Privacy Policy

Effective date: July 26, 2026

Material change on July 26, 2026: we added a paid Pro tier. Payments are processed by Stripe; we never receive card numbers. Activating Pro sends a Stripe checkout session id to our server; nothing is stored there. Saved bank profiles and the Pro license are stored only in your browser. Details are in Sections 2, 3, 10.2, and 10.3. Nothing about check data changed: it still never reaches us.

Clarification added July 26, 2026: we added a free ACH (NACHA) file validator. It works the same way as the rest of the tool: the file you check is processed entirely in your browser and never reaches us. Section 1 now says “check data and ACH files” to make that explicit. No data practice changed.

This policy describes what information Positive Pay Generator, a sole proprietorship (“we”) handles when you use positivepaygenerator.com (the “Service”). The short version is unusual for a privacy policy: the tool is built so that we never receive your data.

1. Your check data and ACH files never reach us

When you use the tool — uploading a check register, mapping columns, generating and downloading a positive pay file, or checking an ACH (NACHA) file in the validator — all of that happens locally in your web browser. The contents of your files (check numbers, amounts, payees, receiver names, account numbers) are:

“Upload” in the tool’s interface means loading a file into your own browser’s memory. When you close or reload the page, that data is gone. We could not produce your check data in response to a subpoena, a breach, or a purchase offer, because we never have it.

2. What we do receive

Server logs. Like essentially every website, when your browser requests our pages, our hosting provider, Cloudflare, automatically logs technical information: your IP address, browser type, the pages requested, and timestamps. We use these logs, if at all, for security and to keep the site running. They are retained by the hosting provider per its privacy policy and are not combined with any other data about you (we have no other data about you).

Email you send us. If you email us — for example, to request a bank format or report a problem — we receive your email address and whatever you include. We use it to reply and to improve the Service, and we keep the correspondence as long as it’s useful for that. Please don’t email us check registers or account numbers; we don’t need them.

If you buy Pro. Payment is handled by Stripe, on Stripe’s own checkout pages, under Stripe’s privacy policy. Your card number goes to Stripe, not to us; we never receive or store it. Stripe makes available to us, in our Stripe dashboard, the ordinary subscription records: the email address and name you give Stripe at checkout, card brand and last four digits, and payment and subscription status. We use these only to provide the subscription, handle cancellations and refunds, and keep required tax records.

Pro activation. When you activate Pro (and occasionally afterward, to renew the license), your browser sends your Stripe checkout session id to our activation endpoint. Our server checks it with Stripe and returns a signed license token to your browser. We store none of this; we run no customer database and no user accounts. The license token lives in your browser’s localStorage (Section 3) and you can remove it at any time on the activation page. The request itself appears in the server logs described above, like any other page request.

That is the complete list. We do not have user accounts, and we do not collect names or the contents of files you process. Payment information is handled by Stripe as described above; we never receive card numbers.

3. Cookies and tracking

The Service sets no cookies. We use one measurement tool: Cloudflare Web Analytics, a cookie-less, privacy-preserving page-view counter served by our hosting provider. It uses no cookies, no cross-site tracking, and no advertising identifiers, does not store IP addresses, and does not fingerprint you across sites; it gives us aggregate counts (pages viewed, referrers, country-level geography) so we can tell which bank-format pages are useful. It never sees the contents of files you process — those stay in your browser (Section 1). Details are in Cloudflare’s Web Analytics documentation.

Local storage on your device. The tool remembers your settings (column mappings, format choice, custom layouts, saved bank profiles, and, for Pro, the license token) in your browser’s localStorage. This data stays on your device. It is not a cookie, it is never transmitted to us, and you can clear it at any time through your browser’s site-data controls.

There are no advertising or tracking scripts and no other third-party embeds on our pages. Because we don’t track individuals, “Do Not Track” and Global Privacy Control signals require nothing extra from us — we honor the spirit of both by default.

Links to external documents (for example, a bank’s published format specification) lead to third-party sites governed by their own privacy policies.

4. Sharing and selling

We do not sell or share personal information for advertising, and never have. The only parties that touch the limited data in Section 2 are our hosting provider (as a service provider processing server logs to deliver the site), our email provider (to deliver mail), and, for Pro subscribers, Stripe (as the payment processor). We would disclose information if legally compelled, though as noted, for your check data there is nothing to disclose.

5. Security

The most effective security measure in this product is architectural: your sensitive data stays on your machine. The site is served over HTTPS. For the little we do hold (email correspondence), we use reputable providers with access limited to the operator.

6. Children

The Service is a business bookkeeping tool, not directed to children, and we do not knowingly collect information from anyone under 13.

7. Your rights — California (CCPA/CPRA)

Honestly stated: we likely do not meet the CCPA’s thresholds to be a regulated “business” (we are a small operator, well under the revenue and volume thresholds, and we do not sell or share personal information). We nonetheless commit to its substance. California residents may ask us to disclose or delete personal information we hold about them; in almost every case the truthful answer will be “we hold none, or only an email thread you sent us,” and we will confirm or delete it on request at support@positivepaygenerator.com. We do not sell or share personal information as those terms are defined in the CCPA, we do not use or disclose sensitive personal information (we don’t collect any), and we will not discriminate against anyone for exercising privacy rights.

8. Your rights — GDPR/UK GDPR

The Service is intended for United States businesses and we do not target the EU/UK. If EU/UK law nonetheless applies to you: the limited processing described in Section 2 rests on our legitimate interest in operating and securing the website (Art. 6(1)(f)); check data processed in your browser never constitutes processing by us, because we never receive it. You have rights of access, rectification, erasure, restriction, portability, and objection, and the right to complain to your supervisory authority. Contact: support@positivepaygenerator.com. Note that our hosting provider’s servers are located in the United States; requests to our site are therefore processed in the United States.

9. Changes to this policy

If we change what data the Service handles — including launching any feature in Section 10 — we will update this policy before the change takes effect, update the effective date, and note the change prominently on the site. We will never retroactively apply a weaker policy to data collected under a stronger one.


10. Planned and activated features

The subsections below were first published for transparency about what we planned to build. Each is marked with its status. Until a subsection is activated (marked in effect, with a dated note), the statements in Sections 1–3 remain the complete and accurate description of the Service. When activating any subsection, we must also revise the on-site claims (“check data never leaves your computer”) to remain accurate.

10.1 Analytics [IN EFFECT as of July 22, 2026]

Activated at launch: cookie-less Cloudflare Web Analytics, as described in Section 3. No cookies, no cross-site tracking, no advertising identifiers, IP addresses not stored — aggregate counts only, never file contents, amounts, payees, or account numbers, which stay in your browser.

10.2 Pro payments [IN EFFECT as of July 26, 2026, in a simpler form than planned]

The Pro tier launched without accounts. There is no email-and-password signup and we hold no account database. As described in Section 2: Stripe processes payment and holds the subscription record; activation gives your browser a signed license token stored locally; our server stores nothing. We see the ordinary subscription records in our Stripe dashboard (email, name, card brand and last four digits, subscription status) and keep them as long as Stripe retains them plus what tax law requires us to keep. Because we hold subscriber emails through Stripe, the rights in Sections 7 and 8 now have real substance for Pro subscribers: email us and we will disclose or delete what we can (Stripe retains what payment regulations require it to retain). If we ever add real accounts, we will update this policy first, as Section 9 promises.

10.3 Saved bank profiles [IN EFFECT as of July 26, 2026, in a stronger form than planned]

We originally planned to store saved bank profiles on our servers, with the protections described in earlier versions of this section. We built it differently, and better for you: saved profiles (bank format choice, column mapping, account number, bank-assigned IDs, and saved custom layouts) are stored only in your browser’s localStorage, on your device. They are never transmitted to us and we could not read them if we wanted to. Delete them at any time in the tool or through your browser’s site-data controls; clearing browser data also removes them. Check register contents continue to be processed only in your browser. If we ever offer server-side profile sync as an option, we will update this policy first with the specifics promised in the earlier draft (encryption, retention, and breach-notification commitments), and it will be opt-in.


Contact

Privacy questions or requests: support@positivepaygenerator.com — Positive Pay Generator