Privacy Notice

Your business files stay with you.

Last updated: August 13, 2026.

Who is responsible

Knurl LLC provides MatchThree and is the controller for personal data that it collects through this website and product.

Knurl LLC
Registered-agent mailing address
7901 4th St N, Ste 300
St. Petersburg, FL 33702
United States

For privacy questions or requests, email support@knurlworks.com.

Business files stay in your browser

MatchThree reads CSV and XLSX files and generates the AP Exception Pack locally in your browser. Knurl does not receive or retain uploaded spreadsheet contents, filenames, vendors, product names, SKUs, prices, quantities, invoice numbers, employee names, customer names, or analysis results. You control where the downloaded workbook is stored and shared.

Personal data we may process

Why we process it

Who receives data

Knurl does not sell personal data and does not send spreadsheet contents or sensitive business values to Cloudflare analytics, Supabase, RevenueCat, Paddle metadata, Resend, or advertising services.

Cookies and local storage

The free MatchThree workflow does not require an account, and MatchThree does not intentionally set advertising or marketing cookies. A passwordless account is required only to purchase, restore, or use paid export access. Cloudflare may use strictly necessary security technologies, Supabase stores an authentication session in browser storage, and Paddle Checkout may use essential checkout and fraud-prevention technologies under Paddle's notice. MatchThree does not store customer projects, spreadsheet files, filenames, mappings, analysis values, or generated reports in browser storage. Clearing browser storage signs you out; signing back into the same account restores eligible paid access.

Retention

Knurl has no customer project database and does not retain uploaded files or generated reports. Supabase retains account and authentication records while the account remains active. RevenueCat retains the opaque account identifier and commerce entitlement history needed to restore or revoke access. Paddle remains the system of record for the transaction, receipt email, and billed time. Cloudflare temporarily retains the opaque account ID, Paddle transaction ID, and reminder and expiration timestamps while the reminder waits to run; it does not store the email address in reminder state. Resend retains delivery records according to its service policies. Support correspondence is retained only as long as reasonably necessary to resolve the request, prevent repeat issues, and meet legal obligations, then deleted or anonymized. Infrastructure security logs are retained according to configured operational needs and provider terms, then deleted or aggregated. Paddle retains transaction records under its independent legal obligations and policies.

International processing

Knurl is based in the United States. Cloudflare, Supabase, RevenueCat, Paddle, Resend, and their service providers may process personal data in the United States and other countries. Where required, those providers use recognized transfer safeguards such as adequacy decisions or contractual protections.

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of your personal data; object to certain processing; withdraw consent where processing relies on consent; and complain to your local data-protection authority. These rights may be subject to lawful exceptions.

Send a request to support@knurlworks.com. We may need to verify that the request concerns you. Account deletion removes the Supabase identity and associated RevenueCat customer where legally appropriate; Paddle may retain transaction records it is legally required to keep. We will respond within the period required by applicable law, including within one month where UK or EEA law applies unless a lawful extension is available. For payment data controlled by Paddle, contact Paddle buyer support directly.

Security

We use proportionate technical and organizational measures, including browser-local file processing, passwordless authentication, server-side access-token validation, verified payment webhooks, encrypted HTTPS transport, restricted deployment credentials, and minimal account and payment data. No internet service can guarantee absolute security.

Changes to this notice

We may update this notice when MatchThree, its providers, or legal requirements change. The date above identifies the current version.