Privacy Policy
Last updated: February 2026
1. Who we are
Borderaux is part of BrokerTools, operated by Hector Fitch. Contact us at admin@morebroking.com.
2. Data we collect
We collect the minimum data necessary to provide our service:
- Email address — provided during signup, used for account management and billing.
- Usage metrics — API call counts and costs, stored for billing and spending limits.
- Session cookies — a single HttpOnly cookie for authentication. Not accessible to JavaScript. No tracking cookies are used.
3. Documents you upload
When you use Borderaux, your documents are processed as follows:
- Files are parsed in memory on our Vercel servers and sent to AWS Bedrock for AI analysis.
- Zero retention: We do not store your uploaded files. They are processed and discarded.
- AWS Bedrock: Your document content is sent to Claude (Anthropic) via AWS Bedrock. Under the AWS Bedrock service terms, your data is not used to train AI models and is not retained after processing.
- Regional processing: All AI processing occurs in AWS EU (Frankfurt, eu-central-1).
4. How we use your data
- To provide the Borderaux service (document extraction, column mapping, claim matching, reconciliation).
- To manage your account, billing, and spending limits via Stripe.
- To send service-related communications (e.g. billing notifications).
5. Data storage and security
- Account data (email, API key, spending) is stored in Upstash Redis (encrypted at rest) and Stripe.
- Document data is not stored. It is processed in memory and discarded.
- All connections use HTTPS/TLS encryption in transit.
- Session cookies are HttpOnly, Secure, and SameSite=Lax.
- Security headers (CSP, HSTS, X-Frame-Options) are enforced on all pages.
6. Your rights (UK GDPR)
Under UK data protection law, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your account and associated data.
- Object to processing of your personal data.
- Data portability — receive your data in a structured format.
To exercise any of these rights, contact admin@morebroking.com.
7. Third-party services
- Stripe — Payment processing. See Stripe Privacy Policy.
- AWS Bedrock — AI processing (EU Frankfurt). See AWS Privacy Notice.
- Vercel — Hosting. See Vercel Privacy Policy.
- Upstash — Database (Redis). See Upstash Privacy Policy.
8. Changes to this policy
We may update this policy from time to time. Changes will be posted on this page with an updated date.