Privacy policy

Last updated 17 August 2026

Short version. You upload a file, we pay Telnyx to send it, we delete the file the moment the send is finished, whether that is delivered or finally failed (a busy line gets redialed first, which can add a few minutes). We do not read the file. We do not sell your data. We set no cookies and run no tracking at all. If you want the long version, keep reading.

Sections
  1. What we process
  2. What we store after delivery
  3. Lawful basis (GDPR)
  4. Sub-processors
  5. Cookies and tracking
  6. What we do not do
  7. Your rights (GDPR, CCPA)
  8. Data retention
  9. Security
  10. Contact

1.What we process

When you send a fax through Shotfax, the service:

  1. Receives your file upload and stores it temporarily in Cloudflare R2, encrypted at rest.
  2. Creates a checkout session via Stripe for the $2.99 flat fee.
  3. After payment, hands the file to Telnyx's fax delivery network, addressed to the destination fax number you provided.
  4. Deletes the file from our R2 storage as soon as the send reaches its final outcome. That is delivery, or the last failed attempt. If a destination line is busy we redial automatically (up to three attempts, and never longer than two hours), so on those sends the file is held for those extra minutes and then deleted the same way. Files tied to abandoned checkouts (payment never completed) are automatically deleted, typically within 65 minutes.

2.What we store after delivery

2a.Lawful basis (GDPR Article 6)

3.Sub-processors

ServicePurposeWhat they receive
CloudflareHosting (Workers, R2, D1)File (transient), job metadata
TelnyxFax deliveryFile contents, destination fax number
StripePayment processingCard details, billing email. PCI-DSS compliant; EU data transferred under Standard Contractual Clauses.
Polar.shMerchant of record for purchases before 12 July 2026Card details, billing email. Retention and transfers per Polar's own privacy policy (polar.sh/legal/privacy).
ResendTransactional email deliveryRecipient email address, delivery metadata

Scroll the table sideways to see every column.

Shotfax is not a HIPAA-compliant service and does not sign Business Associate Agreements. HIPAA covered entities and business associates should not use Shotfax to transmit Protected Health Information. A patient sending their own health records on their own behalf is not restricted by this, but does so under the same best-effort, no-warranty terms as any other document.

3a.Cookies and tracking

Shotfax sets no cookies and runs no tracking of any kind. There is no analytics, no advertising pixel, no tag manager, no retargeting, no session recording, and no fingerprinting. There is nothing to consent to, which is why you were not shown a cookie banner.

Until 17 August 2026 this site loaded a Google Ads conversion tag and Google Tag Manager, behind a consent banner defaulted to denied. Shotfax does not buy ads, so the tag measured a channel that did not exist. It has been removed entirely, along with the banner. If Shotfax ever advertises, this section and the consent banner come back before any tag does.

The only client-side storage the site uses is a short-lived browser value on the receipt page so a reload does not lose your reference number. It never leaves your device.

4.What we do not do

5.Your rights (GDPR, CCPA)

5a.Data controller

The data controller for Shotfax is Povilas Konopackas, a sole trader based in Lithuania, EU. Contact: support@shotfax.com. This is also the address for any GDPR request.

6.Data retention

7.Security

All transmissions use TLS. Files in R2 are encrypted at rest. The fax leg uses Telnyx's private IP network with T.38 error correction for reliability. We follow OWASP guidelines for the web application and keep our attack surface small on purpose.

8.Contact

For privacy questions, reply from the address associated with your receipt or email support@shotfax.com.