Skip to main content
Ezre
  • Terms
  • Privacy
  • Delete account
  • Home

Ezre Legal

Privacy Policy

This policy explains what Ezre collects, how we use it, who we share it with, and how you can manage or delete your data.

Effective date: June 22, 2026

This Privacy Policy applies to Ezre LLC, called Ezre, we, us, or our in this policy, the Ezre mobile app, the Ezre website, and related services. Contact us at alberto@ezre.app with privacy questions or requests.

1. Data We Collect

Account data

We collect your email address and store a password hash. We do not store your plain-text password. We also store email confirmation and password reset information needed to operate those flows.

Session and security data

When you sign in, we create a session token and store a token digest, expiration time, last-used time, IP address, and user agent. Sessions use a 30-day rolling expiration.

Saved card metadata

Ezre uses Stripe to save cards for receipt matching. Card entry is handled by Stripe. Ezre stores Stripe customer and payment method identifiers plus limited card metadata such as card brand, last four digits, expiration month and year, funding type, livemode status, and Stripe card fingerprint. Ezre does not store raw card numbers or CVC codes.

Receipt and purchase data

For supported merchants, Ezre receives and stores receipt data from Square, including merchant name, location name when available, transaction time, item names, item quantities, item notes, totals, tax, tip, discounts, currency, receipt number, receipt URL, provider payment and order identifiers, and limited payment details such as brand, last four digits, expiration, source type, entry method, wallet type, and provider metadata.

Receipt matching data

Ezre stores receipt match status, match confidence, match reason, your confirmation or rejection decision, and provider card identities. Square card fingerprints are stored as HMAC digests rather than raw provider fingerprints.

Merchant connection data

When a merchant connects Square, Ezre stores the provider name, Square merchant ID, merchant name, livemode status, token expiration time, and encrypted Square access and refresh tokens.

Support and deletion requests

If you contact us, request support, or request deletion by email, we collect the information you include in that message so we can respond and process the request.

Camera access

On iOS, Ezre may request camera access through the Stripe card-entry flow so you can scan payment card details when adding a card. Ezre does not use camera access for location, tracking, ads, or analytics.

2. Data We Do Not Collect

Ezre currently does not collect or use:

  • raw card numbers or CVC codes;
  • a disability-status field;
  • advertising data or advertising identifiers;
  • analytics SDK data;
  • tracking data for targeted advertising or advertising measurement;
  • push notification tokens;
  • contacts, microphone, photos, or device location; or
  • health, fitness, biometric, or government ID data.

3. How We Use Data

We use data to:

  • create, authenticate, secure, and support accounts;
  • send email confirmations, password resets, and service messages;
  • save card metadata for receipt matching;
  • receive, normalize, match, and display accessible receipts;
  • let users confirm or reject possible receipt matches;
  • operate merchant Square connections and receipt webhooks;
  • detect, prevent, and investigate fraud, abuse, and security issues;
  • respond to support and account deletion requests; and
  • maintain, debug, and improve service reliability.

4. How We Share Data

We do not sell personal data. We do not use personal data for tracking advertising. We share data only as needed to operate Ezre, comply with law, protect rights and security, or complete a request you make.

Repo-visible service providers include:

  • Stripe: card entry, customer records, setup intents, and saved payment methods.
  • Square: merchant OAuth, payment webhooks, payment details, order details, and receipt URLs for participating merchants.
  • Google Workspace SMTP: transactional email such as email confirmation and password reset messages.
  • AWS/EC2 hosting: hosting the Ezre API and persistent application data.
  • Apple and Google app platforms: app distribution, store review, and platform services as applicable.

We expect service providers that process user data for Ezre to protect that data consistently with this policy and applicable law.

5. Retention and Deletion

We keep account, card metadata, receipt, matching, and merchant connection data while needed to provide Ezre, maintain security, comply with legal obligations, resolve disputes, and operate the service.

  • Sessions use a 30-day rolling expiration.
  • Email confirmation tokens expire after 3 days.
  • Password reset tokens expire after 15 minutes.
  • Verified account deletion requests are generally completed within 30 days, unless we need to keep limited data for security, fraud prevention, legal compliance, dispute resolution, or service operations.

To delete your account, use the Ezre app under Account, then Delete account, or visit Delete account for request instructions.

6. Your Choices

  • You can remove saved payment methods in the Ezre app.
  • You can reject possible receipt matches that are not yours.
  • You can sign out to remove the local session token from your device.
  • You can request account deletion through the app or by email.
  • You can decline camera permission and enter card details without scanning.

7. Security

We use safeguards designed to protect personal data, including HTTPS, secure password hashing, session token digests, encrypted Square tokens, HMAC digests for provider card fingerprints, secure storage for native session tokens when available, and Rails parameter filtering for sensitive values. No system is perfectly secure, and we cannot guarantee absolute security.

8. Children

Ezre is not directed to children under 13. You must be at least 13 to use Ezre. If you believe a child under 13 provided personal data to Ezre, contact us and we will take appropriate steps.

9. Changes to This Policy

We may update this policy as Ezre changes. If changes are material, we will provide notice through the app, website, email, or another reasonable method. The effective date above shows when this policy last changed.

10. Contact

Email privacy questions, access requests, correction requests, deletion requests, or other inquiries to alberto@ezre.app.

© 2026 Ezre LLC. All rights reserved.

Contact alberto@ezre.app