Privacy Policy
Last updated: November 5, 2025
1. Introduction
Mintline ("we", "our", or "us") respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, and safeguard your information when you use our receipt and bank statement processing service.
This policy complies with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Data Controller
Mintline is the data controller responsible for your personal data.
If you have any questions about this privacy policy or our data practices, please contact us:
- Email: privacy@mintline.ai
- General inquiries: contact@mintline.ai
- Address: Amsterdam, The Netherlands
3. Personal Data We Collect
3.1 Account Information
- Name and email address
- Password (encrypted)
- Account preferences and settings
3.2 Financial Documents
- Receipt images and extracted data (vendor names, amounts, dates, items purchased)
- Bank statement data (account numbers, transaction details, balances)
- Matched transaction information
3.3 Usage Data
- IP address and device information
- Browser type and version
- Pages visited and features used
- Date and time of access
3.4 Payment Information
- Payment card details (processed securely by Stripe)
- Billing address
- Transaction history
4. Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contract Performance: Processing is necessary to provide our services to you
- Legitimate Interest: To improve our services, prevent fraud, and ensure security
- Legal Obligation: To comply with tax, accounting, and regulatory requirements
- Consent: For marketing communications (where required)
5. How We Use Your Data
We use your data to:
- Provide and maintain our receipt processing services
- Match receipts with bank statement transactions
- Process payments and manage your subscription
- Send service-related notifications and updates
- Improve our services through AI/ML model training (on anonymized data only)
- Comply with legal obligations and prevent fraud
- Respond to your inquiries and provide customer support
6. Data Sharing and Disclosure
We share your personal data only in the following circumstances:
6.1 Service Providers (Processors)
We use trusted third-party service providers who process data on our behalf:
- Amazon Web Services (AWS): Cloud hosting and storage
- Anthropic: AI-powered data extraction and analysis
- Stripe: Secure payment processing
- Email providers: Transactional and service emails
All processors are bound by contractual data processing agreements ensuring GDPR compliance.
6.2 Legal Requirements
We may disclose your data to comply with legal obligations, court orders, or lawful government requests.
6.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity.
7. International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA). We ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions for certain countries
- Binding Corporate Rules where applicable
8. Data Retention
We retain your personal data for as long as necessary to provide our services and comply with legal obligations:
- Account data: Until you delete your account, plus 30 days
- Financial documents: 7 years (for tax and accounting purposes)
- Payment data: As required by financial regulations (typically 7-10 years)
- Usage logs: 12 months
9. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right of Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restriction: Limit how we use your data
- Right to Data Portability: Receive your data in a machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent for consent-based processing
To exercise these rights, contact us at privacy@mintline.ai. We will respond within 30 days.
10. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption in transit (TLS/SSL) and at rest (AES-256)
- Access controls and authentication (including MFA)
- Regular security audits and penetration testing
- Employee training on data protection
- Incident response procedures
11. Cookies and Tracking
We use cookies and similar technologies to:
- Maintain your session and keep you logged in
- Remember your preferences
- Analyze usage patterns (using Google Analytics)
- Improve our services
You can control cookies through your browser settings. Note that disabling certain cookies may affect service functionality.
12. Children's Privacy
Our service is not intended for individuals under 18 years of age. We do not knowingly collect data from children. If you believe we have collected data from a child, please contact us immediately.
13. Automated Decision-Making
We use AI to automatically extract data from receipts and match transactions. These automated processes do not produce legal effects or significantly affect you. You can always review and correct the results.
14. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of significant changes via email or through our service. Continued use of our service after changes constitutes acceptance.
15. Supervisory Authority
You have the right to lodge a complaint with your local data protection authority if you believe we have violated your privacy rights.
In the Netherlands, you can contact:
Autoriteit Persoonsgegevens
https://autoriteitpersoonsgegevens.nl
In the EU, a full list of supervisory authorities is available at:
https://edpb.europa.eu/about-edpb/board/members_en
16. Contact Us
For any questions about this privacy policy or our data practices, please contact:
- Email: privacy@mintline.ai
- General inquiries: contact@mintline.ai
- Address: Amsterdam, The Netherlands
