Security, Privacy & Data Residency
Taggun's certifications, data handling and retention, storage opt-out, infrastructure hosting, and regional requirements for security reviews.
Security and privacy compliance are core priorities at Taggun. This page collects what technical evaluations and vendor security reviews ask for: certifications, data handling, storage opt-outs, and where your data is processed and stored.
Trust CenterOur security controls, policies, and SOC 2 report are available through the Taggun Trust Center. Request access there for the full documentation set.
Certifications & Compliance
- SOC 2 Type 2 — Taggun holds SOC 2 Type 2 certification. The report and sub-processor list are available via the Trust Center.
- GDPR — We honour applicable data-subject rights, including access and erasure.
- Infrastructure hosting — Taggun's infrastructure is hosted on AWS. Taggun's own assurance documentation is available through the Trust Center.
- Security questionnaires — We support customer security reviews and questionnaires; contact us to start one.
Data Handling & Retention
- Receipt data and personal information. With the default
incognito: false, Taggun stores submitted receipt and invoice files and their extracted result data. These records may contain personal information when identifying details appear on the submitted document or in extracted fields such as customer name, email, or tax ID. - Encryption. Data is encrypted in transit using TLS and at rest using AES-256.
- Minimal scan metadata. Minimal scan metadata containing an
incognitomarker may be retained. This does not include the submitted document or extracted result data. - Retention period. Taggun applies a maximum retention period of 3 years to processed receipt data. Data may be deleted sooner when it is no longer necessary for the service, and you may request deletion at any time. Use
incognito: trueto exclude the submitted document and extracted result data from storage for that request.
Per-Request Storage Opt-Out (incognito)
incognito)Set incognito: true on an extraction or validation request to prevent the submitted document and extracted result data from being stored. The document is processed and the response is returned as normal. Taggun may still retain minimal scan metadata containing an incognito marker.
Incognito scans are not stored for future matchingCurrent-request duplicate and similarity checks can still run against previously stored receipts. However, the incognito scan is not stored for future duplicate or similarity detection. This can limit duplicate-detection history for later submissions.
API Routing and Regional Requirements
Use https://api.taggun.io for standard API requests. Taggun's Privacy Policy lists New Zealand, Australia, France, and the United States as jurisdictions where information may be processed or stored. If your organisation requires region-specific routing or contractual data residency, contact Taggun before integration; do not infer storage residency from an API hostname alone.
Dedicated hosting (Enterprise)
Dedicated and managed hosting arrangements are available for Enterprise customers; contact sales for the current infrastructure and residency options.
For Your End Users
If your application collects receipts from consumers, tell them how their data is used and protected — it improves submission rates and trust. See End-User Capture Guidance for what to include.
Need something not covered here? Contact [email protected] — see Contacting Support.
Updated about 22 hours ago