Privacy

We do not store payment files.

SepaCheck is built for a 14-day Google Ads test. Payment XML never becomes a dataset.

Layer A — validator

Uploaded pain.001 files are read into memory, checked, and discarded with the request. We do not write them to disk, object storage, or logs. Server logs may keep only version, byte size, pass/fail, and error codes.

Layer B — diagnostic waitlist

The €79 form collects email, bank, country, and the bank’s error text — not the payment file. On this host, submissions append to a local waitlist file when no webhook is configured. On Vercel they are acknowledged unless WAITLIST_WEBHOOK_URL is set. There is no live payment processor in this MVP.

What we never do

No bank login, no EBICS, no Verification of Payee, no payment initiation, and no LLM rewriting of your XML.