site data described below, Skhoolar is the controller.
2What we collect
We collect only what the product needs to work:
- Account data. Your name and email address, and an authentication credential. You can sign up with an email and password (managed by our authentication library, Better Auth) or sign in with Google or Microsoft. Your password is never stored in readable form.
- Organisation and department data. Your company / workspace name, its departments, team members you invite, their roles, and each member's department visibility.
- The items you track. The subscriptions, contracts, assets, warranties and licences you enter — vendor names, prices, currencies, renewal and expiry dates, notes, budgets and the spend history that builds up over time. This is your company's commercial data, and it is yours.
- Currency snapshots. When you enter an amount in a currency other than your base currency, we store the exchange rate used at that moment so historical figures stay stable.
- Reminder and email activity. The reminder schedule for your items and delivery status of the emails we send (including bounce/complaint signals from our email provider, used to keep reminders reliable).
- Payment data. If you upgrade to the paid plan or use the metered AI add-on, our Merchant of Record (Dodo Payments) processes your payment. We receive billing status and subscription records; we do not store your full card number.
- AI add-on documents (optional). If you turn on the AI document-extraction add-on and upload a file, that file is sent for extraction and then deleted. See section 6.
- Contact-form messages. If you write to us through the contact page, we receive the name, email and message you submit (handled by our form provider, Formspree).
- Basic technical data. Standard server and security logs (e.g. IP address, timestamps) generated by our hosting provider, the session cookie described in section 8, and aggregate, cookieless page-view analytics (see section 8). We do not run third-party advertising or cross-site tracking.
3Why we use it, and our legal bases
We use the data above to:
- provide the register, reminders and reporting (performance of our contract with you / your organisation);
- authenticate you and keep the service secure (legitimate interests; and, for security, legal obligation where applicable);
- send the reminder ladder and transactional email you ask for (contract / legitimate interests);
- take payment for paid plans and the AI add-on (contract);
- respond to your messages and support requests (legitimate interests);
- meet legal, tax and accounting obligations (legal obligation).
Where the law requires consent (for example, the optional AI add-on, which is off by default), we rely on your choice to enable it.
4Sign-in with Google and Microsoft
If you choose Google or Microsoft to sign in, we request only your basic profile and email address — enough to create or recognise your account. That is the extent of the access.
We do not read your Google or Microsoft mail, files, calendar or contacts. We do not sell this data and do not use it for advertising. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
5Who we share data with (sub-processors)
We do not sell your data. We share it only with the service providers that make SpendRegister run, each bound to protect it and to use it only on our instructions:
- Neon — managed Postgres database hosting (stores your account and item data).
- Vercel — application hosting, scheduled jobs, server logs, and cookieless web analytics (aggregate page views).
- Sentry — error and performance monitoring (technical diagnostics; configured not to collect request bodies or personal data).
- Resend — sends reminder and transactional email.
- Dodo Payments — Merchant of Record; processes payments and billing for paid plans and the AI add-on.
- Google and Microsoft — only if you use them to sign in (see section 4).
- Anthropic — processes an uploaded document for field extraction only when you enable the AI add-on and upload a file (see section 6).
- Formspree — delivers messages sent through the contact form.
- Open Exchange Rates — supplies currency exchange rates; we request rates, we do not send your personal or company data to them.
We may also disclose data if required by law, to protect our rights or users, or as part of a business transfer — in which case we will tell you.
6The AI add-on: documents are processed, then deleted
No AI decides anything in the product — a human resolves every item. The only AI is an optional, metered document-extraction add-on that is off by default.
When you enable it and upload a document, the file is sent to Anthropic solely to read its contents and pre-fill item fields for your review. After extraction, the file is deleted — it is never stored. We keep only a content hash (to prevent duplicate charges) and a usage record for metering. Uploaded documents are not used to train models.
7How long we keep it
We keep your account and workspace data for as long as your account is active, so your register and its year-over-year history remain useful to you. When you or your organisation ask us to delete your data, we action the request manually: our staff remove your organisation's records from the live database. We aim to complete deletion requests within 30 days of a verified request. To make one, email anshu@spendregister.com. Self-serve export and deletion are being rolled out; until then requests are handled by hand.
The exception is records we are legally required to keep for longer, such as billing, invoicing and tax records: we retain those only for as long as applicable law requires, and then delete them. Residual copies in our providers' encrypted backups are removed as those backups age out of their normal rotation.
8Cookies and sessions
We use a single, essential session cookie to keep you signed in. It is strictly necessary for the service to function. We do not use advertising cookies, analytics cookies that track you across sites, or third-party marketing trackers.
To understand which pages are used and improve the product, we use aggregate, cookieless page-view analytics via Vercel Web Analytics — it sets no cookies, does not track you across other websites, and does not build an individual profile of you.
9Security
Data is encrypted in transit (HTTPS). Passwords are hashed, and sensitive secrets (such as operator two-factor secrets) are encrypted at rest. Access to production systems is limited, and department-level visibility is enforced on the server, not just hidden in the interface. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data.
10International data transfers
Skhoolar operates from India. Your register and account data are hosted in Singapore — our database and application run in the Asia-Pacific (Singapore) region. Some of our providers (listed in section 5) — for example email delivery, payments and the optional AI add-on — may process limited data in other countries, including the United States. Where personal data is transferred across borders, we rely on appropriate safeguards such as the providers' standard contractual clauses and equivalent mechanisms.
11Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent (for example, by turning off the AI add-on). You can do much of this yourself in the app; for anything else, contact anshu@spendregister.com and we will respond within the timeframe required by applicable law.
If you belong to an organisation's workspace, some requests may need to go through that organisation as the controller of its data; we will help route them.
12Children
SpendRegister is a business tool intended for use by organisations and their staff. It is not directed at children and we do not knowingly collect data from anyone under 16.
13Changes to this policy
We may update this policy as the product evolves. When we make a material change, we will update the date above and, where appropriate, notify you. Continued use after an update means you accept the revised policy.