1. Information We Collect
We collect information you provide directly and information collected automatically when you use the Service.
Information you provide:
- Email address and display name when you create an account
- Payment information (processed securely by Stripe — we never store your card details)
- Receipt content you input into templates (text, items, prices, etc.)
- Images you upload for the Place in Scene AI feature
- Support requests and communications
Information collected automatically:
- Browser type, version, and language
- Device type and operating system
- IP address and approximate geographic location (used for currency detection)
- Pages visited, features used, and session duration
- Referral source and UTM parameters
- Cookie and local storage data (see Section 5)
2. How We Use Your Information
- Provide, operate, and maintain the Service
- Process transactions and manage subscriptions via Stripe
- Send transactional emails: purchase confirmations, subscription updates, password resets
- Send promotional emails and marketing campaigns (with your consent; you can unsubscribe at any time)
- Detect and prevent fraud, abuse, and violations of our Terms of Service
- Analyze usage patterns and improve user experience
- Respond to your support requests and communications
- Comply with legal obligations
3. AI Data Processing (Place in Scene)
Our Place in Scene feature uses third-party artificial intelligence APIs to generate composite images of receipts placed in realistic scenes. When you use this feature:
- Your receipt image and selected scene parameters are transmitted to third-party AI service providers for processing
- The AI provider may temporarily process this data on their servers to generate the output image
- We do not use your receipt images or scene data to train any AI models
- Generated scene images are stored on our servers and associated with your account for retrieval in your scene history
- You can delete your scene history at any time from your account dashboard
By using the Place in Scene feature, you consent to this data processing. If you do not wish your images to be processed by third-party AI services, do not use this feature.
4. Marketing Emails
We may collect email addresses through various channels, including account registration, promotional campaigns, CSV imports (for internal use), and cross-platform partnerships. Marketing emails are used exclusively for internal purposes — to inform you about product updates, promotional offers, and relevant content from ReceiptGenerator.
We will never sell, rent, or share your email address with third parties for their marketing purposes.
Every marketing email includes a one-click unsubscribe link. You can also opt out by contacting us at support@receiptgenerator.co. Unsubscribing from marketing emails does not affect transactional emails (purchase confirmations, security alerts, etc.).
5. Cookies & Tracking Technologies
We use the following types of cookies and similar technologies:
- Essential cookies: Required for the Service to function — authentication sessions, CSRF protection, and preference storage. These cannot be disabled.
- Analytics cookies: Used to understand how visitors interact with the Service (e.g., Google Analytics via Google Tag Manager). These collect anonymized usage data.
- Functional cookies: Remember your preferences such as currency selection and saved editor state.
- Promotional cookies: Used to track promotional link claims and attribute sign-ups to marketing campaigns.
You can manage your cookie preferences through your browser settings. Most browsers allow you to refuse cookies or alert you when cookies are being sent. Note that disabling essential cookies may impair the functionality of the Service. For users in the EU/EEA, we obtain consent before setting non-essential cookies in accordance with applicable regulations.
6. Data Storage & Security
We use industry-standard security measures to protect your personal information, including encryption in transit (TLS/SSL) and at rest. Our infrastructure is hosted on Vercel and Supabase, both of which maintain SOC 2 compliance.
Receipt content created using the free tier is processed entirely in your browser and is not transmitted to or stored on our servers unless you explicitly save a template (Pro feature). AI-generated scene images are stored in private cloud storage buckets accessible only to your account.
7. Third-Party Services
We share information with the following categories of third-party service providers:
- Payment processing: Stripe — processes payments and stores payment methods securely. See Stripe's Privacy Policy.
- Authentication: Supabase Auth & Google OAuth — manages user accounts and sign-in.
- AI processing: Third-party AI APIs — processes images for the Place in Scene feature (see Section 3).
- Email delivery: Resend — delivers transactional and marketing emails on our behalf.
- Analytics: Google Analytics (via GTM) — collects anonymized usage data.
- Hosting: Vercel & Supabase — host the application and database.
These providers are bound by contractual obligations and their own privacy policies to protect your data. We do not sell your personal information to any third party.
8. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. Download history, scene generations, and saved templates are retained until you delete them or close your account. If you request account deletion, we will remove your personal data within 30 days, except where retention is required by law (e.g., financial transaction records for tax compliance, which may be retained for up to 7 years).
9. Your Rights (General)
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate or incomplete data
- Request deletion of your data ("right to be forgotten")
- Object to or restrict processing of your data
- Request data portability (receive your data in a structured, machine-readable format)
- Withdraw consent at any time (where processing is based on consent)
- Lodge a complaint with a supervisory authority
To exercise any of these rights, contact us at privacy@receiptgenerator.co. We will respond within 30 days.
10. GDPR — European Economic Area (EEA) Users
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the following additional provisions apply under the General Data Protection Regulation (GDPR):
Legal bases for processing:
- Contract performance: Processing necessary to provide the Service you signed up for (account management, payment processing, feature delivery).
- Legitimate interests: Analytics, fraud prevention, service improvement, and direct marketing to existing customers (with an easy opt-out).
- Consent: Marketing emails to non-customers, non-essential cookies, and AI image processing. You may withdraw consent at any time.
- Legal obligation: Retention of financial transaction records as required by tax law.
International data transfers:
Your data may be transferred to and processed in the United States, where our servers and service providers are located. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, to protect your data during such transfers.
Data Protection Officer:
For GDPR-related inquiries, contact us at privacy@receiptgenerator.co. You also have the right to lodge a complaint with your local data protection authority.
11. CCPA — California Users
If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant you additional rights:
- Right to know: You may request a detailed report of the categories and specific pieces of personal information we have collected about you in the past 12 months, the sources of that information, our business purposes for collecting it, and the categories of third parties with whom we share it.
- Right to delete: You may request deletion of your personal information, subject to certain exceptions (e.g., completing a transaction, detecting fraud, complying with legal obligations).
- Right to opt out of sale: We do not sell your personal information as defined by the CCPA/CPRA. If this ever changes, we will provide a "Do Not Sell My Personal Information" link.
- Right to non-discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.
- Right to correct: You may request correction of inaccurate personal information.
- Right to limit use of sensitive personal information: We do not collect sensitive personal information as defined by the CPRA beyond what is necessary to provide the Service.
To exercise your California privacy rights, email privacy@receiptgenerator.cowith the subject line "CCPA Request." We will verify your identity before processing the request and respond within 45 days.
12. Children's Privacy
The Service is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If we learn that we have collected data from a child under 16, we will delete it promptly. If you believe a child has provided us with personal information, please contact us at privacy@receiptgenerator.co.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on the Service. The "Last updated" date at the top of this page indicates when the policy was last revised. Your continued use of the Service after changes are posted constitutes acceptance of the revised policy.
14. Contact Us
If you have questions about this Privacy Policy, our data practices, or wish to exercise your privacy rights:
ReceiptGenerator
Privacy inquiries: privacy@receiptgenerator.co
General support: support@receiptgenerator.co