Privacy Policy
Effective 28 Sep 2026. This policy covers apps.infinihash.com (the "Store") and its Billing Hub, operated by InfiniHash LLC, Michigan, United States. Each InfiniHash app describes the data it holds on its own /security page; this policy applies to those apps for anything they do not cover.
What the Store collects
- Nothing about visitors. The Store has no accounts, no login and no forms other than the app filter. It sets no cookies for visitors. Page views are counted server-side per day and route, without IP addresses or identifiers. When a link carries campaign tags (utm_source, utm_medium, utm_campaign) the tags are counted the same way, and a newsletter signup made from such a page keeps the tags next to the address.
- Server logs. Requests are logged with a request id, path, status and timing for up to 30 days to operate the service. Rate limiting uses the client IP address in memory only.
- Optional analytics. If Google Analytics is enabled on a page it runs with IP anonymization and without advertising features. It is off unless the page's source shows the analytics script.
What the Billing Hub stores
When you subscribe to a paid plan in an app, the app asks the Billing Hub to open Stripe Checkout. The hub then keeps:
- The app and account identifiers, and the email address given at checkout.
- Stripe customer and subscription identifiers, the plan, its status, the current period end and whether it cancels at period end.
- The Stripe webhook events it received (event id, type, time, outcome) and their payloads for 90 days, so a failed event can be replayed.
Card numbers, bank details and full billing addresses never reach us; Stripe holds them under its own privacy policy. Stripe is our payment processor and the only third party that receives billing data.
What the apps store
Each app stores the data you and your team enter, the files you upload (hashed with SHA-256) and an event log of actions in the account, including the time, IP address and browser of reviewer, vendor or client actions taken through links you send. Each app's /security page lists exactly what it holds, its retention setting and how deletion works. Data lives in a per-app database on servers operated by InfiniHash LLC in the United States, backed up nightly with backups kept for 14 days.
Apps send transactional email only: verification, password reset, reviewer or vendor links, reminders and digests you configured. Every emailed link is also shown in the app so email is never required. We do not run marketing lists and the Store has no newsletter.
Your rights
You can export your data from each app, delete records, and delete the account itself. To have Billing Hub records removed after your last subscription ends, or to exercise access, correction or deletion rights under the law that applies to you, email [email protected] from the address on the account. We answer within 30 days. We do not sell personal data.
Retention
- App data: your retention setting, then removed by a scheduled job; account deletion is immediate for records and uploads, and generated PDFs are purged after 30 days unless downloaded.
- Billing Hub: customer and subscription records for as long as a subscription exists and for seven years afterwards where tax law requires; webhook payloads 90 days.
- Server logs and error records: 30 days.
Children
The Store and the apps are business tools for adults and are not directed at children under 16.
Changes
We will post changes here with a new effective date and, for material changes, email account holders in the apps.
Contact
InfiniHash LLC · [email protected]