Privacy Policy
What we read, what we store, and how to delete it. Last updated July 2026.
What we read from your payment processor
Recoupe connects to your payment processor Stripe (Stripe Connect OAuth), Square (Square OAuth), or Braintree (Braintree OAuth) with access you can revoke from your processor dashboard at any time. We read: invoices (amounts, status, customer email/name, hosted payment page URLs), subscriptions, and on Stripe the default payment method's expiry month/year and card fingerprint (for expiring-card warnings). We never read or store full card numbers and we never move money. On Braintree, when your customer updates their card through our hosted page, the card is tokenized in their browser by Braintree the details never touch our servers.
What we store
- Your account: email address, org settings, email copy you write.
- Tracked failed invoices: amount, status, customer email, timestamps.
- Email logs: what we sent, to whom, delivery/open/bounce status.
- Opt-outs: customer emails that unsubscribed (kept to honor the opt-out).
- For Square and Braintree connections: the OAuth access tokens the processor issues us, encrypted at rest (AES-256-GCM) and deleted on disconnect. Stripe connections store only the account id no tokens.
Your customers' rights
Every email we send contains a one-click unsubscribe honored instantly. A spam complaint suppresses the address automatically.
Retention & deletion
Delete your account in Settings: org data (invoices, email logs, reports, settings) is hard-deleted immediately. Aggregated, non-identifying numbers may survive in backups for up to 30 days.
AI-generated recovery copy
When you use default email copy (not custom), Recoupe may generate decline-reason-specific recovery emails via our AI subprocessor (Anthropic, listed on the Subprocessors page). What's sent: the org's default copy (as a voice anchor), the processor's decline code where available (e.g. expired_card; Stripe and Braintree expose these, Square does not), the invoice amount, and the customer's first name. Results are cached server-side; future sends for the same org + decline reason use the cached copy without re-calling the API. No customer data is used to train the provider's models, and generation can be disabled by saving custom copy in Settings.
Subprocessors
See the Subprocessors page for the current list (Vercel, Supabase, Inngest, Resend, Stripe, Anthropic; plus Square or Braintree/PayPal when you connect those processors).
Contact
privacy@recoupe.xyz
Recoupe is not affiliated with Stripe, Square, or PayPal/Braintree. · Privacy · Terms · Subprocessors