Privacy Policy
Last updated: October 8, 2026
Who we are
Statement2Sheet (statement-to-sheet.com) is operated by Bolong Tech Inc., a company in British Columbia, Canada. We follow Canadian privacy law, including PIPEDA, British Columbia's Personal Information Protection Act and Québec's Law 25. Our Privacy Officer is responsible for this policy and can be reached at [email protected].
What we collect
- Your email address, when you sign in. You sign in with a password you confirm by email, or, where offered, with your Google account; we email you to confirm a password and when one is set. We never ask for your online banking credentials.
- If you set a password: we keep only a salted one-way hash of it (scrypt), never the password itself, and it works only after you confirm it from an email we send to your address.
- If you choose Continue with Google: Google tells us your Google account ID, your email address and whether Google has verified it (and your organisation's domain for a Google Workspace account). We do not receive your name, photo, contacts or Google password, and we keep no Google access tokens.
- The statements you upload and what we extract from them: transactions, balances, the statement period and the account number. We keep your corrections with them.
- Developer API data: API keys (we store only a hash), webhook URLs and delivery records, and any metadata you attach to a statement.
- Purchases: credits are sold through Stripe, which handles the payment as the seller (see below). We never receive your full card number; we keep a record of each purchase — its amount, credits and date — the credits you use, for a monthly plan Stripe's customer and subscription references, the plan and its status, and the checkout and payment records our Stripe account keeps (see below).
- A record of each conversion, without its contents: the bank, account type, page count, outcome, dates and statistics such as the number of transactions and corrections. We use it for billing, support and to measure our parser.
- Technical data: the cookies below, hashed (pseudonymised) IP and email addresses used to limit abuse, and operational logs. Our logs never contain statement contents, account numbers or email addresses.
Anonymous usage counts
We count public-page requests, upload-link activations and successful upload, review-edit and export operations using fixed categories. These counts have no visitor, session, user or document identifiers, and are not linked across steps.
For public requests, broad traffic-source and crawler categories are inferred from request headers; the original referrer URL and user-agent text are discarded. Repeated actions can count more than once. Our monitoring logs are configured for 30-day retention.
These counts use no tracking cookies or third-party analytics service.
Cookies
We use only cookies the service needs: a sign-in session (30 days, renewed while you use it), a cookie that lets you return to a statement you uploaded before signing in (30 days), and a short-lived cookie that ties a password confirmation or a Google sign-in to your browser (up to 30 minutes). We use no advertising or third-party tracking cookies.
How we use it
To convert your statements, show and correct the results, produce your downloads, sign you in, keep the service secure, and keep billing records. We do not sell your information or use it for advertising, and no one at Bolong Tech Inc. looks at your statements unless you allow it for a specific statement, as described below.
While we hold a statement, our software may also run newer versions of our parser on it to compare their results with the current one; only content-free statistics of that comparison are kept, and the statement is deleted on the usual schedule. We keep or copy a statement to improve our parser only if you allow it for that statement. If you do, a copy is kept in separate storage for up to 2 years, where our developers may look at it, and you can withdraw that permission at any time by writing to [email protected]. Deleting your account withdraws it too.
How long we keep it
- Uploaded statements, extracted transactions and your corrections are deleted automatically after 14 days, or as soon as you choose “Delete now”. Developer API customers can ask for the original PDF to be deleted as soon as it has been processed, with the results kept for 24 hours; the PDF of a statement that fails is kept for a retry, up to the 14 days.
- Statements you allowed for parser improvement: up to 2 years, or until you withdraw.
- Webhook delivery records: 30 days.
- Hashed IP and email addresses used for abuse limits: about 2 days.
- A sign-in request that is never completed: about a day after it expires.
- The content-free record of each conversion: indefinitely, for billing and statistics; once your account is deleted, it is no longer linked to your email address.
- Your email address, account, password hash and any linked Google account ID: until you delete your account (from your Account page) or ask us to. Purchase and credit records are kept as long as tax and accounting law requires.
Where it is stored, and who helps us
Your statements and their results are stored encrypted in Canada. A few service providers process limited information for us, under contracts that restrict them to that purpose:
- Hosting and storage — data centres in Canada.
- HTTPS delivery and security — Cloudflare processes requests to our service, including uploaded statements. This processing may occur outside Canada. Statement storage and our self-hosted AI processing remain in Canada.
- Email delivery — Resend (United States) receives your email address and the sign-in messages we send you.
- Payments — Stripe (United States) keeps, in our Stripe account, a record of each checkout and payment: your email address, a reference to your account and to the statement you bought for, and the name, billing address, card type and last digits the payment shows. We keep these like our other purchase records, as tax and accounting law requires. For a monthly plan it also keeps the customer record we create (your email address and an account reference) with its saved payment method; we delete that customer record when your account is deleted. Stripe also sells the credits itself — see below.
- AI processing — none by an outside company. When our parser cannot read or reconcile a statement, the pages involved may be read by an AI model that we run on our own servers in Canada. They are never sent to an outside AI provider, and the model neither keeps them nor learns from them. If we ever use an outside provider, we will name it and the country where it processes data here before we start.
If you choose Continue with Google, Google (United States) handles that sign-in under its own privacy policy and learns that you signed in to our service. Signing in with your email and password involves no Google account.
When you buy credits or a monthly plan, Stripe (United States) sells them to you as our reseller — the merchant of record — through its Link service (the charge shows as “LINK.COM*” on your card statement, and receipts come from Link), and handles the payment under its own privacy policy. It receives your name, email address, card or other payment details and billing address, charges any sales tax that applies, keeps the payment method of a monthly plan on file to charge each renewal until you cancel, and handles payment disputes and refunds of a charge. Stripe keeps this information for its own legal and tax records and may process it outside Canada; questions about it, or requests to delete it, go to Stripe.
Information processed outside Canada may be accessible to the authorities of that country under its law.
Security
Everything between your browser and our service travels over HTTPS, and statements are stored encrypted. Statements are stored under random identifiers, and through the service only their owner can open them. Downloads are generated on request and never exposed as storage links.
Business customers
When you send statements through our developer API on behalf of your own clients, you decide what is sent and we process it on your instructions. A Data Processing Agreement is available on request at [email protected].
Your rights
You can ask to see the personal information we hold about you, have it corrected, have it deleted, or withdraw a consent you gave, by writing to [email protected]. Payment information Stripe holds as the seller is covered by Stripe's privacy policy; the records in our Stripe account described above are ours to show you; we keep the purchase records as tax and accounting law requires, and delete the plan's customer record with your account. We answer within 30 days. If you are not satisfied, you can complain to the Office of the Privacy Commissioner of Canada, the Office of the Information and Privacy Commissioner for British Columbia, or, in Québec, the Commission d'accès à l'information.
Changes
If we change this policy, we will publish the new version here and update the date above.