TaxSnap privacy notice
Last updated: 14 August 2026
Controller and contact
Benjamin Aruede is the data controller for this TaxSnap prototype. Privacy and data-rights requests can be sent to benaiwod@gmail.com.
Data processed
In local-only mode, receipt images, extracted receipt fields, notes, settings and usage counts are stored in this browser's IndexedDB. TaxSnap's operator does not receive that local content.
If you create an account, Supabase processes your email address, authentication records and session information. If you choose cloud sync, TaxSnap sends the extracted receipt fields - including merchant, dates, amounts, VAT details, category, payment method and notes - to the configured Supabase project. The current sync does not upload the receipt image.
Purposes and lawful bases
Local data is processed on your device to provide receipt capture, review and export. Account and optional cloud data are processed to provide the features you request and take steps under the service arrangement with you. Limited technical logs may be processed for security and reliability on the controller's legitimate interests.
OCR, payments and service providers
Receipt OCR runs in your browser. Tesseract code, language data, Supabase libraries and fonts load from third-party CDNs, whose operators receive normal connection data such as IP address, time, requested URL and browser information.
Supabase provides authentication and optional cloud storage. Stripe is used only for test-mode Checkout in this prototype; do not enter real payment details. TaxSnap does not store full card details. The committed app contains no analytics or advertising trackers.
Storage, retention and deletion
Local data remains until you clear it in TaxSnap, clear site data in your browser or uninstall the app. Signing out does not delete local receipts. Cloud records remain until they are deleted from the configured Supabase project or you ask the controller to delete the account. There is currently no in-app cloud-account deletion control, so requests are handled manually. Provider logs and backups follow the retention settings of the configured Supabase, Stripe and CDN services; a production deployment must document those settings before accepting real customer data.
International transfers
Supabase, Stripe and CDN processing locations depend on the deployment region and provider configuration and may be outside the UK. Where UK personal data is transferred internationally, the controller must use the safeguards offered by the relevant provider and UK data-protection law.
Your rights
Depending on the circumstances, you may ask for access, correction, deletion, restriction, objection or a portable copy of your personal data. You may also complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint. Contact the controller first if you would like the issue investigated.
Security and sensitive data
Do not put card numbers, National Insurance numbers, passwords, authentication secrets or unrelated sensitive personal data in receipt notes. No internet service is risk-free; export important records and retain the original receipts.