Privacy policy
Last updated: 2 October 2026
Summary in plain words
- Your accounts-payable file never leaves your browser. We never see or store it.
- For your account, we keep your email address, a hashed password and any optional details you add.
- If you save an audit on a paid plan, we keep the findings shown on screen and your notes, never the file.
- Paddle, our reseller, handles payments. We never receive your full card number.
- We use no advertising or analytics cookies. We count visits with Vercel's cookieless statistics, and we never sell your personal information.
- You can delete your account and saved audits yourself at any time.
Who is the controller
Dhali Services ("we", "us"), of Noida, Uttar Pradesh, India, is the controller of the personal data described here, which we collect when you use PaidTwice (paidtwice.vercel.app) or contact us. For privacy questions, contact us via our contact form.
Saved audits are different. Your organisation decides what to save, so it is the controller of any personal data in them (such as a sole-trader vendor's name), and we are its processor. If your details appear in a customer's audit, please contact that customer.
Paddle is a separate controller for what it collects at checkout, and its own privacy notice applies.
What we collect and why
Account details. Your email address, password and any optional details you add, such as your name, company and country. Passwords are handled by our authentication provider and never stored in readable form.
- Why: to create and secure your account, let you sign in and contact you about it.
- Legal basis: our contract with you or, if you use PaidTwice for an organisation, our legitimate interest in providing the service to it.
Saved audits (paid plans, if you choose to save). The findings shown on screen: for each flagged line, details such as the vendor name and ID, invoice number, dates, amount, document or payment reference and description, and why it was flagged. We also store a summary of the scan (such as its name, the file name, row counts, date range, totals and settings) and your status notes and recovered amounts.
- Why: so you can return to an audit and track recoveries.
- Legal basis: as for account details. For personal data in audits, we follow your organisation's instructions.
Plan and purchase information. Your plan, its status and end date, and the billing notifications Paddle sends us. These contain Paddle's customer, order and subscription references, amounts, dates and, for card payments, the card type, last four digits, expiry date and name on the card.
- Why: to give you the access you paid for, handle cancellations and refunds, and keep business records.
- Legal basis: our contract, our legal obligations, and our legitimate interest in accurate records and resolving disputes.
Enquiries. Your email address, name, company, country and message, the topic and form you used and, if you are signed in, a link to your account.
- Why: to reply, discuss your needs and prepare quotes.
- Legal basis: our legitimate interest in answering enquiries, or steps you ask us to take before entering a contract.
Technical data. Your IP address, browser and device details and request times, processed by our hosting and authentication providers. When you sign up or message us, we also keep a hashed (scrambled) copy of your IP address.
- Why: to deliver the site, keep accounts secure, prevent abuse and fix problems.
- Legal basis: our legitimate interest in a secure, reliable service.
Visit and speed statistics. Vercel Web Analytics and Speed Insights record each page view with the page address (before anything is sent we remove record IDs and every query parameter except campaign tags such as utm_source), the referring site, browser, operating system, device type, country, and how quickly the page loaded. They set no cookies and identify a visit only by a hash of the request that Vercel discards after 24 hours, so we cannot tell who you are from them.
- Why: to see which pages are useful and to keep the site fast.
- Legal basis: our legitimate interest in running and improving the site.
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
What we never collect
Your file. Your browser scans the accounts-payable export you choose, on your device. The file is never uploaded to our servers, and we never see or store it, on any plan. Unless you save an audit, scan results also stay in your browser, and a saved audit never includes the lines that were not flagged.
Full card numbers. Paddle handles payment details, so we never receive your full card number or security code.
Where data is stored and our sub-processors
We store our data with Supabase in its London (UK) region. Our providers are:
- Supabase: database, authentication and server functions (the small functions that create accounts and receive payment notifications may run in the Supabase region nearest to the person using the site).
- Vercel: website hosting, content delivery network, and cookieless visit and speed statistics.
- Paddle: payments, as our reseller and Merchant of Record.
- Resend: transactional email, where we use it, including forwarding enquiries to us.
Our processors may use personal data only to provide their services to us. We may also share it with professional advisers, with authorities where the law requires, or with a buyer of our business (we would tell you). We do not sell personal information or share it for cross-context behavioural advertising.
International transfers. Our providers may process data in the UK, the US and other countries, and we may access it from India. For personal data protected by UK or EU law, we rely on adequacy decisions or on safeguards such as the EU standard contractual clauses and the UK International Data Transfer Addendum. If you are in Australia, this means your information may be disclosed to recipients in these countries. Ask us for a copy of the safeguards.
How long we keep data
- Account details: until you delete your account from the account page.
- Saved audits: until you delete them or your account.
- Billing records: Paddle's notifications to us are kept for as long as we need them for accounting, tax and disputes, including after you delete your account. Paddle keeps its own payment records.
- Enquiries: for as long as needed to handle them and any follow-up. Deleting your account does not delete them, so ask us if you want them removed.
- Technical data: for short periods set by our providers. Hashed IP addresses are kept for a few days.
- Visit and speed statistics: Vercel keeps them as aggregate statistics; the hash that groups a visit is discarded after 24 hours.
Deleted data may remain in backups for a short time. We may keep data longer where the law requires it or to establish or defend legal claims.
Security
Our main safeguard is the design: your file never leaves your device. We also use HTTPS for all connections, store data with Supabase (which encrypts it at rest), use database rules so that each account can read only its own saved audits, rely on our authentication provider to store passwords only in hashed form, and limit our own access to what we need to run and support the service.
No system is perfectly secure. If a breach affects your personal data, we will tell you and the authorities where the law requires. Please use a strong, unique password and keep your device secure, because that is where your file is processed.
Your rights and how to exercise them
Depending on where you live, you may have the right to access, correct or delete your personal data, to receive a portable copy, to restrict or object to how we use it (including where we rely on legitimate interests), and to complain to a data protection authority.
UK, EU and EEA. You can complain to us via our contact form. We will acknowledge your complaint within 30 days and tell you the outcome without undue delay. You can also complain to the UK Information Commission (formerly the Information Commissioner's Office) or to your local data protection authority.
Australia. You can ask to access or correct your information. If we do not resolve a privacy complaint to your satisfaction, you can contact the Office of the Australian Information Commissioner (OAIC).
California and other US states. You may have the right to know, access, correct and delete your personal information, including through an authorised agent, and we will not discriminate against you for doing so. In the past 12 months we collected identifiers (such as name, email address and IP address), commercial information (plans, purchases and limited card details), internet activity (technical data and visit statistics), professional information (company name) and account login details, which are sensitive personal information that we use only to run your account. We collect them from you, from Paddle and from your device, and disclose them only to the service providers above, for the purposes above. We do not sell or share personal information, including that of anyone under 16.
How to make a request. Contact us via our contact form using your account's email address, or delete your account yourself from the account page. We may need to verify your identity. We will reply within the legal time limit (usually one month, or 45 days in California), free of charge unless the law allows a fee. Requests about a customer's saved audit go to that customer, and we will help them respond.
Cookies and analytics
Strictly necessary. To keep you signed in, PaidTwice stores your login session in your browser's local storage. Signing out or clearing your browser's site data removes it. This storage is strictly necessary for the service you ask for, so it does not need your consent.
Cookieless statistics. Vercel Web Analytics and Speed Insights set no cookies and store nothing on your device.
No analytics or advertising cookies. If we ever add non-essential cookies, we will ask for your consent first.
Payments. Paddle's checkout may use its own cookies or similar technologies to process payments and prevent fraud, under Paddle's own policies.
Children
PaidTwice is a business tool, not meant for children, and you must be 18 or over to create an account. If we learn that we have collected a child's personal data, we will delete it.
Changes to this policy
We will post any changes here with a new date. If a change is significant, we will tell you by email or in the app before it takes effect.
Contact
For privacy questions or requests, contact us via our contact form or write to Dhali Services, Noida, Uttar Pradesh, India.