1. Does GoSlip need a GDPR page?
Yes. Receipt images and account records can contain personal and financial information. GDPR may apply when a service is established in the European Union or intentionally offers services to, or monitors the behavior of, people in the EU—even when the operator is elsewhere. A public readiness page also gives customers a clear route for privacy requests.
2. Rights requests
Where applicable, users may request access, correction, deletion, restriction, portability, or objection. Identity is verified before a request is fulfilled so another person cannot obtain or erase account data.
3. Deletion and retention
Deletion requests require the current password and a one-time confirmation sent to the account email. After confirmation, we begin the account-deletion process. If a specific record must be retained by law, we will identify it and remove it when that obligation ends.
4. Processors and transfers
GoSlip relies on service providers for infrastructure, storage, AI extraction, messaging, payments, and monitoring. Before serving EU customers, processor agreements, transfer safeguards, records of processing, and any required EU representative or data-protection contact must be formally completed.
5. Readiness, not certification
This page describes product controls and the intended request process; it is not a certification of legal compliance. The final controller identity, lawful bases, retention schedule, processor list, transfer mechanism, and supervisory-authority information require review by qualified privacy counsel before an EU launch.