Production terms require owner approval
Data-processing overview
This page describes the intended hosted processing boundary. It is not a countersigned data processing agreement and does not replace negotiated terms where a DPA is legally required.
01
Roles and instructions
For customer data submitted through the API or dashboard, the customer generally determines the purpose and means of processing and Sales Tax Calculator API processes the data to provide, secure, support, and bill for the service. Account, fraud-prevention, and commercial records may be processed for our own legitimate operational and legal purposes. A signed agreement controls if it assigns these roles differently.
02
Data and people
Processed data may include customer personnel account details, owner or member access, merchant and counterparty location facts, transaction references, tax identifiers when supplied, item-classification and amount facts, API request metadata, billing contacts, usage events, support communications, and security records. Data subjects can include customer users, merchants, and their customers or counterparties.
03
Nature and duration
Processing includes collecting, validating, encrypting, storing, retrieving, calculating, reporting, transmitting service messages, reconciling usage, securing the platform, exporting on authorized request, and deleting or anonymizing eligible data. Processing lasts for the service relationship and the applicable approved retention period, subject to security, accounting, dispute, and legal obligations.
04
Hosted subprocessors
Vercel provides application hosting and functions. Neon provides PostgreSQL database hosting. Stripe provides subscription billing. Resend provides transactional email. Better Auth is a JavaScript library running as part of the application and is not a subprocessor. A new production processor must be assessed and disclosed before it processes customer data.
05
Safeguards
Current technical safeguards include HTTPS, managed secret storage, encryption of sensitive persisted payloads, non-reversible customer-key verification, account-scoped authorization, redacted operational records, database-enforced concurrency controls, signed billing and email-provider webhooks, dependency and bundle checks, and incident and credential-rotation procedures. Exact provider regions and contractual transfer mechanisms require security and privacy owner approval before production activation.
06
Requests and agreements
Send data-subject, export, deletion, or DPA requests to support@salestaxcalculatorapi.com. Production processing that requires a countersigned DPA remains subject to an approved agreement. This public overview is not a signature or acceptance on behalf of either party.
