Privacy Policy
Last updated: April 8, 2026
Overview
This Privacy Policy explains what data Quick Bank Convert collects, how it is processed, and who has access to it. We believe in being transparent about how your data is handled.
1. How Bank Statement Processing Works
When you upload a bank statement to Quick Bank Convert, the following happens:
- Your file is sent from your browser to our server via an encrypted HTTPS connection
- Our server forwards the file to our internal parsing API for data extraction
- The parsed transaction data (dates, descriptions, amounts, categories) is returned to your browser
For anonymous users (not signed in): Your file is sent to our parsing service for processing but is not stored permanently. It is discarded after parsing completes.
For authenticated users (signed in): Your file is sent to our parsing service and is also stored in our cloud storage (Cloudflare R2) so you can access your conversion history. Stored files are associated with your account.
2. Account Data
If you sign in via Google OAuth, we collect and store the following in our database (hosted on Neon PostgreSQL, US West region):
- Your name (from your Google profile)
- Your email address (from your Google profile)
- Your profile picture URL (from your Google profile)
- OAuth tokens for maintaining your session
- Account creation date
This data is used for authentication, session management, and subscription billing.
3. File Storage
For authenticated users, uploaded bank statement files are stored in Cloudflare R2 cloud storage. Files are organized by upload date and associated with your account. Authorized administrators may access stored files for support and debugging purposes.
Anonymous users' files are processed but not stored permanently.
4. Payment Data
If you subscribe to a paid plan, payment processing is handled entirely by Lemon Squeezy, which acts as the Merchant of Record for all purchases. This means Lemon Squeezy is the seller on record, handles billing, collects applicable sales tax / VAT, and issues receipts. We do not store your credit card number, CVV, or full card details. Lemon Squeezy provides us with a tokenized customer and subscription reference for managing your subscription. See Lemon Squeezy's Privacy Policy for how they handle payment data.
5. Analytics and Tracking
We use the following analytics services:
- Google Analytics — Tracks pages visited, time spent, browser type, device information, approximate location (country/city level), and referral source
- Copper Analytics — Website usage analytics
These analytics services do not have access to the contents of your bank statements.
6. Cookies
We use the following cookies:
- Session cookies — To keep you logged in (if authenticated)
- Anonymous parse counter— A cookie that tracks how many conversions you've performed without an account (resets every 24 hours)
- Google Analytics cookies — For website usage statistics
We do not use advertising cookies or sell data to third-party advertisers.
7. Data Sharing
We do not sell or rent your personal data. We share data with the following third parties as necessary to operate the service:
- Our internal parsing API — Receives your bank statement file for data extraction
- Cloudflare R2 — Stores uploaded files for authenticated users
- Neon (PostgreSQL) — Stores account data
- Google — For OAuth authentication and analytics
- Lemon Squeezy — Merchant of Record for payment processing, billing, tax collection, and receipts (paid plans only)
- Copper Analytics — For website usage analytics
- Legal requirements — If required by law, court order, or government request
8. Data Retention
Account data is retained as long as your account is active. Stored bank statement files for authenticated users are retained until you delete your account. If you delete your account, we will delete your personal data and stored files within 30 days.
Anonymous users' files are processed in memory and not retained after parsing.
9. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account, associated data, and stored files
- Export your account data
- Opt out of analytics tracking
California residents have additional rights under the CCPA. EU residents have additional rights under the GDPR. Contact us to exercise any of these rights.
10. Security
We implement security measures including HTTPS encryption for all data in transit, secure OAuth authentication, and encrypted database connections. File uploads are transmitted over encrypted connections. Access to stored files is restricted to authorized administrators.
11. Children's Privacy
Quick Bank Convert is not intended for use by children under 13 years of age. We do not knowingly collect personal data from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes via email or a notice on the website.
13. Contact
For privacy-related questions or to exercise your data rights, contact us at support@quickbankconvert.com.