Security & Data
How OTA Ninja separates sensitive payout-file analysis from payment and support services.
1. What happens when you select a payout file
- You select the supported GetYourGuide spreadsheet or optional PDF on your own device.
- JavaScript running in your browser reads the file.
- The checker compares booking references, amounts and other supported fields in browser memory.
- The diagnosis is displayed on your screen.
- Any CSV, evidence summary or PDF/report you deliberately save remains on your own device.
2. What OTA Ninja does not need
- Your GetYourGuide login or password.
- Your bank login or password.
- Your full bank statement.
- Permanent server storage of your GetYourGuide payout files.
3. Values you type manually
You enter the amount that reached your bank and may optionally enter the bank currency, a known transfer fee, relevant dates and your usual commission rate. Those values are used by the checker to perform the diagnosis.
4. Optional Payment Confirmation PDF
The optional PDF is used to cross-check payment and invoice references when supported. It is processed in the browser like the spreadsheets and is not intentionally uploaded to OTA Ninja.
5. File-reading and diagnosis code
The spreadsheet/PDF reading and reconciliation logic runs locally in the browser. The live site may make ordinary network requests for website delivery, fonts, payment initiation/access verification and security, but those requests must not include the contents of the payout files selected for analysis.
6. Payments are separated from payout files
Stripe Checkout processes the information needed to take a $9 payment. Stripe does not need the GetYourGuide invoice, Payment Confirmation or bank amount to process that payment. OTA Ninja only needs limited payment status information to verify that access should be unlocked.
7. 24-hour paid-access record
After payment, OTA Ninja stores a server-signed access token in your browser for the 24-hour access window. After the first completed diagnosis, the browser stores a local SHA-256 fingerprint of the Payment Confirmation spreadsheet to keep that purchase linked to the same payout period. The token does not contain payout-file contents, and the payout fingerprint is compared locally and is not sent to OTA Ninja.
8. Website delivery and email
Cloudflare is used for domain, DNS, website delivery/security and inbound email routing. Brevo is used to send support replies from support@otaninja.com. These services may process normal network or email-delivery data, but they are separate from the browser-based payout-file analysis.
9. File fingerprints
OTA Ninja creates SHA-256 fingerprints for files on your device. They are one-way identifiers used in the local audit receipt so you can identify the exact files checked. The Payment Confirmation fingerprint is also used locally to keep a paid session tied to one payout period. Fingerprint calculation and comparison happen in your browser; the checker does not intentionally send the original file or these fingerprints to OTA Ninja.
10. Support
If you have a technical problem, contact support@otaninja.com. Do not email a full bank statement or full payout files. If a sample is ever genuinely needed to investigate a bug, we will explain what is required and provide an appropriate method.