Legal & Compliance

Privacy Policy

DataRover is built on trust. This policy describes what data we collect, why we collect it, and how we protect it — across our web platform and mobile applications.

Last Updated: September 11, 2026
Version: 1.0
iOS App Android App Web Platform

01 Information We Collect

We collect information you provide directly, data generated as you use our platform, and limited technical data to keep our services running reliably. Below is a breakdown of each category.

Account Data

Name, email address, company name, job title, and password (hashed).

Financial Data

Invoices, receipts, budget figures, and financial records you upload or sync.

Usage Data

Features accessed, session duration, clicks, and in-app navigation patterns.

Device Data

Device type, OS version, app version, unique device identifiers, and crash logs.

Technical Data

IP address, browser type, referring URLs, and timestamps of service requests.

Communications

Messages you send us via email, support tickets, or our contact form.

Invoice Processing Data

When you use our automated invoice processing feature, we process documents submitted via PDF upload, image capture, email forwarding, or the DataRover mobile app. We extract structured line-item data (vendor, date, amount, description, tax) to populate your accounting records. Document images may be retained for audit purposes as described in Section 7.

AI Interaction Data

Queries you submit to the FP&A Genius conversational AI are processed to generate financial insights. These queries, along with the financial context you provide, are used to deliver your response and may be used in aggregate, anonymized form to improve model accuracy.

02 How We Use Your Data

We use the data we collect strictly to deliver, improve, and support the DataRover platform. We do not sell personal data, and we do not use financial records for advertising purposes.

  • Service delivery: Providing financial reporting, budgeting, forecasting, invoice automation, and dashboard features.
  • AI-powered analysis: Running AI models to generate insights, forecasts, and anomaly detection on your financial data.
  • Account management: Creating and maintaining your account, verifying your identity, and managing permissions within your organization.
  • Integration synchronization: Connecting to and syncing data with accounting platforms you authorize (e.g., QuickBooks, Xero, Oracle).
  • Product improvement: Analyzing aggregated, anonymized usage patterns to improve platform performance and prioritize new features.
  • Customer support: Responding to your questions, resolving issues, and providing technical assistance.
  • Security monitoring: Detecting unauthorized access attempts, fraud, and abuse of our systems.
  • Legal compliance: Meeting our obligations under applicable laws and regulations.

Our AI commitment

DataRover's AI models process your financial data to serve you — not to train general-purpose models shared with other organizations. Your financial records are never used to train models that benefit third parties.

03 Data Sharing & Disclosure

We do not sell, rent, or trade your personal information. We share data only in the limited circumstances described below.

Service Providers

We engage trusted third-party vendors who process data on our behalf — including cloud infrastructure providers, payment processors, email delivery services, and analytics tools. These vendors are contractually bound to process data only as instructed and to maintain appropriate security standards.

Authorized Integrations

When you connect DataRover to an external accounting or storage platform, we share only the data necessary to perform the sync you authorized. You may revoke these connections at any time through your account settings.

Legal Requirements

We may disclose your information if required to do so by applicable law, court order, or governmental authority — or when we believe disclosure is necessary to protect the rights, property, or safety of DataRover, our users, or the public.

Business Transfers

In the event of a merger, acquisition, or sale of substantially all of our assets, your data may be transferred to the acquiring entity. You will be notified in advance via the email address on file, and you will have the opportunity to request deletion of your data before the transfer completes.

With Your Consent

We may share data for any other purpose with your explicit prior consent.

04 Third-Party Integrations

DataRover integrates with a range of accounting, ERP, and cloud storage platforms. When you authorize a connection, data flows between DataRover and the third party under the terms of both this policy and the third party's own privacy practices.

Currently supported integrations include:

QuickBooks
Xero
Oracle
Sage
Microsoft Dynamics
M3
Microsoft Excel
OneDrive
Google Drive

We recommend reviewing each connected platform's privacy policy. DataRover is not responsible for the data practices of third-party services. You can disconnect any integration at any time from your DataRover account settings; disconnection stops future data sharing but does not affect data already synchronized.

05 Mobile Applications

The DataRover mobile app is available on Apple App Store (iOS) and Google Play (Android). The following applies specifically to our mobile applications in addition to all other sections of this policy.

Camera Access

The app may request access to your device camera to photograph invoices and receipts. Camera access is used solely for document capture and is not used to record video or access your photo library without explicit action on your part. You can manage camera permissions in your device's system settings.

Photo Library Access

If you choose to upload an existing image of an invoice or receipt, the app will request access to your photo library for that specific selection. We do not access, scan, or store your photo library beyond the image you explicitly select.

Push Notifications

We may request permission to send push notifications for invoice processing confirmations, budget alerts, and monthly close reminders. You can opt out of notifications at any time through your device's notification settings or within the DataRover app settings.

Crash Reporting & Diagnostics

To improve stability, the app collects crash reports and diagnostic logs. These reports include device model, OS version, app version, and a stack trace of the error. They do not contain your financial data or personal identifiers.

Local Data Storage

The app stores session tokens and user preferences locally on your device in encrypted storage. This data is cleared when you sign out or uninstall the application.

No Background Location Tracking

DataRover does not collect your location in the background. If any location data is ever requested in a future feature, it will require explicit permission and will be clearly disclosed.

Apple & Google platform privacy

On iOS, Apple's App Tracking Transparency framework applies. We do not request permission to track you across other companies' apps or websites. On Android, we comply with Google Play's data safety requirements and declare our data practices in the Play Store data safety form.

06 Data Security

We implement technical and organizational security measures appropriate to the sensitivity of the financial data entrusted to us. Our approach includes:

Encryption in transit

All data transmitted between your device and DataRover servers is encrypted using TLS 1.2 or higher.

Encryption at rest

Stored financial documents and user records are encrypted using AES-256 encryption.

Access controls

Internal access to production data is restricted to authorized personnel on a need-to-know basis, with authentication logs maintained.

Secure authentication

Passwords are hashed using industry-standard bcrypt algorithms and are never stored in plain text. Multi-factor authentication is available and strongly recommended.

Regular security reviews

We conduct periodic security assessments and work to identify and remediate vulnerabilities in our systems.

Incident response

We maintain a documented breach response plan. In the event of a confirmed breach affecting your data, we will notify you within 72 hours as required by applicable law.

No method of electronic storage or transmission is 100% secure. While we work diligently to protect your information, we cannot guarantee absolute security. We encourage you to use strong, unique passwords and enable multi-factor authentication on your account.

07 Data Retention

We retain your data for as long as your account is active or as needed to provide our services. When you close your account, we will delete or anonymize your personal data within 90 days, except where retention is required by law or legitimate business necessity (such as dispute resolution or regulatory compliance).

Account data

Retained for the duration of your subscription plus 90 days after account closure.

Financial records and invoices

Retained for the duration of your subscription. Upon cancellation, you may export your data at any time within a 30-day grace period before deletion.

AI query logs

Anonymized and retained for up to 12 months for model improvement; personal identifiers are removed within 30 days of query submission.

Crash and diagnostic logs

Automatically deleted after 90 days.

Backup copies

May persist in encrypted backups for up to 30 additional days following the primary deletion date.

You can request earlier deletion of your data by contacting us at the address in Section 12. We will honor deletion requests subject to legal obligations that may require us to retain certain records.

08 Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal data. To exercise any of these rights, please contact us using the details in Section 12.

Access

Request a copy of the personal data we hold about you in a portable, machine-readable format.

Correction

Ask us to update or correct inaccurate information associated with your account.

Deletion

Request erasure of your personal data (the "right to be forgotten"), subject to legal retention obligations.

Portability

Receive your data in a structured, commonly used format to transfer to another provider.

Restriction

Request that we limit the processing of your data in certain circumstances.

Objection

Object to processing based on legitimate interests, including profiling for marketing purposes.

Opt-out of AI

Request that your data not be used for AI model improvements (analytical processing to serve you will still apply).

Withdraw Consent

Where processing is based on consent, you may withdraw that consent at any time without affecting prior processing.

We will respond to verified requests within 30 days. For California residents, the CCPA grants additional rights including the right to know what personal information has been collected and sold, and the right to opt out of the sale of personal information. We do not sell personal information. For users in the European Economic Area, UK, or Switzerland, we comply with GDPR obligations and you have the right to lodge a complaint with your local supervisory authority.

09 Children's Privacy

DataRover is a professional financial planning platform designed for use by businesses and finance professionals. Our services are not directed at children under the age of 13 (or under 16 in the European Economic Area), and we do not knowingly collect personal information from minors.

If we become aware that we have inadvertently collected personal data from a child under the applicable age threshold, we will promptly delete that data and the associated account. If you believe a minor has provided us with personal information, please contact us immediately using the details in Section 12.

10 International Data Transfers

DataRover is headquartered in Jakarta, Indonesia. Your data may be processed and stored on servers located in Indonesia or in other countries where our cloud infrastructure providers operate. By using our services, you acknowledge that your information may be transferred across borders.

When we transfer data outside of the European Economic Area, we implement appropriate safeguards — such as Standard Contractual Clauses approved by the European Commission — to ensure your data remains protected to the standard required under GDPR. If you have questions about the specific safeguards in place for your data transfer, please contact our privacy team.

11 Policy Updates

We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will notify you by:

  • Sending an email to the address associated with your account at least 14 days before the change takes effect.
  • Posting a prominent notice within the DataRover web platform and mobile applications.
  • Updating the "Last Updated" date at the top of this page.

Your continued use of DataRover after the effective date of the revised policy constitutes your acceptance of the changes. If you do not agree to the updated policy, you should discontinue use of our services and may request deletion of your data as described in Section 8.

We encourage you to review this policy periodically. The most current version is always available at datarover.us/privacy-policy.

12 Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please reach out to us. We aim to respond to all privacy-related inquiries within 5 business days.

DataRover Privacy Team

Email: support@datarover.us

Website: datarover.us

For data subject requests (access, deletion, portability), please email us with the subject line "Privacy Request – [Your Request Type]" from the email address associated with your DataRover account. We may request verification of your identity before processing the request.