Legal
Privacy policy
Last updated 28 July 2026
Plain English, not a substitute for legal advice. RecoverFlow is run by one person and these documents were written to describe accurately what the software actually does, rather than copied from a generator. They have not been reviewed by a solicitor.
If you need something more formal for a procurement or vendor-review process, including a signed Data Processing Agreement, email admin@recoverflow.org and it will be sorted out properly.
On this page
1. The two different roles we play
This matters more than anything else in this document, and most privacy policies in this category blur it.
For your own account data, we are a controller. Your email address, your company name and your billing records are ours to look after and we decide how they are used.
For your customers' data, we are a processor. When a subscription payment fails, we receive the email address of the person whose payment failed so we can send them a message asking them to update their card. That person is your customer, not ours. We act on your instructions, we do not market to them, we do not sell that data, and we do not use it for anything except recovering that specific payment on your behalf.
If you are subject to the UK GDPR or the EU GDPR, that makes you the controller and RecoverFlow the processor for that data, and you are entitled to a Data Processing Agreement. Email us and you will get one.
2. What we actually store
This list is taken from the database schema rather than written from memory.
About you, the merchant
- Your email address and company name
- Your Stripe account identifier
- An encrypted Stripe access token, which is what lets us read your invoices and retry failed payments
- Your plan, your account settings, and the date you signed up
- Billing records for fees we have charged you, and a Stripe customer identifier for that billing
About your failed payments
- Stripe invoice, subscription and customer identifiers
- The email address of the customer whose payment failed
- The amount and currency
- The decline code and decline reason returned by the card issuer
- When it first failed, when it recovered, or when it was written off
- A record of each retry we attempted and its outcome
- A record of each recovery email we sent, including which step in the sequence it was
- Short-lived tokens for the card update page we send customers to
About your history
- The results of the 90 day backward-looking scan we run when you first connect, which is a summary of what failed and what was estimated recoverable
3. What we never store
We never see or store card numbers, CVCs, expiry dates or bank details. Stripe holds all of that and processes every charge. Card data does not reach our servers at any point, which is why our card update page is built on Stripe's own hosted elements rather than a form we wrote.
We also do not store passwords. Signing in uses a one-time link sent to your email address, so there is no password for us to lose.
4. Email tracking, stated plainly
The recovery emails we send to your customers record whether the message was opened and whether the link was clicked. We do this so you can see which messages actually recover money, and so we can attribute a recovery to a specific action rather than guessing.
We are telling you this because it is a tracking pixel and you should know it exists, particularly if you have your own commitments to your customers about tracking. If you would rather it was switched off for your account, email us and we will turn it off. Attribution gets less precise as a result, which in practice means we charge you for fewer recoveries rather than more.
5. Sub-processors
These are the third parties that touch data in order for the service to work.
| Sub-processor | What it does | Data it touches |
|---|---|---|
| Stripe | Payment processing, account connection, and all card handling | Payment and subscription data, cardholder data (held entirely by Stripe) |
| Render | Application hosting and the PostgreSQL database, United States region | All application data at rest |
| SendGrid (Twilio) | Delivery of recovery emails to your customers | Customer email address and message content |
| Cloudflare | DNS and proxying for the application subdomains | Request metadata in transit |
| GitHub Pages | Hosting of the public marketing site only | No account or customer data |
| Google Analytics | Marketing site traffic measurement only | Marketing site visitors, not application data |
| Advertising measurement on the marketing site only | Marketing site visitors, not application data |
Google Analytics and the LinkedIn tag run on the public marketing site only. They are not present in the application you log into, and they never see your account data or your customers' data.
6. How long we keep things
- While your account is open: we keep your account data and your recovery history so the dashboard and reporting work.
- After you disconnect: your Stripe access token is the thing that matters most, and revoking access in your Stripe dashboard makes it useless immediately regardless of what we hold.
- On request: ask us to delete your account and we will delete your data. Tell us and it gets done, including your customers' email addresses.
- Billing records: we keep invoices and fee records for as long as we are required to for tax and accounting purposes, even after deletion of the rest.
We are being deliberately non-specific about exact retention windows rather than inventing a policy we do not yet operate. If you need a committed retention schedule in writing for a vendor review, ask and we will agree one with you.
7. Your rights, and your customers' rights
Depending on where you are, you may have the right to access the data we hold about you, correct it, delete it, get a copy of it in a portable form, or object to how it is used. Email admin@recoverflow.org and we will action it.
If one of your customers contacts us directly about their data, we will not act unilaterally. We will point them to you, because you are the controller of that relationship, and then we will do whatever you instruct.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. If you are a California resident, that means there is nothing for you to opt out of on that front.
8. Where data lives
The application and its database are hosted in the United States. If you or your customers are in the UK, the EU or elsewhere, using RecoverFlow means data is transferred to and processed in the US. If that is a problem for your compliance position, say so before you connect rather than after.
9. The marketing site
The pages at recoverflow.org that you can read without logging in use Google Analytics and the LinkedIn Insight Tag to measure traffic and advertising. These set cookies.
We do not currently show a cookie consent banner. That is a gap rather than a position, and it is on the list to fix. In the meantime, blocking third-party cookies or using an ad blocker prevents both, and nothing on the marketing site breaks if you do.
The free tools run entirely in your browser. Nothing you type into the estimator, the retry builder or the email generator is transmitted to us or stored anywhere.
10. Changes and contact
If this policy changes in a way that materially affects you, we will email you rather than quietly editing the page. The date at the top always reflects the last change.
Questions, requests, or complaints: admin@recoverflow.org. It goes to Bruce, who is the whole company, so you will get a real answer rather than a ticket number.
Recover