Privacy

What leaves, and what never does.

One thing leaves: your contract's text, so a rate structure can be proposed for you to confirm. Nothing goes to your provider.

The short version

Your commercial agreement’s text is sent to Anthropic’s API so a model can propose the rate structure. That is the only outbound transmission in the product. Everything else stays in your database, and nothing is ever sent to your logistics provider.

What is collected

  • Account — email address and a hashed password, held by Supabase Auth. We never see the password.
  • Documents you upload — rate cards and invoices, and the text extracted from them.
  • Activity you record — the month’s volumes, and where each figure came from.
  • What the audit produced — findings, evidence, claims, and the credits you record.
  • Billing — handled by Stripe. Card details go to Stripe and never reach us.

There is no analytics script, no advertising pixel, and no third-party tracker on this website or in the application.

Who processes it

ProcessorWhat it handlesWhy
SupabaseDatabase, file storage, authenticationWhere your data lives
VercelApplication hostingServes the app and this site
AnthropicText of rate cards and invoicesProposes structure for you to confirm
ResendReplies your provider sends to us, and their attachmentsInbound mail for a claim
StripePayment detailsBilling

That is the complete list. If it changes, this page changes with it.

What is never sent anywhere

Your activity figures, audit results, findings and claim letters. The audit is arithmetic executed against your own rows. The letter is composed for you to copy, download or print — the product has no channel to your provider and never has.

Where it sits, and who can reach it

Documents are held in a private bucket, keyed by organization, under a policy that denies a path it cannot parse rather than allowing it. Every table carries row-level security asking the same question: are you a member of the organization that owns this row.

The application holds no credential that can bypass those policies. There is no service-role key in the request path, so a bug in the application cannot read across organizations even if it tries.

Cookies

One kind: the session cookie that keeps you signed in. No analytics cookies, no advertising cookies, nothing to consent to — which is why this site has no cookie banner.

How long it is kept

For as long as your account exists. Ask us to delete it and we delete it, including the uploaded documents, and we will confirm when it is done.

Your rights

Ask for a copy of your data, a correction, or deletion, by writing to the address below. We will not ask why.

What we do not claim

SpendVerify holds no SOC 2 report and has not commissioned a penetration test. What is described above is the architecture, and it is verifiable in the code. See the security page for that architecture in detail.

Contact

hello@spendverify.com