Skip to the receipt

Endless Receipt

Privacy policy

Last updated 25 August 2026

The short version

There are no accounts, no logins, and no tracking cookies. We collect as little as we can get away with. The thing you type is deliberately public, and we never sell your personal data to anyone.

What is public on purpose

Your name, message, receipt number, amount, and the hostname of your destination (if you added one) are published on the receipt for anyone to read, along with the destination’s own public name, description and icon. Do not put anything private or sensitive in them.

Once a line is published, other people can copy it, screenshot it, quote it, archive it, or repost it anywhere. That is outside our control, and it cannot be undone by us later. Voiding a line removes it from our pages — it does not remove copies other people already made.

What we process

  • The name and message you submit, and your destination link if you added one.
  • Public information retrieved from a destination you submit — its title, description and icon — which we fetch from our own servers and cache so the same page is not read repeatedly.
  • The amount you paid and the Stripe identifiers for the transaction, so a payment can be matched to a receipt.
  • A one-way hash derived from your IP address, used for rate limiting and to stop report spam. The hash cannot be turned back into an address. Our application does not intentionally store raw IP addresses in the Endless Receipt database for ordinary use, but hosting, security, and infrastructure providers may process network information such as IP addresses as necessary to deliver and protect the service.
  • Reports you file, with the same hashed identifier and whatever details you type.
  • A running total of outbound clicks per destination, plus a short-lived hashed identifier used only to avoid counting the same visitor twice inside a thirty-minute window.
  • Ordinary request metadata and server logs generated by our hosting provider, used to keep the site running and to investigate abuse and failures.
  • Internal moderation notes on a receipt, where a line has been reviewed or voided. These are never published.

Why we process it

  • to fulfil your purchase and print your line
  • to operate and display the receipt
  • to prevent abuse, spam, and fraud
  • to enforce the receipt rules and act on reports
  • to troubleshoot failed payments and fulfilment
  • to keep the site and its data secure
  • to comply with legal obligations, including accounting and tax

Payments

Payments are processed by Stripe. Stripe collects your card details and, so it can send you its own payment receipt, your email address. Card details never reach our servers and we do not store them.

Endless Receipt does not intentionally store your payment email in its application database — we keep only the Stripe identifiers needed to reconcile a payment with a receipt number. Stripe may collect and retain payment-related contact information as part of processing your transaction, and its handling of that data is governed by Stripe’s own privacy policy.

Who else is involved

We use a small number of providers to run Endless Receipt:

  • Stripe — payment processing.
  • Supabase — database and backend infrastructure, where receipts and reports are stored.
  • Vercel — hosting and application infrastructure, including server logs and privacy-friendly aggregate analytics.

These providers process data on our behalf so the site can function. We do not sell personal data, and we do not share it for advertising.

Analytics

We use Vercel’s aggregate analytics to count page views and a few product events — how many people opened the form, started a checkout, completed one, or clicked share. No cookies, no cross-site tracking, no advertising profiles.

Destinations we fetch

When you submit a destination, our servers request that page so we can read its public title, description and icon and offer them back to you as a starting point. This is an ordinary request from our infrastructure, and the site you named may see it in its own logs, the same way it sees any other visitor. We identify ourselves in the request.

Only a small amount of the page is read. Nothing on it is executed — no scripts, no embeds, no styles, no fonts — and no browser engine is involved. We do not sign in, send cookies, or submit anything to the page.

A destination’s icon is re-encoded by us into a small image and stored in our own file storage, so that visitors’ browsers load it from us rather than from the destination’s server. Cached title, description and icon are kept against the destination and refreshed occasionally rather than on every page view.

Outbound links

Clicks on user-submitted links pass through our redirect handler at /go/{number} so that a dangerous destination can be switched off centrally. The redirect strips the referrer, so the destination is not told through the HTTP referrer which receipt page you came from.

We count outbound clicks in aggregate, as a single running total per destination, and show it on Receipt Leaders. To stop one person refreshing a link from inflating that number, a short-lived one-way hash of your IP address is used to recognise a repeat visit: at most one click per visitor, per destination, is counted in any thirty-minute window. The hash cannot be turned back into an address, it is not linked to you across destinations, and the record of it is discarded once the window has passed.

Every valid click redirects whether or not it was counted — counting is best-effort and never stands between you and where you were going.

What is kept long-term is the running total and nothing else. Endless Receipt does not intentionally store raw IP addresses in its application database for this purpose, and does not maintain a user-level history of outbound link clicks — there is no record of which visitor clicked which destination, or when. Hosting and infrastructure providers may process ordinary request metadata as necessary to deliver and protect the service.

How long we keep it

Published receipt lines are intended to stay published — that is the product. Payment records are kept as long as we need them for accounting, tax, and fraud purposes. Rate-limit records are short-lived and are cleared automatically. Server logs are retained for the period our hosting provider keeps them.

Your rights

Depending on where you live, you may have rights to access, correct, delete, or restrict the processing of personal data we hold about you, or to object to it. Because there are no accounts, the practical scope here is small: the content you chose to publish, the payment record, and a hashed identifier.

Receipt numbers themselves are not removed — they are the structure of the receipt — but content can be voided. Write to wasted@endlessreceipt.com with your receipt number and we will respond as required by the law that applies to you.

Children

Endless Receipt is not directed at children, and paying for a line requires the legal capacity described in the terms. If you believe a child has submitted content or a payment, contact us and we will deal with it.

Changes

If this policy changes, the date at the top changes with it. Material changes will be reflected here rather than announced individually, since we have no one to email.

Contact

Thank you for wasting your money.

www.endlessreceipt.com