Privacy Policy

Last updated: March 24, 2026

FuelSnap ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our fuel expense tracking service (the "Service"). This policy complies with the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

We do not sell your personal data to third parties.

1. What Data We Collect

Account Information

When you create an account, we collect your email address, name, and create a secure password hash. This information is necessary to provide you access to the Service.

Fuel Expense Data

We collect and store fuel transaction data including station names, fuel type, volume, price per gallon, total cost, dates, locations, odometer readings, vehicle information, and any notes you add. This data is entered by you or extracted from receipt images you upload.

Receipt Images

When you upload photos of gas receipts or pump displays, we process these images using OCR (Optical Character Recognition) technology to extract fuel transaction data. Images may be stored in your account for your records or deleted after processing, depending on your preferences.

Payment Information

Payment processing is handled by Stripe, Inc. We do not store your credit card numbers or banking information. We only store your Stripe customer ID and subscription status to manage your account.

Usage Analytics

We collect information about how you use the Service, including pages visited, features used, device type, browser type, IP address, and general location (city/region level). This helps us improve the Service and understand user behavior.

Communications

If you contact our support team, we may retain records of your communications, questions, and feedback.

2. How We Use Your Data

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Process OCR on uploaded receipt images to extract fuel transaction data
  • Generate analytics, reports, and data exports for your fuel expenses
  • Process subscription payments and manage billing
  • Send transactional emails (receipts, account notifications, service updates)
  • Respond to support requests and customer inquiries
  • Monitor and prevent fraud, abuse, and security issues
  • Analyze usage patterns to improve features and user experience
  • Comply with legal obligations and enforce our Terms of Service

We do not use your data for advertising purposes or sell it to third parties.

3. Third-Party Services

We use the following third-party services to operate the Service. These providers may process your data on our behalf:

Supabase — Database hosting, file storage, and authentication infrastructure. Data is encrypted at rest and in transit.
Google Cloud Vision API — OCR text extraction from uploaded receipt images. Images are processed securely and not retained by Google beyond processing.
Anthropic (Claude API) — AI-powered data extraction to parse OCR text into structured fuel expense records. Text data is processed via API and not used for training.
Stripe — Payment processing and subscription management. Stripe is PCI-DSS compliant and handles all credit card data securely.
Resend — Transactional email delivery (account confirmations, receipts, notifications).
Vercel — Web hosting and content delivery network. Server logs may include IP addresses and request metadata.

All third-party providers are contractually obligated to maintain data security and privacy standards consistent with this policy.

4. Data Storage and Security

We implement industry-standard security measures to protect your data:

  • All data transmission uses HTTPS encryption (TLS 1.2 or higher)
  • Data at rest is encrypted using 256-bit AES encryption
  • Passwords are hashed using bcrypt with salt
  • Database access is protected with Row Level Security (RLS) policies
  • API endpoints require authentication tokens
  • Regular security audits and vulnerability scanning
  • Access controls and role-based permissions for internal systems

While we use commercially reasonable efforts to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.

5. User Rights (GDPR & CCPA)

You have the following rights regarding your personal data:

Right to Access

You can access all your personal data through your account dashboard. You can also export all your data in JSON or CSV format using the Export feature in Settings.

Right to Rectification

You can edit and correct your account information, vehicle details, and fuel logs at any time through the Service.

Right to Erasure ("Right to be Forgotten")

You can permanently delete your account and all associated data (profile, fuel logs, vehicles, receipt images) through Settings > Account > Delete Account. Deletion is immediate and irreversible.

Right to Data Portability

You can export all your fuel expense data in machine-readable formats (JSON, CSV) at any time.

Right to Opt-Out

You can opt out of non-essential emails through your account settings. Transactional emails (receipts, security alerts) cannot be disabled as they are necessary for the Service.

Right to Object

You can object to certain data processing activities. Contact us at business@fuelsnap.app to exercise this right.

To exercise any of these rights, contact us at business@fuelsnap.app. We will respond within 30 days.

6. Cookies and Tracking Technologies

We use the following cookies:

Essential Cookies: Session authentication tokens to keep you logged in. These are required for the Service to function.
Affiliate Tracking Cookies: If you arrive via an affiliate link, we set a 30-day cookie to track referrals for commission purposes.
Analytics Cookies: We may use cookies to track basic usage patterns (pages visited, session duration) to improve the Service.

We do not use third-party advertising cookies or cross-site tracking. You can disable non-essential cookies through your browser settings, but this may limit Service functionality.

7. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act:

  • Right to Know: You can request disclosure of the categories and specific pieces of personal data we collect, use, disclose, and sell.
  • Right to Delete: You can request deletion of your personal data (subject to certain legal exceptions).
  • Right to Opt-Out of Sale: We do not sell personal data, so there is nothing to opt out of.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

To exercise these rights, contact us at business@fuelsnap.app with "CCPA Request" in the subject line.

8. European Union Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), you have rights under the General Data Protection Regulation:

  • Right to access your personal data
  • Right to rectify inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Right to withdraw consent at any time
  • Right to lodge a complaint with a supervisory authority

Our legal basis for processing your data is: (a) performance of a contract (providing the Service); (b) legitimate interests (improving the Service, fraud prevention); (c) consent (for optional features); (d) legal compliance.

9. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. When you delete your account, all associated data (profile, fuel logs, vehicles, receipt images) is permanently deleted within 30 days. Some data may be retained longer if required by law (e.g., payment records for tax purposes may be retained for 7 years).

10. Children's Privacy

The Service is not intended for users under 13 years of age. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently collected data from a child under 13, please contact us immediately at business@fuelsnap.app and we will delete it.

11. International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence, including the United States. We ensure that such transfers comply with applicable data protection laws through standard contractual clauses and other approved transfer mechanisms.

12. Do Not Track Signals

Some web browsers have a "Do Not Track" feature. Because there is no industry standard for how to respond to Do Not Track signals, we do not currently respond to them.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify registered users of material changes via email at least 30 days before they take effect. Continued use of the Service after changes become effective constitutes acceptance of the updated policy.

14. Contact Information

For privacy-related questions, to exercise your rights, or to report a data breach, contact us at:

Email: business@fuelsnap.app

Subject Line: Privacy Request

We will respond to all requests within 30 days.