Data processing
Last updated August 6, 2026
This page describes what TaxesRadar does with data you connect to it, who else touches that data, and on what terms. It is written for the person at your end who has to sign off on a new vendor.
If you need a signed DPA
Email hello@taxesradar.com and one will be executed, naming the operating entity and countersigned. It is not published as a self-serve document here because TaxesRadar is not yet a registered company, and an agreement with nobody on the other side of it is not worth the page it is printed on. The commitments below are the ones that agreement contains.
Who is the controller
For the transaction data you connect, you are the controller and TaxesRadar is the processor: we act on your instructions and for no purpose of our own. For your own account (your email address, your settings, your billing record) TaxesRadar is the controller.
What is actually processed
Less than most people expect, because the product only needs enough to place a sale against a threshold. A stored sale row holds:
- When it happened, to the day.
- The amount and its currency.
- The buyer's country, and US state where the export gives one.
- Whether the buyer supplied a business tax ID, which decides whether the sale is treated as B2B.
- Who the seller was for tax purposes: you, a marketplace, or a merchant of record.
- A deduplication key, which includes an order or transaction reference from your own export where one is present.
It holds no buyer names, no email addresses, no postal addresses, no card numbers and no line items. Those fields are not requested from a connected processor and are discarded from a CSV rather than stored. For live connections, the raw transactions are read during a scan and only the figures the product needs are kept.
What it is used for
Aggregating your sales by jurisdiction, comparing them against registration thresholds, forecasting when a threshold will be crossed, and alerting you. That is the entire purpose. The data is not used to train anything, not sold, not shared with advertisers, and not pooled across accounts to produce benchmarks.
Sub-processors
Each of these is used for one job, and none of them receives the data for a purpose of their own. This list changes rarely; when it does, this page changes with it.
- Supabase - database and authentication. Holds everything above, isolated per account by row-level security.
- Vercel - application hosting and cookieless traffic analytics.
- PostHog - cookieless product analytics, processed in the United States. No cookie or device identifier is set and IP addresses are discarded at ingestion.
- Resend - delivery of alert and account emails.
- Stripe - our own subscription billing. Your connected processors are a separate matter: those are your accounts, read with your own read-only keys.
Security
- Connector credentials are encrypted at rest with AES-256-GCM before they reach the database, under a key held only in the server environment. A database dump alone does not yield a usable key.
- Every table is protected by row-level security keyed to your account, so one account cannot read another's rows even through a compromised client.
- Connections use read-only, restricted API keys. TaxesRadar cannot move money, issue a refund or change anything in your processor account, and you can revoke access from that processor at any time.
- All traffic is over TLS.
- The free threshold check runs entirely in your browser. A file dropped on it is never uploaded, to us or to anyone else.
International transfers
The sub-processors above operate across the EU, the UK and the United States, so data may be processed outside your own country. Each is engaged under its own data processing terms, including the European Commission's standard contractual clauses where they apply. Their current terms are published on their own sites and are the authoritative version.
If there is a breach
You will be told without undue delay and in any case within 72 hours of us becoming aware, by email to the address on your account, with what is known at that point: what happened, which data was affected, and what is being done. You will not be waited on while a full picture is assembled.
Keeping and deleting
Sales history is retained for 800 days, because several registration thresholds are measured over a previous calendar year and a shorter window would make those rules unanswerable in January. Deleting your account removes your profile, your connections, your imported rows and your alert history. Your exposure history can be exported as CSV at any time before you do, and a single import can be deleted without touching the rest.
Your right to check
You can ask what is held for your account and get a straight answer, in writing. The technical claims on this page are checkable in a different way too: the threshold data behind the product, its sources and its gaps are published in full on the data page.
Contact
Data protection questions and requests: privacy@taxesradar.com