Effective August 30, 2026

Privacy policy

Sales Tax Calculator API collects and processes the information needed to operate and secure developer accounts, calculate tax, measure usage, support billing, and explain results.

01

Information we process

Account records can include names, email addresses, organization names, owner or member access, billing contacts, session and security events, API-key prefixes and fingerprints, and usage totals. Tax requests can include transaction dates, currency, item-classification facts, amounts, customer and seller location facts, registrations, evidence references, and tax identifiers when supplied. Do not send payment-card data or unrelated secrets through the Sales Tax Calculation API.
02

How information is used

We use this information to authenticate users, enforce account access, provide sales tax calculations and transaction records, diagnose requests, prevent abuse, deliver service messages, administer subscriptions, reconcile metered usage, and satisfy security, accounting, and legal duties. We do not sell personal information or use tax payloads for advertising.
03

Security and minimization

Customer API-key secrets are revealed once and stored as non-reversible verification material. Sensitive API payloads and provider event data are encrypted at rest. Operational views and logs use scoped identifiers and safe summaries instead of duplicating complete payloads. Access is limited to account owners and members. The data-processing overview describes the hosted processing boundary.
04

Retention, export, and deletion

Service records are kept only for the period required by the applicable plan, customer agreement, security needs, billing and accounting duties, or law. Identity deletion does not silently erase records that must be retained for billing, fraud prevention, or legal obligations. Eligible customer payloads are deleted or irreversibly anonymized under the approved retention process. Contact us to request access, export, correction, or deletion. Backups expire through the hosting provider's backup lifecycle rather than being edited in place.
05

Hosted service providers

The hosted service uses Vercel for application hosting and functions, Neon for PostgreSQL database hosting, Stripe for subscription billing, Resend for transactional email, and Plausible for aggregate website analytics. Plausible does not use cookies, create persistent visitor identifiers, or build advertising profiles. These organizations process data only for their stated service role. Better Auth is application code used within the hosted service and is not a subprocessor. Any additional production processor will be disclosed here before it handles customer data.
06

Location and transfers

Service providers may process information in countries different from yours. We do not promise a specific data-residency region unless it is stated in a signed order. Applicable contractual and transfer safeguards must be approved before production activation.
07

Contact

Privacy, access, export, correction, and deletion requests can be sent to support@salestaxcalculatorapi.com. Security reports should use security@salestaxcalculatorapi.com.