Legal
Privacy Policy
Last updated: February 17, 2026
The short version
- We never sell your personal data.
- Guest receipt data stays in your browser and never reaches our servers.
- Signed-in drafts are stored securely and deleted when you delete them.
- Payments are processed by DodoPayments. We never store your full card number.
- We honor Global Privacy Control (GPC) opt-out signals.
Introduction
This Privacy Policy explains how Receiptmint ("we," "us," or "our") collects, uses, stores, and protects your information when you use our website and receipt generation tools (the "Service"). We are committed to minimizing data collection and protecting your privacy.
By using the Service, you agree to the practices described here. If you do not agree, please do not use the Service.
Information We Collect
Account information
When you create an account, we collect basic profile data required for authentication and account access. If you sign in with Google, this includes your name, email address, and profile image from Google. If you sign up with email and password, we collect your name, email address, and securely hashed password.
Receipt content
Content you enter (store names, items, prices, dates) may be stored to support draft saving for signed-in users.
Automatically collected information
- Device info — browser type, operating system, and screen resolution.
- Usage data — pages visited, features used, time spent, and interaction patterns (collected via Google Analytics and Vercel Analytics).
- Network data — IP address (approximate location) and referring URL.
- Error and performance data — Sentry captures error reports and performance metrics. In some cases, Sentry may record anonymized session replays to help us diagnose and fix issues. PII is not sent to Sentry from the client side.
Payment information
Payments are processed by DodoPayments, which acts as our merchant of record. DodoPayments handles your full payment details under their own privacy policy. We may receive limited data (last four digits, billing country, transaction ID) for subscription management.
How We Use Your Information
- Provide, maintain, and improve the Service and its features.
- Save and restore receipt drafts across sessions (signed-in users).
- Process payments and manage subscriptions.
- Respond to support requests, feedback, and inquiries.
- Detect, prevent, and address abuse, fraud, and security issues.
- Analyze usage trends to improve experience and reliability.
- Diagnose errors and monitor performance via Sentry.
- Comply with legal obligations and enforce our Terms.
AI-Powered Features
The Service may introduce features powered by artificial intelligence, such as content suggestions, auto-fill, or template generation. If and when AI features are available:
- Input data you provide (such as receipt fields or prompts) may be sent to third-party AI providers for processing.
- We will only send the minimum data necessary to generate the requested output.
- We will require that AI providers do not use your data to train their models.
- AI-generated content will follow the same retention policies as your receipt drafts.
AI features are optional. Core receipt creation functionality does not require AI. We will update this policy when AI features are introduced, including naming the specific providers used.
Legal Bases for Processing (GDPR)
If you are in the EEA, UK, or a jurisdiction requiring a legal basis for processing personal data:
- Contractual necessity — account management, draft storage, and core features.
- Legitimate interests — service improvement, security, abuse prevention, and error monitoring.
- Legal obligation — compliance with applicable laws, tax requirements, and regulations.
- Consent — non-essential cookies and marketing communications. You may withdraw consent at any time.
Data Sharing
We may share data with the following categories under appropriate safeguards:
- Infrastructure — Convex (database and backend services).
- Authentication — Google OAuth and email/password sign-in.
- Transactional email — Resend for password reset and account access emails.
- Payments — DodoPayments (merchant of record) for billing, subscriptions, and tax compliance.
- Analytics — Google Analytics and Vercel Analytics.
- Error monitoring — Sentry for error tracking, performance monitoring, and session replay.
- Legal and safety — when required by law, subpoena, or court order, or to protect rights, safety, or property.
Sub-Processors
The following third-party services process data on our behalf:
| Provider | Purpose | Data processed |
|---|---|---|
| Convex | Database, backend | Account data, receipt drafts |
| OAuth, Analytics | Auth tokens, usage data | |
| Resend | Transactional email | Email address, password reset delivery metadata |
| DodoPayments | Payments, tax | Billing info, transaction data |
| Vercel | Hosting, analytics | Web vitals, usage data |
| Sentry | Error tracking | Error reports, session replays |
We maintain data processing agreements with each sub-processor. This list is updated when we add or remove providers.
Data Retention
- Account data — retained while active. Deleted within 30 days of account deletion, except where longer retention is required by law.
- Receipt drafts — retained while your account is active. Deleted when you delete your account or individual receipts.
- Payment records — transaction metadata retained for up to 7 years for tax and legal compliance, as required by applicable law.
- Usage and analytics — retained in aggregated or anonymized form. Raw analytics data is retained for up to 26 months (Google Analytics default).
- Error reports — Sentry retains error data for 90 days.
- Guest data — stored locally in your browser only. Never retained on our servers.
Data Security
We implement industry-standard technical and organizational measures including encrypted data transmission (TLS/SSL), secure cloud infrastructure, and access controls. No method of electronic transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR. If the breach is likely to result in a high risk to you, we will also notify you directly without undue delay.
International Data Transfers
Your information may be transferred to and processed in countries other than your own, including the United States (where our infrastructure providers operate). When transferring data internationally, we use appropriate safeguards such as standard contractual clauses to protect your information.
Children's Privacy
The Service is not directed to children under 18. We do not knowingly collect personal information from children. If we learn we have collected data from a child, we will delete it promptly. If you believe a child has provided us with personal data, contact support@receiptmint.com.
Your Rights
For all users
- Access — request a copy of the personal data we hold about you.
- Correction — request correction of inaccurate or incomplete data.
- Deletion — request deletion of your personal data and account.
- Portability — request your data in a structured, machine-readable format.
EEA / UK residents (GDPR)
- Right to restrict or object to processing.
- Right to withdraw consent at any time.
- Right to lodge a complaint with your local data protection authority.
California residents (CCPA / CPRA)
- Right to know what personal information is collected, used, and shared.
- Right to delete your personal information.
- Right to opt out of the sale or sharing of personal information (we do not sell or share your data for advertising).
- Right to non-discrimination for exercising privacy rights.
To exercise any of these rights, contact us at support@receiptmint.com or through our contact page. We will verify your identity and respond within 30 days (GDPR) or 45 days (CCPA).
Third-Party Links
The Service may contain links to third-party websites. We are not responsible for their privacy practices or content. We encourage you to review the privacy policies of any external services you visit.
Changes to This Policy
We may update this policy to reflect changes in our practices or the law. When material changes are made, we update the "Last updated" date and notify you by email or through the Service at least 30 days before changes take effect. We review this policy at least annually.
Contact Us
If you have questions about this Privacy Policy or your personal data, you can reach us through:
- Email: support@receiptmint.com
- Web: receiptmint.com/contact