Privacy Policy
Last updated: 16 Jun 2026
Thank you for using Paypers (“we”, “our”, or “us”).
We respect your privacy and are committed to protecting your personal information.
This Privacy Policy explains how Paypers collects, uses, discloses, and safeguards your personal data when you use our Service, including when you connect with LINE, Gmail, Google Sheets, and Google Drive, and which service providers process your data on our behalf.
By using Paypers, you agree to this Privacy Policy.
We process your personal data in accordance with the Thai Personal Data Protection Act B.E. 2562 (PDPA) and, where applicable, the GDPR. This policy was updated on 16 June 2026 to add a clear description of the personal data we process and the legal basis for each purpose, a full list of the service providers (sub-processors) that handle your data and where they are located, details of international data transfers, and a complete statement of your rights as a data subject.
For the purposes of the PDPA, Paypers is the Data Controller of your personal data. Our contact details, including our Data Protection contact, are in Section 11.
1. Information We Collect
1.1 Information You Provide
- Account identity: your email address, first name, last name, and basic profile when you sign in via Google or LINE
- Business information: your business or legal name, Tax ID (เลขประจำตัวผู้เสียภาษี), business type, business size, phone number, and address — used to generate tax-compliant documents and to look up registry information
- Business documents: receipts, invoices, and similar files you upload or send to the Service
- Files, receipts, or metadata created through the Service
- User input when editing, renaming, or deleting files or folders
1.2 Information Accessed from Gmail (Email Receipt Detection)
If you connect Gmail to Paypers, we may access specific email content and attachments to detect receipts or invoices automatically.
We only process:
- Email subject lines, sender addresses, dates, and attachments
- Email body text — processed by automated and AI systems only to detect whether an email is a receipt or invoice and to extract the relevant details
We do not:
- Read or store unrelated personal emails
- Share your Gmail content with third parties except the service providers listed in Section 6 that help us process it
- Use your Gmail content for advertising or third-party marketing, or sell it to third parties
Email body text is processed in real time and is not stored. The email metadata we detect (subject line, sender, date, and message identifier), the attachment references, and the receipt data we extract are retained as described in Section 4 (Data Retention and Deletion).
1.3 Information Accessed from Google Drive
If you connect Google Drive, Paypers will request permission to:
- Create a dedicated “Paypers” folder
- Add, rename, or delete files within that folder only
- Create Google Sheets and write/append/update data to generate reports (e.g., append rows, update headers/columns, add/rename/delete sheets) inside authorized folders
We do not access any other folders or files outside the Paypers directory.
1.4 Information Accessed from LINE
When you connect LINE, we may collect:
- Your LINE ID and display name
- Messages or attachments you send to our Paypers LINE bot (for uploading receipts)
1.5 Usage Data
We collect usage data (e.g. browser type, IP address, device information, usage logs, crash reports, and product-analytics events) to help us improve system performance and user experience.
You may opt out of product analytics at any time in Settings → Privacy. Opting out does not affect your ability to use the Service.
2. How We Use Your Data
We use your information for the following purposes. For each purpose, we rely on a legal basis under the Personal Data Protection Act B.E. 2562 (PDPA), in accordance with Section 24 and Section 19:
| Personal data | Purpose | Legal basis (PDPA) |
|---|---|---|
| Name, last name, email | Create and manage your account; identify you; communicate about the Service; connect Google services for billing | Performance of a contract (Section 24(3)) |
| Business information (name, Tax ID, type, size, phone, address) | Generate tax-compliant documents and reports; look up company-registry data | Performance of a contract (Section 24(3)) |
| Business documents (receipts, invoices) | Read, classify, and extract data; generate financial summaries and reports | Performance of a contract (Section 24(3)) |
| Business documents (receipts, invoices) | Debug, test, and improve the accuracy and reliability of our document-processing system — including its extraction logic, classification rules, and workflows. We do not use your documents to train or fine-tune AI/ML models. | Legitimate interest (Section 24(5)) — you may object (see Sections 2.3 and 5) |
| Gmail content, Google Drive files, LINE messages | Detect, organize, and store receipts; deliver the features you request | Performance of a contract (Section 24(3)) |
| Usage, analytics, and crash data | Maintain security, debug, and improve the Service | Legitimate interest (Section 24(5)) / consent (analytics) |
| Contact details | Send product news and marketing (where permitted) | Consent (Section 19) — you may opt out anytime |
In summary, we use your information to:
- Detect and extract receipts automatically from connected email accounts
- Save and organize those receipts into your linked Google Drive folder
- Generate digital “ใบแทนใบเสร็จ” or other summary files
- Generate reports in Google Sheets (e.g., summary logs, monthly statements, expense categorizations) and keep them in your Drive
- Notify you via LINE when processing is complete
- Improve system accuracy and security
We never use your email or file content for advertising, third-party marketing, or sale to third parties.
2.1 AI Processing of Your Documents
To provide the Service, your uploaded documents and receipts are processed by automated and AI systems to read, classify, and extract information and to generate financial summaries and reports. This processing includes sending document content to the AI and OCR providers listed in Section 6 (for example, Google Gemini and OpenAI).
- This processing is necessary to deliver the core features you request and applies whenever you use the Service. Accepting this Privacy Policy and our Terms of Use is required to use Paypers.
- AI-generated results may contain errors or omissions. Paypers is a document- and expense-management tool and is not an accounting, legal, or tax advisor. You are responsible for reviewing results for accuracy before relying on them.
2.2 Marketing Communications
We may send you product news and marketing messages where permitted. You can opt out at any time in Settings → Privacy or via the unsubscribe option in each message. Opting out of marketing does not affect your ability to use the Service.
2.3 System Improvement
We may use the business documents you submit to debug, test, and improve the accuracy and reliability of our document-processing system — for example, by diagnosing extraction errors, refining our classification rules, and improving our processing logic and workflows.
- We rely on our legitimate interest in maintaining, securing, and improving the quality of the Service (PDPA Section 24(5)). We have assessed that this interest does not override your fundamental rights and freedoms.
- We do not use your documents to train or fine-tune AI or machine-learning models, and we do not sell, rent, or share them with third parties for that purpose. Documents are shared only with the service providers listed in Section 6 to deliver and improve the Service.
- Wherever practical, we use de-identified or aggregated data for this purpose.
- You have the right to object to this processing at any time (see Section 5) by contacting us at support@paypers.ai. Objecting does not affect the core document processing described in Section 2.1, which is required to provide the Service.
3. Data Security
- All data transfers use HTTPS/TLS encryption.
- Gmail and Google Drive access tokens are securely stored and encrypted.
- Your email and document content is processed primarily by automated and AI systems. We do not read your personal emails for any purpose other than detecting and extracting receipts.
- Authorized personnel may access limited personal data only when strictly necessary for support, troubleshooting, security, or legal compliance, and are bound by confidentiality obligations.
- We require our service providers (Section 6) to maintain appropriate security measures under written data processing agreements.
- You can revoke permissions anytime from your Google Account → Security > Third-party access.
4. Data Retention and Deletion
We retain personal data only for as long as necessary to achieve the purposes described in this Privacy Policy. When data is no longer necessary, we delete or anonymize it, unless we are required to retain it by law (for example, for accounting or tax purposes).
| Type of Personal Data | How Long We Keep It | How We Delete or Remove It |
|---|---|---|
| Email body text (Gmail) used to detect receipts or invoices | Processed in real time and not stored | Not retained — discarded immediately after processing |
| Email metadata (subject line, sender address, date, Gmail message identifier) and attachment references used to detect and extract receipts | Retained while your account is active, until you delete the relevant receipt, disconnect and request deletion, or delete your account | Records and any associated files are deleted from our database and storage |
| Extracted receipt data (merchant name, transaction date, amount, tax information, expense details) and generated files | Same as above — retained while your account is active, until you delete the item or delete your account — unless we are required to keep it by law (e.g. accounting or tax) | Records are deleted or anonymized so they can no longer identify you |
| Google OAuth tokens (access and refresh tokens) | Until you disconnect Google or delete your account | Cleared from our database; you may also revoke access at Google Account → Security > Third-party access |
| Usage, analytics, and crash data | Retained for as long as needed to secure, debug, and improve the Service | Deleted or aggregated when no longer needed |
| Pseudonymized consent history | Retained after account deletion only where needed to comply with the law or to establish, exercise, or defend legal claims | Personal identifiers removed |
Please note: disconnecting Gmail or Google Drive stops future processing and removes our access to your account, but it does not by itself delete receipts or data already extracted. To remove that data, delete the individual items, delete your account, or contact us.
You can request full data deletion at any time via support@paypers.ai.
5. Your Rights
Under the PDPA (and the GDPR where applicable), you have the following rights as a data subject. These rights are provided in accordance with Sections 19 and 30 to 36 of the PDPA (the right to lodge a complaint is provided under Section 73):
Right to Withdraw Consent
If you have given consent to us to collect, use, or disclose your personal data, whether before or after the effective date of the PDPA, you have the right to withdraw such consent at any time throughout the period your personal data is available to us, unless restricted by law or you are still under a beneficial contract. However, the withdrawal of consent shall not affect the collection, use, or disclosure of personal data to which you have already legally given consent. In addition, withdrawing your consent may mean that we will not be able to continue providing the services to you, and we may need to terminate your existing relationship and/or contract with us.
Right to Access
You have the right to access your personal data that is under our responsibility, to request a copy of such data, and to request that we clarify how we collected your personal data.
Right to Data Portability
You have the right to obtain your personal data where we organize it in an automatic, machine-readable, or usable format that can be processed or disclosed by automatic means; to request that we send or transfer such data directly to other data controllers where technically feasible; and to request data sent or transferred by us directly to other data controllers, unless not technically feasible.
Right to Object
You have the right to object to the collection, use, or disclosure of your personal data at any time in the following circumstances:
- when personal data is collected under an exemption to consent requirements, such as for legitimate interest or public interest;
- when personal data is collected, used, or disclosed for direct marketing purposes; or
- when personal data is collected, used, or disclosed for the purposes of scientific, historical, or statistical research.
Right to Erasure
You have the right to request that we erase, destroy, or anonymize your personal data if you believe that the collection, use, or disclosure is against relevant laws, when retention is no longer necessary in connection with the purposes under this Privacy Policy, or when you withdraw consent or object as specified above.
Right to Restrict Processing
You have the right to request that we suspend the processing of your personal data for a particular period in the following circumstances:
- when we are correcting your data following your request to keep it accurate, up to date, complete, and not misleading;
- when you initially requested erasure or destruction but later request restriction instead;
- when retention is no longer necessary but you request continued retention for the establishment, compliance, exercise, or defense of legal claims;
- when we are verifying your data following your request;
- when you object to processing of personal data that was collected without your consent, and you consider it no longer necessary to process for legitimate or public interest; or
- when you object to processing of personal data collected, used, or disclosed for scientific, historical, or statistical research.
Right to Rectification
You have the right to rectify your personal data so that it is up to date, complete, and not misleading.
Right to Lodge a Complaint
You have the right to lodge a complaint with the competent authorities under relevant laws if you believe that our collection, use, or disclosure of your personal data violates or does not comply with relevant laws.
In addition, you may withdraw your optional consent to marketing, at any time in Settings → Privacy. Withdrawing an optional consent does not affect the lawfulness of processing carried out before withdrawal, and does not limit the core document processing described in Section 2.1, which is required to provide the Service.
To exercise any of these rights, contact us at support@paypers.ai.
6. Service Providers and Sub-Processors
We do not sell or rent your personal data. We share it only where necessary to operate the Service, and only with the third-party service providers listed below. All such sharing is limited to the minimum data required and follows each provider’s official API scopes under secure OAuth consent.
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| Supabase | Primary database, authentication, and file storage | Account, business, document, and usage data | Singapore |
| Google Cloud Platform | Application hosting and receipt-image storage | All app data and document images | Singapore |
| Google (Gemini AI) | AI reading, classification, and extraction; assistant chat | Receipt/document content and chat messages | United States |
| OpenAI | Signature image processing | Signature images | United States |
| Langfuse | AI performance monitoring and quality | AI prompts and outputs (document content), user IDs | United States |
| Sentry | Error and crash tracking | Error context, user IDs, request data | United States |
| PostHog | Product analytics | User IDs and usage events | United States |
| Stripe | Billing and subscription payments | Name, email, billing and payment data | United States / global |
| LINE | Chatbot messaging and login | LINE profile, messages, and uploaded images | Japan / global |
| Google (Drive, Sheets, Gmail) | Read and write files and emails in your own Google account | Receipt files, reports, email content | Your own Google account |
| Amazon Web Services | Thai company-registry (DBD) lookups | Tax IDs / business identifiers | Thailand |
| Slack | Internal operational alerts | User IDs and links to receipt images | United States |
| Vercel | Web frontend hosting | Web traffic, IP address, request data | United States |
| Cloudflare | DNS, content delivery, and web analytics | Web traffic and IP addresses | Global edge network |
| Upstash | Rate limiting and caching | User IDs / IP addresses (transient) | Singapore / United States |
| Userjot | In-product feedback and feature requests | User IDs and feedback content | United States |
| Google Analytics (consent-gated) | Web/marketing analytics | Pseudonymous identifiers and page views | United States |
| Meta (Facebook Pixel) (consent-gated) | Web/marketing analytics and ad measurement | Pseudonymous web identifiers, page views, events | United States |
We may update this list as our providers change and will revise the “Last updated” date accordingly. Beyond these providers, limited data may be disclosed where required by law, to enforce our Terms, or to protect our rights, users, or the public.
7. International Data Transfers
Paypers is operated from Thailand. Your core data (database and document images) is stored in Singapore. As shown in Section 6, some of our service providers process personal data in other countries, including the United States and Japan.
Where we transfer personal data to a country that has not been recognized by the Personal Data Protection Committee (PDPC) as providing an adequate level of protection, we rely on one or more of the following safeguards permitted under Sections 28 and 29 of the PDPA:
- Data processing agreements with appropriate contractual safeguards (such as Standard Contractual Clauses) — for example with Supabase, PostHog, and Cloudflare;
- Your explicit consent, given after being informed that the destination country may not provide the same level of data protection as Thailand; and/or
- Transfer necessary for the performance of our contract with you, to deliver the Service you request.
By accepting this Privacy Policy and using Paypers, you acknowledge and consent to these international transfers for the purposes described above. You may withdraw this consent by discontinuing use of the Service and contacting us to delete your data.
8. Reports in Google Sheets
- Reports are created inside your Google Drive (within the Paypers directory by default).
- By default, report access is restricted to your Google account unless you choose to share them.
- You may delete or modify any report at any time; Paypers will reflect changes upon next sync or job run.
- If you relocate reports outside the Paypers directory, some automations may not function.
9. Children’s Privacy
Paypers is not intended for users under 13 years old.
We do not knowingly collect data from minors.
10. Your Consent and Policy Updates
When you start using Paypers you are asked to accept this Privacy Policy and our Terms of Use (required), and you may separately choose whether to allow optional use of your data for marketing. We record the version of the policy you accepted.
We may update this Privacy Policy from time to time. When we make material changes, we revise the version date above and, where required, ask you to review and accept the updated policy before continuing to use the Service. You will be notified via email or within the app.
11. Contact Us
If you have any questions about this Privacy Policy, or to exercise your rights, please contact:
Paypers Co., Ltd. (Data Controller)
Address: My Office, No. 2823/3, Floor 2, Room 283, Charoen Krung Road, Bang Kho Laem, Bang Kho Laem, Bangkok 10120, Thailand
Data Protection Contact