Supplier Statement Reconciler
Privacy Policy
Supplier Statement Reconciler reads your Zoho Books payables; it never writes to them. What it keeps are your accounts-payable records as they stood at the moment of each reconciliation, the statements you upload for a short, fixed period, and the results. The only personal data it holds are the supplier contact and company names your Zoho Books already contains — no user names, no email addresses, no bank details, no payment data.
1. Who we are
Supplier Statement Reconciler (the “extension”) is built and operated by Orumio (“we”, “us”).
| Operator | Orumio |
|---|---|
| Representative | Masanori Iwata |
| Address | Mitsuhashi Building 3F, 1-3-3 Kita-Aoyama, Minato-ku, Tokyo 107-0061, Japan |
| Contact | support@orumio.com |
| Telephone | We will disclose this without delay in writing or by email upon request. Please send requests to the contact address above. |
When you connect the extension to your Zoho Books organisation and upload a supplier’s statement, you are the controller of the data in that organisation and in the statement, and we act as your processor: we process it only to provide the extension to you, on your instructions, under the Terms of Service.
2. What the extension processes
2.1 From Zoho Books
The extension reads your accounts payable to build the snapshot a statement is reconciled against. It asks Zoho for read-only access to five things — settings, contacts, bills, vendor payments and vendor credits — and refuses to start if a grant contains any scope that can create, update or delete. What it stores from them are list-level facts: bill and credit references, dates, amounts, balances, payment status, and the supplier’s contact and company name as recorded in Zoho Books. It does not store line items.
Tax identifiers on a supplier record are hashed before storage and never appear in a result. The extension does not read the names or email addresses of your Zoho Books users; of your organisation it keeps the identifier and connection status only.
2.2 Statements you upload
A supplier statement — CSV, Excel, or a text-based PDF — contains the supplier’s invoice references, dates, amounts and balances, and often the supplier’s name, address and contact details on its letterhead. The extension extracts the lines it needs to reconcile, keeps the original file and the extracted text for seven days so you can check a result against the source, and then deletes both (§8). Scanned or photographed statements are refused at upload and are not stored.
2.3 Stored by the extension
| Data | Personal data? | Why it exists |
|---|---|---|
| Your Zoho Books organisation identifier and connection status | No — business identifiers | Identifies your connection |
| A Zoho refresh token, encrypted before it reaches the database | No — a credential | Lets the extension read your payables for a reconciliation while nobody is signed in. Access tokens are held in memory only and never written anywhere |
| A snapshot of your payables at the moment of each reconciliation (bills, vendor payments, vendor credits; references, dates, amounts, status; supplier contact and company names) | Supplier contact names, where Zoho Books holds a person’s name | The fixed record the statement is compared against, so a result can be reproduced later |
| The statement file you uploaded, and the text extracted from it | Whatever the supplier printed on it — typically a company name and address, sometimes a contact name | So you can check a result against its source; deleted after seven days |
| Reconciliation results: matches, exceptions, their reasons and the decisions you record | Only by reference to the snapshot rows above | The product’s output and your audit trail |
| Counts of the calls the extension makes to Zoho’s API | No | Staying inside Zoho’s rate limits and diagnosing failures |
3. Why we process it
One purpose only: to reconcile a supplier’s statement against your Zoho Books payables and show you what does not prove out before you pay, close the period, or dismiss a discrepancy.
We do not, and the extension has no mechanism to:
- use your data for marketing, advertising or profiling;
- sell or share your data with anyone;
- use your data to train machine-learning models;
- benchmark, aggregate or compare your suppliers, balances or terms against other customers’.
The extension makes no automated decisions about people. It matches statement lines to accounting records on deterministic evidence and lists what it could not prove; every decision about an exception is yours.
4. Who else processes it (sub-processors)
The extension talks to a deliberately small number of external services.
| Service | Role | Data it can see |
|---|---|---|
| Zoho Books | The accounting platform your payables live in | All of your accounting data — Zoho Books is the source of truth, governed by your agreement with Zoho |
| Vercel Inc. | Application hosting, scheduled jobs and runtime logs | Data in transit while a request is served, plus runtime logs (§6) |
| Vercel Blob (Vercel Inc.) | Storage of uploaded statement files for the period in §8 | The statement files you upload, at rest |
| Neon Inc. | Database (Postgres), encrypted at rest with automated backups | Everything listed in §2.3, at rest |
Our database and application servers are located in the United States. If you are in the European Economic Area or the United Kingdom, this means your data is transferred outside that region. We are established in Japan, which the European Commission and the United Kingdom have each recognised as providing adequate protection. Write to support@orumio.com if you need the details of the safeguards that apply to the onward transfer to our hosting providers.
5. How it is protected
- Minimisation first. The snapshot holds list-level fields, not line items; user names and email addresses are never read; tax identifiers are hashed before storage; uploaded statements live for seven days.
- Read-only by construction. The extension requests only read scopes, refuses to start if a grant contains a scope that can write, and its Zoho client can only issue read requests.
- Encryption in transit. The extension is served only over HTTPS, and all connections to Zoho Books, the database and file storage use TLS.
- Encryption at rest. Our database provider encrypts all data and backups at rest. There is no self-managed backup or export pipeline.
- Credentials encrypted a second time. The Zoho refresh token is encrypted with AES-256-GCM before it reaches the database and cryptographically bound to your organisation, so a row copied into another tenant fails to decrypt. Access tokens are never stored.
- Tenant isolation. Every table carries your organisation identifier and the database enforces row-level security, so a query cannot reach another customer’s rows even by mistake.
- Access control. The extension is operated by a single person. There are no staff accounts, contractors, or support agents with access to customer data. Every account with access is protected by two-factor authentication and a unique password stored in a password manager.
6. Logging
The extension writes operational logs so that failures can be diagnosed. Those logs record identifiers, classifications, counts and timestamps — never access tokens, never raw payloads, and never personal data. Logs are held in our hosting provider’s runtime log storage; nothing is forwarded to any third-party log or analytics service.
7. Cookies and tracking
The extension sets only the cookies it needs to function: a session cookie once you sign in, and short-lived cookies that protect the Zoho Books authorisation flow against forged requests. They identify a session, not a person, and expire on their own. There are no advertising, analytics or tracking cookies.
8. How long it is kept
- Uploaded statement files and the text extracted from them: seven days, then deleted. The reconciliation keeps a record that a file existed, not its contents.
- Payables snapshots, reconciliation results and their evidence: twelve months, so a result stays reproducible for an audit cycle.
- When you disconnect, the stored refresh token is destroyed immediately and everything belonging to your organisation is deleted within 30 days. A scheduled job re-checks that you have not reconnected before it purges, so a reconnection withdraws the deletion rather than racing it.
- Deletion you initiate — of a statement, or of a reconciliation — removes the file and its extracted text on the next scheduled run. The reconciliation’s decisions and exceptions remain, without the evidence bodies, until their own window lapses, so your audit trail survives the deletion of content.
- Earlier deletion on request, at any time, by writing to support@orumio.com.
9. Requests from suppliers and their staff
The personal data the extension holds about a supplier — a contact name, or the details on a statement’s letterhead — came from your Zoho Books organisation or from a document the supplier sent you. A request to access, correct or delete it belongs to you as the controller. If a person contacts us directly, we will refer them to you and tell you promptly, and we will delete or correct data on your instruction.
If you are a supplier and are not sure which of your customers uses the extension, write to support@orumio.com and we will help you reach them.
10. Security incidents
If we confirm an incident affecting your data, we notify the affected customers directly and in plain language — what happened, what data was involved, what we have done, and what if anything you need to do — targeting within 72 hours of confirming it.
11. Changes to this policy
If we change what the extension does with data, we update this page and its version number before the change ships. Material changes are announced to customers with an active connection.
12. Contact
Questions, requests, or anything that looks wrong in this policy: support@orumio.com.
Supplier Statement Reconciler · Version 1.0, 3 September 2026 · Terms of Service
Supplier Statement Reconciler is an independent product of Orumio and is not affiliated with, endorsed by, or sponsored by Zoho Corporation. Zoho Books is a trademark of its owner.