Privacy Policy

Clear, practical privacy terms
for a free MVP tool.

This page explains what CheckPay processes, how long data is kept, and the controls in place when you upload payslip and AVAC documents.

Last updated: February 10, 2026Back to homepage

Upload-only flow

We process files you submit to generate your reconciliation report.

Short retention

Uploads are handled in temporary processing storage and removed after processing.

No ad tracking

We do not use advertising cookies or sell uploaded payroll data.

1. What We Process

  • Payslip and AVAC PDF files you upload.
  • Extracted payroll fields required for reconciliation (for example: names, dates, pay lines, and amounts).
  • Technical request metadata such as IP address and timestamps for security and reliability.

2. Why We Process It

  • To compare expected overtime/allowances against what was paid.
  • To return your analysis report in the same session.
  • To detect misuse, enforce rate limits, and troubleshoot service errors.

3. Storage and Retention

  • Files are sent to our analysis backend during processing.
  • The backend uses temporary files while parsing and removes them when processing completes.
  • Generated report data is kept in short-lived in-memory session state (up to ~30 minutes) and clears on refresh/new session.

4. Cookies

  • We set one essential HttpOnly cookie (`checkpay_session`) with an approximately 30-minute lifetime.
  • This cookie supports session continuity and basic abuse protection.
  • We do not use advertising cookies.

5. Third-Party Services

  • In production, we may use Vercel Speed Insights for aggregated performance metrics.
  • We do not use ad networks and we do not sell uploaded payroll content.
  • If you self-host with a custom backend, your infrastructure and hosting logs are governed by your own setup.

6. Security Controls

  • File type and size validation is applied before processing.
  • API endpoints are protected by origin checks and rate limiting.
  • Production configuration requires secure (HTTPS) upstream processing.

7. Your Choices

  • Upload only documents required for your check.
  • You can stop using the service at any time.
  • This MVP does not use user accounts or a long-term report database, so historical retrieval/export is generally not available.

Questions about privacy?

Email us at privacy@checkpay.com.au and we'll respond as quickly as we can.