Skip to content

Privacy policy

Last updated 7 August 2026

Nextpense is operated by Nextcore Technology. This explains what the service collects, why, who else sees it, and what you can do about it. It is written to be read rather than to be survived.

Two situations, two different roles

If your employer gave you a Nextpense account, they decide what goes into it and how long it is kept. They control that data; we hold and process it for them. Requests about it should go to them first — though you can always delete your own account, which no employer setting can prevent.

If you contacted us through this website, that enquiry is ours and this policy governs it directly.

What we collect

Your account. Name and email address, and optionally a phone number and profile picture. A password, stored only as a bcrypt hash — we cannot read it, and neither can anyone with a copy of our database. If you enable two-factor authentication, an encrypted one-time-password secret and hashed recovery codes.

What you do in the product. Documents you file, approvals and rejections you make, comments you write, and delegations you set. Each decision records who made it, when, and a signature bound to the document's contents at that moment.

Security records. Every session stores an IP address and a browser or device description, so you can see and revoke your own sessions from Settings. Audit events record the IP address of whoever caused them. Sign-in attempts, including failures, are logged so we can lock an account that is being attacked.

Files you upload. Invoices, receipts and attachments, including photographs you take with the mobile app's camera.

Website enquiries. If you complete the demo form: your name, work email, company, approximate approval volume, whatever you write in the message, and the IP address and browser it came from.

We do not use analytics, advertising trackers, or any third-party script on this website. There is nothing here recording what you look at.

The mobile app

The app asks for two permissions, each only at the moment you use the feature that needs it:

  • Camera — to photograph an invoice or receipt.
  • Photo library — to attach an image you already have.

Photographs you choose are uploaded to your workspace and stored as attachments. The app does not read your other photos, contacts, location, microphone, or calendar.

Your signed-in session is held in the device's secure storage — the Keychain on iOS, Keystore-backed storage on Android — not in ordinary app preferences.

Why we hold it

To run the service for the organisation that asked us to. To keep accounts secure, which is the only purpose the sign-in logs and session records serve. And to meet obligations that apply to records of financial approval.

Who else sees it

  • Neon — our database, hosted in Singapore.
  • Vercel — application hosting.
  • Microsoft — only if your workspace has email notifications enabled, and only to deliver them.

We do not sell personal data. We do not share it for advertising. We do not share it with anyone else unless the law requires it, and we will tell the affected organisation if that ever happens and we are permitted to.

If your workspace enables optional integrations — an accounting system, or automatic reading of uploaded documents — data goes to that provider too. Those are off unless your administrator turns them on, and the settings page says plainly which are active.

How long we keep it

Documents and their contents are retained for seven years by default. Each workspace can shorten that. When content is purged the audit record of what happened survives, because an approval is a financial record and deleting it would erase the evidence that a payment was authorised.

Demo enquiries are kept while we are in contact and for a reasonable period after, then deleted.

Deleting your account

You can delete your account yourself, at any time, from Settings → Profile in the app or on the web. It happens immediately — no waiting period, no email to confirm, no need to ask us.

Your name, email, phone number, picture, password and two-factor secrets are erased, and every session ends at once. Approvals you already made stay on the record under the name you had at the time. They belong to the organisation whose money they committed and usually carry a retention obligation, so we cannot remove them — but nothing left behind identifies you or offers a way to reach you.

Full details, including what survives and why.

Your choices

You can ask what we hold about you, have it corrected, have it erased within the limits above, or receive a copy. Write to sales@nextcoretechnology.com. If your employer provided your account we may need to refer you to them, and we will say so rather than leave you waiting.

You can also change what we email you about, or switch it off entirely, from Settings → Notifications. Approval requests are part of the service rather than marketing, so turning those off means you will not be told when something needs you.

How it is protected

Each workspace is isolated inside the database itself, by PostgreSQL row-level security, with the application connecting as a role that cannot bypass it. A query that forgets to scope returns nothing rather than everything.

Passwords are hashed and never stored in a readable form. Stored credentials and two-factor secrets are encrypted at rest. The audit log is append-only, enforced by the database, so no application bug and no administrator can rewrite history. All traffic uses HTTPS.

No system is perfectly secure, and we do not hold any security certification. We would rather say that than imply one.

Children

Nextpense is business software, not intended for and not directed at anyone under 18.

Changes

If this policy changes we will update the date at the top, and tell account holders directly when the change is significant.

Contact

Nextcore Technology — sales@nextcoretechnology.com

Back to Nextpense