A company’s receivables ledger is, in a fairly literal sense, the company. It’s the list of who owes you money, how much, and how reliably they pay. Which is your customers, your pricing, your cash position and your near future, all sitting in one table.
Asking a business to connect that table to software that will then talk to its customers in its name is a big request. It’s only a reasonable one if the limits are explicit and you can check everything the software did.
So here are the limits. This is written for the owner or finance lead who has to make the call, not for a security team, though we’ll happily send a questionnaire response to anyone who asks.
The least access we can ask for
Chasing Co. connects to Xero, MYOB and QuickBooks through their official APIs, using the narrowest scope each platform offers for reading invoices, contacts, payments and credit notes. It doesn’t ask for bank feed write access, or payroll, or purchases, or anything at all outside receivables.
Most platforms show you that exact list on the consent screen. If yours ever shows more than it should, something is wrong and you should stop and email us.
The access is read-only. Chasing Co. can see your ledger and cannot change it. That’s the default on every plan and it stays that way until you turn on write-back, which is a separate switch with its own consent step. Switched on, write-back does two things and only two: records a payment against an invoice once Chasing Co. has matched it above your confidence threshold, and adds a note to a contact when a sequence escalates. It can’t create, void, edit or delete an invoice. Not “won’t” as a policy. Can’t, as a permission.
You can revoke us from inside your accounting platform any time, without asking us or telling us. We also revoke ourselves, and confirm it in writing, when you leave.
Everything gets written down
Every message Chasing Co. sends: channel, recipient, full text, timestamp. Every reply it reads, plus how it classified that reply and what it decided to do about it. Every payment match, with its confidence score and whether a person confirmed it. Every override, pause, edit and approval by someone on your team, with a name against it.
The log is append-only. We can’t edit it and neither can you. Entries can be annotated, never changed. It exports as CSV or JSON on every plan.
It’s the first thing we’d point at if you ever asked what Chasing Co. said to one of your customers. You shouldn’t have to take our word for anything.
Where it lives
You pick a region when you onboard: Australia or Singapore. Ledger data, threads, scores, forecasts and the audit log stay in that region. Backups stay there too. Nothing is replicated across.
Data is encrypted in transit on TLS 1.2 or better, and at rest. Production access is restricted to named engineers behind multi-factor auth, logged and reviewed. We’re a small company, so the list of people with production access is short. If you want to know how many, ask and we’ll tell you the number.
What we won’t do with it
We don’t train on customer data. Not your invoices, not your contacts, not the text of your conversations. The models Chasing Co. uses to read replies and draft messages run under agreements that prohibit the provider training on our traffic, and we don’t fine-tune on it ourselves. Improvements come from aggregate, de-identified patterns, the kind of thing that reads as “disputes surface most often in the second reply,” not from anybody’s actual words.
We don’t sell, share or enrich. Chasing Co. doesn’t look your customers up in third-party databases, doesn’t append credit bureau information, and doesn’t tell anyone but you anything about them. When we prepare for a demo, we use the file you sent and nothing else.
We don’t chase consumers. Chasing Co. is built for business-to-business receivables. It isn’t a collection agency, holds no collection licences, and must not be pointed at private individuals. That’s a contractual condition and also a technical one, since sequences are configured per customer segment and personal contacts are excluded.
When you leave
Cancel from the billing page whenever you like. Three things then happen in order. Every sequence stops that day. We generate a complete export, audit log included, and send it to you without being asked. We revoke our own tokens to your ledger and confirm in writing that we’ve done it.
Your data is deleted from our systems within thirty days, except where law requires us to keep specific records longer, and in that case we tell you which records and why.
No exit fee. No notice period past the end of the current month. No copy of your data that quietly stays with us.
Why bother writing this
Most security pages are a wall of badges. We don’t have badges. We’re a small company and pretending otherwise would be its own kind of red flag.
What we have instead is a short list of commitments simple enough that you can hold us to them, and an audit log that lets you check whether we did. If any of the above turns out not to be true, we’d like to hear about it. I suspect you would too.