Security & Data

How OTA Ninja separates sensitive payout-file analysis from payment and support services.

Last updated: 6 September 2026
Core security design: supported payout files are analysed locally in your browser. Payment providers and support-email providers do not need the contents of those files.

1. What happens when you select a payout file

2. What OTA Ninja does not need

3. Values you type manually

You enter the amount that reached your bank and may optionally enter the bank currency, a known transfer fee, relevant dates and your usual commission rate. Those values are used by the checker to perform the diagnosis.

4. Optional Payment Confirmation PDF

The optional PDF is used to cross-check payment and invoice references when supported. It is processed in the browser like the spreadsheets and is not intentionally uploaded to OTA Ninja.

5. File-reading and diagnosis code

The spreadsheet/PDF reading and reconciliation logic runs locally in the browser. The live site may make ordinary network requests for website delivery, fonts, payment initiation/access verification and security, but those requests must not include the contents of the payout files selected for analysis.

6. Payments are separated from payout files

Stripe Checkout processes the information needed to take a $9 payment. Stripe does not need the GetYourGuide invoice, Payment Confirmation or bank amount to process that payment. OTA Ninja only needs limited payment status information to verify that access should be unlocked.

7. 24-hour paid-access record

After payment, OTA Ninja stores a server-signed access token in your browser for the 24-hour access window. After the first completed diagnosis, the browser stores a local SHA-256 fingerprint of the Payment Confirmation spreadsheet to keep that purchase linked to the same payout period. The token does not contain payout-file contents, and the payout fingerprint is compared locally and is not sent to OTA Ninja.

8. Website delivery and email

Cloudflare is used for domain, DNS, website delivery/security and inbound email routing. Brevo is used to send support replies from support@otaninja.com. These services may process normal network or email-delivery data, but they are separate from the browser-based payout-file analysis.

9. File fingerprints

OTA Ninja creates SHA-256 fingerprints for files on your device. They are one-way identifiers used in the local audit receipt so you can identify the exact files checked. The Payment Confirmation fingerprint is also used locally to keep a paid session tied to one payout period. Fingerprint calculation and comparison happen in your browser; the checker does not intentionally send the original file or these fingerprints to OTA Ninja.

10. Support

If you have a technical problem, contact support@otaninja.com. Do not email a full bank statement or full payout files. If a sample is ever genuinely needed to investigate a bug, we will explain what is required and provide an appropriate method.