Spensify

Privacy Policy

  • Effective date: July 31, 2026
  • Last updated: July 31, 2026

This Privacy Policy explains how PT. United Teknologi Integrasi ("Provider," "we," "us") collects, uses, stores, discloses, and protects personal data when you use Spensify.

This Policy has been prepared with reference to Indonesian Law No. 27 of 2022 on Personal Data Protection ("PDP Law") and other applicable requirements. It should be read together with the User Agreement and Terms and Conditions.

1. Who is responsible for your data

Spensify is used through a workspace owned by a company or other organization ("Organization"). Responsibility for personal data depends on the processing context:

  • The Organization generally acts as the Personal Data Controller for employee, expense, Approval, Budget, payout, and other business data entered into its workspace. The Organization determines why that data is used.
  • The Provider generally acts as a Personal Data Processor when it processes workspace data on the Organization's instructions.
  • The Provider may act as a separate Personal Data Controller for account and service administration, platform security, abuse prevention, legal compliance, and direct communications with you.

If you use Spensify through an Organization, that Organization's privacy notice and internal policies may also apply. For requests concerning data within a workspace, you may first contact the Organization's administrator or privacy contact.

2. Personal data we process

The data processed depends on the features used and the Organization's configuration.

a. Account and profile data

  • name, email address, username, profile image, and internal user identifiers;
  • hashed password, email-verification status, and account recovery or change information;
  • Google identifier and basic profile information if you choose to sign in or link an account through Google; and
  • language, theme, color accent, and interface preferences.

b. Organization and employment data

  • company, team, position or role, access rights, manager or approver, and membership status;
  • company contact information, address, tax number, currency, and policy configuration; and
  • relationships among users, teams, Approvals, Budgets, and organizational units.

c. Expense and document data

  • transaction date, vendor, vendor address, description, category, payment method, currency, amount, tax, and line items;
  • receipts, invoices, payment evidence, attachments, OCR extraction results, document hashes or fingerprints, and possible-duplicate indicators;
  • notes, reasons, comments, statuses, change history, and Approval decisions; and
  • data in reports, exports, or other documents generated through the service.

Receipts or documents may contain another person's personal data. You and the Organization must ensure that this data is relevant and can be processed lawfully.

d. Financial and Disbursement data

  • account holder name, bank name and code, encrypted account number, last four digits of the account number, currency, and verification status;
  • reimbursement or payment amounts, Disbursement instructions and batches, statuses, references, evidence, and payment-attempt history; and
  • Budget information, allocations, adjustments, and reconciliation records.

Personal financial data may be classified as specific personal data under applicable law. Spensify does not store your online banking password, PIN, or credentials.

e. Technical, device, and security data

  • IP address, user agent, browser type, operating system, device name or type, access time, session status, and session identifiers;
  • authentication, security, language, theme, and interface-state cookies;
  • device identifiers and push-notification tokens if device notifications are enabled;
  • preferences, drafts, table filters, and display settings stored in the browser; and
  • audit trails, account activity, application logs, error information, and security metadata.

f. Communications and preferences

  • notification preferences, in-app messages, service emails, push notifications, delivery status, and read time; and
  • the contents of questions, security reports, privacy requests, or support communications you submit.

Please do not enter unnecessary personal data—including health, biometric, criminal, children's, or other sensitive data—into free-text fields or attachments unless it is necessary and permitted by the Organization and applicable law.

3. Sources of data

We obtain data:

  • directly from you when you create or update an account, upload a document, complete a form, or communicate with us;
  • from the Organization when an administrator invites you, assigns a role, configures a team, or imports business data;
  • automatically from your device and use of the service;
  • from an authentication provider, such as Google, if you choose that feature; and
  • from service providers that process documents, deliver notifications, or support a requested feature.

We process personal data only when there is a lawful basis. Depending on the role and context, that basis may be consent, performance of an agreement, compliance with a legal obligation, protection of vital interests, performance of a task in the public interest, or another legitimate interest that is balanced against your rights.

PurposeExample dataLegal basis generally used
Create accounts, authenticate users, and provide the serviceAccount, session, role, and workspace dataPerformance of an agreement or steps taken at your request
Manage expenses, Approvals, Budgets, reports, and DisbursementsTransaction data, documents, decisions, and payout accountsPerformance of an agreement; lawful Organization instructions
Operate Smart Scan, OCR extraction, duplicate detection, and categorizationReceipts, transaction data, fingerprints, and categoriesPerformance of an agreement or legitimate interest in providing requested functions
Deliver notifications and service communicationsEmail, device token, preferences, and delivery statusPerformance of an agreement, legitimate interest, or consent where required
Maintain security and prevent misuseIP, device, session, audit trail, and log dataLegitimate interest; legal obligation
Support users and handle requestsAccount data and communication contentPerformance of an agreement or legitimate interest
Meet legal obligations and enforce rightsTransaction, audit, and communication recordsLegal obligation or legitimate interest
Maintain and improve service reliabilityLimited usage, performance, and error dataLegitimate interest, subject to data minimization

Where processing is based on consent, you may withdraw that consent. Withdrawal does not affect processing already performed lawfully and may make an optional feature unavailable.

We do not sell personal data. We also do not use workspace data for behavioral advertising.

5. Smart Scan and automated processing

Spensify may use OCR, language models, or automated rules to:

  • read information from receipts and documents;
  • suggest a currency or category;
  • create fingerprints and flag possible duplicate documents; and
  • help organize or validate expense data.

Automated results may be inaccurate or incomplete. They are assistive outputs and must be reviewed by a user or other authorized person. Spensify is not intended to make a solely automated decision that independently produces legal or similarly significant effects for you. The Organization remains responsible for Approval, reimbursement, Budget, and payment decisions.

6. Cookies and browser storage

We use necessary or functional cookies and browser-storage technologies to:

  • maintain login sessions and secure authentication flows;
  • save language, theme, color, and sidebar choices;
  • remember an email address only if you select that option;
  • preserve drafts, filters, dashboard layouts, and table preferences; and
  • manage device identifiers and push-notification prompts.

Authentication cookies are necessary for the service to operate. You can clear preference cookies and data in localStorage or sessionStorage through your browser settings, but doing so may remove preferences or locally saved drafts.

7. Disclosure of data

We may disclose limited personal data to:

  • the Organization, workspace administrators, approvers, team members, auditors, or others according to their roles and access rights;
  • cloud hosting, database, file-storage, and backup providers;
  • OCR and document-processing providers;
  • language-model providers if AI-assisted categorization or data-resolution features are enabled;
  • authentication, email, push-notification, and communications providers;
  • exchange-rate data providers or other technical services, to the extent personal data is required;
  • professional advisers, auditors, insurers, or parties to a corporate transaction subject to confidentiality obligations; and
  • regulators, courts, or authorities where required by law or necessary to protect rights and safety.

Service providers may process data only under applicable instructions and contractual obligations. Providers may differ by deployment configuration and region. You may request the applicable provider list through the contact in Section 15.

8. Cross-border data transfers

Some service providers may process data outside Indonesia. If a cross-border transfer occurs, we or the Organization, as applicable, will implement PDP Law requirements, including ensuring an equivalent or higher level of protection, adequate and binding safeguards, obtaining consent where required, or using another lawful mechanism.

You may request information about the applicable destination countries and transfer mechanisms through the contact in Section 15.

9. Retention and deletion

We retain data only for as long as necessary for the described purposes, the Organization's instructions, contract administration, dispute resolution, security, and legal compliance.

Before this Policy is published, the following periods must be completed according to an approved retention schedule:

Data typeRetention period
Account, profile, and membership dataWhile the account or service relationship is active and for [ACCOUNT RETENTION PERIOD] afterward
Expense, Approval, Budget, Disbursement, and business documentsAs instructed by the Organization and required by law, for at least or no longer than [BUSINESS RECORD RETENTION PERIOD], as applicable
Sessions, audit trails, security logs, and technical logs[SECURITY LOG RETENTION PERIOD] from creation unless needed longer for an investigation
Extractions, temporary uploads, and failed or canceled jobs[TEMPORARY FILE RETENTION PERIOD] after processing ends
Support and privacy requests and consent records[COMMUNICATION RETENTION PERIOD] after the request closes or consent ends
BackupsDeleted or overwritten within [BACKUP DELETION CYCLE] after removal from active systems

Data may be retained longer where required by law, involved in a dispute or investigation, or needed to establish, exercise, or defend legal claims. When the applicable period ends, data will be deleted, destroyed, anonymized, or returned according to our role and lawful instructions.

10. Security

We use technical and organizational measures that are reasonable and proportionate to risk, including role-based access controls, workspace separation, password hashing, encryption of certain bank-account information, session controls, audit trails, backups, and security monitoring.

No system is completely secure. You must protect your credentials, use secure devices, review active sessions, and promptly report suspected unauthorized access.

If a personal-data protection failure occurs, we will assess, contain, document, and notify the parties required by law within the applicable time and with the required information.

11. Your rights

Subject to applicable law and lawful exceptions, you may request:

  • information about the identity and accountability of the party processing data and the basis, purpose, and use of the data;
  • access to and a copy of personal data and available processing records;
  • updating or correction of inaccurate data;
  • cessation of processing, deletion, or destruction;
  • withdrawal of consent;
  • objection to a decision based solely on automated processing that produces legal or similarly significant effects;
  • proportionate restriction of processing;
  • data portability in a commonly used and structured format where applicable; and
  • submission of a complaint or claim for damages under applicable law.

We may request reasonable information to verify your identity and authority. If the Provider processes data only on the Organization's instructions, we may refer the request to the Organization or ask you to contact it. A request may be refused or limited where permitted or required by law, with an appropriate explanation.

To exercise a right, contact sales@spensify.ai.

12. Organization accounts and administrator access

Administrators and authorized personnel within the Organization may access, correct, export, restrict, or delete workspace data; change roles; and terminate your access. The Organization is responsible for ensuring that these actions have a lawful basis and are consistent with notices provided to you.

If you leave the Organization, business data created within its workspace may remain under the Organization's control and be retained according to its retention policies and legal obligations.

13. Children

Spensify is intended for users in a business context and is not directed to children. Users must have legal capacity or the required authority to use the service. Do not enter children's data unless it is strictly necessary, has a lawful processing basis, and meets applicable consent requirements.

14. Changes to this Policy

We may update this Privacy Policy to reflect changes to the service, practices, providers, or law. The updated date will appear at the top. We will communicate material changes through the application, email, or another reasonable method. If new consent is legally required, we will request it before continuing the relevant processing.

15. Contact

Questions, complaints, security reports, or privacy-rights requests may be sent to:

PT. United Teknologi Integrasi
Jl. Siantar No.18, Cideng, Gambir Jakarta Pusat, Jakarta
sales@spensify.ai

If your request concerns data in an Organization's workspace, include the Organization's name so the request can be routed correctly.

On this page