1. Who we are
ReceiptRoller Inc. operates Connected and is responsible for the personal information described in this policy. Connected is a professional networking service for exchanging a business profile and managing one-to-one connections. This policy applies to the Connected website, API, and mobile app when available. It does not govern the separate websites or privacy practices of Google, Apple, or another external service.
2. Information we handle
- Sign-in and account data: the identity provider you use, its stable account identifier, and a name supplied by that provider if available. We issue Connected access and refresh tokens. We do not ask you to create a Connected password.
- Profile and exchange data: your display name, headline, company, department, title, work email, phone number, products or services and related links that you choose to enter; your exchange card code and the limited card preview.
- Images and scanned cards: profile photos, images attached to one-to-one messages, and business-card images you choose to retain. When you request a scan, we store an editable extraction draft even if you choose not to retain the original image. The draft may contain another person's name, employer, role, and contact details. Scanned cards are private to the scanning account and are not verified Connected identities.
- Relationship and in-app chat data: connection requests and status, your work-sharing choices, notes you write about a connection, in-app relationship notices, and messages and read status in one-to-one conversations.
- Technical and support data: information needed to operate and protect the website and API, such as request times, IP address and device/browser information that hosting or security systems may process; and information you provide when contacting us.
We receive profile information primarily from you, sign-in claims from your chosen identity provider, and connection requests from other Connected users. Please do not put sensitive personal information in profile fields, notes, or messages unless it is necessary and you are authorized to do so. Only scan or upload someone else's card when you are entitled to use it for your professional contact records.
3. How we use information
We use information to authenticate accounts, show and update profiles, enable card exchange and connection requests, apply your sharing choices, show your private notes and notices, prevent abuse, secure and troubleshoot the service, respond to inquiries, and meet legal obligations. We do not sell your profile data or use it for an advertising feed.
4. Who can see your information
Exchange links are shareable. Anyone with a valid card link can access a limited preview containing your display name and an internal person identifier. A card link does not itself reveal your work email, phone number, services, or private notes. You can rotate the code to invalidate the previous link.
When you accept a connection, the current work profile is initially shared with that connection. For later updates to work details or services, you choose which active connections can see the updated information. You may stop sharing your work information with an individual connection or end the connection entirely. Each person can choose whether the other receives an in-app notice when a connection is ended. Private relationship notes are visible only to the person who wrote them.
Information that someone already viewed, copied, or saved outside Connected may remain with them after you change sharing settings or delete your account. Other users are responsible for their own handling of that information.
5. Service providers and other disclosures
We use Microsoft Azure to host the API, database, and private image storage. When you ask Connected to read a business card, the image is sent to OpenAI's API to extract text into an editable draft. Connected requests that OpenAI not store the API response as application state; OpenAI may still process and retain data for safety and abuse monitoring under its API policies. Do not use card scanning if you do not want the image sent to OpenAI.
Before publishing a one-to-one message, message image or caption, profile details (including name, work and contact fields, and services), or profile photo, Connected sends the submitted text and/or image to OpenAI's Moderation API for an automated safety check. This applies even to messages sent in a private conversation. OpenAI may process that information outside Japan under its API policies. If you do not want a particular item sent to OpenAI for this check, do not submit it to those features.
AB Support (ActionBridge) provides the contact-form ticket system and support chat. When you submit the form or use chat, AB Support receives the information you enter and technical data needed to operate those features. If you choose Google or Apple sign-in, that provider handles your authentication under its own terms and privacy notice. The landing page loads fonts from Google, so a visit to that page may result in a request to Google's font service. We may disclose information to service providers that help us operate Connected, to comply with law or a valid legal process, or to protect the rights and safety of users and the service. We do not grant service providers permission to use your information for their own advertising.
6. Retention and deletion
We keep account, profile, relationship, and in-app chat information while your account is active or as needed to provide the service. For each business-card scan you choose whether the original image is retained in private storage. If you choose not to retain it, Connected sends it for extraction but does not save it in its image storage. The extracted draft is saved until you delete that scan or your account. You can delete a scan and any retained image through the app API. Profile and chat images are kept while needed for those features. Connected provides an authenticated account-deletion API; the mobile app will make that action available in-app before public release. If you cannot access the app, use the account deletion request form. Staff verify ownership before manually deleting an account. The form stores your submitted name, email, message, request status and an internal review memo in Connected's database. We also attempt to create an AB Support ticket for follow-up. The name, email and message in the Connected request record are removed when the request is completed; limited decision and account-deletion audit records remain. Deleting an account removes its Connected profile, card, account, associated connection records and in-app messages from active storage, including messages in shared conversations. Related private images are queued for deletion from storage and automatically retried if storage is temporarily unavailable. Support tickets and support-chat conversations are handled separately in AB Support and may need to be addressed in a privacy or deletion request. Limited operational logs, backups, or records required for legal or security reasons may remain until their normal retention period ends.
Ending a connection is different from deleting your account. Ending work sharing hides your current work information from that connection but leaves in-app chat open. Ending the full connection stops new messages and work sharing, while both participants can still view the prior in-app chat history and attachments. Neither action can remove copies another person made outside Connected.
7. Your choices and privacy requests
You can edit your profile, select which active connections receive work updates, rotate your exchange code, end sharing or a connection, and delete your account. Depending on applicable law, you may also ask us to access, correct, delete, or restrict the use of your personal information. Use our contact form for a privacy request or complaint. We may need to verify that a request comes from the account holder before acting on it, and will respond according to applicable law.
8. Security and international access
We use access controls, encrypted connections, and other reasonable safeguards to protect personal information. No service can guarantee absolute security. Our company is based in Japan, and service providers or users may access or process information from other countries. Where cross-border processing occurs, we take steps required by applicable law. For details about our security measures or processing locations, please contact us.
9. Children
Connected is designed for professional use and is not directed to children. If you believe a child has provided personal information to Connected, please contact us so we can review and address the situation.
10. Changes to this policy
We may update this policy as the service changes. We will post the revised version here with a new effective date and provide additional notice where required by law. New features such as trade-show scheduling will be described before those features are released.
11. Contact
ReceiptRoller Inc.
1535 Kawakami, Iizuna Town, Kamiminochi District, Nagano Prefecture 389-1226, Japan
receiptroller.co
For account deletion, use the deletion request form. For other questions or a privacy request, use the Connected contact form.
12. Push notifications
If you enable push notifications in the mobile app, we store an app installation identifier, an Apple Push Notification service (APNs) device token, and whether the app uses Apple's sandbox or production service. We send that token and a generic notification to Apple so it can alert your device to a new message, connection request, acceptance, or relationship notice. Connected does not include message text or the sender's name in the push alert. The notification includes a connection identifier so the app can open the relevant screen. You can turn off notifications in your device settings; the mobile app can also unregister its token when you sign out.
13. Reports, blocks, and moderation
We check submitted messages, message images and captions, profile details, and profile photos before they become available to others. An automated check may reject an item; when checking is temporarily unavailable, we do not publish it and you can try again. Automated decisions can be mistaken. You can revise the item or use our contact form to ask us to review a rejection. For rejected or unavailable checks, we keep an event record with the content type, outcome, any flagged categories, a provider request identifier when available, and an account reference. We do not save the rejected text or image in that event record. The account reference is removed from these records on account deletion.
You may block another Connected member or report a message, profile, or connection. We store your block choices and reports, including your reason, optional explanation, a snapshot of reported content, and a private copy of a reported image when available. Authorized ReceiptRoller personnel may review reports, record an outcome, and suspend an account. Reports and moderation records may be retained after an account is deleted when needed to investigate abuse, protect users, or meet legal obligations; identifying account references are removed from the active account record on deletion where feasible. Access to this information is restricted to authorized personnel. Blocking prevents new connection requests and messages between the two people, but both may continue to read their earlier chat history and attachments. The person you block does not receive a block notification.
14. Administrative access to messages
Authorized ReceiptRoller administrators can search and read one-to-one message text and view attached images, including conversations that have not been reported, to investigate abuse, respond to support or safety concerns, and protect the service. They can also review an image copy saved as part of a report. This access is limited to administrators, and searches, conversation views, and image views are logged. We do not use private messages for advertising. Please avoid sharing sensitive personal information in Connected chat unless necessary.
15. Sign in with Apple credentials
When you send an Apple authorization code to Connected during sign-in, we exchange it with Apple and store the resulting Apple refresh token in encrypted form so that we can revoke your Apple authorization when you delete your Connected account. The token is not shown to other users. On deletion, we request revocation from Apple and remove the stored token with your account. For an older account that has no stored Apple token, we may need a fresh Apple authorization code or ask you to remove Connected's authorization manually in your Apple account settings. We do not use Apple tokens for advertising.
16. Website analytics
On the landing, help, legal, and convention pages, we offer optional Google Analytics 4 to understand page visits and improve the site. Its measurement tag is loaded only after you choose “Accept” in the website analytics notice. If enabled, Google may receive page URLs and visit events, along with browser, device, and network information, and may set first-party analytics cookies such as _ga. We do not intentionally send Connected profile details, private messages, or contact-form contents as analytics events. We do not use this tag for advertising personalization.
Your choice is stored in your browser's local storage so it can be remembered. Choose “Reject” to continue without loading the analytics tag. You can reopen the notice using “Cookie settings” at the bottom of any public page and change your choice. Withdrawing consent stops future analytics loading after the page refreshes and attempts to remove analytics cookies from this site. Browser or device settings can also clear stored choices and cookies. Google processes analytics data under its own privacy policy.
17. Organizer accounts and event spaces
Organizer sign-in uses a verified Google identity and a secure browser session cookie. We use the verified email in that session to check staff invitations. We store organization names, membership roles, invited email addresses, invitation expiry and acceptance status, and event information entered by organizers. Invitation secrets are stored as hashes; we do not automatically email invitations.
Organization owners can see team names, roles, and pending invited addresses. Authorized team members can access their organization's event information; published and ended event information is public. Organizer account deletion removes that account's membership, while shared organization and event records remain. Contact us about ownership or organization records before deleting an owner account, or to request removal of invitation data. Private organizer pages do not load Google Analytics.
Event registration shares your entered attendee name and verified Google email with the authorized event team for registration and entry. We store ticket selections, registration/payment status, random entry-pass codes, check-in time and staff reference. Payment card details are collected by Stripe, not Connected. Saving an entry pass allows offline display; staff camera frames are processed locally and are not uploaded. Unconfirmed scans are temporarily retained in that browser session for retry. Account deletion removes attendee name/email/account links and revokes passes; anonymous financial records remain for accounting, refund and reconciliation. Deleting an account does not automatically refund paid tickets. Registration does not consent to sponsor messages.