Privacy Policy
Last updated: July 29, 2026
Our approach
HSA Trackr handles information that may reveal health and financial context. We limit optional measurement, separate it from account and receipt workflows, and do not sell personal information. The site works when you choose Essential only.
Information we collect
- Account information: your email address and authentication records when you create or use an account.
- Expense information: amounts, dates, providers, categories, notes, and reimbursement status that you choose to enter.
- Receipt information: images and related details that you choose to upload or extract.
- Payment information: Stripe processes purchases. HSA Trackr receives transaction status and fulfillment details, not your full card number.
- Operational information: security, rate-limit, delivery, and error records needed to operate and protect the service.
Optional analytics and aggregate counters
Google Tag Manager and configured Google Analytics tags, Vercel Analytics, and Vercel Speed Insights load only after you choose Allow analytics and only on eligible public pages. We do not use optional analytics on account, expense, receipt, reimbursement-record, onboarding, eligibility-search, or API routes. Advertising storage, advertising user data, and ad personalization remain disabled.
Separately, selected public product pages and sales milestones use a same-origin aggregate counter. It records only fixed labels for the page category, product category, placement, and action. Those actions can include a high-intent landing, product selection, checkout or onboarding milestone, aggregate payment signal, or purchased-file access. It does not store a cookie, user or session ID, IP-derived key, referrer, URL, query, search, receipt, account detail, Stripe event ID, card detail, amount, or transaction record. Counts are grouped by UTC day, retained for up to 90 days, and are directional product signals. Only Stripe transaction evidence is treated as revenue.
How we use information
- Provide authentication, receipt storage, expense tracking, exports, and reimbursements.
- Process receipt images and return extracted fields for your review.
- Complete purchases and deliver purchased files.
- Send requested sign-in, service, and fulfillment messages.
- Protect the service, diagnose errors, prevent abuse, and maintain reliability.
- Measure eligible public pages only when you allow optional analytics.
Service providers
We use service providers under their applicable terms to operate HSA Trackr. These include Vercel for hosting and selected analytics, Neon for application database infrastructure, Supabase for receipt storage, Google for authentication and receipt-image processing, Resend for email delivery, Stripe for payments, Upstash for rate limits and aggregate counters, Sentry for error monitoring, and, only after your choice on eligible public pages, Google analytics services. Their processing depends on the feature you use and the privacy choice you make.
Security and retention
We use HTTPS, access controls, and service-provider security features to protect information. No system can guarantee absolute security. We retain account and user-provided records while needed to provide the service, meet legal or security obligations, resolve disputes, or complete a requested deletion. Provider backups and logs may take additional time to expire under their retention schedules. Sentry session replay is disabled.
Your choices
- Analytics: choose Essential only or Allow analytics, then use the persistent Privacy choices control to change your selection. We honor a browser Global Privacy Control signal by keeping optional analytics off.
- Access and correction: view and update available account and expense information through the service.
- Export and deletion: use available account controls or contact us for help requesting a copy or deletion of information associated with your account.
Contact
For privacy questions or requests, email [email protected]. We may need to verify your request before acting on account data.