DueqoPrivacy PolicyTerms

Privacy Policy

Effective and last updated August 29, 2026

This Privacy Policy explains how the operator of Dueqo ("Dueqo," "we," "us," or "our") handles information when you use the Dueqo receivables and invoice-collection service. Privacy requests may be sent to [email protected].

1. Scope and roles

Dueqo is intended for businesses and professionals managing accounts receivable. A workspace customer generally controls the customer, invoice, and correspondence data entered into its workspace. Dueqo processes that data to provide the service and controls account, security, service administration, and direct billing data where applicable.

Workspace users are responsible for having a lawful basis to upload customer information and contact customers through Dueqo.

2. Information we collect

Account and authentication data

When you register directly, we process your name, email address, password hash, email-verification state, and optional authenticator secret and recovery-code hashes. Google sign-in provides the authorized Google account identifier, name, email address, and profile image. We also process session identifiers, CSRF tokens, request information, login-attempt records, and security logs.

Workspace and receivables data

We process workspace membership and settings; customer names, companies, email addresses, references, and notes; invoice amounts, dates, status, balances, and payments; collection actions, reminder drafts, payment promises, conversation history, audit events, and CSV import results.

Connected mailbox data

If you connect Gmail, Microsoft, or a business mailbox, Dueqo accesses only the permissions required to send reviewed reminders and synchronize replies related to Dueqo collection conversations. We store connected account details and related message/thread identifiers. Dueqo is not designed to scan or profile your general mailbox. OAuth tokens and configured mailbox credentials are encrypted at rest and deleted when the connection is disconnected.

AI-processed data

For a user-requested AI feature, Dueqo may send the minimum relevant invoice context, reminder instructions, or selected conversation content to the configured AI provider to draft, classify, extract a payment promise, or summarize. AI cannot by itself send mail, mark invoices paid, alter balances, or change subscriptions.

Billing and technical data

We process plan and subscription status, billing periods, provider identifiers and webhook events. PayPal handles full payment credentials. We also process request IDs, timestamps, rate limits, metrics, browser/device request data, and errors needed to operate and secure the service.

3. How we use information

We use information to authenticate users, administer workspaces, provide receivables and collection features, calculate balances and priorities, send user-approved reminders, synchronize related replies, provide AI assistance, manage subscriptions, prevent abuse, support users, maintain backups and auditability, and comply with law.

We do not sell personal information or Google user data. We do not use Gmail data for advertising, retargeting, data brokerage, surveillance, lending, or credit-worthiness decisions.

4. Google API Limited Use disclosure

Dueqo's use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including its Limited Use requirements.

Google user data is used only for requested, prominent user-facing features. Humans do not read Gmail content except with affirmative agreement for specific support, when necessary for security or abuse investigation, when required by law, or when lawfully aggregated for internal operations.

5. Service providers and sharing

We share information only as needed with Google and Microsoft for authentication or connected-mailbox features; the provider operating a business mailbox; PayPal for billing; Resend, Brevo, or the configured SMTP provider for verification and password-recovery messages; and the configured AI provider, which may include OpenAI-compatible services such as OpenAI, DeepSeek, or Kimi, for features you request. We may also use hosting, database, monitoring, backup, and security providers.

Provider availability depends on the deployment configuration. The minimum information required for a requested operation is sent to the active provider. We may also disclose information to advisers or authorities where legally necessary, or to a successor in a corporate transaction subject to applicable notice and safeguards.

Providers may process information only for contracted purposes. We do not permit Gmail data to be used for advertising or unrelated model development.

6. Legal bases

Where applicable, processing relies on contract performance, legitimate interests in operating and securing a business service, legal obligations, and consent where required. Optional Gmail consent can be withdrawn by disconnecting Gmail or revoking Google Account access.

7. Retention and deletion

We retain account and workspace information while the service is active. Unsent reminder drafts are cleaned up after 7 days under the default configuration, completed or failed webhook delivery logs are cleaned up after 30 days, and successful account-email delivery records are retained only for operational troubleshooting and then removed under the service retention schedule. Connected mailbox credentials are deleted when the connection is disconnected. Invoice, attachment, payment, conversation, and audit records remain with the workspace until deletion because they form the receivables history.

A workspace owner may schedule deletion in product. A 7-day cooling-off period allows cancellation before workspace data is permanently deleted. Account deletion anonymizes the user profile and removes workspace access after ownership has been transferred. Data subject to a legal hold, payment dispute, fraud investigation, tax requirement, or mandatory accounting retention may be isolated and retained only for that obligation. Backup copies remain inaccessible to ordinary use and expire through the operator's backup rotation.

8. Security

Safeguards include production transport encryption, password hashing, optional two-factor authentication, account and network login protection, role-based access controls, workspace isolation, encrypted mailbox credentials, verified billing webhooks, audit events, controlled database migrations, backups, and secret management. No system can guarantee absolute security.

9. International processing

Dueqo and its providers may process information in other countries. Where required, we use recognized transfer safeguards.

10. Your choices and rights

Depending on location, you may request access, correction, deletion, restriction, objection, or portability and may complain to a regulator. Contact [email protected]. Disconnecting or revoking a mailbox stops future access but does not automatically delete records lawfully retained by Dueqo.

11. Children

Dueqo is a business service and is not directed to children under 18 or the minimum consent age in their jurisdiction.

12. Changes

We will update the date and provide notice or request consent where required. Material new uses of Google user data require notice and consent before that use begins.

13. Contact

Dueqo Privacy Team
[email protected]