Privacy Policy
Last Updated: March 2026
1. Introduction
Welcome to StatsReceipt (statsreceipt.com). We respect your privacy and are committed to protecting your personal data in compliance with the GDPR (General Data Protection Regulation, EU 2016/679) and the LOPDGDD (Ley Orgánica 3/2018, Spain).
This policy explains what data we collect, why we collect it, and how we manage it.
2. Data Controller
The data controller is the individual operator behind StatsReceipt, based in Spain. For any privacy-related inquiries, data deletion or access requests, contact us at:
📧 fruizdelope@gmail.com
3. Data We Collect
- Authentication (Firebase Auth): When you sign in via Google, we receive your name, email address, and profile photo from Google. This data is used solely to identify your account and manage access to features.
- Pro Verification: If you purchase a Pro license, we store your email address securely in our database (Firebase Firestore) solely to verify your Pro status and unlock features.
- MRR Receipt Data (TrustMRR): When you generate an MRR Receipt, we fetch publicly available startup revenue data from TrustMRR on your behalf. This data is cached for 24 hours in Firebase Firestore to improve performance. We do not store the data permanently or use it for any purpose other than generating your receipt.
- Analytics: We use Google Analytics (GA4) to understand website traffic and usage patterns. This data is anonymized and does not contain personally identifiable information.
- Local Storage: We use your browser's local storage to save preferences and track free usage limits (e.g., number of receipts generated).
- Server Logs: Our hosting provider (Google Cloud / Firebase App Hosting) may collect standard server access logs including IP addresses, request timestamps, and user agents. These are retained for operational and security purposes only.
4. Legal Basis for Processing
- Consent: By signing in with Google, you consent to the processing of your authentication data.
- Contract: Pro license verification is necessary to fulfill the purchase agreement.
- Legitimate Interest: Analytics and server logs are processed under our legitimate interest in maintaining and improving the service.
5. Payments
We use Lemon Squeezy as our Merchant of Record for payments. When you purchase a Pro license or subscription:
- Lemon Squeezy processes your payment securely.
- We do not store or handle your credit card information.
- Lemon Squeezy shares the confirmation of your purchase (including your email) with us so we can unlock your features.
- Please refer to Lemon Squeezy's Privacy Policy for more details.
6. Data Sharing & Third Parties
We do not sell, trade, or rent your personal identification information to others. We share data only with:
- Google (Firebase): Authentication, Firestore database, App Hosting, Analytics.
- Lemon Squeezy: Payment processing.
- TrustMRR: Public API for startup revenue data (server-side only, no user data is sent).
7. Your Rights (GDPR / LOPDGDD)
Under European and Spanish data protection law, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate data.
- Erasure: Request deletion of your personal data ("right to be forgotten").
- Portability: Request your data in a machine-readable format.
- Objection: Object to the processing of your data.
- Withdraw Consent: Withdraw consent at any time by signing out and contacting us.
To exercise any of these rights, email us at privacy@statsreceipt.com. We will respond within 30 days.
You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD).
8. Data Retention
- Authentication data: Retained while your account is active. Deleted upon request.
- Pro verification (email): Retained for the duration of your license.
- MRR cache: Automatically deleted after 24 hours.
- Analytics: Retained per Google Analytics default settings (14 months).
- Server logs: Retained per Firebase App Hosting defaults (30 days).
9. Cookies
StatsReceipt uses only essential cookies and local storage for application functionality. Google Analytics uses cookies to track anonymous usage data. No third-party advertising cookies are used.
10. Updates
We may update this policy from time to time. The updated version will be indicated by an updated "Last Updated" date and the updated version will be effective as soon as it is accessible.
11. Contact
If you have any questions about this Privacy Policy, or wish to exercise your data rights, contact us at:
📧 fruizdelope@gmail.com