Privacy Policy
Effective September 22, 2026.
Paystubs is built without accounts, which also shapes this policy: there is no profile to aggregate, no login history, and nothing to sell. This page describes what actually leaves your browser, where it goes, and how to have it removed.
Questions: the reply address on your Creem receipt email (Creem is the merchant of record, so billing contact always has a route)
What we collect
While you build. Nothing. The form, the payroll math, and the watermarked preview all run in your browser. No draft is stored until you choose to pay.
When you check out. The pay stub details you entered are sent to our servers so the final PDF can be rendered and delivered after payment. Email is optional: leave it and you get a receipt plus a way to find the order later; leave it blank and nothing about the purchase changes.
Payment details. Card numbers are handled by our checkout provider on their own hosted page. We never receive or store full card numbers, and we cannot see them.
Technical data. Standard request metadata (IP address, user agent) reaches our hosting provider and is used to rate-limit abuse — with no accounts to rate limit against, the request is the only signal we have. We do not load third-party analytics or advertising scripts, and our email contains no tracking pixels.
Cookies and local storage. This site sets no advertising or analytics cookies and loads no third-party scripts. It also writes nothing to your browser's local or session storage.
How long we keep it
An unpaid draft stops being usable when the payment window closes (24 hours by default). A paid pay stub stays encrypted only while you might still need to download it; when that period ends, a scheduled deletion job — one the operator runs, and can be asked to run — removes the row along with any unused download links. The route this policy actually guarantees is deletion on request: use the self-service lookup below or write to the contact address, and we delete by hand.
We deliberately do not publish a fixed “your data is available for N years” promise, because we would rather state what the system actually guarantees. Keep your own copies of every document you download — payroll record-keeping obligations sit with the employer, not with this tool, and they are yours to satisfy.
Invoices and payment records for the transaction itself are retained by our payment provider for as long as its accounting and tax obligations require. That retention applies to the payment, not to your pay stub contents.
Email, precisely
If you give us an email address we use it for three things only: your receipt, an order-lookup link when you ask for one, and a reply if you contact support. There is no newsletter, no marketing, no third-party sharing of the address, and no way to “unsubscribe” — because there is nothing to unsubscribe from.
The stored address is encrypted like the rest of the order, and the searchable index we keep for it is a keyed hash, so a database dump alone does not hand anyone a customer list.
Deleting your data
If you left an email at checkout, open the order lookup page, request a link, and choose “Delete everything on this address”. That removes the stored pay stub data and any unused download links for every order on that address.
Checked out anonymously, or want something gone that is not listed? Write to the reply address on your Creem receipt email (Creem is the merchant of record, so billing contact always has a route) and describe the order (the order number from your receipt is enough). Deletion requests are handled manually within a few business days. Files you already downloaded to your own device are outside our reach — deleting here does not remove them.
Who else touches it
Our infrastructure is limited to what the product needs: hosting and serverless functions (Vercel), the database that holds encrypted drafts (Supabase Postgres), and checkout, fraud screening and payment records (Creem, which acts as merchant of record for your purchase). Each is a service provider acting on our instructions, and we do not sell or share personal data for advertising purposes — including “cross-context behavioral advertising” as California's CCPA/CPRA defines it.
Where it is processed
Our infrastructure — hosting and serverless functions (Vercel), the database (Supabase), payments (Creem) and transactional email (Resend) — is located in the United States. If you visit from the UK or the EU, your data is therefore transferred to the US. Those transfers rest on each provider's own safeguards (their standard contractual clauses and UK extension addenda), not on agreements we signed on their behalf; beyond TLS in transit and encryption at rest, we add no further safeguards of our own.
Why we're allowed to process it
Where the law asks us to name a basis: we process your pay stub details to perform the contract of selling you a document; we process request metadata on our legitimate interest in preventing abuse of a payment system that has no accounts to throttle; and if you leave an email, that happens because you chose to, so we can send your receipt. We do not request special-category data (health, biometrics, religion and the like) — please don't enter any in a field.
Your rights
If you live in a US state with a comprehensive privacy law (California, Virginia, Colorado and others), you may request access to or deletion of the personal data described above, and you will not be penalized for exercising it. The self-service delete above satisfies most of these requests; anything else can go to the reply address on your Creem receipt email (Creem is the merchant of record, so billing contact always has a route) and we will respond within 45 days. We do not sell personal information, so there is no opt-out to offer.
If you are in the EU or the UK, you have the same access and deletion rights plus the right to request rectification, to restrict processing, and to object to it — and the right to complain to a data protection supervisory authority. The same routes apply: the lookup page is self-service, and anything else goes to the contact address above.
How it is protected
Traffic is HTTPS end to end. Stored pay stub contents are encrypted with AES-256-GCM before they are written, with the key held separately from the database. Download links and lookup links are single-use, expire in about 15 minutes, and are stored only as one-way hashes — so even a full database read does not yield working credentials.
No system is perfectly secure. If a breach ever affects your pay stub data, we will tell you rather than let you find out from a search engine.
Children and changes
This service is for adults conducting business bookkeeping. We do not knowingly accept data from anyone under 18. If we change this policy we update the effective date above.