paymentaudit.Analyze your statement
PAYMENT AUDIT

Privacy Policy

Draft for professional legal review before production launch. These terms are not a finalized legal agreement.

Information used for your audit

We collect your processing statement, email address, optional business name, extracted facts, confirmed figures and selected assumptions to prepare and deliver your audit. Payment confirmation is handled through Stripe. The application does not collect full card details.

Private statement handling

Statements use private storage and temporary signed access. Raw PDFs are deleted after successful report generation, with automated cleanup within 24 hours. Abandoned or failed uploads expire after 24 hours. Structured metrics are retained separately for report access and support.

Service providers

The configured service uses Vercel for hosting, Supabase for database and file storage, OpenAI for statement extraction, Stripe for checkout, and Resend for transactional delivery. OpenAI requests disable response storage; provider-side security and abuse-monitoring retention may still apply under the operator’s account terms. This is not a claim of zero retention by all providers.

Report links and communications

Keep your secure report link private. We use your email for report delivery and related transactional support. A processor-availability notification is optional and separate. We do not automatically enroll customers in marketing.

Deletion and analytics

You can request deletion from your audit page. We collect basic funnel event counts without session recording. A hashed network identifier supports rate limits; expired counters are cleaned up automatically.

Before production launch

The operator must identify its legal entity and contact details, define structured-data retention periods, verify provider contracts and regions, and describe applicable privacy rights and response procedures with legal counsel.