Privacy Policy
Effective September 1, 2026
ApproveAP is operated by D3 Networks LLC, 322 S College Rd #1104, Wilmington, NC 28403, USA. This policy explains how we handle information when you visit our website, request a demo, or use the invoice approval service. If your organization has an order form or data-processing agreement with us, that agreement may contain additional terms.
Information we receive
- Account and contact information, such as names, work email addresses, company, role, authentication settings, and support messages.
- Demo-request information, including entity country, invoice volume, accounting workflow, approver count, and payment process.
- Customer content, including invoices, attachments, sender information, extracted invoice fields, coding, vendor details, approval decisions, and payment records entered after a payment happens elsewhere.
- Connected-account information from QuickBooks Online when a customer authorizes the connection, described in its own section below.
- Technical information such as IP address, device and browser data, sign-in events, security logs, and service activity.
Information may come directly from you, from your organization or its payor, from invoice emails and documents, or from a service you authorize us to connect.
How we use information
- Provide, secure, support, and improve ApproveAP.
- Receive and store invoices, extract proposed fields, remember vendor coding, route approvals, create audit evidence, and perform the accounting handoff selected by the customer.
- Authenticate users, enforce permissions, detect misuse, investigate errors, and protect customers and the service.
- Respond to demo requests, support questions, and administrative messages.
- Meet contractual, accounting, security, and legal obligations.
Depending on the context and applicable law, we process personal information to perform a contract, at the direction of a customer, for legitimate interests such as operating and securing the service, with consent, or to meet a legal obligation.
AI-assisted extraction
ApproveAP sends invoice documents to Google to extract proposed invoice fields, match a vendor, and suggest an expense account. We use a paid API tier with model training disabled, so the documents are not used to train a model. The AI does not approve invoices, initiate payments, or make a decision with legal or similarly significant effects. Every extracted figure is a proposal that traces back to the source document, and customers remain responsible for reviewing the invoice, coding, exceptions, and approval decision.
QuickBooks Online
Connecting QuickBooks Online is optional, and ApproveAP is fully usable without it. When a company administrator authorizes a connection, we request the QuickBooks accounting scope and nothing else. We do not request access to a profile, email address, phone number, or postal address held by Intuit.
We read the vendor list, chart of accounts, classes, locations, company name, accounting and currency preferences, and the bills and payments we have created, which we re-read to detect changes made inside QuickBooks. When a customer turns write-back on, we create the approved bill, attach the original invoice to it, record a bill payment after a payment is entered in ApproveAP, and create a vendor when an administrator chooses to. We write nothing else.
Access and refresh tokens are encrypted individually before storage. One customer's QuickBooks information is never shown to another customer.
When a customer disconnects, we ask Intuit to revoke the grant and we destroy the stored tokens. Vendors, accounts, classes, and locations already imported stay in ApproveAP, because they are part of that customer's own approval and audit record rather than a copy of someone else's data. A customer can ask us to delete them.
Service providers
We share information only as needed to operate the service, follow a customer's instructions, complete a business transaction, or comply with law. These are the providers that process customer information on our behalf:
- Supabase for the database, user authentication, and storage of original invoice documents.
- Netlify for application hosting.
- Resend for receiving invoice email and sending approval requests, reports, and notices.
- Google for the AI extraction described above. Invoice documents are sent to Google to be read.
- Inngest for scheduling background work. It carries record identifiers rather than invoice documents.
- Intuit for QuickBooks Online, and only when a customer authorizes that connection.
We may disclose information to advisers, auditors, authorities, or other parties when reasonably necessary to protect rights, investigate misuse, comply with legal process, or complete a merger, financing, acquisition, or sale of assets. We do not sell personal information or share it for cross-context behavioral advertising.
Retention
Demo and support information is kept only as long as reasonably needed for the request, our business records, or legal obligations. The service is designed to preserve invoices and approval events as an audit archive. Customer content is therefore retained according to the customer agreement and applicable law, including after an individual user leaves the customer organization. Backups and security logs may remain for a limited period after primary records are removed.
Security and international processing
We use administrative, technical, and organizational safeguards designed for the sensitivity of the information we process. Each customer's records are isolated from every other customer's at the database layer, an approval decision once recorded cannot be altered or deleted, and invoice documents are served only through short-lived links. No internet service can guarantee absolute security. ApproveAP and its service providers may process information in the United States and other countries. Where required, transfers are handled under appropriate contractual or legal safeguards.
Cookies and similar technology
ApproveAP uses the cookies and browser storage needed for sign-in, security, company selection, and core service operation. The public website carries no analytics and no advertising trackers. If that changes, this policy and any required consent controls will be updated first.
Your choices and rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, or portability of personal information, and to complain to a data-protection authority. Because most service information is controlled by the customer organization, we may direct a request to that organization. We may need to verify identity and may retain information when the customer agreement, an audit requirement, or law requires it.
Children
ApproveAP is a business service and is not directed to children under 18. We do not knowingly collect their personal information.
Changes and contact
We may update this policy as the service or legal requirements change. We will update the effective date and provide additional notice when required. To ask a privacy question or exercise a right, email support@approveap.com or write to D3 Networks LLC, 322 S College Rd #1104, Wilmington, NC 28403, USA.