Policy and support record

Privacy Policy

How Bank Statement Converter handles account, document, billing, and usage data.

2026/08/04

Bank Statement Converter is browser-based document-conversion software. This policy explains how the service handles information when you visit the website, sign in, convert a statement, or use billing features.

What we collect

When you sign in with Google, we receive the account details needed to create and operate your account, such as your name, email address, and profile image.

When you run a conversion, we process the PDF you upload, extracted statement data, generated files, page and transaction counts, processing status, and technical error information. When paid checkout is enabled, billing records may include Stripe customer, Checkout, subscription, invoice, and webhook identifiers. Payment-card details are entered through Stripe Checkout; we do not store full card numbers or card security codes.

How we use information

We use this information to authenticate users, convert and export statements, maintain the credit ledger, reconcile enabled billing, prevent duplicate or unauthorized actions, diagnose failures, and provide support.

Storage and deletion

Document files and generated conversion artifacts are stored in a private Cloudflare R2 bucket. Account, conversion, credit, and billing metadata are stored in Cloudflare D1.

Each conversion has a seven-day expiry. Scheduled cleanup removes its uploaded, intermediate, evidence, and export objects. You can delete a conversion earlier from the product. Operational metadata and ledger records may remain after the document objects are removed when needed for billing reconciliation, security, fraud prevention, or legal obligations. The account deletion flow removes eligible account-linked database records.

Provider logs and backups may have separate retention controlled by the provider. We do not publish an unverified retention duration for them.

Service providers and disclosures

  • Cloudflare hosts the application, database, private object storage, queues, workflows, containers, access controls, and operational analytics.
  • Google provides sign-in, may provide configured document-processing services, and provides Google Tag Manager and Google Analytics when browser measurement is configured. Browser analytics receives only bounded event and page dimensions; URL query and hash values are removed.
  • Microsoft provides Clarity for aggregate interaction analysis and Bing Webmaster Tools for search discovery and indexing diagnostics. Clarity is configured to mask page text and does not receive account identifiers, filenames, statement contents, transaction rows, conversion identifiers, or payment identifiers from our analytics events.
  • Stripe provides secure Checkout, receipts, subscriptions, billing management, and payment-event processing when paid checkout is enabled.
  • Depending on runtime controls, eligible statement pages may be processed by a configured document-processing provider such as AWS Textract or Google.

Each provider receives only the information required for its configured function. Operational conversion analytics must not contain filenames, statement text, transaction rows, account numbers, amounts, names, emails, or Stripe identifiers.

Product boundary

Bank Statement Converter is document-conversion software. It is not a bank, lender, investment product, accounting service, tax service, financial adviser, file-sharing service, cyberlocker, or document-falsification service. Conversion results can contain errors and must be reviewed before use.

Your choices and privacy rights

You can delete individual conversions, delete your account, change or withdraw optional browser analytics from the footer Cookie settings, or request access to, correction of, or deletion of eligible personal data, subject to applicable law. We may ask for reasonable information to verify that a requester controls the relevant account.

For a privacy question or request, email support@bankstatementconverters.co. We aim to provide an initial response within two business days.

See the Cookie Policy and Terms of Service.