This policy describes what information NerdFax collects when you send a fax — with or without an account — and how it is used, stored, and eventually deleted.
| Category | Examples | Why |
|---|---|---|
| Document content | The file you upload to fax | To convert and transmit it |
| Recipient & sender fax numbers, sender name, company (optional) | Phone-formatted fax numbers, a name, an optional company name | To route the fax and print a sender line on every page (required by U.S. law) |
| Payment information | Handled entirely by Stripe, our payment processor — NerdFax never receives or stores your card number | To charge for a completed send |
| Account information (optional) | Name, email, and optional company, either via Google sign-in or by creating a password directly with NerdFax | To show your fax history and let you return to the product |
| Technical/operational data | IP address (for abuse prevention and rate limiting), timestamps, delivery status | To operate the service reliably and prevent abuse |
| Product analytics | Page views, device/browser category, and privacy-safe journey events such as reaching a workflow step or selecting a call to action | To understand where customers encounter friction and improve NerdFax |
Document content is deleted from NerdFax's storage on a bounded schedule after your fax reaches a final outcome (delivered, failed, or rejected) — currently within 24 hours. NerdFax's internal record retains the sender/recipient names, fax numbers, and non-content transmission facts (dates, delivery status, page count, and a cryptographic proof) needed to operate accounts, fax history, and dispute resolution — this internal record is never deleted. The public trace link NerdFax gives you to share, however, is built to a hard allowlist that never includes a fax number, a name, a company, or the document itself — only the non-identifying facts above.
NerdFax shares the minimum necessary information with the vendors that make the service work: Stripe (payment processing), Sinch (fax transmission), Google Cloud Platform (application hosting and document storage), Neon (database hosting), SendGrid (transactional email — receipts, verification, and account notices), Heap, and Google Analytics (privacy-restricted product analytics). These analytics services are configured to receive only general page visits and deliberately named journey events. NerdFax does not send either service fax documents, previews, filenames, names, email addresses, fax or phone numbers, trace tokens, payment identifiers, or raw form contents. Google advertising signals and ad personalization are disabled. Google explains how it uses information from sites that use its services.
See the separate Health Data & HIPAA Disclosure page for how NerdFax handles documents containing protected health information (PHI). In short: NerdFax's Business Fax Number product supports HIPAA-regulated workflows — Business Associate Agreements are in place with our infrastructure and fax-transport providers, and a customer executes their own BAA with NerdFax directly from their account before sending or receiving PHI. The anonymous, one-time send flow is not intended for PHI.
You may request access to, correction of, or deletion of your account information at any time by contacting us (see Section 8). Document content is already deleted automatically as described in Section 4, regardless of whether you have an account. You may also ask us to delete product-analytics data associated with your NerdFax account. Depending on where you live, you may have additional rights under local law; we honor requests consistent with those rights on a good-faith basis.
Questions about this policy or your information: support@nerdfax.com.