Privacy Policy

Last updated: 24 August 2026

Sumeria Solutions Ltd ("we", "us", "our") operates the Expense Claim System (the "Service"). This policy explains how we collect, use, store, and protect personal information when you use the Service, including our use of cookies.

1. Who we are

The data controller for the Service is Sumeria Solutions Ltd. For privacy enquiries, contact us at support@bccdapps.co.uk.

Where your organisation uses the Service to manage its own expense claims, that organisation is typically the data controller for claim, receipt, and reimbursement data, and we process that information on its behalf as a processor. We are the controller for account, authentication, support, and (where billing is enabled) subscription information.

2. Information we collect

Depending on how you use the Service, we may process:

  • Account details — first name, last name, email address, password hash, authentication identifiers (including Google or other social login identifiers where you choose those options), last login time, and login activity.
  • Expense and company data — expense claims, line items (including mileage), categories, descriptions, notes, approval and rejection comments, company name, roles, and related workflow status.
  • Financial details — bank account name, sort code, and account number you enter for reimbursement.
  • Receipts and attachments — images or files uploaded with expense claims.
  • Notification preferences — Telegram chat identifiers if you choose to link Telegram for alerts.
  • Subscription and billing data — where billing is enabled, customer and subscription identifiers processed by Stripe. We do not store full card numbers.
  • Technical and usage data — cookies described below, action logs (pages visited and actions taken), and server diagnostic information such as IP address and browser type that hosting logs may record.

We do not use personal information for marketing profiling or automated decision-making that produces legal or similarly significant effects.

3. How we use your information

We use personal information to:

  • Provide, maintain, and improve the expense management Service.
  • Authenticate users and manage access within your company.
  • Process expense submissions, approvals, payments, and reconciliation workflows.
  • Send transactional emails such as account verification, password reset, invitations, and subscription notices.
  • Send optional notifications (for example via Telegram) where you have enabled them.
  • Monitor security, prevent misuse (including duplicate form submissions), and troubleshoot issues.
  • Meet legal, regulatory, and accounting obligations.

We rely on one or more of the following, depending on the activity:

  • Contract — to provide the Service you or your organisation has signed up for.
  • Legitimate interests — to secure the Service, prevent fraud, and improve reliability, balanced against your rights.
  • Legal obligation — where we must retain or disclose information to comply with law.
  • Consent — where required, for example optional notification channels. You may withdraw consent at any time without affecting core Service use.

Our first-party cookies are strictly necessary to provide the Service you request, so we do not rely on consent to set them. See Cookies and similar technologies.

5. Who we share information with

We do not sell personal information. We may share data with:

  • Your organisation — company owners, approvers, payers, reconcilers, overseers, and other authorised users, according to their role.
  • Service providers — hosting, email delivery (Resend), authentication (including Google sign-in and, where still used, Auth0), payment processing (Stripe, where billing is enabled), and notifications (Telegram, where you link it). These providers process data on our instructions or as independent controllers of their own services (for example when you sign in with Google).
  • Authorities — where required by law or to protect rights, safety, and security.

Some providers may process data outside the UK. Where this occurs, we use appropriate safeguards such as UK adequacy regulations or standard contractual clauses.

6. Cookies and similar technologies

Cookies are small files stored on your device. The Service uses strictly necessary first-party cookies so that you can sign in, submit forms securely, and keep your company context. We do not use advertising, tracking, or analytics cookies, and we do not run a non-essential cookie consent prompt because we do not set those cookies.

Cookies we set

First-party cookies used by the Expense Claim System
Cookie Purpose Duration
Expense3Auth Keeps you signed in. Set when you log in (including “remember me”). HttpOnly; Secure in production; SameSite=Lax. 14 days (sliding)
Expense3Session Maintains your working session (including current company) while you use the Service. HttpOnly; Secure in production. 60 minutes of inactivity
SelectedCompanyId Remembers your company after the session expires so you are not sent back to onboarding. Validated against your account before use. HttpOnly; Secure in production; SameSite=Lax. 30 days
Expense3Antiforgery Protects forms against cross-site request forgery. HttpOnly; Secure in production; SameSite=Strict. Session (browser session)
.AspNetCore.Mvc.CookieTempDataProvider Carries one-time status messages (for example after you save or submit a form). HttpOnly. Until the message is shown, then cleared
Identity.External Temporary cookie used during Google (or other social) sign-in to complete the login handshake. Session
.AspNetCore.Correlation.* Temporary correlation cookies used during social sign-in to prevent login CSRF. Session
Identity.TwoFactorUserId Set only if you use two-factor authentication, to complete the second login step. Session
Identity.TwoFactorRememberMe Set only if you choose to remember this browser after two-factor authentication. Up to 14 days

Cookie names starting with a dot (for example correlation cookies) are set by ASP.NET Core during sign-in. Exact suffixes may vary. Development-only fake login uses the same Expense3Auth cookie with a shorter lifetime.

Similar technologies on your device

We also use browser storage that is not a cookie:

  • localStorage — to restore list filters, remember in-progress mileage fields, and remember that you dismissed this site’s cookie notice.
  • sessionStorage — to remember that you dismissed the subscription banner during the current browser tab session.

These items stay on your device and are used only to make the Service work as you expect. You can clear them with your browser settings.

Third-party cookies and content

Pages load fonts and libraries from Google Fonts, jsDelivr (Bootstrap), Cloudflare’s cdnjs (Font Awesome), and code.jquery.com (jQuery). Those providers may process your IP address and technical data under their own policies. They are not used by us for advertising.

If you use optional or external features, those providers may set their own cookies:

  • Google — if you sign in with Google.
  • Stripe — if you open Stripe Checkout or the customer billing portal (where billing is enabled).
  • Telegram — if you open Telegram to link notifications.
  • Auth0 — if a legacy sign-in path is used for your account.

We do not control third-party cookies. See the relevant provider’s privacy policy for details.

Managing cookies

You can block or delete cookies in your browser. If you block strictly necessary cookies, you will not be able to stay signed in or submit forms. Guidance is available from the ICO at ico.org.uk/for-the-public/online/cookies.

7. How long we keep information

We retain personal information for as long as your account and company data are active, and for a reasonable period afterwards to meet legal, tax, and audit requirements. Action and audit logs may be retained to support security investigations and compliance. You may request deletion subject to our legal obligations and your organisation's records needs.

8. Security

We apply appropriate technical and organisational measures to protect personal information, including access controls, encrypted connections in production, hashed credentials, and HttpOnly cookies for authentication and session data. No online service can guarantee absolute security, but we work to protect data against unauthorised access, loss, or misuse.

9. Your rights

Under UK data protection law, you may have the right to:

  • Access the personal information we hold about you.
  • Request correction of inaccurate information.
  • Request erasure in certain circumstances.
  • Restrict or object to certain processing.
  • Request data portability where applicable.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

To exercise your rights, contact support@bccdapps.co.uk. If your account is managed by an employer or organisation, some requests may need to be coordinated with your company administrator.

10. Children

The Service is intended for business use and is not directed at children under 16. We do not knowingly collect personal information from children.

11. Changes to this policy

We may update this policy from time to time. Material changes will be reflected on this page with an updated "Last updated" date. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.

12. Contact

Questions about this privacy policy or our use of personal information or cookies: support@bccdapps.co.uk.