Legal
Privacy Policy
Effective May 9, 2026
OnPoint Technologies (“OnPoint”, “we”, “us”) provides a document intelligence API used by businesses to extract structured data from passports, ID documents, and government documents. This Privacy Policy explains what we collect, what we do with it, and what we don’t do with it.
1. The data you send us
When you call our extraction API or use the in-browser demo, you send us a document image — a passport, ID card, or government document (JPG, PNG, or PDF). We treat that image, the machine-readable zone (MRZ) we decode from it, and the structured fields we return as customer data.
- Images are never stored. The document image is processed in memory and released the moment the HTTP response is returned to your server. It is never written to any database, object store, or backup — there is nothing to purge later.
- Extracted results: kept up to 30 days, then purged. If the request was made from a signed-in account or with an API key, we store the structured result (the fields we return, including the decoded MRZ) so it appears in your extraction history in the dashboard. It is deleted automatically once it is older than 30 days. Anonymous requests made from the public demo, without signing in, are not stored at all.
- Deleted with your account. When you delete your account, every stored result belonging to it is purged immediately. The usage record behind each billed scan is retained — timestamp, success, latency, credits charged — but with no extracted values in it.
- No model training, no third parties, no routine review. Customer data is never used to train models and is never shared, sold, or sent to any third party beyond the sub-processors listed in §6. Stored results are not reviewed as a matter of course; access is limited to OnPoint administrators, for support and abuse investigation only.
2. The data we keep about your account
To run the service we do retain a small amount of operational data about you and your team:
- Account. Email, name, password hash (bcrypt), email verification status, and timestamps.
- API keys. A salted hash of each key (the plaintext is shown to you exactly once), label, last-used timestamp.
- Usage metadata. For each extraction we keep a permanent row containing: timestamp, success/failure, latency, page count, the API key used, a confidence score, and which credit the scan was billed against. This row is the billing record for the charge, so it is not deleted — but once the 30-day window in §1 has passed it contains no extracted values, and it never contains the image.
- Billing. Stripe customer ID, payment status, credit ledger transactions. Card numbers are handled by Stripe directly and never reach our servers.
3. Where data lives
Account, billing, and usage metadata are stored in a managed Postgres database in the European Union. Backups are encrypted at rest and retained for 14 days. We use Stripe (US) for payments and Resend (US) for transactional email; both are subject to their own privacy policies.
4. How we use it
- To run the extraction API and bill you for credits used.
- To enforce rate limits, detect abuse, and respond to security incidents.
- To send transactional email (verification, receipts, security).
- To compute aggregate, anonymized service metrics.
We do not sell personal data. We do not share personal data with advertisers, brokers, or analytics partners.
5. GDPR / your rights
OnPoint acts as a processor of customer data (document content) and a controller of account data. If you are based in the EU/UK you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your account and all associated data — including every stored extraction result (also available self-service from the dashboard). Two categories survive, both disconnected from you:
- the de-identified usage row we keep as the record of each charge: a timestamp, whether it succeeded, and what it cost, with no extracted values and no link back to you; and
- your payment and invoicing records. Tax and accounting law requires us to retain these for several years, so an erasure request does not remove them. We detach them from your account and remove the email address attached to them, leaving the transaction itself.
- Export your data in a portable format.
- Object to processing or restrict it.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email onpoint.tech@outlook.com. We respond within 30 days.
6. Sub-processors
The current sub-processors that touch operational data:
- Railway (US/EU) — application hosting.
- Stripe (US/IE) — payments and invoicing.
- Resend (US) — transactional email delivery.
- Cloudflare (US/EU) — DDoS protection and edge.
7. Security
Transport is TLS 1.2+ with HSTS preloaded. Data at rest is encrypted using AES-256. Access to production systems is gated by SSO with hardware-backed keys and is audit-logged. Suspected security incidents can be reported to onpoint.tech@outlook.com.
8. Children
OnPoint is not intended for use by individuals under 16. We do not knowingly collect data from children.
9. Changes
Material changes to this policy are notified by email at least 30 days before they take effect. The effective date at the top of this page always reflects the current version.
10. Contact
OnPoint Technologies — Data protection inquiries: onpoint.tech@outlook.com.