Privacy Policy
Last updated September 15, 2026
This page says, specifically, what Make A Check (makeacheck.com) stores, why, how it is protected, and how to get it deleted. It's written to be read.
What we store
| Data | Why | How it's held |
|---|---|---|
| Email address | It is your login and where sign-in codes and receipts go | Plain text (we have to send to it) |
| Password | Sign-in | Never stored. We keep a salted scrypt hash, from which the password can't be recovered |
| Name and address on the check, bank name | Printed on your checks | Plain text |
| Routing and account numbers | Printed along the bottom of your checks | Encrypted with AES-256-GCM. The key is held outside the database and outside our code repository. Only the last four digits are stored in readable form |
| Check register | Your record of what you printed: number, date, payee, amount, memo | Plain text |
| Credit balance and purchase history | To know how many checks you can print and to handle refunds | Plain text; includes Stripe's session ID for each purchase, not your card |
| Sign-in codes and sessions | Two-step sign-in | Hashed. Codes expire in 10 minutes; sessions in 30 days or when you sign out |
| IP address and browser type | Rate-limiting abuse and, per session, so you can recognise your own sign-ins | Plain text, tied to sessions and short-lived rate-limit records |
What we don't store
- Card numbers. Payment happens on Stripe's page. Stripe tells us "paid" and which credit pack; the card never reaches us. Stripe's own privacy policy applies to what you enter there.
- Images of your checks. The check is drawn in your browser at print time. We keep the register entry, not a picture.
- What you type on the free VOID-check page. The check, the PDF and the image are made inside your browser; the routing number, account number, name and address you enter are never sent to us or stored anywhere. The page loads our list of bank names as a plain file, and Google Analytics counts the visit — neither carries anything you typed.
- Advertising trackers — there are none. See Analytics below for the one measurement tool we use, and where.
Who can see your bank numbers
The full routing and account numbers are decrypted for exactly one purpose: sending them to your signed-in browser so it can draw the line along the bottom of your check. That happens only after you've entered your password and the emailed code. The service is built not to write them to logs, emails, your account page or support tools. The server operator can, in principle, access the encryption key and the database; we don't do so except to run the service or when required by law.
Analytics
We use Google Analytics on the public pages only — the home page, the free VOID-check page, the sign-in page, and these legal pages — to count visits and see which searches and links bring people here. It sets a first-party cookie to tell repeat visits apart and sends page views to Google; Google's advertising features are switched off, and Google states that it does not log or store IP addresses for this version of Analytics. It is not loaded on the pages where you print checks or manage your account, so nothing about your bank, payees or checks ever reaches it. You can block it with any content blocker without affecting the service.
Third parties
- Google Analytics — visit counts on the public pages, as described above.
- Stripe — payments. Receives your email address and the amount.
- Our transactional email provider — sends your sign-in codes and receipts. Receives your email address and the message.
- Our hosting provider — the server the service runs on.
We don't sell or rent your information. Beyond the providers above, we share it only to investigate fraud or abuse, when the law requires it, or with someone who takes over running the service under this same policy.
How long we keep it
- Your checking accounts: until you remove them from your account page, or your account is closed. Removal erases the encrypted numbers immediately; what stays is the name on the check and the last four digits, so your printed-check register still makes sense.
- Your check register and purchase history: while your account exists.
- Sign-in codes: 10 minutes. Sessions: 30 days or sign-out. Rate-limit records: about an hour.
- Backups: encrypted-at-rest copies of the database are kept for up to 30 days; deleted data ages out of them on that schedule.
Your choices
- Remove any checking account at any time from your account page.
- To export or delete everything, or to close your account, email us from the address on the account. We'll confirm within a few days and complete deletion within 30. Deletion covers everything except the purchase records we must keep for tax and accounting, and Stripe's own records of your payments.
Security, honestly
Passwords are hashed with scrypt; bank numbers are encrypted with AES-256-GCM under a key kept off the database; a new device needs a one-time email code to sign in; all traffic is HTTPS; the database lives on a server with its own service account and no public port. No system is unbreakable. If we ever learn of a breach affecting your data we will tell you by email promptly and say plainly what was exposed.
Changes
If this policy changes in a way that matters, we'll update the date above and, for material changes, email account holders.
Contact
Email support@makeacheck.com, call (732) 732-7327, or reply to any email we've sent you. See our contact page.