Privacy Policy
Version 2026-09-10
1. The two kinds of data here
This distinction matters more than anything else in this document.
Your account data — your name, email, company, plan and usage. We decide how this is handled, so we are the controller of it.
The content you send us to render— the HTML of your invoices, contracts or statements, which frequently contains your own customers' personal data. We only process this to produce the document you asked for. You remain the controller; we act as your processor and do nothing else with it.
2. What we collect, and why
| Data | Why |
|---|---|
| Email, name, company | To create and identify your account |
| Password (hashed, never stored in plain text) | To sign you in |
| Acceptance of these documents — version, time, IP, browser | To evidence consent, as the law requires |
| API keys (hashed) | To authenticate your requests |
| Usage records — timestamps, sizes, durations, status | To meter credits, bill correctly and answer support questions |
| The submitted HTML and the produced PDF | To render the document and to make it retrievable from your dashboard |
| Payment records | Legally required accounting records |
We do not sell your data, we do not use your documents to train models, and we do not read the content you render except where you explicitly ask us to investigate a specific problem.
3. How long we keep it
Rendered documents and the submitted HTMLare deleted on your plan's retention window — 7 days on Free, 30 on Base and Startup, 90 on Boost, 180 on Growth, 365 on Enterprise. If you use your own storage bucket, the document is written there and your retention rules apply, not ours.
Account data is kept while your account is open. After closure it is recoverable for 30 days, then erased or anonymised.
Billing records and consent records outlive the account: the first because accounting law requires it, the second because a record proving consent that deletes itself along with the account cannot answer the question it exists for.
4. Who else processes it
These are our subprocessors. Each one holds only what its purpose requires.
| Provider | Purpose | Location |
|---|---|---|
| Oracle Cloud | Runs the rendering service | Mumbai, India |
| Supabase | Database — accounts, keys, usage | Mumbai, India |
| Upstash | Rate-limit and quota counters | Mumbai, India |
| Cloudflare R2 | Stores rendered documents | Asia-Pacific |
| Resend | Sends verification and account email | United States |
| Razorpay | Processes payments | India |
| Vercel | Serves the dashboard | Global edge network |
We will give notice before adding a subprocessor that handles rendered content.
5. How it is protected
Everything travels over TLS. Passwords are hashed with bcrypt and API keys are stored as hashes, so neither can be read back from our database. If you connect your own storage bucket, those credentials are encrypted at rest with a key held only in our production environment. Access to production data is limited to people who need it.
6. Your rights
You can ask for a copy of your data, correct it, delete it, or object to how we use it. Account closure and erasure are available from the dashboard without asking us. For anything else, write to privacy@pdfspectrum.com and we will respond within 30 days.
Where the content you rendered contains someone else's personal data, requests from that person should go to you — you are the controller of it, and we will assist you in answering them.
7. Cookies
The dashboard stores a session token so you stay signed in, and a small number of preferences in your browser. We do not use advertising or cross-site tracking cookies.
8. Changes
The version in force is shown at the top of this page. For material changes we will email the address on your account before they take effect.
9. Contact
privacy@pdfspectrum.com