Privacy Policy
Last updated: July 19, 2026
1. Overview
Stripe Fee Auditor ("we", "our", "the Service") is a tool that analyzes Stripe Balance CSV exports to help you understand your fee structure. We are committed to handling your data with care and transparency. The data controller for the personal data described in this policy is the operator of Stripe Fee Auditor. You can contact the operator at support@feeauditor.com.
Fee analysis is produced by a deterministic algorithm (not a generative AI / LLM model). We do not send your CSV to third-party AI providers for analysis.
2. Data We Collect
CSV file content (processed, not retained as a file)
When you upload a Stripe Balance CSV, the file is transmitted to our server over an encrypted HTTPS connection, processed in memory for that request to generate your analysis, and is not stored as a raw CSV file on disk, object storage, or a durable blob. We store only the computed analysis result (JSON aggregates such as totals, rates, fee mix, and selected charge-level fields needed for the report). A Stripe Balance export typically contains transaction amounts and fees — not full card numbers — and is not treated as cardholder data under PCI DSS card storage rules; still, we minimize what we keep after analysis (including stripping free-text descriptions where they are not needed).
Computed analysis result
The computed analysis (fee totals, rates, high-fee charge flags, monthly breakdowns, etc.) is stored in our database and linked to a random report ID plus a private access token. Retention depends on whether the report is an unpaid preview, you save an email link, beta full access applies, or you pay — see section 6.
Email address
Email is optional for viewing a preview (you can continue without it). If you choose to submit your email (report gate, checkout, Fee Monitor, waitlist, or monthly tips), you are requesting that we store it for the purpose you selected: private report link / transactional messages, payment follow-up, monthly CSV reminders, waitlist updates, or the newsletter. Marketing or newsletter emails are sent only when you explicitly subscribe. We do not sell your email or personal information.
UTM and attribution parameters
When present, we may store campaign attribution with the report row — for example utm_source, utm_medium, utm_campaign, utm_content, landing path, and HTTP referrer — to understand which pages or campaigns led to an upload. These are marketing analytics fields, not the contents of your CSV.
IP address
We log your IP address for rate limiting (to prevent abuse). Rate limit records are deleted after approximately 2 days.
Operational logs
Our hosting and infrastructure providers may process limited technical logs such as request timestamps, IP addresses, URLs, error traces, and user-agent data so the Service can run securely and reliably.
Analytics
We use Plausible Analytics (EU-hosted, privacy-focused, no cookies by default) to measure aggregate traffic. First-party funnel events may also be logged server-side without raw CSV or full report payloads. If Google Analytics 4 is configured, it is used for product analytics, not advertising retargeting. We do not use third-party cookie-based behavioural advertising.
3. How We Use Your Data
- To generate your fee analysis report
- To send transactional messages about your report (when email is provided and a mail provider is configured)
- To provide Fee Monitor reminders and subscription-related messages when you subscribe
- To send monthly Stripe fee tips only when you explicitly subscribe
- To enforce rate limits and prevent abuse
- To operate payments and unlock paid features
- To understand aggregate traffic and improve the Service (via Plausible Analytics — see section 2)
We do not use your financial data for advertising, profiling, or any purpose beyond providing the Service.
4. Legal Bases
Where data protection law requires a legal basis, we rely on:
- Contract — to process your CSV, generate reports, unlock paid access, and send transactional report messages.
- Legitimate interests — to prevent abuse, secure the Service, debug errors, keep minimal operational logs, and measure aggregate website usage.
- Legal obligations — where payment, tax, accounting, dispute, or consumer-protection records must be retained.
- Consent — where we specifically ask for it (for example optional marketing).
5. Third-Party Services
We use the following infrastructure and service providers (their own policies apply):
- Vercel — hosting and edge infrastructure (vercel.com/legal/privacy-policy)
- Neon — PostgreSQL for report metadata and analysis results (neon.com/privacy-policy)
- Polar — checkout, payment processing, receipts, and order-related records as our payment provider / merchant of record where applicable (polar.sh/legal/privacy)
- Resend — transactional email delivery when enabled (resend.com/legal/privacy-policy)
- Plausible Analytics — privacy-oriented, aggregate traffic metrics (plausible.io/privacy)
- Google Analytics 4 — product analytics only when configured (policies.google.com/privacy)
We only share with them what is needed to run the Service (for example payment receipts, report identifiers needed for checkout, or an email address you give us). These providers may process data in countries outside your own. Where required, we rely on their published transfer safeguards and data processing terms.
6. Data Retention
| Data | Retention |
|---|---|
| Raw CSV file | Not stored as a file; processed in memory for the request only |
| Computed result (unpaid preview, no email) | About 1 hour after creation (may be briefly extended during checkout) |
| Computed result (unpaid, after you save an email) | Extended to about 72 hours from when the email is saved, so you can reopen the private link |
| Computed result (after successful payment) | Up to 30 days from payment, then deleted automatically |
| Computed result (beta full access) | Up to 30 days from report creation while the beta flag is enabled |
| UTM / attribution fields | Deleted with the report row when it expires or on a verified deletion request |
| Checkout session link state | Short-lived server-side checkout state expires after about 24 hours |
| Payment webhook event IDs | Kept for up to 90 days to prevent duplicate payment processing |
| Fee Monitor subscription email | Kept while the subscription is active or until deletion request where legally possible; payment records are retained by Polar under their policy |
| Email address (report / lists) | Report emails are kept while the corresponding report row exists; newsletter and waitlist emails are kept until unsubscribe, deletion request, or list cleanup |
| IP address (rate limit) | Deleted after about 2 days |
| Site analytics (Plausible) | Processed by Plausible under their retention policy; we do not send raw CSV or report contents there |
7. Security
Data is transmitted over HTTPS. CSV content is processed on the server for analysis and is not written to a public bucket. Report access uses a secret token in addition to the report ID. We use rate limiting and other controls to reduce abuse.
8. Your Rights (GDPR / CCPA and similar laws)
Deletion / erasure: email support@feeauditor.com with subject "Data deletion request" and your report ID (and any access details we need to verify the request). We will delete the stored analysis and related personal data we hold for that report where legally possible. Rows are also removed automatically when they expire. We do not operate a user account system, so there is no separate "profile" beyond what is tied to an active report or subscription row.
Access / know: you may ask what personal data we hold about you in connection with a report or email you provided (subject to verification).
Do not sell / share for ads: we do not sell personal information and we do not share it for cross-context behavioural advertising. If you are a California resident, you may still contact us to exercise CCPA rights that apply to you.
Depending on where you live, you may also have rights to correct, restrict, object to, or receive a copy of your personal data, and to complain to a local data protection authority. We will not discriminate against you for exercising privacy rights that apply to you.
9. Automated Analysis
Reports are generated automatically from the CSV data you provide using deterministic fee calculations — not a machine-learning model that profiles you. The report is informational only and does not make legal, financial, credit, employment, or other similarly significant decisions about you.
10. Children
The Service is not directed at children. We do not knowingly collect data from children under 13, or under the higher age threshold that may apply in your country.
11. Changes
We may update this Privacy Policy. Material changes will be reflected in the "Last updated" date above. Continued use of the Service after changes constitutes acceptance where permitted by law.
12. Contact
For privacy-related questions or data requests, contact us at: support@feeauditor.com