WhoPaid

Privacy Policy

Last updated 26 July 2026

Fill this in before going live: every reference below to [LEGAL ENTITY] must be replaced with the registered business name that matches your Stripe account, together with a mailing address. This policy is a working draft and has not been reviewed by a lawyer.

This policy explains what [LEGAL ENTITY] ("we") does with information when you use WhoPaid. "You" means the business with a WhoPaid account. WhoPaid is a web application — you use it in a browser and your data is processed on our servers.

The short version

Check images you upload travel encrypted to us and the account and routing numbers are masked on arrival. The original, un-masked image is deleted as soon as masking is confirmed, and in every case within hours. We do not keep un-redacted account numbers, and un-redacted images are never sent to any third party.

What happens to an uploaded check

Account and routing numbers exist only in memory during masking. They are never written to our database.

What we store, and for how long

Who else is involved

We do not sell your information, and we do not share it for advertising.

Payment information

Card and bank details are entered on payment pages hosted by Stripe. Card numbers never pass through WhoPaid, and we never see or store them. Stripe's handling of that data is governed by Stripe's privacy policy. From Stripe we receive only what we need to run your account: billing contact, plan or credit status, and payment history.

Account information

We hold your business name, the email addresses of the people you authorise to sign in, your plan or credit balance, and a record of checks processed for billing. Signing in is by email verification or through your own identity provider; we do not store passwords.

Security

Data is encrypted in transit and at rest. Access to your account is gated at the front door and every request is authenticated. Actions within the account are logged. Because long-term storage holds redacted images only, even a worst-case breach of that storage would not expose account or routing numbers.

This website

This marketing site sets no cookies, runs no analytics, and loads nothing from third parties. If you email us, we keep the email so we can reply.

Your choices

You can ask us what information we hold, ask us to correct it, ask us to export it, or ask us to delete it once billing obligations are settled. Write to hello@whopaid.today.

Changes

If this policy changes in a way that affects how check data is handled, we will tell account holders by email rather than only updating this page.

Contact

[LEGAL ENTITY]
[MAILING ADDRESS]
hello@whopaid.today