Receipt Template Maker

Privacy Policy

Effective date: August 18, 2026

This Privacy Policy explains what personal data Receipt Template Maker processes, why it is processed, how long it is retained, who receives it, and the choices and rights available to you.

1. Controller

The data controller is the Receipt Template Maker operator identified in the Terms. The operator’s complete legal name, registered address, and privacy email must be inserted before account registration or paid services are enabled.

2. Data we process

  • Account data: email address, user ID, authentication status, profile preferences, and security events.
  • Service data: saved receipt configuration, template selections, export history, and support requests. Do not enter real customer or sensitive data.
  • Billing data: plan, payment status, provider customer and subscription identifiers, invoices, refunds, and limited transaction metadata. Full card details are handled by the payment provider, not Receipt Template Maker.
  • Technical data: IP address, browser and device information, timestamps, referral URL, error logs, security signals, and cookie or local-storage identifiers.
  • Communications: messages, abuse reports, intellectual-property notices, and privacy requests.

3. Sources

Data is collected from you, your browser or device, authentication and hosting providers, payment processors, and security or analytics providers configured for the Service.

4. Purposes and legal bases

  • Contract: create and administer accounts, provide the editor and exports, process subscriptions, and deliver support.
  • Legitimate interests: secure the Service, prevent fraud and abuse, diagnose failures, understand aggregate product performance, and establish or defend legal claims, balanced against user rights.
  • Legal obligation: maintain required accounting records, respond to lawful requests, and meet tax or compliance obligations.
  • Consent: optional analytics, marketing communications, or non-essential cookies where consent is required. Consent may be withdrawn at any time.

5. Receipt content and analytics

Receipt content must not be sent to product analytics. Analytics events should be limited to product-level actions and must not include merchant names, customer names, addresses, item descriptions, uploaded logos, payment references, or full receipt data.

6. Recipients and processors

  • Hosting and content-delivery providers.
  • Supabase or another configured provider for authentication, database, storage, and server-side functions.
  • PayPal, Stripe, or another disclosed payment provider when payments are enabled.
  • Email, customer-support, error-monitoring, security, and consent-aware analytics providers actually configured for the Service.
  • Professional advisers, authorities, or counterparties where necessary for legal compliance, claims, safety, or a business transaction.

7. International transfers

Providers may process data outside your country. Where GDPR applies, transfers outside the EEA will rely on an adequacy decision, Standard Contractual Clauses, or another lawful safeguard. Provider locations and safeguards must be confirmed in the production vendor register.

8. Retention

  • Account data: for the account lifetime and a limited period afterward for security, disputes, and legal obligations.
  • Saved receipts: until deleted by the user, account deletion, or the applicable product retention period.
  • Billing and tax records: for the period required by applicable accounting and tax law.
  • Security logs: normally up to 12 months unless needed for an investigation or legal claim.
  • Support and abuse records: normally up to 24 months, or longer where necessary for enforcement or claims.
  • Local editor drafts: remain in the browser until cleared by the user or browser.

9. Security

We use proportionate technical and organizational measures such as transport encryption, access controls, least-privilege permissions, secrets kept server-side, row-level authorization, validation, backups, and monitoring. No online service can guarantee absolute security.

10. Your rights

  • Access, correction, deletion, restriction, and portability where applicable.
  • Object to processing based on legitimate interests and object at any time to direct marketing.
  • Withdraw consent without affecting earlier lawful processing.
  • Complain to a competent supervisory authority. In Lithuania, this is the State Data Protection Inspectorate, where it has jurisdiction.
  • California and other regional rights may include access, correction, deletion, and information about disclosures, subject to applicable thresholds and exceptions. Receipt Template Maker does not sell personal data and does not knowingly share it for cross-context behavioral advertising.

11. Exercising rights

Submit a request through the Contact page. We may verify identity and will respond without undue delay, generally within one month where GDPR applies. Requests are normally free, though manifestly unfounded or excessive requests may be handled as permitted by law.

12. Children

The Service is not directed to children and we do not knowingly collect personal data from anyone under 18. Contact us if you believe a child has provided data.

13. Automated decisions

Receipt Template Maker does not make decisions based solely on automated processing that produce legal or similarly significant effects. Automated security controls may flag suspected abuse for restriction or human review.

14. Changes and contact

We will update this notice when practices materially change and provide additional notice where required. Privacy questions and requests may be submitted through the Contact page.