Privacy Policy
Last updated: 1 September 2026
Who we are and what this policy covers
Blue Crow Ltd ("Blue Crow Ltd", "we", "us" or "our") is the controller responsible for the personal data described in this policy. Blue Crow Ltd is registered in England and Wales under company number 16499488. Our registered office is 61 Bridge Street, Kington, United Kingdom, HR5 3DJ.
Blue Crow Ltd trades as Blue Crow Technology and Blue Crow Systems. This policy applies when you visit our websites, contact us, buy or use our services, or use software and browser extensions supplied under either trading style. References to "Blue Crow" in this policy include Blue Crow Ltd and both trading styles.
This policy describes processing for which Blue Crow determines the purpose and means. Where we process personal data only on a client's documented instructions, that client is normally the controller and its privacy information and our contract with it will also apply.
Personal data we collect
Depending on how you interact with us, we may collect:
- Identity and contact details – such as your name, work email address, telephone number, job title and organisation.
- Enquiry, customer and supplier information – your messages, service requirements, quotations, contracts, support history and business relationship with us.
- Service data – information necessary to deliver consultancy, support, security, cloud, CRM or software services. The exact information depends on the service and our role as controller or processor.
- Technical and security data – such as IP address, browser and device information, request timestamps and security logs generated when you access our website or an online service.
- Usage data – aggregate information about website pages and performance from our privacy-focused analytics service.
- Marketing preferences – including whether you have asked to receive or stop receiving communications.
- Product support data – diagnostic details and other information you choose to provide when asking for help with Blue Crow Systems software.
- Product account and subscription data – such as the Google account email used with Receipt Export Pro, your chosen billing plan, trial eligibility and start/end times, subscription and entitlement status, and related Stripe customer, subscription and price identifiers and dates. Blue Crow does not receive or store complete payment-card details.
We do not knowingly collect personal data from children under 16.
Blue Crow Systems software and browser extensions
AI Prompt Protect
AI Prompt Protect checks text for potential sensitive information locally on your device before it is pasted or sent to a supported AI service.
The extension does not send prompt text, detected values, confidential custom terms or original-to-placeholder mappings to Blue Crow for scanning. Settings are stored locally in the browser, while sensitive placeholder mappings and session counters use browser-session storage. Blue Crow cannot access this locally stored information merely because you use the extension.
Product telemetry and billing are disabled in the current pre-release build. If you contact us for support, we will process the information you choose to send as support data. Please use synthetic examples and do not send live passwords, secrets, customer prompts or other sensitive content. If a future version adds accounts, billing or optional telemetry, we will provide relevant information at the point of collection and update this policy where required.
Receipt Export Pro
Receipt Export Pro scans a webpage selected by the user or a PDF the user chooses, extracts receipt or invoice details such as merchant, date, currency, total and VAT, and appends the selected details and source reference to a Google Sheet in the user's own Google Drive. Access to webpage content occurs only when the user invokes the extension on the active tab.
When the user connects Google, Receipt Export Pro requests access to the user's
Google account email and the limited Google Drive drive.file scope.
The email identifies the user for account, one-time trial eligibility and subscription entitlement purposes.
Drive access is used to create and manage the Receipt Export Pro folder,
spreadsheets and temporary OCR files that the app creates or the user opens with
it. The Google access token, account email, Drive folder identifier, preferences
and a short-lived entitlement cache are stored in Chrome extension storage. Some
preferences may be synchronised by Chrome through the user's Google account, but
this does not make them accessible to Blue Crow merely because the extension is
used.
Receipt and PDF content is extracted in the browser where possible. When Google Drive OCR is needed, the selected PDF is uploaded directly from the browser to the user's Google Drive, converted temporarily for text extraction, and the extension requests deletion of that temporary file immediately after the OCR attempt. Google processes this content under its own terms and privacy policy. Blue Crow's servers do not receive receipt images, webpage content, PDF contents, extracted receipt rows or the contents of the user's Google Sheets.
To check plan access, activate a one-time trial or purchase Pro, the extension sends a Google identity token to Blue Crow's licensing service hosted by Cloudflare. The service asks Google to verify the account email and stores that email, trial start and end times, trial eligibility, plan and entitlement or subscription status, relevant Stripe customer, subscription and price identifiers, the current subscription period end and update timestamps. Where applicable, the selected billing plan is also sent when checkout is requested. Stripe processes names, email addresses, billing addresses, tax information and payment details needed for checkout, subscriptions, invoices, refunds and fraud prevention. Blue Crow does not store complete card details.
Receipt Export Pro does not sell Google user data, use it for advertising, or use it to train general-purpose AI or machine-learning models. Receipt Export Pro's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Its use of extension data will also adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
How we collect personal data
We collect personal data:
- directly from you through forms, email, telephone, meetings and contracts;
- when you request support or use a service that sends information to us;
- from Google when you authorise Receipt Export Pro to access your account email, and from Stripe when it sends subscription and payment-status events;
- automatically through limited website hosting, security and aggregate analytics systems;
- from your organisation, professional advisers, service partners or public business sources where necessary for a legitimate business purpose.
Information processed only on your device by a local-first product is not collected by Blue Crow.
How and why we use personal data
We use personal data for the following purposes and lawful bases:
- Enquiries and services – to respond to you, take steps at your request before entering a contract, and perform our contracts.
- Customer, supplier and support administration – to manage our relationships and provide support, based on contract and our legitimate interests in operating the business effectively.
- Product delivery and entitlement management – to connect a Google account, create and update user-requested Drive files, determine available product features and administer subscriptions, based on contract and steps taken at the user's request.
- Payments and tax administration – to process subscriptions, invoices, refunds and applicable taxes through Stripe, based on contract and our legal obligations.
- Security, fraud prevention and service improvement – based on our legitimate interests in protecting and improving our websites, systems, products, customers and business.
- Legal and regulatory compliance – where processing is necessary to meet a legal obligation or establish, exercise or defend legal claims.
- Marketing – with consent where required, or on the basis of our legitimate interests where permitted by law. You can opt out at any time.
Where we rely on legitimate interests, we consider the impact on your rights and do not use that basis where your interests override ours.
Website analytics, cookies and forms
We do not use advertising cookies or analytics cookies on this website. We use Cloudflare Web Analytics to understand aggregate page usage and performance. Cloudflare describes this service as cookie-free and states that it does not collect or use visitors' personal data. Cloudflare may operate strictly necessary security measures as part of hosting and protecting the website.
Website forms are delivered using Web3Forms. Web3Forms processes the information you enter on our behalf so it can route the submission to us and protect the form against abuse. Its infrastructure and approved subprocessors may process form details, technical logs and spam-prevention signals. Do not include sensitive information in a general website form unless we have asked you to do so through an appropriate secure channel.
Who we share personal data with
We do not sell personal data. Where necessary, we may share it with:
- service providers supporting website hosting, analytics, form delivery, email, cloud systems, customer support and business operations;
- professional advisers such as accountants, insurers and legal advisers;
- regulators, courts, law-enforcement bodies or other parties where required by law or necessary to protect legal rights;
- a prospective buyer, seller or restructuring adviser if our business or assets are involved in a genuine corporate transaction.
Our principal website providers include Cloudflare for hosting, security and aggregate analytics, and Web3Forms for form delivery. Providers must process data only for authorised purposes and apply appropriate safeguards.
Product providers include Google for account authentication, Drive, Sheets and OCR; Cloudflare for Receipt Export Pro's licensing service; and Stripe for checkout, subscriptions, billing, tax and fraud prevention. These providers process data under their applicable terms, privacy information and contractual roles.
International transfers
Some service providers or their subprocessors may process personal data outside the United Kingdom. Where UK data protection law treats this as a restricted transfer, we use an applicable adequacy regulation or contractual and organisational safeguards designed to protect the data. You may contact us for more information about the safeguards relevant to your data.
How long we keep personal data
We keep personal data only for as long as needed for the purpose for which it was collected, including support, contractual, security, tax, accounting and legal requirements. Retention depends on the nature of the relationship, whether an account or contract remains active, applicable limitation periods and any legal duty to retain records.
- Enquiry and support records are reviewed when the matter closes and deleted or anonymised when no longer reasonably required.
- Customer, supplier, contract and financial records are retained for the period required by applicable law and legitimate business record-keeping needs.
- Marketing contact details are kept until you opt out or they are no longer needed; we may retain minimal suppression information to respect an opt-out.
- Web3Forms states that form-submission data is retained for up to three years unless a shorter period applies or it is deleted earlier.
- AI Prompt Protect local extension data remains under your browser's control and can be cleared by you; sensitive session data is designed to expire with the browser session.
- Receipt Export Pro's local access token, account details, preferences and caches remain in extension storage until cleared or the extension is removed. Disconnecting Google clears the locally stored access token. The user's Drive folder and Sheets remain in the user's Google account until the user deletes them.
- Receipt Export Pro asks Google Drive to delete temporary OCR files immediately after each OCR attempt. Trial records are retained as reasonably required to enforce the one-time trial. Subscription and entitlement records are kept while the account or subscription is active and afterwards only as reasonably required for support, accounting, tax, fraud prevention, legal claims and suppression of cancelled access.
Security
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, disclosure or access. No internet or storage system can be guaranteed completely secure, so please use an agreed secure channel when sharing sensitive information.
Your data protection rights
Depending on the circumstances, UK data protection law may give you rights to:
- ask for access to your personal data;
- ask us to correct inaccurate or incomplete data;
- ask us to erase data or restrict how it is used;
- object to processing based on legitimate interests or direct marketing;
- receive certain data in a portable format;
- withdraw consent at any time where processing relies on consent;
- complain to the Information Commissioner's Office (ICO), although we would appreciate the opportunity to address your concern first.
These rights are not absolute and exemptions may apply. We may need to confirm your identity before acting on a request.
Automated decision-making
Blue Crow does not use personal data covered by this policy to make decisions that produce legal or similarly significant effects based solely on automated processing. Local warnings generated by AI Prompt Protect are advisory and remain under the user's control.
Third-party websites and services
Our websites and products may link to third-party websites or services. Their own privacy notices apply when they process data for their purposes, and we are not responsible for their content or privacy practices.
Changes to this policy
We may update this policy when our services, products, providers or legal obligations change. We will publish the revised version on this page and update the date above. We will provide a more prominent notice where a material change requires it.
Contact us
For privacy questions or to exercise a data protection right, email support@bluecrowsystems.com or write to Blue Crow Ltd at 61 Bridge Street, Kington, United Kingdom, HR5 3DJ. You can also use our contact page for general enquiries.
You can contact the ICO or make a complaint through ico.org.uk.