Privacy Policy
Last updated October 10, 2026
Who is responsible for your data
The controller of personal data processed in connection with the service is the administrator of the xlsconverter.com service (referred to below as "we" or "the administrator"). You can reach us about any privacy matter at [email protected].
This policy explains what data we process when you visit xlsconverter.com, use the one-time demo, create an account, subscribe to a plan, use pipelines or call the API.
Data we process
- Account data: your email address, a hashed password (we never store passwords in readable form), your name if you provide it, team membership and role.
- Billing data: plan, billing period, invoices and payment status. Card details are entered on the payment page of our payment operator and are processed by that operator. We receive only a reference, the card brand and the last four digits.
- Uploaded files: the spreadsheets and other files you convert, and the converted results.
- Conversion metadata: file name, size, source and target format, options used, row count, status, timestamps and errors.
- Demo data: a hashed form of your IP address, used only to enforce the rule of one demo conversion per account and IP.
- Technical logs: IP address, user agent, request time and response codes, kept for security and troubleshooting.
- Integration data: connection settings for your sources and destinations (for example an S3 bucket, a Google Drive or Dropbox folder, an SFTP server), with credentials stored encrypted.
Purposes and legal bases
- Providing the service you requested (conversion, batches, pipelines, API), running your account and subscription. Legal basis: performance of a contract (Article 6(1)(b) GDPR).
- Billing, invoicing and keeping accounting records. Legal basis: legal obligation (Article 6(1)(c) GDPR).
- Security, fraud and abuse prevention, enforcing the one-time demo rule, troubleshooting. Legal basis: our legitimate interest in a secure and fair service (Article 6(1)(f) GDPR).
- Transactional emails such as sign up codes, receipts, failed job alerts and security notices. Legal basis: performance of a contract.
- Handling your requests and questions sent to support. Legal basis: performance of a contract or legitimate interest.
We do not sell personal data and we do not use it for advertising.
Uploaded files and automatic deletion
Your files belong to you. We process them only to perform the conversion and the steps you configured.
- Uploaded files and converted results are deleted automatically, by default one hour after the conversion finishes.
- Paid plans can shorten this window. Enterprise accounts have retention controls, including deletion immediately after download and a custom retention window.
- Conversion history keeps metadata only (file name, formats, status, timestamps), not file contents.
- Deleting a job in your account removes its files at once.
Passwords of protected workbooks
When you convert a password protected workbook, you type the password yourself. It is used in memory for that single conversion only. It is never written to disk, never stored in a database and never written to logs.
Security measures
- Encryption in transit with TLS 1.2 or higher.
- Encryption at rest (AES-256) for stored files and integration credentials.
- Isolated processing of each conversion job.
- API keys stored hashed, webhooks signed with HMAC SHA-256.
- Access to production systems limited to authorized personnel.
Optional AI column normalization
On paid plans that include AI column normalization, you can ask the service to match the headers of your file to a target schema. When you use this optional feature, only the column headers and a small sample of rows are sent to an AI text model provider. Full files are never sent. Customer files are never used to train AI models, neither by us nor by the provider.
Recipients of data
We share data only with service providers that process it on our behalf and under a data processing agreement, in these categories:
- hosting provider (servers, storage and backups),
- payment operator (subscriptions, payments and card data),
- transactional email provider (sign up codes, receipts and notifications),
- AI text model provider, used only for optional column normalization on paid plans, and only for headers plus a small sample of rows.
Data is also sent to destinations you configure yourself (for example your own S3 bucket, cloud folder, SFTP server or webhook endpoint). We may disclose data to public authorities when the law requires it.
Cookies
We use only strictly necessary cookies: a session cookie that keeps you signed in, a CSRF cookie that protects forms, and a preference cookie (for example the selected billing period). We do not use advertising cookies, we do not use tracking pixels and we do not use third party analytics cookies. Because only strictly necessary cookies are set, no consent banner is shown.
How long we keep data
- Uploaded files and results: one hour after the conversion finishes by default, shorter if your plan settings say so.
- Conversion metadata: for the history window of your plan, then removed or anonymized.
- Account data: as long as the account exists, then deleted within 30 days of account closure.
- Billing records: for the period required by tax and accounting law.
- Technical logs: up to 90 days, longer only when needed to investigate a security incident.
- Hashed demo IP: up to 12 months.
Your rights
You have the right to access your data, to rectify it, to have it deleted, to restrict processing, to data portability and to object to processing based on legitimate interest. To use any of these rights, write to [email protected]. We answer within one month.
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the country where you live or work. Residents of US states with privacy laws (for example California) have equivalent rights to know, delete and correct their data, and we do not sell or share personal data for cross context behavioral advertising.
International transfers
Some service providers may process data outside the European Economic Area. In such cases transfers are protected by the standard contractual clauses approved by the European Commission or by another lawful transfer mechanism. Enterprise accounts can choose an EU or US processing region for their files.
Data processing agreement for business customers
When you convert files that contain personal data of other people, you act as the controller and we act as your processor. A data processing agreement is available in your account settings.
Children
The service is intended for businesses and professionals. It is not directed to children, and we do not knowingly collect data of persons under 16. If you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy
We may update this policy when the service or the law changes. The date of the latest update is shown at the top of this page. We will notify account holders by email about material changes before they take effect.