FightMyFees

Privacy Policy

Last updated August 26, 2026

FightMyFees is operated by Fight My Fees, LLC, a California limited liability company. We analyze a business’s own vendor spending to find fees worth negotiating. This page describes exactly what we collect, why we collect it, and what happens to it. We have tried to write it in plain language rather than in the broadest terms a lawyer would allow.

Who this applies to

This policy covers business owners and their staff who create an account with us. FightMyFees is a business-to-business service. We do not knowingly collect information from consumers acting in a personal capacity, and we do not offer the service to anyone under 18.

What we collect

Account information

Your email address, a password, and optionally your business name. We store passwords only as a scrypt hash. We cannot read your password and neither can anyone who obtains a copy of our database.

Bank transaction data, if you choose to connect an account

We use Plaid to connect to your financial institution. When you connect an account, you enter your banking credentials on Plaid’s screen, not ours. Your banking username and password are never transmitted to FightMyFees and we never store them.

The connection is read-only. It allows us to retrieve transaction records — date, description, amount, and the account they belong to. It does not permit us to move money, initiate payments, or change anything about your account, and no configuration of it could.

Plaid provides us with an access token representing your permission. We encrypt that token with AES-256-GCM before storing it. The encryption key is held in our server environment and never in the same database as the token, so a copy of the database alone is not sufficient to use it.

Documents you upload

Vendor statements and invoices you upload or forward to us. These typically contain your business name, a merchant or account identifier, and a breakdown of what a vendor charged you. Some payroll documents contain aggregate wage and tax figures.

Uploaded documents are stored outside our public web directory under randomly generated filenames. They are not reachable by URL. The only way to retrieve one is through a request that proves you own it.

When we extract data from a statement, merchant IDs and account numbers are reduced to their last four digits. We do not need the full number to negotiate on your behalf, so we do not retain it.

What we do not collect

We do not collect your Social Security number, your customers’ personal information, or individual employee records. We do not ask for or store passwords to your vendor portals. We do not use advertising trackers or sell data to advertisers.

Why we use it

To identify which vendors you pay and how much; to determine which portion of those charges is negotiable; to prepare an analysis for you; and, if you engage our negotiation service, to represent your interests to that vendor. If you use our monitoring service, we continue reviewing the same data to detect when a negotiated rate drifts back up.

We also use aggregate, de-identified figures — such as an effective processing rate within a volume band — to improve the accuracy of our analysis for all customers. This aggregate data never identifies you, your business, or your vendors.

Who we share it with

We do not sell your data. We share it only in these situations:

Our conflict of interest, stated plainly

FightMyFees was founded by someone who previously worked in payment processing and maintains relationships with providers in that industry and in payroll. If you decide to switch vendors and we introduce you to a partner, we may receive compensation for that referral.

Our recommendation is always to keep your existing vendor and pay less, because that is better for you and it is the service we are selling. Where a referral fee could apply, we tell you before any introduction is made. You are never obligated to accept one.

How long we keep it

While your account is open, and afterwards only as long as necessary to complete a negotiation, calculate fees owed, or meet a legal or tax obligation. You may disconnect a bank account at any time, which stops any further retrieval of transactions. You may ask us to delete your data and we will, except where we are required to retain records of a completed engagement.

Your choices

Security

We describe what we actually do rather than making certification claims. Bank connection tokens are encrypted at rest. Passwords are hashed with scrypt. Sessions are stored server-side and can be revoked. Every database read is scoped to the account that made the request, enforced in a single data layer rather than route by route. Uploaded documents are stored outside the web directory and are only served through an ownership check.

FightMyFees does not currently hold SOC 2, ISO 27001, PCI, or HIPAA certification, and we will not claim otherwise until we do. No system is perfectly secure. If we become aware of a breach affecting your data, we will tell you.

Changes

If we change this policy in a way that materially affects how we handle your data, we will notify account holders by email before it takes effect.

Contact

Fight My Fees, LLC — California, United States.
Questions about this policy, or requests about your data: privacy@fightmyfees.com