Skip to content

Privacy Policy

Effective: 21 September 2026

This policy explains what data PDFPipe (the "Service") collects, why, and the choices you have. It applies to the website and the API. Questions go to hello@pdfpipe.xyz.

1. Data we collect

Account data: your email address and authentication credentials. Billing data: handled by our payment processor; we store a plan and a customer reference, not your card number. Usage data: API request counts, timestamps, and document metadata needed to meter and secure the Service. Product and website analytics: page views and product events (such as signups and renders) recorded against a random per-browser session id and, once you sign in, your API key, so we can see where people get stuck. There is no cross-site tracking. For account lifecycle messages, your email address, plan, and a few account events are shared with our product analytics provider.

2. Document content

The HTML, URLs, and rendered PDFs you send are processed to fulfill your request. Unless you set store: true, a PDF rendered from HTML is held in a short-lived cache, scoped to your account, for up to 10 minutes so identical requests are served instantly, and is then discarded. When you set store: true, the document is kept for the retention window of your plan and then deleted. Templates and schedules you save keep their HTML until you delete them. We do not read, sell, or use your document content to train models.

3. E-invoice validation

Invoices you submit to the e-invoice validator or the validation API are processed in memory for the duration of the request and are not written to disk, logged, or retained. We do not keep a copy of the file, its contents, or the report after the response is returned. Because invoices routinely contain personal data such as names, addresses, contact details, and bank details, this is the deliberate design: the data never comes to rest on our systems.

For the free validator we record the IP address of each request and a daily counter, to enforce the rate limit and prevent abuse. That is the only data retained from a free validation, our lawful basis for it is legitimate interest in keeping the service available, and the counters reset daily.

When you validate through the API with an API key, we act as a processor on your behalf for the invoice content. If you are established in the EEA or the UK and need a data processing agreement, see our data processing agreement or email us to have one countersigned.

4. International transfers

PDFPipe is operated from India, and our infrastructure providers may process data in the European Union, the United States, and elsewhere. Where personal data is transferred out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable. A copy is available on request. For e-invoice validation specifically, invoice content is processed transiently and is never stored in any jurisdiction.

5. How we use data

To provide and secure the Service, meter usage and bill accurately, prevent abuse and fraud, respond to support requests, and meet legal obligations. We do not sell personal data.

6. Service providers

We share the minimum data necessary with infrastructure, payment, and email providers that process it on our behalf under contract. These providers are not permitted to use your data for their own purposes. They are: Cloudflare (hosting, API compute, database, document storage, and backup PDF rendering), Oracle Cloud Infrastructure (PDF rendering and e-invoice validation, India), Dodo Payments (payments and billing), Resend and MailerSend (transactional email), PostHog (product analytics, EU), and Ahrefs (cookieless website traffic analytics). The sub-processors for customer data, with regions, are listed in our data processing agreement.

7. Retention

Account and billing records are kept while your account is active and as required by law. Stored documents follow your plan's retention window. You can request deletion of your account and associated personal data at any time.

8. Your rights (GDPR and CCPA)

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to not be discriminated against for exercising these rights. We do not sell personal information. To make a request, email hello@pdfpipe.xyz and we will respond within the timeframe required by law.

9. Cookies

We use only essential cookies for authentication and session handling. Analytics use a random session id kept in your browser's local storage, not advertising or cross-site tracking cookies.

10. Security

Data is encrypted in transit. Access to systems is restricted and audited. See our security page for more detail.

11. Changes

We may update this policy and will revise the effective date above. Material changes will be announced through the Service.

12. Contact

PDFPipe, Mumbai, India. hello@pdfpipe.xyz

See also our Terms of Service.