Privacy Policy
Last updated: July 9, 2026
FirstDollar ("we", "us") turns the first payment your business ever received into a commemorative certificate. This policy explains what data we handle, why, and the choices you have. The short version: we are built around data minimization — we read as little as possible, store even less, and encrypt what we keep.
1. Who is responsible for your data
The data controller is the operator of myfirstdollar.site: Michele Fontanella, Italy. For any privacy request, contact privacy@myfirstdollar.site.
2. What we collect and why
- Account data — your email address, a hash of your password (we never store or see the password itself), an optional display name, your marketing-consent choice and login timestamps. If you sign in with Google, we receive your email, name and Google account identifier from Google. Legal basis: performance of a contract (providing the service); consent, for marketing emails.
- Certificate data — when you connect your Stripe account we read your payment history in memory, page by page, keep only the oldest successful charge (charge ID, amount, currency, date, Stripe account ID, live-mode flag) and your business name, then disconnect from your account automatically, typically within seconds. That single record is stored encrypted at rest with AES-256-GCM. Your other transactions are never stored, and your customers' personal data is never collected. Legal basis: performance of a contract.
- Content you add — business name, subtitle and logo, if you choose to personalise a premium certificate. If you share a certificate, its public share page and preview image display this content. Legal basis: performance of a contract.
- Purchase data — premium payments are processed entirely by Stripe Checkout; we never see your card details. We store the Checkout session reference and the buyer email (encrypted) to deliver and support your purchase. Legal basis: performance of a contract; legal obligations (accounting).
- Technical data — our hosting provider keeps standard server logs (IP address, request time, user agent) for security and abuse prevention. Legal basis: legitimate interest.
3. What we never do
- We never see your Stripe password or API keys — the connection uses Stripe's official OAuth flow on Stripe's own pages.
- We never move money, issue refunds or write anything to your Stripe account.
- We never store your transaction history — only the single first charge described above.
- We never sell or rent your personal data, and we use no advertising or profiling.
4. Cookies and analytics
We use a single essential session cookie to keep you signed in and secure forms (CSRF protection). It is strictly necessary for the site to work and is deleted when the session ends.
We also use Google Analytics 4 to understand how the site is used (pages visited, rough location, device type), with IP anonymization enabled. We use no advertising or profiling cookies. If you prefer not to be counted, you can use your browser's tracking protection, a content blocker, or Google's official opt-out add-on.
5. Third-party services
- Stripe (Stripe, Inc. / Stripe Payments Europe) — account connection and payment processing. See Stripe's privacy policy.
- Google — optional "Sign in with Google", web fonts served from Google's servers (your IP address reaches Google when fonts load), and Google Analytics 4 (IP anonymized). See Google's privacy policy.
- Cloudflare cdnjs — serves the open-source scripts used on the certificate page (image/PDF generation, QR code).
- Hosting and email providers — host the site and deliver transactional emails (e.g. password resets).
Where these providers process data outside the EU/EEA, transfers rely on safeguards such as the EU Standard Contractual Clauses.
6. Retention
- Account and certificate data: kept until you ask us to delete them or you delete your account.
- Password-reset links: expire after 30 minutes and are single-use.
- Share-preview images: cached copies are refreshed when your certificate changes.
- Purchase records: kept as long as required by tax and accounting law.
7. Your rights (GDPR)
You have the right to access, rectify, delete and export your personal data, to restrict or object to processing, and to withdraw consent at any time (e.g. unsubscribe from marketing). Deletion requests are honoured: we remove your certificate, its encrypted record and your account data. Write to privacy@myfirstdollar.site — we reply within 30 days. You may also lodge a complaint with your supervisory authority (in Italy, the Garante per la protezione dei dati personali).
8. Security
Transaction records are encrypted at rest with AES-256-GCM; deduplication uses keyed hashes so charge IDs are not stored in plaintext; passwords are hashed with a modern algorithm (bcrypt); all traffic runs over HTTPS; Stripe access is read-only in practice and revoked immediately after issuance.
9. Children
The service is intended for business owners and is not directed at children under 16.
10. Changes
We may update this policy as the service evolves; the date above always reflects the latest version. Material changes will be highlighted on the site.