Privacy Policy

Effective 13 August 2026

This policy explains what GetPaid.Tools (“GetPaid”, “we”) records when you use getpaid.tools, why we record it, and how long we keep it. It covers the Site only.

1. The short version

We record who accepted our terms and when. We keep web server logs of every request. We record which pages and features get used — including the text of searches you run in Compliance Research Tools. We do not sell any of it, we run no advertising trackers, and the figures you type into the calculators are not sent to us.

Two things are easy to assume and wrong, so they are stated up front. First, logging does not start when you accept the terms — our content delivery network records every request from the moment you arrive, including from people who never register. Second, the usage records are not anonymous in any strong sense: they carry your IP address and a device identifier your browser keeps, and so does the acceptance record holding your name and email, which means the two can be connected. Section 2 sets out exactly what that means.

2. What we collect

a. Your acceptance of the terms

You accept the terms when you register. At that moment we record, as a durable legal record:

  • the full name you entered;
  • the email address you entered, converted to lower case;
  • the date and time of the acceptance — both your browser’s clock and our server’s, since the first can be wrong or altered;
  • the IP address the acceptance was sent from, as seen by our server, and the country our network derives from it;
  • your browser’s user-agent string, which identifies the browser and operating system;
  • the version of the terms you accepted (currently version 1), a fingerprint of the exact wording that was on screen, and the page you were on when you accepted;
  • the device identifier your browser is holding — the random id described in section 4.

Registering is where we deliberately collect information that identifies you by name, and the purpose of the acceptance half of it is narrow: to be able to show who agreed to which words, and when. The wording fingerprint is there so that a later edit to the terms cannot make an old acceptance look like agreement to text you never saw.

b. Registering for an account

Some tools ask you to register before you use them. Registering records your name, work email address, company, phone number and job title. We use them to run your account, to send the sign-in code that gets you in, and to tell us that someone has registered. Amazon Web Services Cognito handles the sign-in itself, Stripe holds the customer record these details are kept on, and Resend delivers the code email. We keep them for as long as the account exists.

c. Request logs, kept whether or not you accept

Our content delivery network records a standard entry for every request to the Site: IP address, timestamp, the URL and query string requested, the response status and size, your browser’s user-agent string, and the referring page.

This happens at the network edge, before any of our page code runs. If you arrive, read a page and leave without registering, that visit is still logged. Registering is not the point at which collection begins, and not registering does not stop it.

d. Usage events

We record how the Site is used. Each event carries the device identifier described in section 4, a randomly generated session identifier, the event name, a timestamp, the page path, the referring page, your IP address, your user-agent string and your country, plus properties specific to the event. As built, those properties are:

  • the literal text of searches you run in Compliance Research Tools, and how many results each returned;
  • which library page you opened, and what you clicked to get there;
  • JavaScript error messages, when something on the Site breaks.

The session identifier is random, is not derived from your name or email, is held in your browser’s session storage, and is discarded when you close the tab. The device identifier is random in the same way, but it is held in local storage and it outlives the tab — that is what it is for, and section 4 says how to be rid of it.

These records are not anonymous. Usage events carry your IP address and your device identifier, and so does the acceptance record that holds your name and email. Anyone with access to both could therefore link a search you typed to the person who registered from that browser — and the search text is recorded verbatim, so treat the search box as something we can read. We do not currently perform that linking for any purpose beyond investigating abuse or a fault, but we are telling you it is possible rather than describing the data as anonymous when it is not.

e. What we do not collect

The values you enter into the tools stay in your browser. The calculators run entirely on your machine: the dates, amounts, states and account details you type into a tool are not transmitted to us and are not stored on our servers. We do not want consumer or debtor personal information and ask you not to enter it anywhere on the Site — see section 8 of the Terms of Use.

Note the boundary between this and section 2d: calculator inputs are not sent to us, but what you type into the Compliance Research Tools search box is. They are different boxes on different pages.

We do not use advertising or cross-site tracking technology, we do not run third-party analytics services, and we do not build advertising profiles.

3. Why we collect it

  • The acceptance record — to evidence agreement to the terms, and to contact you if something you relied on turns out to be wrong.
  • Request logs — to operate and secure the Site, diagnose faults, and investigate abuse.
  • Usage events — to understand which tools and which parts of the library are actually used, and what people search for and fail to find, so we can improve them and decide what to build next.

We may also use the email address you gave us to tell you about changes to the terms, about a correction to something the Site got wrong, and about new tools. Every such message will say how to stop receiving them.

4. Storage in your browser

When you register we store a small record in your browser’s local storage under the key gp.terms, holding the version of the terms you accepted and the time you accepted it. It is what stops us putting the same question to you twice. It contains no name and no email address.

We also store a device identifier under the key gp.did. It is a random id your browser makes the first time it loads a page here and then keeps. It is not a fingerprint: nothing about your computer, your screen, your software or you is measured or built into it, and a second browser on the same computer gets a different one. It travels with the usage events in section 2d and with the acceptance record in section 2a, and what it buys us is the ability to tell one browser’s activity from another’s, and to connect a registration to the activity around it.

Clearing your browser storage, or browsing in a private window, erases both of them: the terms record, and the device identifier along with the history it could be connected to. The Site sets no advertising cookies.

5. Where it goes and who can see it

It is held in our own Amazon Web Services account in the United States, apart from the registration details in section 2b, which also sit with the processors named there. Acceptance records go to a private database table with point-in-time recovery enabled; usage events and request logs go to private storage buckets that are not publicly readable. Amazon Web Services processes all of it as our infrastructure provider. Access is limited to the people who run the Site.

We do not sell your personal information and we do not share it with third parties for their own marketing. We may disclose it where we are legally required to — a subpoena, a court order, or a regulator’s lawful demand — and to professional advisers under a duty of confidence. If the Site or the business behind it is transferred to someone else, this record may transfer with it, subject to this policy.

6. How long we keep it

Our retention periods are:

  • Acceptance records — for as long as the agreement they evidence could be disputed, and no longer than the longest limitations period that applies to it.
  • Request logs — 90 days.
  • Usage events — 24 months.

7. Security

The acceptance record is held in a private, access-controlled table with point-in-time recovery enabled, and usage data in private, non-public storage. Traffic to and from the Site is encrypted in transit. No system is perfectly secure, and we cannot guarantee that a determined attacker will never reach it.

8. Your choices and your rights

You can ask us what we hold about you, ask us to correct it, or ask us to delete it. Deleting an acceptance record removes the evidence that you agreed to the terms, so we will ask you to stop using the Site if you make that request. Depending on where you live — California, Colorado, Connecticut, Virginia and others — you may have additional statutory rights, including the right not to be discriminated against for exercising them.

To make a request, write to hello@getpaid.tools.

9. Children

The Site is a professional tool and is not directed to anyone under 18. We do not knowingly collect information from children.

10. Changes to this policy

We may update this policy. The effective date at the top of the page changes when we do. Where the change is substantive we will also raise the terms version, which asks you to read and accept again on your next visit.

11. Contact

Questions about this policy: hello@getpaid.tools.