Privacy Policy
Last updated: July 2026
Reseeti ("we," "us") provides invoicing and business-management software for small and medium businesses. This policy explains what information we collect through Reseeti, why, who we share it with, and what control you have over it.
1. Who this applies to
Two kinds of people's data pass through Reseeti: business owners and their staff (who sign up, log in, and use the app), and those businesses' own customers (whose names, phone numbers, and invoice details a business owner enters into Reseeti to create invoices). If you're a customer of a business that uses Reseeti, Reseeti is a data processor acting on that business's instructions — for questions about your own data, contact that business directly, not Reseeti.
2. Information we collect
From business owners and staff (account holders)
- Phone number, used for account sign-in (one-time SMS codes) and, if turned on, login-alert texts.
- Business name, address, and logo, as entered in Business Settings.
- Two-factor authentication setup (an authenticator app secret, if enabled) and a list of devices that have signed in, used for account security.
- Payment details when upgrading to Pro — handled directly by Paystack, OPay, or Monnify; Reseeti never receives or stores card numbers.
Entered by the business, about their own customers
- Customer names, phone numbers, and (optionally) email addresses, addresses, and tax IDs.
- Invoice contents: items, prices, quantities, payment status.
- A signature image, if a customer signs an invoice electronically.
Collected automatically
- Basic device/browser information (used for the Security page's device list and to detect a sign-in from an unrecognized device).
- Usage events (e.g. an invoice marked paid, a reminder sent) — used for the in-app Activity Log and to understand how the product is used.
- Error reports (via Sentry) when something goes wrong, to help us fix it — see Section 4.
3. How we use this information
To operate the core service (creating and sharing invoices, tracking payments, managing inventory and customers); to send the messages a business owner asks Reseeti to send (payment reminders via SMS/WhatsApp, login alerts); to process subscription payments; to provide customer support when contacted; to detect and prevent abuse or fraud; and to improve the product.
AI features (the Invoice Assistant, Business Insights, and Receipt Categorization) send the relevant text or image to a third-party AI provider to process. Business Insights only ever sends aggregated numbers (totals, counts), never raw customer names or phone numbers. The Invoice Assistant and Receipt Categorization do process the text/image you provide directly, which may include customer names.
4. Who we share information with
Reseeti uses the following sub-processors to operate the service. Each only receives the data needed for its specific function:
- Supabase — database, authentication, and file storage (all business data lives here).
- Twilio — sends SMS reminders and login alerts.
- Meta (WhatsApp Business Platform) — sends WhatsApp reminders, if enabled.
- Resend — sends transactional emails (invoice emails, feedback notifications).
- Paystack, OPay, and Monnify — process Pro subscription payments.
- An AI provider (Anthropic or Google, depending on configuration) — processes the specific AI-feature requests described in Section 3.
- Google Drive, Dropbox, or OneDrive — only if a business owner explicitly connects one, to receive that business's own data backups.
- Sentry — receives error reports (stack traces, error messages) to help diagnose bugs. Request bodies and full user data are deliberately excluded from what's sent.
We do not sell personal information to anyone, ever.
5. Data retention and backups
Business data is retained for as long as the account is active. Automated backups run daily (both a platform-wide backup we maintain, and — for businesses that opt in — a copy sent to that business's own connected cloud storage). Backups are retained on a rolling basis and are not kept indefinitely.
6. Security
Data in transit is encrypted (HTTPS). Passwords aren't used at all — sign-in is by one-time SMS code, optionally with a second authenticator-app factor. Sensitive tokens (e.g. connected cloud-storage access) are encrypted at rest. Offline data cached on a device is encrypted using a key that never leaves that device. See our Security settings page for the account-level controls available to you (two-factor authentication, session management, login alerts).
7. Your rights
You can access, correct, or delete most of your own data directly within Reseeti (customer records, products, business settings). You can export a full copy of your business's data at any time from Settings → Export Data. To delete your account entirely, contact us using the details below.
8. Children's privacy
Reseeti is a business tool, not directed at children, and we don't knowingly collect information from anyone under 18.
9. Changes to this policy
We'll update the "Last updated" date above when this policy changes. Material changes will be communicated in-app.
10. Contact
Questions about this policy or your data can be sent through the in-app Feedback button, or to the business's own registered support contact.