Skip to content
Recoupe

Privacy Policy

What we read, what we store, and how to delete it. Last updated July 2026.

What we read from your payment processor

Recoupe connects to your payment processor Stripe (Stripe Connect OAuth), Square (Square OAuth), or Braintree (Braintree OAuth) with access you can revoke from your processor dashboard at any time. We read: invoices (amounts, status, customer email/name, hosted payment page URLs), subscriptions, and on Stripe the default payment method's expiry month/year and card fingerprint (for expiring-card warnings). We never read or store full card numbers and we never move money. On Braintree, when your customer updates their card through our hosted page, the card is tokenized in their browser by Braintree the details never touch our servers.

What we store

  • Your account: email address, org settings, email copy you write.
  • Tracked failed invoices: amount, status, customer email, timestamps.
  • Email logs: what we sent, to whom, delivery/open/bounce status.
  • Opt-outs: customer emails that unsubscribed (kept to honor the opt-out).
  • For Square and Braintree connections: the OAuth access tokens the processor issues us, encrypted at rest (AES-256-GCM) and deleted on disconnect. Stripe connections store only the account id no tokens.

Your customers' rights

Every email we send contains a one-click unsubscribe honored instantly. A spam complaint suppresses the address automatically.

Retention & deletion

Delete your account in Settings: org data (invoices, email logs, reports, settings) is hard-deleted immediately. Aggregated, non-identifying numbers may survive in backups for up to 30 days.

AI-generated recovery copy

When you use default email copy (not custom), Recoupe may generate decline-reason-specific recovery emails via our AI subprocessor (Anthropic, listed on the Subprocessors page). What's sent: the org's default copy (as a voice anchor), the processor's decline code where available (e.g. expired_card; Stripe and Braintree expose these, Square does not), the invoice amount, and the customer's first name. Results are cached server-side; future sends for the same org + decline reason use the cached copy without re-calling the API. No customer data is used to train the provider's models, and generation can be disabled by saving custom copy in Settings.

Subprocessors

See the Subprocessors page for the current list (Vercel, Supabase, Inngest, Resend, Stripe, Anthropic; plus Square or Braintree/PayPal when you connect those processors).

Contact

privacy@recoupe.xyz

Recoupe is not affiliated with Stripe, Square, or PayPal/Braintree. · Privacy · Terms · Subprocessors