Privacy Policy

Effective Date: August 6, 2026Last Updated: August 6, 2026

1. Overview

Recoverflow ("we," "us," or "our") provides an automated payment recovery platform designed to detect failed payments processed through Stripe and notify end-customers via SMS with secure payment update links.

This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our website, services, and software applications (collectively, the "Service").

By accessing or using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.

2. Roles and Responsibilities (Data Controller vs. Data Processor)

To comply with global data privacy regulations (including GDPR and CCPA):

  • Account Holders (Our Clients): We act as a Data Controller regarding the account information collected directly from you (e.g., your login email address and payment details).
  • End-Customers (Our Clients' Customers): When we process end-customer data received via Stripe webhooks to send SMS messages, we act as a Data Processor (or Service Provider) on behalf of our account holders, who act as the Data Controllers.

3. Data We Collect

We collect information that identifies, relates to, or could reasonably be linked with a particular individual or device:

  • Account Data: Email address, user identification credentials, and account settings provided during registration.
  • Invoice & Customer Data: When a payment failure occurs, we collect customer data imported automatically via Stripe webhooks on behalf of our account holders. This includes end-customer names, email addresses, phone numbers, Stripe invoice IDs, transaction amounts, and failure codes.
  • System & Event Logs: Timestamps, API transmission data, system activity logs, and delivery statuses (e.g., SMS dispatch outcomes, link creation, and recovery success metrics).

4. How We Use Your Data

We use the collected information strictly for legitimate operational purposes:

  • To detect failed payment events and generate secure, single-use payment recovery links.
  • To deliver transactional SMS messages to end-customers regarding unpaid invoices.
  • To generate dashboard performance metrics and transaction analytics for account holders.
  • To maintain, secure, debug, and improve our platform performance.
  • To verify webhook integrity and prevent fraudulent activity.

We do not sell, rent, or trade personal data or end-customer information to third parties.

5. Third-Party Service Providers

We share data with select third-party service providers solely to fulfill core platform operations. Each provider operates under strict confidentiality obligations:

  • Stripe, Inc.: Payment processing and webhook event triggers.
  • Twilio Inc.: Telecommunications gateway used for transactional SMS delivery.
  • Supabase, Inc.: Cloud database infrastructure used for secure data storage.

6. SMS & Telecommunications Disclosures (A2P 10DLC & TCPA)

Because our Service uses SMS messaging, the following disclosures apply to all mobile phone numbers processed through our system:

  • Transactional Purpose: SMS messages dispatched via Recoverflow are strictly transactional and limited to billing, invoice recovery, and payment link delivery.
  • Message & Data Rates: Standard message and data rates applied by the recipient's mobile carrier may apply to all sent and received text messages.
  • Opt-Out & Help: Recipients may opt out of receiving further SMS notifications at any time by replying STOP to any message. For assistance, recipients can reply HELP.
  • Mobile Data Sharing Prohibition: No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

Account holders are solely responsible for ensuring they have obtained necessary authorizations and consents from their end-customers to transmit SMS notifications regarding their accounts.

7. Data Security & Storage

We implement industry-standard administrative, technical, and physical security measures to protect personal data:

  • All database records are hosted on Supabase and secured via strict Row-Level Security (RLS) policies.
  • API keys, webhook secrets, and sensitive tokens are stored strictly as encrypted, server-side environment variables and are never exposed in client-side code.
  • Inbound Stripe webhook payloads are verified via cryptographic signature headers to prevent unauthorized payload injection.

While we take reasonable steps to secure your data, no security system is completely impenetrable.

8. Data Retention & Deletion

  • Account Data: Retained for as long as your account remains active or as necessary to fulfill business operations and legal compliance obligations.
  • Invoice & Event Logs: Retained to display historical performance metrics to account holders.
  • Data Deletion Requests: Account holders may request the deletion of their account and associated data at any time by contacting us.

9. Privacy Rights

Depending on your geographic location, you may have rights under applicable local laws (e.g., GDPR, CCPA):

  • The right to access, update, or correct your personal data.
  • The right to request the erasure of your personal data.
  • The right to object to or restrict processing.

Submitting Requests:

  • Account Holders: You may exercise your rights by submitting a request to privacy@recoverflow.com.
  • End-Customers: If you are an end-customer whose billing data was processed via Recoverflow on behalf of a merchant, please direct your request directly to the merchant (Data Controller).

10. Contact Information

For questions, legal notices, or privacy inquiries regarding this policy, please contact us at:

Recoverflow™

Email: privacy@recoverflow.com

Back to home

© 2026 Recoverflow. All rights reserved.