Legal
Privacy Policy
1. Scope
This Privacy Policy explains how PuraFi (“PuraFi,” “we,” “us”) collects, uses, and protects information when you use our payments platform, websites, and related services (the “Services”). It applies to companies that use PuraFi, their employees and approvers, and visitors to our websites. It also covers the PuraFi Expense Agent, our free expense-reporting service used through AI assistants such as ChatGPT; Section 5 describes it in detail.
2. Information we collect
- Account & identity data, name, work email, role, and authentication details used to provision access.
- Company & financial data, organization details, payment instructions, expense and bill records, and statement data needed to operate the Services.
- Payment-card & banking data, handled through our regulated payment and custody partners under their own onboarding and verification; PuraFi limits its own access to what is needed to operate. This category applies to the payments platform only — the PuraFi Expense Agent does not collect, process, or store payment-card or bank-account information.
- Usage & device data, log data, device and browser information, and analytics about how the Services are used.
3. How we use information
We use information to provide and secure the Services, process and reconcile payments, prevent fraud and abuse, meet legal and regulatory obligations, and improve the product. PuraFi’s AI features draft and explain; they do not move money without human authorization, and we do not train foundation models on your data.
4. How we share information
We share information with payment, banking, and infrastructure providers strictly to operate the Services; with your connected accounting and HR systems at your direction; and where required by law. We do not sell personal information.
5. The PuraFi Expense Agent
The PuraFi Expense Agent is a free expense-reporting service you use through an AI assistant such as ChatGPT, and on your PuraFi expense dashboard. This section describes exactly what it collects and where that information goes.
What it collects. The expense details you provide: merchant names, amounts, dates, categories, business purposes, trip labels, and payment-method type (personal card, cash, or other — never card numbers). The receipt images and documents you upload, which are stored as part of your expense records and included in generated report files. For mileage, the start and end locations you describe for a specific drive — we do not collect GPS coordinates or track your location. The names and business relationships of meal attendees when you supply them, because IRS substantiation rules require them on the expense record. The email address of the manager, approver, or finance contact you send reports to. Optional employer profile details you save — employee ID, department, and cost center — which print on your report headers. And your name and the email addresses on your PuraFi account, including the domain of your verified work email.
How it uses them. To keep your ledger, compute mileage at the IRS rate, build report files, deliver reports at your direction, and track reimbursement. If you have a verified work email, the expense categories and filing rules you save may seed a shared, anonymous setup template for your employer’s email domain that colleagues at that domain can inherit; you can avoid this by not saving categories or rules. We also keep aggregate, domain-level counts of Expense Agent usage for internal product analytics.
Who receives them. When you use the Expense Agent inside an AI assistant, the information its tools return — your expense details, name, email, approver addresses, and report links — is transmitted to that assistant’s operator (for example, OpenAI) as part of your conversation. To calculate driving distances we send the start and end locations you enter (and nothing else) to third-party geocoding and routing services. We use Clerk for account sign-in and Amazon SES to send report and approval emails on your behalf. Generated report files, receipt images, and approval pages are served from links containing a random, unguessable token: anyone you share such a link with can open the files without signing in, and an approval link additionally lets its recipient approve or reject that one report.
How long we keep them. Approval links expire 14 days after a report is submitted; approver sign-in links expire after 20 minutes and are single-use. Report files, receipt images, and their download links are retained while your account is open, so your expense records remain available for tax and audit purposes. When you delete your account, all of your expense records, reports, receipt images, generated files, and saved settings are erased immediately and irreversibly, and every previously shared download, approval, and verification link stops working.
Your controls. From your PuraFi dashboard you can download a complete copy of your data at any time — a ZIP containing your full ledger plus every report file and receipt image — and you can permanently delete your account and all associated data yourself, or by emailing privacy@purafi.ai.
6. Security
We apply bank-grade safeguards including encryption in transit and at rest, dual-admin controls on money movement, least-privilege access, and full audit trails. No method of transmission or storage is perfectly secure, and we continually review our controls.
7. Your rights
Depending on your location, you may have rights to access, correct, delete, or port your personal information, and to object to or restrict certain processing. Company-administered data is handled in coordination with the organization that controls the account. Contact us to exercise applicable rights; Expense Agent users can also export or delete their data directly from their dashboard, as described in Section 5.
8. Data retention
We retain information for as long as needed to provide the Services and to meet legal, tax, accounting, and audit obligations, after which it is deleted or anonymized. Expense Agent retention timelines are set out in Section 5.
9. Contact us
Questions about this policy or your data can be sent to privacy@purafi.ai.
