Cookie preferences
We use cookies for essential functionality. With your consent, we also use analytics (Google, PostHog) and marketing pixels (Meta, LinkedIn) to improve LandedFees. You can withdraw consent anytime in Settings.
Trust
Last updated 24 August 2026
This page is written for the security or procurement reviewer evaluating LandedFees. It covers what we store, where it lives, who processes it, how we authenticate requests, how you can report a problem, and how you can export or delete your data. Everything below is authoritative. If we make a change, the "Last updated" date at the top moves.
/dashboard/settings/sso./dashboard/api-keys.X-RateLimit-Limit/X-RateLimit-Remaining/X-RateLimit-Reset response headers. Higher limits available by request.lc_session). HttpOnly, Secure, SameSite=Lax.The following third parties process customer data on our behalf. The erasure column indicates how we complete a right-to-erasure (GDPR Article 17) request against that processor. "API erasure" means we call a dedicated delete endpoint (durable queue in migration 113). "Cascade delete" means data is removed via the primary database delete. "Manual filing" means we submit a documented request to the processor because they have no self-serve deletion API.
| Processor | Purpose | Data | Region | Erasure |
|---|---|---|---|---|
| Supabase | Managed Postgres, storage, and auth back-end. | Account records, calculation history, uploaded invoices, encrypted secrets. | EU (Frankfurt, eu-central-1). | Cascade delete |
| Vercel | Application hosting and edge network. | Request logs (30-day retention), build artifacts. | US + EU edge; primary functions run in iad1 and fra1. | Cascade delete |
| Dodo Payments | Subscription billing, invoicing, and tax collection. | Customer name, billing address, payment method reference, subscription state. | US primary. | API erasure |
| Brevo | Transactional and lifecycle email. | Email address, send/open events, template variables. | EU. | API erasure |
| Resend | Auth OTP and receipt email delivery. | Email address, message-id. | US. | API erasure |
| PostHog | Product analytics (consent-gated). | Pseudonymous distinct-id, event stream, feature usage. | US. | API erasure |
| Google Analytics 4 | Aggregate web analytics (consent-gated). | Client-id cookie, page views, campaign parameters. | US. | Manual filing |
| Meta Pixel | Marketing measurement (consent-gated). | Pseudonymous browser fingerprint tied to consent. | US. | Manual filing |
| LinkedIn Insight tag | Marketing measurement (consent-gated). | Pseudonymous browser fingerprint tied to consent. | US. | Manual filing |
When the sub-processor list changes we publish the change here and, for logged-in users, notify the address on the account. Consent-gated processors (PostHog, GA4, Meta, LinkedIn) only receive data when the user has opted in via the cookie banner, and are torn down synchronously on revocation (LFQG-111 vendor artifact cleanup).
If you believe you have found a security issue in LandedFees, please email info@growyourbrand.io with reproduction steps, affected URL, and impact. Please do not test against other customers' data.
LandedFees is a pre-funding independent product. We are not SOC 2 audited, and we do not hold ISO 27001, HIPAA, or FedRAMP attestations. We do not plan to pursue these attestations until the product reaches revenue or funding milestones that justify the annual audit spend (a SOC 2 Type II typically runs $30k to $100k per year plus engineering overhead, which would be indefensible at our current scale).
What we can offer today:
Every account holder has an unconditional right to export or delete their data, independent of jurisdiction. The self- serve endpoints:
All security, privacy, procurement, and disclosure correspondence goes to info@growyourbrand.io. Signed by the LandedFees team.