RICHFAX / SECURITY & PRIVACY

Know where your document goes.

A practical explanation of the current RichFax data flow, what is protected, and what you still need to consider before sending.

Updated · RichFax by RichScripts

From preparation to delivery

StepWhat happens to your information
Prepare or scan in RichFaxDocument preparation runs in your browser. These preparation steps do not upload the document.
Continue between a PDF tool and RichFaxA one-time transfer stores the PDF locally in this browser for up to 15 minutes. The transfer is removed when opened; expired transfers are cleaned up on a later transfer.
Use standalone PDF-editor toolsThe tools have separate notices and access checks. Their size/fingerprint verification endpoint receives source files over HTTPS before authorized browser processing. Review that tool’s notice; do not assume every PDF-tool step is upload-free.
Save the fax or continue to checkoutAfter account/email verification, the prepared PDF and recipient details are uploaded to RichFax. The server verifies the PDF and page count and calculates the quote.
Pay onceStripe Checkout collects payment and billing information. RichFax stores payment references and totals, not card numbers.
Transmit the faxAfter confirmed payment, RichFax sends the PDF and destination to Sinch Fax for transmission to the receiving fax service.
Receive a fax or notificationThe Inbox reads authorized incoming records and PDFs from Sinch. Receiving emails include PDF attachments; outgoing event emails attach a metadata report.

Storage, expiry and deletion

Saved fax PDFs are encrypted on the RichFax service using AES-256-GCM. This protects the stored document; it is not a claim that every fax hop, recipient device, email copy or backup is end-to-end encrypted.

Unsent drafts expire after 24 hours. Completed or refunded outgoing PDFs are removed from active local document storage. Provider-file deletion is queued after ownership and service-mode checks, and cleanup failures require attention. Documents associated with unresolved orders are removed from local storage after at most seven days, while reconciliation metadata can remain.

Contacts and order metadata remain until removed through the account workflow. Backups can retain copies until their retention cycle ends. Incoming files remain subject to the provider’s retention period; no specific permanent storage duration is promised. Read the full privacy notice.

Account and access controls

Sending requires a verified email. Passwords are stored as salted hashes. Web sessions use HttpOnly cookies; verification and reset codes expire after 15 minutes and work once. A successful password reset revokes existing sessions.

Contacts and orders are scoped to an account. Incoming PDF access checks the linked receiving number and provider project, service, direction and destination. The Inbox and document responses are not cached by RichFax’s service worker.

Never share your password or verification code. The account settings allow metadata export and account deletion after active payment or fax orders are resolved. Account deletion does not recall documents from recipients or delete copies already downloaded or emailed.

Email attachments are separate document copies

RichFax notifications use the configured SMTP service and [email protected]. Receiving emails contain the received PDF; outgoing delivery/failure/refund emails contain an order report with metadata. Your email provider and mail client therefore handle those messages and attachments.

If attachments are unsuitable for your document-handling requirements, do not assume a secure-link-only notification setting is available; it is not currently offered. Review whether the present workflow meets your needs before using it. The Inbox remains available for authorized PDF viewing and downloading.

Current compliance limits

RichFax does not claim HIPAA or PHIPA compliance. We do not advertise a signed BAA, a Canadian data-residency guarantee, a compliance certification or a legally certified delivery service. Use a service that satisfies your organization’s requirements when a regulated workflow is required.

A secure website connection does not make every stage of a fax transmission end-to-end encrypted. A successful gateway result does not prove human reading, legal acceptance or agency processing. A handwritten signature overlay from a PDF tool is not a certificate-based digital signature.

Before sending a private document

  • Verify the recipient’s current fax number and department through their own instructions.
  • Send only documents you are authorized to share with that recipient.
  • Check every page of the final PDF and remove information the recipient does not need.
  • Use a device and mailbox appropriate for the document’s sensitivity.
  • Keep a copy of the transmission report and confirm separately with the recipient when needed.

An overlay that hides text visually is not secure redaction. The current PDF editor does not promise removal of underlying text. Review a proper redaction workflow when permanent removal is necessary.

Questions or an access problem?

Contact [email protected] with the order/fax reference and a short description. Do not email passwords, verification codes, card data or the original sensitive file. See service terms and privacy for the current governing notices.