Privacy Policy
Last Updated: September 14, 2026
DTLA Professional Services, LLC (doing business as "PayXT", and also operating Receipt Organizer XT and the "IntentXT" software products; collectively "we", "us", or "our") respects your privacy and is committed to protecting the personal and financial information of our users. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our websites (including payxt.app, scan.payxt.app, and intentxt.payxt.app), use the PayXT or Receipt Organizer XT applications, use the IntentXT Chrome extension and related dashboards, or otherwise use our services (collectively, the "Services"). Our Services are offered to users in the United States, the European Union / European Economic Area (EU/EEA), the United Kingdom, and other supported regions.
Products covered: This Policy applies to (a) PayXT — invoicing and payment-link software for independent contractors and businesses; (b) Receipt Organizer XT (also referred to as a PayXT product) — receipt scanning, bank-feed matching, expense triage, and Schedule C–ready export at scan.payxt.app; and (c) IntentXT — a B2B social intent lead finder delivered as a Chrome extension and web dashboard that helps users monitor public conversations on platforms such as Reddit, LinkedIn, and Facebook, flag leads, and generate AI-assisted reply drafts.
Data controller: For personal data processed in connection with PayXT, Receipt Organizer XT, and IntentXT, the controller is DTLA Professional Services, LLC, 770 S Grand Ave, Los Angeles, CA 90017, USA. Contact: payxt.app/contact, email support-24-7@payxt.app, or phone (213) 444-2224.
User data privacy summary. This policy covers payxt.app, scan.payxt.app (Receipt Organizer XT), the PayXT mobile app, and the IntentXT Chrome extension and dashboard. The four sections below — Collection, Handling, Storage, and Sharing — are the required user-data disclosures for Apple App Privacy / Google Play Data safety questionnaires that point to this URL. Read them first. Product-specific privacy for IntentXT is also published at intentxt.payxt.app/privacy.
Chrome Web Store Limited Use. This applies to the IntentXT Chrome extension. IntentXT's use and transfer of information received from Google APIs to any other app will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Collection
We collect account data needed to run our products, plus product-specific content you provide (for example receipt images, bank transaction data you authorize through Plaid, invoices, or public social posts for IntentXT). We do not collect bank login passwords. We do not collect private social-network messages, social-network passwords, or general browsing history unrelated to our Services.
Receipt Organizer XT (scan.payxt.app)
- Account and authentication data. Email address, display name, authentication tokens, and membership/plan status when you sign in with email and password or Google. We may use your account email to send transactional account messages (for example password-reset links).
- Receipt images and OCR results. Photos or images you capture or upload for scanning. From those images we extract structured fields such as merchant name, purchase date, total amount, suggested tax category, confidence score, and line items (description and price when readable).
- Bank / financial account data via Plaid. When you connect a financial institution through Plaid Link, we receive account metadata (for example institution name and account masks/names) and transaction data needed to match receipts (amounts, dates, merchant/descriptor text, and related transaction identifiers). Your bank username and password are entered only in Plaid’s interface and are not stored on PayXT / Receipt Organizer XT servers.
- Matching and triage data. How you classify expenses (for example Business vs Personal), payment-source choices for unmatched receipts (such as cash / out of pocket), tax categories you confirm or edit, and export/ledger selections.
- Subscription and billing data. Stripe customer and subscription identifiers and plan status for Pro membership. We do not store full payment card numbers on our servers.
- Device and usage information. IP address, browser or app type, operating system, and diagnostic logs reasonably needed to operate and secure the service. Receipt Organizer XT does not use AppsFlyer or Meta advertising SDKs.
IntentXT Chrome extension and dashboard
- Public post text you view or select. On Reddit, LinkedIn, and public Facebook groups, the extension reads the title and text of public posts that match keywords you configure, plus the post URL, platform, optional author display name shown on the page, and a short snippet.
- Company profile data you type. Company name, product description, value proposition, target pain points, and similar settings used to generate AI reply drafts.
- Account and authentication data. Email address, display or legal name, authentication tokens, and account status (including Free, Pro, promotional, or lifetime entitlements) when you sign in with email and password or Google.
- Leads you flag or that scans save. Post title, URL, platform (Reddit, LinkedIn, or Facebook), optional author, snippet, matched keyword, timestamps, and pipeline status you set.
- Monitoring settings you configure. Target keywords, negative keywords, Facebook public group URLs, Auto-Pilot on/off, and related scan preferences.
- Credits and purchases. Plan or entitlement, credit balance and usage events (for example an AI draft), and purchase or redemption identifiers needed to unlock that entitlement.
- Optional destinations you enter. A CRM or Zapier webhook URL, a Slack or Discord alert webhook URL, and a Telegram bot token and chat ID, if you turn those features on.
- Extension telemetry. Extension version, feature usage events, error and diagnostic logs, and security-related signals needed to operate and protect IntentXT. The extension does not include an advertising SDK.
PayXT invoicing app, websites, and support
- Account information. Name, email address, phone number, and business details when you create a PayXT, Receipt Organizer XT, or IntentXT account.
- Invoice and transaction data. Invoices you generate, including amounts, taxes, and dates. To facilitate payments you may connect Stripe. We do not store your clients' full credit card numbers on our servers.
- Purchase and license data. If you buy through a marketplace (for example Payhip, AppSumo, Apple, or Google) or redeem a deal or license code, we receive the order email, order identifiers, entitlement type, and redemption timestamps needed to unlock and support the purchase.
- Device, usage, and attribution information. Device identifiers (such as advertising IDs where permitted), IP address, browser or app type, operating system, app or extension version, install and open events, referral and campaign data, and how you interact with our websites and Services. Attribution partners listed below apply to the PayXT invoicing mobile app, not Receipt Organizer XT.
- Website data. On payxt.app, scan.payxt.app, and intentxt.payxt.app we collect standard server logs (IP address, browser type, referring page, and access time) and, where enabled, website analytics via Google Analytics. On intentxt.payxt.app, if you use Talk to Us or signed-in dashboard chat, we collect the messages you send in that chat.
- Support communications. Information you send by contact form, email, or phone. Because California is a two-party consent state, by calling our support lines you consent to the call being answered, recorded, transcribed, and processed by our AI assistant (Sona) for quality and support purposes.
Handling
We process the data above only to operate the features you use.
- Receipt OCR (Receipt Organizer XT). When you scan or upload a receipt, the image is sent to our secure Firebase Cloud Function. The function calls Google Gemini (Gemini Developer API, using a server-side API key that is never exposed to the client) to extract merchant, date, total, tax category suggestion, confidence, and line items. Extracted fields are saved to your account and used to match bank transactions and support tax categorization / Schedule C export. We do not use your receipt images to train our own AI models.
- Bank linking via Plaid (Receipt Organizer XT). Bank connections are established through Plaid Link. Plaid acts as our service provider for account linking. You authorize access in Plaid’s UI. We receive a temporary public token, exchange it server-side for a Plaid access token, and sync transaction data needed for matching. We do not receive or store your bank login credentials.
- Matching and triage (Receipt Organizer XT). We compare OCR fields and bank transactions (merchant/descriptor, amount, and date) to suggest matches, then store your Business/Personal (and related) triage decisions for the ledger and exports you request.
- Membership billing (Receipt Organizer XT). Stripe processes Pro checkout and subscription status. Plan limits (scans, bank connections, feed size) are enforced against your account membership record.
- AI reply drafts (IntentXT). When you request a draft, the selected public post text and your company profile are sent to our backend API. The API sends that prompt to a trusted large language model provider (Google Gemini) to generate the reply drafts you asked for. A successful draft uses one AI credit on your account. We do not use public post text or your company profile to train our own models. You remain responsible for reviewing any draft before you post it.
- Optional intent check (IntentXT). If AI intent pre-filter is on, public post title and text plus the matched keyword are sent to the same API and then to Google Gemini to decide whether the post looks like a B2B lead. That check is used only to sort Inbox versus Filtered.
- Keyword scans (IntentXT). Reddit matching runs in the extension against public Reddit content. LinkedIn and Facebook scans you start are handled by our API: we send the keyword you entered (and, for Facebook, the public group URLs you configured) to Apify so matching public posts can be retrieved, then save new leads to your account.
- Account, credits, and billing. We use your account email and authentication token to sign you in, enforce plan limits, record credit use, and fulfill Stripe, Apple, Google, or marketplace purchases and deal-code redemptions.
- Account emails (Receipt Organizer XT). When you request a password reset (and for similar transactional account messages we send), we generate a reset link with Firebase Authentication’s Admin SDK and send the email via Twilio SendGrid from noreply@payxt.app. That path does not use Firebase’s default password-reset mailer. The message includes your email address and a one-time reset link; we do not put your password in the email.
- PayXT invoicing. We use account and invoice data to generate checkout links and itemized invoices, and to pass the transaction details you initiate to your connected Stripe account. PayXT invoicing subscription status may be validated through RevenueCat and the Apple or Google store that billed the purchase.
- Alerts and CRM (IntentXT). Chrome desktop alerts stay on your device. If you configure a Slack or Discord webhook, or Telegram, a short lead alert is sent only to that destination when a match is found. Send to CRM runs only when you choose it, and posts the lead to the webhook URL you configured.
- PayXT invoicing marketing measurement. In the PayXT invoicing mobile app, AppsFlyer and Meta receive device and usage data described in the cookies section below to measure installs and in-app events, subject to your device tracking choices. This does not apply to Receipt Organizer XT.
AI prompts for IntentXT drafts/classification and Receipt Organizer XT OCR are sent to Google Gemini through the Gemini Developer API (a server API key; not Google Cloud Vertex AI), only to generate the result you requested. We do not use that content to train our own models.
Storage
Where data is stored depends on the product and feature.
- Receipt images (Receipt Organizer XT). After OCR, receipt images are typically uploaded to a dedicated Google Cloud Storage bucket and linked from your
scanned_receiptsrecords so you can review matches later. Images remain associated with your account until you delete them with your account (or they are otherwise removed as part of account deletion). OCR may still succeed if image upload fails; in that case only extracted fields are stored. - OCR and triage records (Receipt Organizer XT). Extracted receipt fields, match/triage status, tax categories, and related metadata are stored in Google Cloud Firestore under your user account (including
scanned_receiptsand pending transaction records). - Bank connection metadata (Receipt Organizer XT). Institution name, account list metadata, connection status, and sync cursors are stored in Firestore
bank_connectionsdocuments that your signed-in client can read for the product UI. Plaid access tokens are not stored in those client-readable documents. - Plaid access tokens (Receipt Organizer XT). After you authorize Plaid Link, Plaid access tokens are stored server-side in a Firestore
userSecretsdocument that is readable and writable only by our backend (Firebase Admin SDK). Client apps and Firestore security rules cannot read or write this collection. Access tokens are never returned to the client. We use them only to sync accounts/transactions and to disconnect Items when you remove a bank or delete your account. - Bank credentials. We do not store your bank login credentials on PayXT or Receipt Organizer XT servers. Credential entry and authentication with your financial institution are handled by Plaid.
- On your device (IntentXT). Company profile data, keywords, scan preferences, alert and CRM webhook settings, Telegram bot token and chat ID, and a local copy of your leads are stored in the extension's local storage (
chrome.storage.local) on your browser profile. We do not sync that profile to Chrome Sync. - In our database (IntentXT). Flagged leads and leads saved from scans are stored in Google Cloud Firestore, tied to your account user ID, so the extension and dashboard can show the same pipeline. Typical lead fields are title, URL, platform, optional author, timestamps, and status.
- Account and credits. Sign-in records are stored in Firebase Authentication. Entitlement, credit balance, membership, and usage events are stored in Firestore.
- PayXT invoicing records. Account details and invoice and transaction records you create are stored in our Google Cloud / Firebase database. Full payment card numbers are processed by Stripe (or by Apple or Google for in-app subscriptions), not stored on our servers.
- AI prompts. Content sent to Google Gemini is transmitted to produce the OCR result, draft, or classification you requested. We do not keep a separate product archive of every prompt beyond what is needed to return the result, operate the service, and (where applicable) record credit or scan usage.
Sharing
User data is never sold. We do not sell, rent, or trade personal information, receipt images, bank transaction data, lead pipelines, company profiles, or public post text to data brokers or advertisers for their own marketing. Data is shared with the processors listed below solely to run the product you are using.
- Plaid — Receipt Organizer XT bank account linking and transaction sync. You authorize Plaid via Plaid Link; we receive account/transaction data and store Plaid access tokens server-side as described above, not your bank password. Plaid End User Privacy Policy.
- Google Gemini (Google AI) — (a) Receipt Organizer XT: receipt images you submit for OCR extraction; (b) IntentXT: public post text and company profile fields you submit for a reply draft or intent check — only to generate that result. Google Privacy Policy.
- Google Cloud / Firebase — hosts our APIs, authentication, databases, Cloud Functions, and Cloud Storage for PayXT, Receipt Organizer XT, and IntentXT. Firebase Privacy.
- Twilio SendGrid — Receipt Organizer XT transactional account emails (for example password-reset messages) sent from noreply@payxt.app. Your account email address and the content of that message are processed by SendGrid solely to deliver the email. This is separate from Firebase’s default authentication email delivery. Twilio Privacy Notice.
- Apify — the keyword, and for Facebook the public group URLs you configured, when you run an IntentXT LinkedIn or Facebook scan so public matching posts can be retrieved. We do not send your company profile or CRM settings to Apify. Apify Privacy Policy.
- Stripe — payment and transaction details you initiate in PayXT invoicing, Receipt Organizer XT Pro membership, and payment details if you buy IntentXT Pro on our site. We do not store full card numbers. Stripe Privacy Policy.
- Payhip and similar marketplaces (including AppSumo) — order email and entitlement data if you purchase through that marketplace, so we can unlock your plan. Payhip Privacy Policy.
- RevenueCat — PayXT invoicing in-app subscription status across iOS and Android (not used by Receipt Organizer XT). RevenueCat Privacy Policy.
- Apple and Google — in-app purchases and subscriptions billed by those stores for apps we distribute there, under their store terms.
- AppsFlyer and Meta — device and usage data from the PayXT invoicing mobile app to measure installs and in-app events, as described in the cookies section below. Receipt Organizer XT and IntentXT extension lead contents are not sent to these partners.
- Google Analytics — website usage on payxt.app and intentxt.payxt.app (page views and similar analytics), where enabled. Extension lead contents and receipt images are not sent to these tags. Google Privacy Policy.
- Tawk.to — chat messages you send via IntentXT Talk to Us or signed-in dashboard support chat. Tawk.to Privacy Policy.
- Webhook destinations you configure (IntentXT) — data is shared only with the HTTPS webhook URL you enter, and only when you use that feature. Send to CRM posts platform, title, URL, author if available, matched keyword, snippet, and date found. Slack or Discord alerts post a short lead alert to the webhook you configure. Telegram receives a short lead alert only if you enter a bot token and chat ID.
- Legal obligations — if we are required to disclose information to comply with applicable law, governmental requests, a judicial proceeding, court order, or legal process.
IntentXT processes public data natively visible via your browser or retrieved via third-party infrastructure (Apify). We are not liable for actions taken by third-party social networks against your account for utilizing automated keyword monitoring tools.
The numbered sections below add detail on cookies, legal bases, retention, your rights, and how to contact us. They do not narrow the statements in Collection, Handling, Storage, and Sharing.
1. Information We Collect
We collect information that you voluntarily provide to us when you register for a Service, express an interest in obtaining information about us or our products, purchase a license or subscription, or otherwise contact us. The personal information that we collect depends on the context of your interactions with us and which product you use.
1.1 Information common to our Services
- Account Information: Name, email address, phone number, and business details when you create an account.
- Communications & Support: We collect personal information when you contact us. Because California is a "two-party consent" state, by calling our support lines, you explicitly consent to your call being answered, recorded, transcribed, and processed by our AI assistant (Sona) for quality and support purposes.
- Device, Usage & Attribution Information: Device identifiers (such as advertising IDs where permitted), IP address, browser or app type, operating system, app/extension version, install/open events, referral and campaign data, and how you interact with our websites and Services. We use this to improve performance, resolve bugs, measure marketing effectiveness, and attribute downloads and in-app or in-product events to advertising campaigns.
- Purchase & License Data: If you buy through third-party marketplaces (for example Payhip, AppSumo, Apple, or Google) or redeem a deal/license code, we may receive order email, order identifiers, entitlement type (including lifetime or promotional access), and redemption timestamps needed to unlock and support your purchase.
1.2 PayXT invoicing-specific information
- Financial & Gateway Data: To facilitate payments, you may connect Stripe (and related merchant tools). We do not store your clients' full credit card numbers on our servers. Sensitive payment processing is handled by your connected Stripe merchant account.
- Transaction Data: Information about the invoices generated, including transaction amounts, taxes applied, and dates.
1.3 Receipt Organizer XT-specific information
When you use Receipt Organizer XT (web app at scan.payxt.app and related mobile builds), we may collect and process:
- Receipt images & OCR fields: Images you capture or upload; extracted merchant, date, total, suggested tax category, confidence, and line items; and Storage links to retained images used for review and matching.
- Bank linking via Plaid: Institution and account metadata and transaction feed data you authorize through Plaid. Bank login credentials are not collected or stored by us; Plaid handles credential entry. Plaid access tokens are stored only in server-side secrets inaccessible to clients.
- Expense triage & tax categorization: Business/Personal (and related) decisions, payment-source choices, category labels, and export selections for Schedule C–ready CSVs.
- Membership: Stripe-managed Pro subscription status and plan limits.
- Account emails: Password-reset (and similar transactional) messages may be sent via Twilio SendGrid from noreply@payxt.app, as described in Sharing above—not via Firebase’s default authentication mailer.
Important for financial / OCR app review: Receipt Organizer XT is a productivity tool for organizing receipts and bank-backed expenses. It is not a bank, money transmitter, or tax-preparation firm. OCR and matching suggestions can be imperfect; you remain responsible for verifying extracted data and tax classifications before filing.
1.4 IntentXT-specific information
When you use IntentXT (Chrome extension, website, or dashboard), we may collect and process:
- Account & authentication data: Email, display/legal name, authentication tokens, and account status (including Free, Pro, promotional, or lifetime entitlements).
- Company profile you provide: Company name, product description, value proposition, target pain points, and similar settings used to generate AI reply drafts.
- Keyword & monitoring configuration: Target keywords, negative keywords, Facebook public group URLs you configure, and related scan preferences (for example Auto-Pilot settings).
- Lead / pipeline data you save: Information about social posts you choose to flag or sync, which may include post title or snippet, post URL, platform (Reddit, LinkedIn, Facebook), timestamps, optional author fields when available, and lead status you set in the dashboard. IntentXT is designed to help you work with publicly available social content that you select; we do not claim to operate those third-party social networks.
- AI drafting inputs/outputs: Content needed to generate short reply drafts (for example your company profile and selected post context). Drafts are generated to assist you; you remain responsible for reviewing and posting any reply.
- Extension / product telemetry: Extension version, feature usage events, error/diagnostic logs, and security-related signals reasonably necessary to operate and protect IntentXT.
Important: IntentXT is not a full CRM. It focuses on social intent capture and reply assistance. Third-party platforms (Reddit, LinkedIn, Facebook, and others) have their own terms and privacy policies; your use of those platforms remains subject to their rules.
2. Cookies, Analytics, and Marketing Measurement
We use cookies, pixels, SDKs, web beacons, local storage, and similar technologies on our websites and in our mobile App / browser extension to operate the Services, understand usage, measure advertising performance, and improve PayXT and IntentXT.
2.1 Website analytics
On payxt.app and intentxt.payxt.app we may use Google Analytics / Google Tag Manager (or similar tags) to analyze website traffic, monitor aggregate user behavior, and understand how our pages are used. Our hosting infrastructure may also collect standard server/log data (IP address, browser type, referring pages, and access times) for security, performance, and diagnostics.
2.2 Mobile attribution and advertising analytics (AppsFlyer & Meta)
In the PayXT invoicing mobile App we use third-party measurement and advertising partners to track app marketing performance, installs/downloads, opens, and related in-app conversion events (for example trial starts and subscription-related events), including:
- AppsFlyer: Mobile attribution and analytics to measure which campaigns, ads, and channels drive app installs and key in-app events, and to help us optimize marketing spend and performance reporting.
- Meta (Facebook) SDK / App Events and related Meta advertising technologies (sometimes called Meta Pixel in web contexts): Used to measure and optimize ads on Meta platforms (including Facebook and Instagram), log app events, and support advertising analytics and retargeting where permitted by law and platform settings.
These partners may receive or process device and usage data such as advertising identifiers (IDFA on iOS when authorized; GAID on Android), IP address, device model, OS version, app events, and campaign/attribution parameters. On iOS, certain advertising tracking is subject to Apple’s App Tracking Transparency (ATT) prompt. If you deny tracking permission, we limit or disable advertiser tracking features accordingly (for example Meta Advertiser Tracking), though some limited measurement or aggregated reporting may still occur as allowed by Apple, Google, and applicable law.
For more information about how these partners process data, see their policies:
- AppsFlyer: AppsFlyer Privacy Policy
- Meta: Meta Privacy Policy
- Google Analytics: Google Privacy Policy
2.3 Cookie Policy
This Cookie Policy explains how PayXT, IntentXT, and our partners use cookies and similar technologies on our websites and, where applicable, analogous identifiers in our App or extension.
What are cookies? Cookies are small text files stored on your device when you visit a website. Similar technologies include pixels, tags, local storage, and mobile SDKs that store or access identifiers on your device.
We (and our service providers) may use the following categories:
- Strictly necessary: Required for basic site/app security, load balancing, and core functionality.
- Performance / analytics: Help us understand traffic and usage (for example Google Analytics on the website).
- Advertising / marketing measurement: Help us measure ad campaigns, attribute installs and conversions, and improve marketing performance (for example AppsFlyer and Meta technologies in the App, and any advertising tags we may use on the website).
Your choices:
- Browser cookies: You can usually block or delete cookies in your browser settings. Blocking cookies may affect some website features.
- iOS tracking: Use the system App Tracking Transparency prompt and Settings → Privacy & Security → Tracking to control cross-app tracking.
- Android advertising ID: You can reset or limit your advertising ID in your device’s Google/ads settings.
- Opt-out resources: Industry tools such as the Digital Advertising Alliance opt-out (where available) and partner-specific controls linked above.
Where required by law (including in the EU/EEA and UK), we treat certain analytics and advertising cookies/identifiers as optional and will obtain consent or honor opt-out/objection rights as applicable before using non-essential cookies or similar technologies.
Our website does not currently alter its practices or respond to browser "Do Not Track" (DNT) signals because no uniform technological standard has been established.
3. How We Use Your Information
We use the information we collect or receive for the following business purposes:
- To facilitate account creation and logon processes for PayXT, Receipt Organizer XT, and IntentXT, including sending transactional account emails such as password-reset messages for Receipt Organizer XT via Twilio SendGrid from noreply@payxt.app.
- PayXT invoicing: To generate secure checkout links and itemized invoices for your clients, and to securely pass transaction data to your authorized payment gateways (Stripe).
- Receipt Organizer XT: To OCR receipt images, sync authorized bank transactions via Plaid, suggest and store matches, support Business/Personal triage and tax categorization, enforce membership limits, and export ledgers you request.
- IntentXT: To provide keyword monitoring, lead flagging/pipeline features, entitlement/license validation, and AI-assisted reply drafts based on settings and content you provide.
- To respond to user inquiries and offer customer support (including via email, phone/SMS, and contact forms).
- To measure marketing performance, attribute downloads/installs and key in-app or in-product events, analyze campaign effectiveness, and improve our advertising (including via AppsFlyer and Meta for the PayXT invoicing mobile App).
- To enforce our terms, conditions, and policies for business purposes, legal reasons, and contractual obligations; and to protect the security and integrity of our Services.
4. How We Share Your Information
User data is never sold. The definitive third-party statement is in Sharing above. We only share information with your consent, to comply with laws, to provide you with services, to protect your rights, or to fulfill business obligations. Specifically, we may share data with:
- Bank linking (Plaid): For Receipt Organizer XT, Plaid processes account linking and provides transaction data under your authorization. We do not share your bank password with Plaid from our servers because we never receive it.
- Payment Processors & Marketplaces: For PayXT invoicing and Receipt Organizer XT Pro, we transmit necessary details to Stripe. For IntentXT purchases sold via third-party marketplaces (e.g., Payhip), those marketplaces process checkout under their own policies; we receive what is needed to fulfill and support your order/entitlement.
- Cloud Infrastructure: We use enterprise-grade cloud service providers (such as Google Cloud/Firebase) to host our databases, Storage, and secure server functions for PayXT, Receipt Organizer XT, and IntentXT.
- Transactional email (Twilio SendGrid): For Receipt Organizer XT, password-reset and similar account emails are sent via Twilio SendGrid from noreply@payxt.app (not Firebase’s default mailer). SendGrid receives the recipient address and message content needed to deliver that email.
- AI / Model Providers: For Receipt Organizer XT OCR and IntentXT reply drafting/intent checks, we send limited images or prompts/context to trusted AI providers (Google Gemini / Google AI services) solely to generate the requested result. User data is never sold.
- Analytics & Attribution Partners: AppsFlyer and Meta (Facebook/Instagram advertising and measurement tools), as described in Section 2, to measure installs, app events, and marketing performance (primarily for the PayXT invoicing mobile App; not Receipt Organizer XT).
- Website Analytics: Google Analytics / Google tags for website usage analysis where enabled.
- Subscription Management: For PayXT invoicing mobile subscriptions, we may use RevenueCat to manage and validate in-app subscription status across iOS and Android. Receipt Organizer XT Pro uses Stripe. IntentXT may use Stripe and/or license/deal-code systems for Pro and lifetime entitlements.
- Legal Obligations: If we are legally required to do so in order to comply with applicable law, governmental requests, a judicial proceeding, court order, or legal process.
5. Data Security
We have implemented appropriate technical and organizational security measures designed to protect the security of any personal information we process. Sensitive credentials are transmitted and stored using industry-standard protections. For Receipt Organizer XT, bank login credentials are never stored on our servers; Plaid access tokens are kept in a server-only secrets collection that client applications cannot read, and are not stored alongside client-readable bank connection metadata. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure.
6. Third-Party Websites and Services
Our Services may generate links to third-party payment gateways (such as checkout.stripe.com), integrate third-party SDKs and services (including Plaid, AppsFlyer, Meta, Google, Stripe, RevenueCat, Twilio SendGrid, and AI providers), and interact with third-party social platforms (such as Reddit, LinkedIn, and Facebook) when you use IntentXT. We cannot guarantee the safety and privacy of data you provide directly to any third parties. Data collected by third parties is governed by their own privacy policies. We are not responsible for the content or privacy and security practices of those third parties, including financial institutions you link via Plaid or social networks you browse or post on.
7. Legal Bases for Processing (EU/EEA and UK)
If you are in the EU/EEA or UK, we process personal data under the EU General Data Protection Regulation (GDPR) and UK GDPR, as applicable, on one or more of the following legal bases:
- Contract: Processing necessary to provide the PayXT, Receipt Organizer XT, or IntentXT service you request (account creation, invoicing features, receipt OCR, Plaid-connected bank feeds, Stripe Connect or subscription onboarding support, subscription/entitlement checks, lead pipeline features, AI draft generation you request).
- Legitimate interests: Improving security, preventing fraud/abuse, diagnosing technical issues, understanding product usage in a privacy-respecting way, and operating our business—balanced against your rights and expectations.
- Consent: Where required for non-essential cookies, certain advertising/measurement technologies (including AppsFlyer and Meta features that rely on tracking permissions), or optional communications. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
- Legal obligation: Where we must retain or disclose information to comply with applicable law, tax, accounting, or regulatory requirements.
8. Your Privacy Rights (including EU/EEA, UK, and California)
Depending on your location, you may have rights regarding your personal information.
8.1 EU/EEA and UK (GDPR / UK GDPR)
If you are in the EU/EEA or UK, you may have the right to:
- Access your personal data and obtain a copy.
- Rectify inaccurate or incomplete personal data.
- Erase personal data (“right to be forgotten”) in certain circumstances.
- Restrict or object to certain processing, including processing based on legitimate interests and processing for direct marketing.
- Data portability (receive data you provided in a structured, commonly used, machine-readable format, where technically feasible).
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with your local supervisory authority (for example, your EU Member State data protection authority, or the UK Information Commissioner’s Office).
We will respond to GDPR requests within the timeframes required by law (generally within one month, extendable where permitted).
8.2 California and other US state laws
Depending on your state (e.g., California CCPA/CPRA), you may have the right to:
- Request access and obtain a copy of your personal information.
- Request rectification or erasure of your personal data.
- Restrict the processing of your personal information.
- Opt out of certain “sale” or “sharing” of personal information for cross-context behavioral advertising, including by adjusting device tracking settings or contacting us.
To exercise these rights, contact us using the information in Section 14. We will consider and act upon any request in accordance with applicable data protection laws. We will not discriminate against you for exercising privacy rights.
9. Account and Data Deletion
You have the right to request the complete deletion of your PayXT, Receipt Organizer XT, and/or IntentXT account and associated personal data.
Receipt Organizer XT (in-app)
In Receipt Organizer XT, open Settings → Billing, then use the Danger zone → Delete account controls. For email/password accounts you must re-enter your password and type DELETE to confirm. That calls our authenticated deleteAccount Cloud Function, which permanently deletes (for your user ID): pending transactions, scanned receipts (OCR metadata), bank connections, your user profile document, server-side userSecrets (including Plaid access tokens), receipt images under your Storage prefix, and your Firebase Authentication user. Active Stripe Pro subscriptions should be canceled via Manage membership first if applicable. Google-only accounts without a password cannot complete the password-gated in-app flow; sign in with email/password if available, or contact us at support-24-7@payxt.app to close the account.
PayXT invoicing and IntentXT
For PayXT invoicing, you can delete your account directly within the PayXT mobile app settings, or request deletion via our contact form or data deletion page. For IntentXT, request deletion via payxt.app/contact or email support-24-7@payxt.app, and identify the product and account email. Upon request, we will permanently delete your account and remove associated personal data from our active systems within 30 days, subject to legal and tax retention requirements. Deletion of your account may not automatically delete data already processed by independent third parties (such as Plaid, AppsFlyer, Meta, Google, Stripe, Apple, RevenueCat, Payhip, or social platforms); you may need to exercise rights directly with those providers where available.
10. Data Retention
We retain personal data only as long as needed for the purposes described in this Policy, including to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. Typical retention practices include:
- Account data: Kept while your account remains active, then deleted or anonymized within approximately 30 days after account deletion, unless longer retention is required by law. Receipt Organizer XT in-app deletion removes active account data immediately as described in Section 9.
- Receipt Organizer XT receipts & bank feed: Receipt images, OCR records, bank connection metadata, pending transactions, and server-side Plaid tokens are retained while your account is active so you can match, triage, and export; they are wiped with account deletion as described above.
- PayXT invoicing transaction / invoice records: May be retained longer where needed for tax, accounting, fraud prevention, or legal claims.
- IntentXT lead pipeline & configuration: Retained while your account is active so you can use the product; deleted or anonymized with account deletion requests subject to backups and legal holds.
- Analytics and marketing measurement data: Retained according to our analytics partners’ retention settings and our business needs, typically in aggregated or pseudonymized form where practicable.
- Support communications: Retained as needed to handle your request and improve support quality.
11. International Data Transfers
DTLA Professional Services, LLC is based in the United States. If you use PayXT, Receipt Organizer XT, or IntentXT from the EU/EEA, UK, or other regions, your personal data may be transferred to and processed in the United States and other countries where our service providers operate (including Google/Firebase, Plaid, Stripe, and AI providers). Those countries may not provide the same level of data protection as your home country.
Where required by GDPR/UK GDPR, we rely on appropriate transfer safeguards, such as the European Commission’s Standard Contractual Clauses (SCCs) and/or the UK International Data Transfer Agreement / Addendum, and additional technical and organizational measures as appropriate. By using the Service from outside the United States, you acknowledge these transfers subject to applicable law and your rights described above.
12. Children
PayXT, Receipt Organizer XT, and IntentXT are business productivity applications intended for adults and business users. They are not directed to children under 16, which is the age boundary we apply for EU/UK GDPR. We do not knowingly collect personal data from children under 13, the US Children's Online Privacy Protection Act (COPPA) threshold, and we do not knowingly collect personal data from children under 16. If you believe a child has provided us personal data, contact us and we will take steps to delete it.
13. App Store, Google Play, and Extension Distribution
PayXT and Receipt Organizer XT may be distributed through the Apple App Store and Google Play (and Receipt Organizer XT is also available on the web at scan.payxt.app). In addition to this Privacy Policy and our Terms of Service, your download and use of those apps may also be subject to the platform provider’s terms:
- Apple Licensed Application End User License Agreement (Standard EULA): If you download from the Apple App Store, your use of the iOS app is also governed by Apple’s standard Licensed Application End User License Agreement, available at https://www.apple.com/legal/internet-services/itunes/dev/stdeula/.
- Google Play: If you download from Google Play, your use of the Android app is also subject to the Google Play Terms of Service. Google’s collection and use of information is described in the Google Privacy Policy. Our own data practices for store-distributed apps are described in this Privacy Policy, which is the privacy policy URL we provide for Apple App Privacy and Google Play User Data / Data safety questionnaires (see also Google Play’s User Data policy).
In-app purchases and subscriptions billed by Apple or Google are handled according to their store rules. Refunds for those store-billed subscriptions are handled by Apple or Google, not directly by us, except where required by applicable law. Receipt Organizer XT Pro membership billed via Stripe is managed through Stripe Customer Portal / in-app billing controls.
IntentXT is distributed as a Chrome extension and web product (including via direct download packages and third-party marketplaces such as Payhip). Browser vendors and marketplace operators have their own terms. Purchases and refunds made through a marketplace are subject to that marketplace’s buyer policies in addition to these Terms and this Privacy Policy.
Changes
If our practices change, we will update this page and the “Last Updated” date. If we make material changes to this policy, we will notify you via the email address associated with your account or through a prominent notice inside the applicable App, Chrome Extension, or Dashboard prior to the change taking effect. Continued use of PayXT, Receipt Organizer XT, or IntentXT after the updated date means the updated policy applies. The live policy is always at https://payxt.app/privacy.
14. Contact Us
If you have questions or comments about this Privacy Policy, wish to exercise privacy rights (including GDPR requests), or need help with account/data deletion for PayXT, Receipt Organizer XT, or IntentXT, contact us:
DTLA Professional Services, LLC
PayXT · Receipt Organizer XT · IntentXT
770 S Grand Ave
Los Angeles, CA 90017
United States
Phone / SMS: (213) 444-2224
Email: support-24-7@payxt.app
Contact form · Data deletion · Receipt Organizer XT · IntentXT site