Privacy policy
Short version. You upload a file, we pay Telnyx to send it, we delete the file the moment the send is finished, whether that is delivered or finally failed (a busy line gets redialed first, which can add a few minutes). We do not read the file. We do not sell your data. We set no cookies and run no tracking at all. If you want the long version, keep reading.
1.What we process
When you send a fax through Shotfax, the service:
- Receives your file upload and stores it temporarily in Cloudflare R2, encrypted at rest.
- Creates a checkout session via Stripe for the $2.99 flat fee.
- After payment, hands the file to Telnyx's fax delivery network, addressed to the destination fax number you provided.
- Deletes the file from our R2 storage as soon as the send reaches its final outcome. That is delivery, or the last failed attempt. If a destination line is busy we redial automatically (up to three attempts, and never longer than two hours), so on those sends the file is held for those extra minutes and then deleted the same way. Files tied to abandoned checkouts (payment never completed) are automatically deleted, typically within 65 minutes.
2.What we store after delivery
- A job record with: job ID, destination fax number, page count, amount charged, status (delivered or failed), timestamp, your email address (only if you chose to give one), and operational metadata about whether we successfully delivered your transactional notification email (time sent, internal Resend message ID, and a scrubbed error note if sending failed temporarily).
- The sender name you enter. It is printed in the fax header on every page because US law (47 U.S.C. 227(d)) requires faxes to identify their sender, and it stays in the job record for the same 90 days.
- A keyed one-way hash (HMAC-SHA256) of your IP address, used only to enforce a daily sending limit that keeps the service from being abused for bulk fax campaigns. We never store the raw IP, and the hash cannot be reversed without the server-side key.
- A record that you ticked the recipient-consent confirmation and the EU withdrawal-right acknowledgment at checkout.
- Your file's original name is not stored. Uploads are saved under a generic internal name.
- The file itself is deleted. We keep no copy of the document you sent.
- Stripe holds the payment record. We never see or store credit card details.
2a.Lawful basis (GDPR Article 6)
- Contract, Art. 6(1)(b). Processing your file, the destination number, and your email to deliver the fax and the receipt you paid for.
- Legitimate interests, Art. 6(1)(f). Stamping your sender name into the fax header on every page. US telecommunications law (47 U.S.C. 227(d)) requires every fax transmitted into US networks to carry the sender's identity and a telephone number. Operating the service in compliance with the destination country's law, and protecting you from sender-identification liability, is a legitimate interest that outweighs any interest in omitting a name you provide voluntarily for exactly this purpose.
- Legitimate interests, Art. 6(1)(f). The 90-day job record (dispute and chargeback handling) and the hashed-IP daily limit (abuse prevention).
3.Sub-processors
| Service | Purpose | What they receive |
|---|---|---|
| Cloudflare | Hosting (Workers, R2, D1) | File (transient), job metadata |
| Telnyx | Fax delivery | File contents, destination fax number |
| Stripe | Payment processing | Card details, billing email. PCI-DSS compliant; EU data transferred under Standard Contractual Clauses. |
| Polar.sh | Merchant of record for purchases before 12 July 2026 | Card details, billing email. Retention and transfers per Polar's own privacy policy (polar.sh/legal/privacy). |
| Resend | Transactional email delivery | Recipient email address, delivery metadata |
Scroll the table sideways to see every column.
Shotfax is not a HIPAA-compliant service and does not sign Business Associate Agreements. HIPAA covered entities and business associates should not use Shotfax to transmit Protected Health Information. A patient sending their own health records on their own behalf is not restricted by this, but does so under the same best-effort, no-warranty terms as any other document.
3a.Cookies and tracking
Shotfax sets no cookies and runs no tracking of any kind. There is no analytics, no advertising pixel, no tag manager, no retargeting, no session recording, and no fingerprinting. There is nothing to consent to, which is why you were not shown a cookie banner.
Until 17 August 2026 this site loaded a Google Ads conversion tag and Google Tag Manager, behind a consent banner defaulted to denied. Shotfax does not buy ads, so the tag measured a channel that did not exist. It has been removed entirely, along with the banner. If Shotfax ever advertises, this section and the consent banner come back before any tag does.
The only client-side storage the site uses is a short-lived browser value on the receipt page so a reload does not lose your reference number. It never leaves your device.
4.What we do not do
- We do not retain copies of your documents after delivery.
- We do not read, analyze, or process the contents of your files.
- We do not sell or rent your personal data.
- We do not use your data to build advertising profiles or retarget you.
- We do not run Google Analytics, Meta Pixel, or any tracking, advertising or analytics technology whatsoever.
5.Your rights (GDPR, CCPA)
- Access. Email us with a job ID for a copy of the metadata we hold.
- Deletion. Job records auto-delete after 90 days. Earlier deletion on request.
- Portability. All data we hold is the metadata above. We will send it as JSON.
- Objection and restriction. You may object to processing or ask us to restrict it. In practice, once the fax is sent there is nothing left for us to process.
- Complaint to a supervisory authority. You may lodge a complaint with the Lithuanian supervisory authority, the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, VDAI), vdai.lrv.lt. EU and UK users may also complain to the supervisory authority in their country of residence (list at edpb.europa.eu/members).
5a.Data controller
The data controller for Shotfax is Povilas Konopackas, a sole trader based in Lithuania, EU. Contact: support@shotfax.com. This is also the address for any GDPR request.
6.Data retention
- File contents. Deleted from R2 on the delivery webhook, or on the final failure once any automatic redials are exhausted. A redialed send holds the file at most two hours. Abandoned checkouts (no payment) are cleared automatically, typically within 65 minutes.
- Job records. 90 days, then auto-deleted. We keep job metadata for 90 days so we can handle late-reported delivery issues, chargeback disputes, and accounting reconciliation. Nothing longer is needed.
- Payment records. Held by Stripe (and by Polar.sh for purchases before 12 July 2026) per their retention policies.
7.Security
All transmissions use TLS. Files in R2 are encrypted at rest. The fax leg uses Telnyx's private IP network with T.38 error correction for reliability. We follow OWASP guidelines for the web application and keep our attack surface small on purpose.
8.Contact
For privacy questions, reply from the address associated with your receipt or email support@shotfax.com.