Skip to content

RevPulse legal

Privacy Policy

A plain-language account of what RevPulse collects, why we need it, how it is protected, and the choices available to you.

Last updated · 8 September 2026

01

Optional AI services and your permission

RevPulse uses Microsoft Corporation's Azure OpenAI service in Microsoft Foundry for finance answers, invoice drafting, and bank statement image reading, and Azure AI Document Intelligence for receipt extraction. These are optional services. Before you first use each AI feature, we identify the recipient, describe the data and purpose, and ask you to choose Allow once, Always allow, or Cancel. Allow once asks again for every new request. Always allow saves permission for that feature, for you in the current workspace across your devices, until you change it in Settings or the sharing notice changes. Accepting our general terms or privacy policy, or enabling AI for a workspace, does not grant this permission.

We collect the question, instructions or receipt you provide and, where needed, retrieve the relevant records from your current workspace. Finance answers send your question, screen context, recent messages and a small selection of earlier user requests in the selected conversation, the saved record currently in view when page context is enabled, and a limited snapshot of income, expenses, invoices, client names, record descriptions, amounts, dates, categories, tax summaries, stock evidence, storefront status, order fulfilment counts, and verified payment totals and platform fees separated into sandbox and live activity. Commerce aggregates exclude buyer contacts, addresses, policies and banking details. Invoice drafting sends your instructions, business name and the selected client's name, company name and internal identifier, or those details for up to 100 active clients if none is selected. Receipt extraction sends the complete selected image or PDF, including any personal or financial information printed on it. Bank statement AI reading sends rendered images of all unlocked PDF pages, including names, addresses, account details, transactions and balances. RevPulse unlocks password-protected statements in memory and does not save the PDF password or send it to Microsoft. CRM data includes current pipeline counts and a bounded selection of opportunity titles, client names, assigned team member names or emails, stages, estimated values and currencies, next actions and dates. Private CRM conversation history and client contact details are excluded.

Microsoft processes this data to generate the requested answer, draft, receipt extraction or bank statement extraction and to operate and secure its services, including applicable abuse monitoring. RevPulse does not use these requests to train AI models. Microsoft's published Azure service terms restrict the use of customer inputs and outputs for model training without customer permission. Processing location and provider retention depend on the Azure service and deployment; some processing may occur outside South Africa.

We require Microsoft and every other provider receiving personal information to provide the same or equal protection as this policy through applicable data-protection terms, confidentiality, access restrictions and security safeguards. Azure processing is covered by Microsoft's Products and Services Data Protection Addendum. Data is sent over encrypted connections. RevPulse does not grant AI services direct access to your account credentials or unrestricted access to your workspace.

RevPulse retains completed finance questions and answers in your private conversation history, uploaded receipts in Documents, and limited operational audit records. You can delete conversation history and use the available document or account-deletion controls, subject to the retention obligations described below. You can review each feature’s permission in Settings and switch back to Ask every time to stop future automatic sharing. We record the notice version, feature, choice, and time when a saved preference changes, and log the permission used for each AI request. It cannot recall data already sent. Manual bookkeeping, invoicing and document storage remain available without AI permission. Statement extraction uploads are processed in memory. Reconciliation retains the original file checksum, reviewed transaction rows and review history; it does not store the original PDF. Keep the original statement or upload it separately to Documents as supporting evidence.

02

Introduction

RevPulse is committed to protecting personal information in line with applicable South African law, including the Protection of Personal Information Act (POPIA). This policy explains our data practices for the business-finance service.

03

Information we collect

  • Identity and contact data, including name, email, phone, address, birth information, nationality, and identity-document details.
  • Business, CIPC, tax, income, expense, invoice, client, document, banking, payment, and subscription information.
  • Native billing data, including an opaque RevPulse account identifier that is not your email address; product, package, purchase, subscription, and store transaction identifiers; purchase and subscription dates; entitlement, renewal, cancellation, refund, and revocation status; the relevant store and sandbox or production environment; and app, device, operating-system, IP, and network-request metadata needed to deliver and secure billing.
  • FICA-related details such as proof-of-address and politically exposed person declarations.
  • Device, browser, IP address, session, security, audit, and usage information needed to operate and protect the service.

04

Sensitive information

Some workflows involve financial, tax, identity, health-related tax-credit, or political-exposure information. We process these fields only for stated service, security, legal, or compliance purposes and apply access controls appropriate to their sensitivity.

05

How we use information

  • Create and secure accounts, business workspaces, memberships, and authentication sessions.
  • Provide bookkeeping, invoicing, reporting, document, estimate, email, payment, and support features.
  • Present store-localised subscription options, process and restore purchases, verify account-wide access, reconcile renewals, cancellations, refunds, and revocations, prevent fraud or duplicate subscription access, and resolve billing support or disputes.
  • Detect fraud and abuse, enforce access boundaries, troubleshoot issues, and improve reliability.
  • Meet legal obligations and communicate material service, security, billing, or policy information.

07

Sharing and disclosure

  • Vetted service providers such as hosting, storage, email, security, and payment processors receive only the information needed for their role.
  • RevenueCat provides native purchase verification and entitlement reconciliation. Apple App Store and Google Play process native charges, subscriptions, restores, refunds, and store-account management under their own terms and privacy policies. RevPulse does not receive your full card or store payment credentials.
  • Regulators, law-enforcement bodies, courts, or SARS may receive information where disclosure is lawfully required.
  • A business reorganisation may transfer information subject to appropriate safeguards and notice where required.
  • We do not sell personal information.

08

Security

We use layered technical and organisational safeguards, including encrypted transport, authentication, business-scoped authorisation, access logging, restricted administrative access, and security review. No system is risk-free, so users must also protect their email and devices.

09

Retention

We retain information only while needed for service, legal, tax, security, backup, and dispute purposes. Financial and supporting records may need to remain for statutory periods, commonly five years or longer depending on the record and obligation.

For native billing, RevPulse retains the opaque customer mapping and product, transaction, entitlement, and status records needed to provide subscription access, reconcile purchases and refunds, investigate fraud, support customers, and meet accounting, tax, legal, security, or dispute obligations. RevenueCat, Apple, and Google retain their processor records under their own policies. Account deletion does not erase records that must lawfully be retained.

10

Your rights

  • Request access to or correction of personal information.
  • Request deletion, restriction, or objection where the law permits and retention duties do not override the request.
  • Request a portable copy where applicable and withdraw consent for future consent-based processing.
  • Lodge a complaint with South Africa’s Information Regulator.

11

International processing

Some suppliers may process data outside South Africa. Where this occurs, we use lawful transfer mechanisms and contractual, organisational, or technical safeguards appropriate to the destination and service.

RevenueCat, Apple, and Google may process native billing data in countries where they or their service providers operate. Their processing is governed by their privacy terms as well as the safeguards applicable to RevPulse’s use of those processors.

12

Advertising and cross-app tracking

RevPulse does not use native billing data for advertising, advertising attribution, behavioural profiling, data brokerage, or tracking you across other companies’ apps or websites. RevenueCat advertising and attribution integrations are not enabled. Billing-related device and network metadata is used only to operate, secure, verify, restore, and support purchases and access.

13

Cookies and sessions

RevPulse uses essential cookies and similar browser storage to maintain secure sessions, CSRF protection, account preferences, and theme settings. Our basic public-page counter operates without analytics cookies.

When Google Analytics is enabled, you can choose to allow optional analytics cookies using Analytics preferences in the public-page footer. Google Analytics measures public-page visits and browser/device information. We do not send account details, financial records, form contents, or URL query strings to Google Analytics, and advertising features are disabled. Declining keeps Google Analytics unloaded; withdrawing consent stops future collection. You can change your choice at any time in the footer.

14

Children

RevPulse business services are not intended for people under 18, and we do not knowingly create business accounts for children. Contact us if you believe a child’s information was submitted improperly.

15

Changes and contact

We may revise this policy when the service or law changes and will communicate material updates through the service or by email where appropriate. Privacy questions and rights requests can be sent to privacy@solcol.co.za or dpo@solcol.co.za.