Data processing

Last updated August 6, 2026

This page describes what TaxesRadar does with data you connect to it, who else touches that data, and on what terms. It is written for the person at your end who has to sign off on a new vendor.

If you need a signed DPA

Email hello@taxesradar.com and one will be executed, naming the operating entity and countersigned. It is not published as a self-serve document here because TaxesRadar is not yet a registered company, and an agreement with nobody on the other side of it is not worth the page it is printed on. The commitments below are the ones that agreement contains.

Who is the controller

For the transaction data you connect, you are the controller and TaxesRadar is the processor: we act on your instructions and for no purpose of our own. For your own account (your email address, your settings, your billing record) TaxesRadar is the controller.

What is actually processed

Less than most people expect, because the product only needs enough to place a sale against a threshold. A stored sale row holds:

It holds no buyer names, no email addresses, no postal addresses, no card numbers and no line items. Those fields are not requested from a connected processor and are discarded from a CSV rather than stored. For live connections, the raw transactions are read during a scan and only the figures the product needs are kept.

What it is used for

Aggregating your sales by jurisdiction, comparing them against registration thresholds, forecasting when a threshold will be crossed, and alerting you. That is the entire purpose. The data is not used to train anything, not sold, not shared with advertisers, and not pooled across accounts to produce benchmarks.

Sub-processors

Each of these is used for one job, and none of them receives the data for a purpose of their own. This list changes rarely; when it does, this page changes with it.

Security

International transfers

The sub-processors above operate across the EU, the UK and the United States, so data may be processed outside your own country. Each is engaged under its own data processing terms, including the European Commission's standard contractual clauses where they apply. Their current terms are published on their own sites and are the authoritative version.

If there is a breach

You will be told without undue delay and in any case within 72 hours of us becoming aware, by email to the address on your account, with what is known at that point: what happened, which data was affected, and what is being done. You will not be waited on while a full picture is assembled.

Keeping and deleting

Sales history is retained for 800 days, because several registration thresholds are measured over a previous calendar year and a shorter window would make those rules unanswerable in January. Deleting your account removes your profile, your connections, your imported rows and your alert history. Your exposure history can be exported as CSV at any time before you do, and a single import can be deleted without touching the rest.

Your right to check

You can ask what is held for your account and get a straight answer, in writing. The technical claims on this page are checkable in a different way too: the threshold data behind the product, its sources and its gaps are published in full on the data page.

Contact

Data protection questions and requests: privacy@taxesradar.com