Privacy Policy
Recoura is a failed-payment recovery service for businesses that use Stripe or Square. This policy explains what data Recoura Technologies LLC ("Recoura," "we," or "us") collects, how we use and share it, and the choices you have. It covers both our website at recoura.io and the Recoura application at app.recoura.io (together, the "Service").
- 1. Our two roles
- 2. What we collect
- 3. How we use it
- 4. Data from your Stripe and Square accounts
- 5. Who we share it with
- 6. Cookies, analytics & advertising
- 7. How long we keep it
- 8. How we protect it
- 9. Where data is processed
- 10. Your privacy rights
- 11. California privacy rights
- 12. Children's privacy
- 13. Changes to this policy
- 14. Contact
1. Our two roles
Recoura handles two different kinds of data, and our responsibility is different for each.
Data about you, our customer. When you visit the site, create an account, or subscribe to a plan, we are the business responsible for that data (the "controller" under laws like the GDPR). This policy governs how we handle it.
Data about your customers. When you connect Stripe or Square, Recoura processes information about the people who pay you, such as a failed charge and the email tied to it, only to provide the recovery service to you and on your instructions. For that data you are the controller, and we act as your service provider (a "processor" under the GDPR and a "service provider" under California law). We do not use your customers' data for our own purposes. If you are one of those customers and want your information corrected or removed, please contact the business you pay, not us; we will support them in responding.
2. What we collect
Account information. Your email address, and any name or business name you provide, so we can create and secure your account and communicate with you. Authentication is handled through standard sign-in; we do not store a password for you in readable form.
Billing information. If you subscribe to a paid plan, our third-party payment processor collects and processes your card or payment details to charge you. Recoura receives only limited billing records such as your plan, billing status, and the last four digits and brand of your card. Full card numbers never touch our servers.
Connection data. When you connect a processor, we store what is needed to keep that connection working. For Stripe, that is a single account identifier and no access tokens. For Square, that is an access token, stored encrypted at rest, because Square's connection model requires one. Either connection can be revoked at any time from your settings or your processor's dashboard.
Recovery data from Stripe and Square. Described in section 4.
Usage and device data. Basic technical information such as pages viewed, actions taken in the app, approximate location derived from IP, device and browser type, and server logs. We use this to run, secure, and improve the Service.
3. How we use it
- To provide the Service: showing your revenue at risk, and preparing and sending recovery invoices and reminders through Stripe or Square at your direction.
- To power optional AI features, such as AI-drafted reminders and the AI recovery assistant, which you review before their output is sent or acted on.
- To create and secure your account, authenticate you, and prevent fraud and abuse.
- To bill you for paid plans and manage your subscription.
- To send you service messages and respond to support requests.
- To understand and improve how the Service is used, in aggregate.
- To comply with our legal obligations and enforce our Terms of Service.
We do not build advertising profiles about you, and we do not sell your personal information in the ordinary sense. Our marketing site does use Google's advertising tools to measure how well our own ads perform, which we describe in section 6. We use no advertising or tracking tools inside the application.
4. Data from your Stripe and Square accounts
Once you connect a processor, Recoura reads only what it needs to find and recover failed payments, and stores as little of it as possible:
- A rolling 90 days of failed payments, including the customer identifier and email tied to the charge, the amount, the currency, and why it failed.
- A lightweight summary of your subscriptions, limited to their status and monthly value.
- A log of the recovery actions taken on your behalf.
Successful payments are read from your processor on demand and are never stored. Older records are pruned automatically. Card numbers never reach our servers at any point; they stay with Stripe or Square. Recoura cannot move money out of your account, holds no balances, and initiates no transfers.
5. Who we share it with
We share data only with the service providers that operate the Service, and only so they can perform their function for us. These include our cloud hosting and database provider, our email-delivery provider, our payment processor, our product-analytics and error-monitoring providers, the advertising and conversion-measurement provider for our marketing site (Google), the AI provider that powers our optional AI features (currently Anthropic, the maker of Claude), and, if you enable them, the messaging tools you connect such as Slack or Microsoft Teams.
How our AI features handle data. Some plans include optional AI features, such as AI-drafted reminders and the AI recovery assistant, that help you plan and carry out recoveries. When you use them, we send our AI provider only what is needed for the feature, such as the failed-payment and subscription information described above and your own message templates. The provider processes that information solely to return the result to us and does not use it to train its models. Card numbers are never included, these features are off unless you choose to use them, and you stay in control: you review any message before it is sent and decide whether to act on any suggestion.
Stripe and Square are not our subprocessors; they are your payment providers, and their handling of your and your customers' data is governed by their own agreements with you.
Beyond that, we disclose data only when the law requires it, to protect our rights or the safety of others, or as part of a merger, acquisition, or sale of assets, in which case this policy continues to apply and we will notify you of any change in control.
We do not sell your personal information for money. Our use of Google's advertising tools on the marketing site, described in section 6, may however be considered "sharing" for cross-context behavioral advertising, or a "sale," under some U.S. state privacy laws. You can opt out at any time through your browser's cookie controls or Google's Ads Settings, and we honor the Global Privacy Control browser signal; see sections 6 and 11.
6. Cookies, analytics & advertising
Analytics. We use privacy-friendly, cookieless product analytics that collect only aggregate, non-identifying data such as page views, referrers, and coarse country and device type. These set no advertising cookies and do not track you across other sites.
Advertising and conversion measurement. Our marketing site uses Google Ads conversion tracking so we can measure how many people who sign up arrived from one of our ads. When active, this uses Google's cookies and sends limited event data, such as the fact that a signup happened and an ad-click identifier, to Google LLC acting as our service provider. We do not upload your email address and we do not build advertising profiles, and we use none of these tools inside the application at app.recoura.io.
Your choices. You can opt out of these advertising cookies at any time through your browser's cookie controls or Google's Ads Settings (adssettings.google.com). We also treat an enabled Global Privacy Control (GPC) browser signal as a valid opt-out and turn off advertising cookies when we detect it.
International transfers. Google LLC is based in the United States and processes this data there. For visitors in the EEA, the UK, and Switzerland, Google relies on the EU-U.S. Data Privacy Framework and Standard Contractual Clauses as its transfer safeguard. The application itself uses only the cookies or local storage strictly necessary to keep you signed in and the Service functioning.
7. How long we keep it
We keep failed-payment records on a rolling 90-day basis and prune them automatically. We keep your account and billing records for as long as your account is active and for a reasonable period afterward to meet legal, tax, and accounting obligations. You can ask us to delete your data at any time, and when you disconnect a processor we delete the connection data we held for it.
8. How we protect it
All traffic is encrypted in transit (HTTPS). Sensitive connection credentials, such as a Square access token, are encrypted at rest. We minimize what we collect, limit internal access to what is needed to run the Service, and rely on Stripe and Square to hold the card data we deliberately never touch. No system is perfectly secure, but we work to keep the data we hold safe.
9. Where data is processed
Recoura is operated from the United States, and the data we hold is processed here. If you access the Service from outside the United States, you understand that your data will be transferred to and processed in the United States, where privacy laws may differ from those in your location.
10. Your privacy rights
You can ask us to show you, correct, export, or delete the personal data we hold about you, and to close your account. Depending on where you live, for example the EU, UK, or California, you may have additional legal rights over your personal data, including the right to object to or restrict certain processing. To exercise any of these, email support@recoura.io, and we will respond within the timeframe the applicable law requires. If your request concerns data about your own customers that we process on a business's behalf, we will refer you to that business, who directs how their data is handled.
11. California privacy rights
If you are a California resident, the California Consumer Privacy Act, as amended, gives you the right to know what personal information we collect and how we use it, to request access to or deletion of it, to correct inaccurate information, and to not be discriminated against for exercising these rights. In the past twelve months we have collected the categories of personal information described in section 2 (identifiers, commercial information such as your subscription, internet and device activity), used them for the purposes in section 3, and disclosed them to the service providers described in section 5, including, on the marketing site, the advertising and conversion-measurement disclosure to Google described in section 6.
Do not sell or share, and your privacy choices. We do not sell your personal information for money. Our marketing site's use of Google's advertising tools may be considered "sharing" for cross-context behavioral advertising under California law. You can opt out at any time through your browser's cookie controls or Google's Ads Settings, and we treat an enabled Global Privacy Control (GPC) browser signal as a valid opt-out request. To make any other request, email support@recoura.io. You may use an authorized agent to submit a request on your behalf, and we will take reasonable steps to verify your identity before responding.
12. Children's privacy
The Service is for businesses and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will delete it.
13. Changes to this policy
We may update this policy as the Service evolves or the law changes. When we make a material change we will update the date above and, where appropriate, notify you by email or in the app. Continuing to use the Service after a change means you accept the updated policy.
14. Contact
Privacy questions or requests? Reach us at support@recoura.io. Recoura Technologies LLC is located in the United States.