3PL invoice audit
Privacy policy
Version 2026-09-20. The short version: we read one invoice and a stripped orders export to find billing errors, we keep the file for 30 days and the extracted lines for 13 months, we never sell or share your data, and you can delete everything yourself at any time.
1. Who we are
The site is operated by the operator of this site (“we”). We are the controller of the data described here. For anything the self-serve pages do not cover, write to support@feecatch.com.
2. What the site does
You give us a business e-mail address, one invoice from your fulfilment provider (3PL) and, optionally, an export of your store’s orders, your rate card and a product list. We extract the invoice’s lines, compare them with what shipped and what your contract says, and show you the differences with their evidence. The free audit shows the findings on screen; a paid report adds the full document and a claim letter.
3. What we collect and why
| Data | Why | Kept |
|---|---|---|
| Your business e-mail address, the time you accepted these terms, and your two optional choices (monthly e-mail, anonymised copy) | To send the sign-in link, the result and the report; to know what you agreed to | While your business record exists |
| The invoice file (PDF, CSV or XLSX) and any rate card or product file you upload | To extract the lines and the rates | 30 days after the audit completes |
| The extracted invoice lines, the rate card rules, the intake answers and the findings | The audit itself; re-downloading a paid report; recognising the same invoice if it is uploaded again | 13 months |
| From your orders export: only the columns named in section 4 | To match invoice lines to orders and shipments | 13 months |
| Payment: amount, date, currency and Stripe’s references | Accounting and refunds | As long as tax law requires; detached from your business if you delete it |
| A salted hash of your IP address on each sign-in link request | Rate limits (a few requests per address per day); the address itself is never stored | With the link record, until your business record is deleted |
| First-party usage events: the step you reached, counts, the campaign parameters in the link you arrived by | To see where people get stuck and which ads work; no third-party analytics | Kept as counts; detached from you when you delete your data |
| Messages you exchange with support | To answer you | Until the matter is closed |
The anonymised copy (optional, on by default at the start step). If you leave the box ticked, we keep a copy of the extracted invoice in which order names are replaced by synthetic ones, tracking numbers by carrier-shaped fakes, SKUs by codes, dates shifted by a fixed offset and amounts kept. Any name, address, e-mail or phone number is dropped before the copy exists. We use these copies to teach the tool new invoice layouts and to test it. Untick the box, or start again with it unticked, and no copy is made. Because a copy identifies nobody, it is not deleted with your data.
4. What we never read
Your orders export never leaves your browser as a file. The page reads it on your device, keeps only these columns and sends those alone: Name, Created at, Fulfilled at, Fulfillment Status, Cancelled at, Lineitem sku, Lineitem quantity, Refunded Amount, Shipping Method, Tags. Customer names, e-mail addresses, phone numbers, billing and shipping addresses and order notes are dropped on your device and never reach us; the page lists the dropped columns before you confirm, and the server refuses the upload if any other column arrives. From the invoice itself, extraction keeps the billing fields of each line — order reference, tracking number, SKU, quantity, charge type, amount, dates — and the line’s short description; it has no field for a recipient’s name or address.
We do not read your store’s inventory, your customers, your prices or your bank details. We never ask for your provider’s or your store’s login.
5. How your invoice is read
The invoice’s text (or the page images of a scanned PDF) is sent to Anthropic’s API, which turns it into structured lines. Anthropic processes it under its commercial terms, which do not allow using it to train models, and does not keep it beyond short-lived abuse monitoring. The checks themselves run on our own servers.
6. Who processes data for us
| Provider | What for | Where |
|---|---|---|
| Fly.io | Hosting and the database | United States (Virginia) |
| Tigris | File storage for uploads and reports | United States |
| Anthropic | Reading the invoice into lines (section 5) | United States |
| Resend | Sending our e-mails | United States |
| Stripe | Payment for the report; your card details go to Stripe, never to us | United States / EU |
| Cloudflare | Telling people from bots on our forms (Turnstile); network and DNS | Global |
| Advertising measurement, only if you allow it (section 7) | United States |
Each provider acts on our instructions under a data-processing agreement. If you are in the EEA, the UK or Switzerland, transfers to the United States rely on the providers’ certification under the EU–US Data Privacy Framework or on standard contractual clauses. We do not sell data and we do not share it with anyone else.
7. Cookies and the advertising tag
| Cookie | Purpose | Lifetime |
|---|---|---|
__tplaudit | Keeps you signed in after you open your link. Strictly necessary; contains only a signed record id. | 14 days |
tpl_consent | Remembers your answer to the cookie question so we do not ask again. | 180 days |
| Google Ads tag | Loaded only after you choose “Allow”, and only to attribute a visit to an ad. Google sets its own cookies then; see Google’s policy. | Set by Google |
| Cloudflare Turnstile | May set a cookie on the forms that use it, to tell people from bots. | Set by Cloudflare |
There is no analytics script and no other third-party cookie. You can change your answer at any time on the cookie choices page; declining costs you nothing.
8. How long we keep things
- Original files: deleted 30 days after the audit completes, or immediately on request.
- Extracted lines, rate cards, findings and the stripped orders: 13 months, so a paid report can be re-downloaded and a repeated invoice recognised.
- Your e-mail address and consents: while your business record exists.
- Payment records: as long as accounting law requires, detached from your business once you delete it.
- Automatic database snapshots: a few days, then they expire; a snapshot is never restored to bring deleted records back.
9. Your rights and how to delete everything
Delete everything now. Go to delete my data, enter your address, open the link we send and confirm. Files, lines, findings, rate cards, order snapshots and every address on the business record are removed at once. The unit of deletion is the business: on a company domain, colleagues who signed in with the same domain share the record, and the confirmation page says so before the button.
Stop the monthly e-mail. Every list message carries an unsubscribe link; one click is enough.
Change the anonymised-copy choice. Start again with the box unticked, or write to us.
You also have the right to ask what we hold about you, to have it corrected or handed over in a machine-readable form, to object to processing based on our legitimate interests, and to complain to your data-protection authority. Write to support@feecatch.com for any of these; we answer within a month.
10. Legal bases
- Running the audit you asked for and delivering the report: performance of a contract.
- The monthly e-mail, the anonymised copy and the advertising tag: your consent, which you can withdraw as described above.
- Rate limits, bot protection, abuse prevention and usage counts: our legitimate interest in running the site safely.
- Keeping payment records: a legal obligation.
The site is for businesses; we do not knowingly collect data from anyone under 18.
11. Security
Everything travels over TLS. Sign-in links work once and expire after 15 minutes; only a hash of each link is stored. The session cookie is signed and unreadable by scripts. Files sit in a private bucket reachable only by our server. Keys and secrets are held by the hosting provider, never in the code. Reports are watermarked with the recipient’s address.
12. Changes
When this policy changes in substance, the version at the top changes, and you accept the new text the next time you start an audit. This version: 2026-09-20.