Privacy policy

Last updated 16 April 2026

Short version. You upload a file, we pay Telnyx to send it, we delete the file the moment Telnyx tells us the fax went through (or failed). We do not read the file. We do not sell your data. We run a small Google Ads conversion tag so we can measure which ads actually bring paying customers. It sees that a purchase happened and the amount. It does not see your file, your fax number, or your email. If you want the long version, keep reading.

Sections
  1. What we process
  2. What we store after delivery
  3. Sub-processors
  4. Ad measurement and cookies
  5. What we do not do
  6. Your rights (GDPR, CCPA)
  7. Data retention
  8. Security
  9. Contact

1.What we process

When you send a fax through Shotfax, the service:

  1. Receives your file upload and stores it temporarily in Cloudflare R2, encrypted at rest.
  2. Creates a checkout session via Polar.sh (merchant of record) for the $2.99 flat fee.
  3. After payment, hands the file to Telnyx's fax delivery network, addressed to the destination fax number you provided.
  4. Deletes the file from our R2 storage as soon as Telnyx confirms delivery or failure. Files tied to abandoned checkouts (payment never completed) are swept every 5 minutes and cleared within 65 minutes.

2.What we store after delivery

3.Sub-processors

ServicePurposeWhat they receive
CloudflareHosting (Workers, R2, D1)File (transient), job metadata
TelnyxFax deliveryFile contents, destination fax number
Polar.shPayment processing, merchant of recordCard details, billing email
ResendTransactional email deliveryRecipient email address, delivery metadata
Google (Ads, Tag Manager)Ad measurement only. Counts which ad clicks led to paid faxes.Ad click ID (GCLID), page URL, purchase event and amount. No file, fax number, or email.

Telnyx is HIPAA-compliant when configured under a Business Associate Agreement. Cloudflare offers BAAs for healthcare customers. If you need a HIPAA-compliant fax service for PHI, contact us before sending so we can set it up correctly.

Google processes ad measurement data under Google Ads Data Processing Terms and transfers it to the US under the EU-US Data Privacy Framework. Google is certified under the DPF.

3a.Ad measurement and cookies

We run ads on Google to reach people who need to send a one-off fax. To know which ads actually work, we use one Google Ads conversion tag (gtag) and Google Tag Manager on every page.

What the tag does:

What the tag does not do:

Consent model. We use Google Consent Mode v2 with all four ad and analytics signals defaulted to denied on every page. Until you click Accept on the cookie banner, the Google tag receives a denied consent state, does not write the _gcl_* cookies, and does not send identifiers. If you click Decline (or never interact with the banner), consent stays denied for the session. If you click Accept, consent is updated to granted for ad measurement only and the choice is remembered in localStorage so you are not asked again on the same browser. You can reverse the choice by clearing site data.

You can block the tag with any browser extension (uBlock Origin, Privacy Badger, etc.) without affecting fax delivery.

4.What we do not do

5.Your rights (GDPR, CCPA)

5a.Data controller

The data controller for Shotfax is Povilas Konopackas, a sole trader based in Lithuania, EU. Contact: support@shotfax.com. This is also the address for any GDPR request.

6.Data retention

7.Security

All transmissions use TLS. Files in R2 are encrypted at rest. The fax leg uses Telnyx's private IP network with T.38 error correction for reliability. We follow OWASP guidelines for the web application and keep our attack surface small on purpose.

8.Contact

For privacy questions, reply from the address associated with your receipt or email support@shotfax.com.