Privacy Policy

Last updated: August 10, 2026

1. Overview

Stripe Fee Auditor ("we", "our", "the Service") is a tool that analyzes Stripe Balance CSV exports to help you understand your fee structure. We are committed to handling your data with care and transparency. The data controller for the personal data described in this policy is the operator of Stripe Fee Auditor. You can contact the operator at support@feeauditor.com.

Fee analysis is produced by a deterministic algorithm (not a generative AI / LLM model). We do not send your CSV to third-party AI providers for analysis.

2. Data we collect

The raw Stripe CSV is transmitted over HTTPS, processed in memory for the analysis request, and is not stored as a file or sent to an AI provider. We retain only the computed report data needed to show totals, rates, fee drivers, and selected transaction evidence.

A report is linked to a random ID and private access token and is retained for up to 30 days. An email address is stored only when you explicitly join monitoring early access, the CFO pilot, or another optional list.

We may retain first-touch attribution, aggregate funnel events, and an IP address used for abuse prevention. These analytics do not contain the raw CSV.

3. How we use your data

We do not use your financial data for advertising, profiling, or any purpose beyond providing the Service.

  • Generate and display the complete free fee audit
  • Measure aggregate product usage and improve the Service
  • Record optional monitoring or CFO-pilot interest
  • Enforce rate limits, prevent abuse, and debug errors
  • Send updates only for an option you explicitly choose

4. Legal bases

Where data protection law requires a legal basis, we rely on:

  • Contract - to process the CSV and provide the report you request
  • Legitimate interests - to secure, debug, and measure aggregate use of the Service
  • Consent - for optional early-access, pilot, or marketing messages
  • Legal obligations - where applicable records must be retained

5. Third-Party Services

We use the following infrastructure and service providers (their own policies apply):

We only share with them what is needed to run the Service (for example payment receipts, report identifiers needed for checkout, or an email address you give us). These providers may process data in countries outside your own. Where required, we rely on their published transfer safeguards and data processing terms.

  • Vercel — hosting and edge infrastructure (vercel.com/legal/privacy-policy)
  • Neon — PostgreSQL for report metadata and analysis results (neon.com/privacy-policy)
  • Polar — checkout, payment processing, receipts, and order-related records as our payment provider / merchant of record where applicable (polar.sh/legal/privacy)
  • Resend — transactional email delivery when enabled (resend.com/legal/privacy-policy)
  • Plausible Analytics — privacy-oriented, aggregate traffic metrics (plausible.io/privacy)
  • Google Analytics 4 — product analytics only when configured (policies.google.com/privacy)

6. Data retention

  • Raw CSV file - not stored as a file; processed in memory for the request only
  • Computed free report - up to 30 days from report creation
  • Early-access or CFO-pilot email - until deletion request or list cleanup
  • Attribution fields - deleted with the related report row
  • IP rate-limit records - approximately 2 days
  • Aggregate analytics - retained under the configured analytics provider policy

7. Security

Data is transmitted over HTTPS. CSV content is processed on the server for analysis and is not written to a public bucket. Report access uses a secret token in addition to the report ID. We use rate limiting and other controls to reduce abuse.

  • No OAuth, no API keys — you export a CSV yourself; we never get ongoing access to your Stripe account.
  • In-memory processing — the raw CSV file is not stored as a blob; we keep computed aggregates for your report link (see section 2).
  • Descriptions stripped before storage — free-text Stripe descriptions are used only during analysis, then removed from persisted report JSON where possible.
  • Deterministic math, not LLM — fee logic is open for review; we do not send your CSV to third-party AI providers (see section 1).

8. Your Rights (GDPR / CCPA and similar laws)

Deletion / erasure: email support@feeauditor.com with subject "Data deletion request" and your report ID (and any access details we need to verify the request). We will delete the stored analysis and related personal data we hold for that report where legally possible. Rows are also removed automatically when they expire. We do not operate a user account system, so there is no separate "profile" beyond what is tied to an active report or subscription row.

Access / know: you may ask what personal data we hold about you in connection with a report or email you provided (subject to verification).

Do not sell / share for ads: we do not sell personal information and we do not share it for cross-context behavioural advertising. If you are a California resident, you may still contact us to exercise CCPA rights that apply to you.

Depending on where you live, you may also have rights to correct, restrict, object to, or receive a copy of your personal data, and to complain to a local data protection authority. We will not discriminate against you for exercising privacy rights that apply to you.

9. Automated Analysis

Reports are generated automatically from the CSV data you provide using deterministic fee calculations — not a machine-learning model that profiles you. The report is informational only and does not make legal, financial, credit, employment, or other similarly significant decisions about you.

10. Children

The Service is not directed at children. We do not knowingly collect data from children under 13, or under the higher age threshold that may apply in your country.

11. Changes

We may update this Privacy Policy. Material changes will be reflected in the "Last updated" date above. Continued use of the Service after changes constitutes acceptance where permitted by law.

12. Contact

For privacy-related questions or data requests, contact us at: support@feeauditor.com

Terms of Service · Refund Policy