PayAppCheck

Privacy Policy

Last updated: July 27, 2026

1. Who we are

This Privacy Policy explains how Ludvig Bergerud, a sole trader (enskild firma) registered in Sweden and operating PayAppCheck (payappcheck.com) ("we", "us", "our"), collects, uses, and protects information when you use the Service. We are the data controller for the information described in this Policy. Our registered business address is Lilla Bergaliden 1, 252 23 Helsingborg, Sweden. Contact us about privacy at [email protected].

2. Information we collect

(a)
Account information: such as your name, email address, business name, and account credentials.
(b)
Uploaded documents and extracted data: the AIA G702/G703 and related construction payment documents you upload, and the figures and data extracted from them ("Customer Data").
(c)
Usage data: log data, device and browser information, IP address, and information about how you interact with the Service, collected for security, diagnostics, and product improvement.
(d)
Payment and buyer data: collected and processed by Paddle, our reseller and Merchant of Record, under Paddle's own privacy policy (paddle.com/legal/privacy). We do not collect or store your payment card details. We receive limited transaction information from Paddle (such as your name, billing country, subscription status, and the last digits of the card) to manage your account.

3. How we use information

We use information to: provide, operate, and secure the Service; extract data and perform calculations on your uploaded documents; generate Excel/CSV/JSON output; manage your account, subscription, and support requests; detect and prevent fraud and abuse; comply with legal obligations; and improve and maintain the Service. Where the GDPR applies, our legal bases include performance of our contract with you, our legitimate interests in operating and securing the Service, and compliance with legal obligations.

4. Document handling, retention, and AI

4.1 Retention of uploaded source documents. Your uploaded source documents (the original PDFs/scans) are automatically deleted within 7 days by default. You can change this in your account settings: from "delete immediately after processing" or 24 hours, up to a maximum of 30 days. We do not retain your uploaded source documents indefinitely.
4.2 Retention of extracted results and history. The extracted data, reconciliation results, and output associated with your account are retained for 90 days by default, after which they are automatically deleted. You can change this in your account settings: from 30 days up to a maximum of 1 year. We do not retain processed results indefinitely. You can export your data at any time before it is deleted.
4.3 You control your retention periods. You can adjust both retention windows above at any time in your account settings. Changes apply going forward and to data already stored, so shortening a window also removes older data on our next scheduled cleanup.
4.4 Data storage location. Customer Data is stored on servers located in the United States.
4.5 No AI training on customer documents. We do NOT use customer documents or Customer Data to train artificial-intelligence or machine-learning models. Our data-extraction sub-processor processes your documents only to return the extracted data to us, under API terms that prohibit using your content to train its models, and we do not enable any data-sharing or model-improvement option for your content.
4.6 Account data retention. We retain account information for as long as your account is active and for a reasonable period afterward as needed to comply with legal, tax, accounting, and dispute-resolution obligations, after which it is deleted or anonymized.

5. Sub-processors and disclosure

We share information only as needed to operate the Service, with the following sub-processors:
(a)
Railway: cloud hosting and the PostgreSQL database; hosts the Service and stores your data in the United States;
(b)
Google: the Gemini API, our AI document-extraction provider, processes your uploaded documents to return the extracted data, under API terms that prohibit using your content to train its models. Google also provides the optional "Sign in with Google" login (Google Identity Services) and the web fonts used on our pages, so your browser connects to Google servers when you use the site;
(c)
Cloudflare: DNS and content delivery / network security for payappcheck.com;
(d)
Resend: to send transactional email, such as email-verification and account notices;
(e)
Paddle: as Merchant of Record, to process payments, taxes, invoicing, and refunds.
If you connect an integration that sends data to a destination you control (for example Slack notifications or webhooks to your own endpoints), we transmit the relevant data (such as document summaries or extracted results) to the destination you configured. Those services act on your instructions and are governed by your agreements with them, not by this Policy.
We may also disclose information where required by law, to enforce our Terms, or to protect rights, safety, and security. We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising.

6. Your rights

Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to restrict or object to certain processing. California residents (under the CCPA as amended by the CPRA) have the rights to know, to delete, to correct, to opt out of the sale/sharing of personal information (note: we do not sell or share your information), and to limit the use of sensitive personal information, and the right not to be discriminated against for exercising these rights. EU/EEA/UK residents have rights under the GDPR/UK GDPR, including the right to lodge a complaint with a supervisory authority. To exercise any right, contact [email protected]; we will verify your request and respond as required by applicable law.

7. Cookies and analytics

We use strictly necessary cookies to operate the Service (for example, to keep you logged in). We do not currently use third-party analytics or advertising trackers; if we introduce analytics in the future, we will update this Policy first. You can control cookies through your browser settings; disabling some cookies may affect functionality.

8. Security

We use reasonable administrative, technical, and organizational measures to protect information, including encryption in transit. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the updated version with a revised "Last updated" date and, where required, notify you.

10. Contact

[email protected], or by post to Ludvig Bergerud, Lilla Bergaliden 1, 252 23 Helsingborg, Sweden. For payment-related data handled by Paddle, see paddle.com/legal/privacy.
PayAppCheck

Pay applications, checked to the cent. Built for US construction finance.

© 2026 PayAppCheck. Made for US construction finance.[email protected]

PayAppCheck checks the math. You review and approve. Not legal, accounting or tax advice.

Billing and payment inquiries are handled by Paddle, our merchant of record.

AIA, G702, and G703 are marks of The American Institute of Architects. PayAppCheck is not affiliated with, endorsed by, or sponsored by AIA.