Privacy Policy | RecoverFlow

Legal

Privacy policy

Last updated 28 July 2026

Plain English, not a substitute for legal advice. RecoverFlow is run by one person and these documents were written to describe accurately what the software actually does, rather than copied from a generator. They have not been reviewed by a solicitor.

If you need something more formal for a procurement or vendor-review process, including a signed Data Processing Agreement, email admin@recoverflow.org and it will be sorted out properly.

1. The two different roles we play

This matters more than anything else in this document, and most privacy policies in this category blur it.

For your own account data, we are a controller. Your email address, your company name and your billing records are ours to look after and we decide how they are used.

For your customers' data, we are a processor. When a subscription payment fails, we receive the email address of the person whose payment failed so we can send them a message asking them to update their card. That person is your customer, not ours. We act on your instructions, we do not market to them, we do not sell that data, and we do not use it for anything except recovering that specific payment on your behalf.

If you are subject to the UK GDPR or the EU GDPR, that makes you the controller and RecoverFlow the processor for that data, and you are entitled to a Data Processing Agreement. Email us and you will get one.

2. What we actually store

This list is taken from the database schema rather than written from memory.

About you, the merchant

About your failed payments

About your history

3. What we never store

We never see or store card numbers, CVCs, expiry dates or bank details. Stripe holds all of that and processes every charge. Card data does not reach our servers at any point, which is why our card update page is built on Stripe's own hosted elements rather than a form we wrote.

We also do not store passwords. Signing in uses a one-time link sent to your email address, so there is no password for us to lose.

4. Email tracking, stated plainly

The recovery emails we send to your customers record whether the message was opened and whether the link was clicked. We do this so you can see which messages actually recover money, and so we can attribute a recovery to a specific action rather than guessing.

We are telling you this because it is a tracking pixel and you should know it exists, particularly if you have your own commitments to your customers about tracking. If you would rather it was switched off for your account, email us and we will turn it off. Attribution gets less precise as a result, which in practice means we charge you for fewer recoveries rather than more.

5. Sub-processors

These are the third parties that touch data in order for the service to work.

Sub-processorWhat it doesData it touches
StripePayment processing, account connection, and all card handlingPayment and subscription data, cardholder data (held entirely by Stripe)
RenderApplication hosting and the PostgreSQL database, United States regionAll application data at rest
SendGrid (Twilio)Delivery of recovery emails to your customersCustomer email address and message content
CloudflareDNS and proxying for the application subdomainsRequest metadata in transit
GitHub PagesHosting of the public marketing site onlyNo account or customer data
Google AnalyticsMarketing site traffic measurement onlyMarketing site visitors, not application data
LinkedInAdvertising measurement on the marketing site onlyMarketing site visitors, not application data

Google Analytics and the LinkedIn tag run on the public marketing site only. They are not present in the application you log into, and they never see your account data or your customers' data.

6. How long we keep things

We are being deliberately non-specific about exact retention windows rather than inventing a policy we do not yet operate. If you need a committed retention schedule in writing for a vendor review, ask and we will agree one with you.

7. Your rights, and your customers' rights

Depending on where you are, you may have the right to access the data we hold about you, correct it, delete it, get a copy of it in a portable form, or object to how it is used. Email admin@recoverflow.org and we will action it.

If one of your customers contacts us directly about their data, we will not act unilaterally. We will point them to you, because you are the controller of that relationship, and then we will do whatever you instruct.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. If you are a California resident, that means there is nothing for you to opt out of on that front.

8. Where data lives

The application and its database are hosted in the United States. If you or your customers are in the UK, the EU or elsewhere, using RecoverFlow means data is transferred to and processed in the US. If that is a problem for your compliance position, say so before you connect rather than after.

9. The marketing site

The pages at recoverflow.org that you can read without logging in use Google Analytics and the LinkedIn Insight Tag to measure traffic and advertising. These set cookies.

We do not currently show a cookie consent banner. That is a gap rather than a position, and it is on the list to fix. In the meantime, blocking third-party cookies or using an ad blocker prevents both, and nothing on the marketing site breaks if you do.

The free tools run entirely in your browser. Nothing you type into the estimator, the retry builder or the email generator is transmitted to us or stored anywhere.

10. Changes and contact

If this policy changes in a way that materially affects you, we will email you rather than quietly editing the page. The date at the top always reflects the last change.

Questions, requests, or complaints: admin@recoverflow.org. It goes to Bruce, who is the whole company, so you will get a real answer rather than a ticket number.