Privacy Policy

Last updated 24 September 2026

This Privacy Policy explains what information ALLI Recon collects, how it is used and protected, who it is shared with, and the rights you have under the Philippine Data Privacy Act of 2012 (Republic Act No. 10173).

1. Who we are

ALLI Recon is operated by ALLI Recon OPC, a one person corporation organized under Philippine law with registered office at 21st Floor, Unit 2116, Park Triangle Corporate Plaza North Tower, 32nd Street corner 11th Avenue, Bonifacio Global City, Fort Bonifacio, Taguig City 1635. ALLI Recon OPC is the data controller for the personal data described in this policy.

Under the Data Privacy Act of 2012, ALLI Recon OPC is the personal information controller for the data described here.

This policy covers two kinds of people: account holders who use the product, and visitors to our public pages who may never create an account. Almost everything below concerns account holders. The one category we collect about a visitor is the marketing conversion event described in section 2, on the basis described in section 4, with the limits described in section 10. Visitors who send the contact form or book a call also give us what they enter there, as section 5 describes.

2. The information we collect

We collect the following categories of information:

  • Account information. Your name, email address, and a securely hashed password, managed through our authentication provider.
  • Organization and workspace details. The organizations and client workspaces you create, and the team members you invite.
  • Financial and operational data. The marketplace payouts, payout line items, COD remittances, expected orders, classifications, and journal entries that you connect or upload, and that ALLI Recon generates for you. This includes a copy of the chart of accounts from the ledger you connect, so its accounts can be offered for mapping by name.
  • Integration access tokens. OAuth access and refresh tokens for Xero, QuickBooks Online, Google and connected marketplaces, stored encrypted at rest (see section 6).
  • Technical and usage data. Log data, device and browser information, and error diagnostics, used to operate and improve the service.
  • Marketing conversion events. When you create an account or send the contact form, we send Meta Platforms one event from our server recording which of those two actions happened, the time it happened, and the page it happened on, and, for the account signup only, the IP address and browser user agent your request carried, together with which of the two organization types you chose at signup, accounting firm or direct seller. So that Meta can tell which of its advertisements led to a signup, the account signup event also carries your email address, your first name and your last name, each converted to a SHA-256 hash before it leaves our server, a hashed identifier for your new account, and, if you arrived from a Meta advertisement, the click identifier Meta attached to the link you followed. Meta receives the hashes rather than the plain text, but a hash of your email address is still a way to recognise you, and Meta matches it against the accounts it holds. The click identifier is read from the address of the page you landed on and held until you register; it is not a cookie and it is never read by Meta from your browser. The contact form event carries none of these identifiers. No tracking script runs in your browser for this and no advertising cookie is set. Section 5 names the recipient, section 4 the basis, and section 10 what this means for your rights.
  • Cookies. Strictly necessary cookies that keep you signed in. We do not use advertising cookies. The map on our contact page is not loaded until you press Show map. If you do, Google may set its own cookies (see section 5).

3. How we use your information

We use your information to provide reconciliation, to post journals you approve, or that a posting schedule you switched on approves, to the ledger you connected for that workspace, your Xero organization or your QuickBooks Online company, to secure and operate the service, to provide support, and to improve the product. We do not use your financial data to train advertising profiles, and we do not sell it.

4. Legal bases for processing

We process personal data on the bases recognized by the Data Privacy Act: the performance of our contract with you, your consent (for example, when you connect a ledger or a marketplace), and our legitimate interests in securing and improving the service, balanced against your rights.

For the marketing conversion events described in section 2, the basis is our legitimate interest in measuring whether our advertising works, balanced against your rights. The identifiers the signup event carries serve the same interest: measuring whether advertising works means telling the advertising platform which signups its advertisements produced. Section 10 explains what those events can and cannot reveal about a person.

5. Service providers we use

We rely on a small set of processors that handle data on our behalf, each under its own data processing terms:

  • Supabase for database, authentication, and storage.
  • Vercel for application hosting.
  • Inngest for background job processing. A running job carries reconciliation and settlement data as its job state.
  • Postmark for transactional email.
  • Sentry for error monitoring. Reports are scrubbed of personal data and access tokens before they are sent.
  • Meta for advertising measurement. We send it the marketing conversion events described in section 2, and nothing else about a visitor. This is a separate relationship from the advertising spend integration listed below, which only reads data and only exists for an ad account you connect.
  • GoHighLevel, which we use through Jenius, for our contact form and booking calendar. What you enter in either is sent to it and kept as a contact record so we can reply: your name, email address, phone number and business name, the answers you choose on the form, and the time you book.

Our contact page can show our office on a Google map. Nothing is requested from Google until you press Show map. When you do, your browser connects to Google directly, and Google receives your IP address and browser details and may set cookies, under Google's own privacy policy. We receive nothing from the map.

Separately, these are the services you connect yourself. We exchange data with them on your instruction, and only for the workspace you connected them to:

  • Xero and Intuit QuickBooks for the accounting integration you authorize. We read your chart of accounts, so you can choose which account each figure posts to by name. We write journal entries, and nothing else: we do not create or change customers, suppliers, invoices, bills or payments. We read back the journals we posted, and we ask which of them changed since we last looked, so an edit or a deletion on your side does not go unnoticed.
  • Lazada and TikTok Shop for the marketplace integrations you authorize. We read finance and order data only.
  • Google for the spreadsheet export you authorize. We write to the one spreadsheet you pick.
  • Meta for advertising spend, if you connect an ad account. We read the daily spend total only.

Some of these providers may process data outside the Philippines. Where they do, we rely on their contractual safeguards (see section 12).

6. Integration access tokens

When you connect a ledger or a marketplace, we store the resulting access tokens encrypted at rest. These tokens are used only to sync data and to post journals on your behalf. They are never sold and never shared for marketing. They are not returned to your browser, with one exception: when you pick a Google spreadsheet, Google's file picker runs in your browser and needs a short lived Google access token to do it, so that one token is passed to the page while the picker is open. The long lived refresh token never leaves our servers. You can revoke any of them at any time by disconnecting the integration.

7. How we share information

We do not sell personal data. We share it only with the service providers listed in section 5, and where we are required to by law or valid legal process.

8. Data retention and deletion

We retain your data while your account is active.

An owner can delete their own account from the account menu. It is refused while anyone else is still a member of the organization, and while an invoice is outstanding, so that a shared workspace is never emptied by one person alone. A member removed from an organization by an owner or manager keeps their account, unless that account was created from the organization's own invitation and belongs nowhere else, in which case removing them deletes it; the person removing them is told which of the two they are doing before they confirm.

Deletion is immediate and cannot be undone, and we are plain about what it leaves. Your sign in is destroyed, and the name and email address on your member record are replaced with placeholders, so the record can no longer identify you. Three things remain. First, the audit trail: every action recorded under your name keeps your name and email address on that record, because a trail that forgot who acted would be worthless to the accountants who rely on it, which is the same reason an invoice keeps the name of the person who issued it. Second, the member record itself stays as an anonymous anchor, so that the financial records linked to it remain intact. Third, our hosting provider keeps encrypted backups for its own retention window, which we cannot reach into. Records already posted to your accounting ledger or written to your spreadsheet stay where they are, because they are your books.

For anything else, or if you cannot use that path, ask us and we act on the request by hand, aiming to complete it within 60 days. There is no automatic purge running on a schedule today. We keep specific financial, transaction, and reconciliation records for longer only where a legal, tax, or audit obligation under Philippine law requires it, for the period that obligation specifies. The data deletion page explains how to make the request.

9. How we protect your data

We encrypt sensitive integration tokens at rest and run all traffic over HTTPS. Each organization's data is isolated at the database using row-level security, not only in the application. Access to production data is restricted and logged.

10. Your rights under the Data Privacy Act

Subject to the Act, you have the right to be informed; the right to access; the right to object; the right to erasure or blocking; the right to rectification; the right to data portability; the right to damages; and the right to lodge a complaint with the National Privacy Commission (NPC).

One limit on those rights, stated plainly. The account signup event described in section 2 carries a hashed identifier for your account, so it is linked to you: we can tell which event was yours, and Meta can match it to a Meta account you hold. We cannot retract an event from Meta once it has been sent. Meta keeps it under its own data policy, and Meta's own account tools let you see and disconnect the activity that businesses have shared about you. Deleting your ALLI Recon account removes the identifiers from our records, as section 8 describes, but does not reach what Meta already received. The contact form event carries no identifier at all, so we cannot find, correct, or delete the one that belongs to a specific person. Every other category in section 2 is account data, and every right above applies to it in full.

Deleting your account is the right to erasure exercised on the account record: it removes what identifies you from that record. Section 8 names the three things that remain and why.

To exercise any of these rights, contact us at hello@allirecon.com.

11. Children's data

ALLI Recon is a business tool and is not directed to anyone under 18. We do not knowingly collect data from children.

12. International data transfers

Some of our service providers operate outside the Philippines, so your data may be stored or processed abroad. Our infrastructure sub-processors (for example, our database, hosting, and email providers) may process data outside the Philippines under appropriate contractual and security safeguards, consistent with the Data Privacy Act of 2012.

13. Changes to this policy

We may update this policy as the product and our legal structure evolve. When we do, we will revise the date above and, for material changes, take reasonable steps to notify you.

14. Contact and data requests

For any privacy question or data request, contact hello@allirecon.com. You may also raise concerns with the National Privacy Commission.

Questions about this document? Contact hello@allirecon.com.