Expenz
PrivacySecurityTermsEULASign in

Privacy Policy

Effective August 6, 2026 · J&J Collins Technologies LLC

Overview

J&J Collins Technologies LLC ("we," "us," or "our") operates Collins-Expenz, an expense capture and approval platform that syncs approved expenses to QuickBooks Online and can match receipts to bank or card transactions you choose to connect. This Privacy Policy explains what information we collect, how we use it, and the choices available to you.

By using Collins-Expenz, you agree to the practices described here. If you use the service on behalf of a company, your organization may have additional policies that also apply.

Information we collect

We collect information needed to run expense workflows for your workspace:

  • Account information — name, email address, and authentication data provided through our identity provider (Clerk), including organization membership.
  • Expense data — descriptions, amounts, dates, categories, vendors, payment cards, job or customer assignments, approval status, and related metadata you or your team enter.
  • Receipt files — images and PDFs you upload with expenses or to Shoe Box. Receipts are stored in secure cloud object storage associated with your workspace, not on end-user devices as the system of record.
  • Bank and card transaction data — if you connect a financial account, we receive transaction history and related account metadata (such as institution name, account name, and last-four digits) through our integration partner Plaid. We do not receive or store your online banking username or password.
  • Integration data — when you connect QuickBooks Online or a bank/card account, we store encrypted connection tokens and synced reference data needed to operate those integrations.
  • Technical data — server logs, IP address, browser or app type, and diagnostic information used for security, support, and reliability.

How we use information

We use collected information to:

  • Provide expense capture, submission, approval, and receipt management features
  • Match Shoe Box receipts to bank or card transactions you have connected and create draft expenses for your review
  • Authenticate users and enforce role-based access within each workspace
  • Sync approved expenses and related reference data with QuickBooks Online at your direction
  • Operate, secure, troubleshoot, and improve the service
  • Respond to support requests and communicate about the service
  • Comply with legal obligations and enforce our Terms of Service

We do not sell your personal information. We do not use your expense content or receipt files to train generalized AI models.

Role visibility and workspace access

Collins-Expenz is multi-tenant. Each client organization ("workspace") has its own data boundary. Within a workspace, access depends on assigned role:

  • Employees can view and manage their own expense submissions.
  • Accountants and owners can review, approve, or reject expenses across the workspace and manage integrations.
  • Viewers have read-only access to workspace expense data.

Your workspace administrator controls membership and roles. If you have questions about who can see your data inside your company, contact your workspace owner.

Bank and card connections (Plaid)

If you choose to connect a bank or card account, you will use Plaid Link to select your institution and authorize access. Connecting an account is optional and requires your explicit action each time. By connecting, you consent to our collection, processing, and storage of the financial data described below for the purposes stated in this policy.

Through Plaid, we may receive and store:

  • Transaction details — amounts, dates, merchant or description names, and pending/posted status
  • Account metadata — financial institution name, account name, account type, and account mask (last four digits)
  • Encrypted connection credentials — tokens that allow us to sync new transactions until you disconnect

We use this information to:

  • Import transactions into your workspace
  • Match transactions to receipts you placed in Shoe Box
  • Create draft expenses for your review when a match is found

We do not use Plaid data to sell personal information, for unrelated marketing, or to train generalized AI models. Each user connects their own accounts; workspace administrators and accountants may see matched results according to their role.

You can disconnect a bank or card connection at any time from the Accounts area of your workspace. When you disconnect, we stop syncing new transactions from that connection. You may also request deletion of stored transaction data by contacting privacy@expenz.app. Plaid's handling of data you provide through Link is also described in Plaid's End User Privacy Policy.

QuickBooks Online

If your workspace connects QuickBooks Online, we access only the Intuit account and data scopes you authorize during OAuth. We use that access to:

  • Import reference data (accounts, vendors, customers, jobs)
  • Create Purchase transactions in QuickBooks for approved expenses
  • Retry failed sync operations when you or an administrator requests it

We do not access your QuickBooks data without a valid connection authorized by a workspace administrator. You can disconnect QuickBooks from the Accounts area of your workspace. Intuit's own privacy policy also applies to data held in QuickBooks Online.

Service providers

We use trusted subprocessors to operate Collins-Expenz, including:

  • Clerk — authentication, organization membership, and sign-in
  • Cloud hosting and database providers — application hosting and PostgreSQL data storage
  • Object storage providers — receipt file storage
  • Intuit / QuickBooks Online — accounting integration when connected
  • Plaid — bank and card account linking and transaction data when you choose to connect

These providers process data on our behalf under contractual obligations appropriate to their role. A current subprocessor list is available on request.

Data retention and deletion

We retain workspace data for as long as your organization uses the service and as needed to provide support, meet legal obligations, resolve disputes, and enforce agreements.

Bank and card data. Imported transactions and account metadata are retained while the connection is active and while your workspace remains active. When you disconnect a Plaid connection, we stop importing new transactions. You may request deletion of previously imported transaction data at any time by contacting privacy@expenz.app; we process verified deletion requests within a reasonable period (typically within 30 days).

Receipts and expenses. Shoe Box receipts, expense records, and attached receipt files are retained while your workspace is active. If you remove a receipt from Shoe Box before it is converted to an expense, we delete or archive it according to the feature workflow.

Workspace closure. When a workspace is deactivated, we delete or anonymize associated data within a reasonable period (typically within 90 days) unless law requires longer retention.

We review this Privacy Policy and our retention practices when we make material product or legal changes, and at least annually.

Security

We use administrative, technical, and organizational measures designed to protect your information, including encrypted transport (HTTPS), encryption of sensitive integration tokens at rest, access controls, tenant isolation, and restricted production access. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or export personal information, or to object to certain processing. To make a request, contact us at privacy@expenz.app. You can disconnect bank or card accounts from the Accounts area without contacting us. Workspace employees should also contact their organization's administrator for role or access changes.

Children

Collins-Expenz is a business service not directed to children under 16. We do not knowingly collect personal information from children.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised version on this page and update the effective date. Material changes may also be communicated through the service or by email where appropriate.

Contact

Questions about this Privacy Policy or our data practices: privacy@expenz.app.

© 2026 J&J Collins Technologies LLC. Collins-Expenz.

Privacy PolicySecurityTerms of ServiceEULAContact