Privacy Policy

Our privacy policy and how we use your data

Effective July 20, 2026

This Privacy Policy explains how RecoupPay, a Hallman Lab service operated by Daniel Hallman, collects, uses, shares, and keeps personal information. It covers the RecoupPay site, accounts, API, recovery pages, messages, and related support.

RecoupPay serves businesses that manage failed or overdue payments. A business that submits customer recovery data decides why and how that data is used. For that data, the business is the controller or business and RecoupPay is its processor or service provider. For site, account, plan billing, support, and security data, RecoupPay decides how the data is used.

1. Information we collect

We may collect these categories of personal information:

  • Account details: name, email, profile image, organization, role, sign-in and verification status, multi-factor settings, and support requests.
  • Session and security data: session tokens, IP address, user agent, sign-in times, device and browser details, audit events, rate-limit data, and suspected abuse or error details.
  • Plan and business data: business name, team membership, plan, invoices, subscription status, billing customer ID, and payment status. Our billing provider receives full plan-payment details; RecoupPay does not store full card or bank account numbers.
  • Connected-account data: provider account and customer IDs, OAuth grants, account status, invoices, subscriptions, payment events, failure codes, transaction amounts, currency, and the results of hosted payment actions. Providers may also give us business and contact details tied to the connected account.
  • Recovery-case data: customer name, email, phone number, locale, time zone, customer and invoice IDs, invoice number, amount, currency, dates, memo, payment status, failure reason, and attachment name, type, size, and hash. The current upload flow records attachment metadata, not the attachment bytes.
  • Message and consent data: message text and subject, sender and recipient, consent source and policy version, send time, delivery, bounce, complaint, open, click, reply, opt-out, wrong-number, and suppression records. We may store hashed or encrypted contact fields where the service supports it.
  • Recovery-page activity: link views, short-lived session data, action records, selected action, provider redirect, result, and security checks. Payment card and bank details are entered on the payment provider’s page, not on a RecoupPay recovery page.
  • Grouped measures: recovery rates, recovered amounts, time to recovery, message-step results, provider cost, and other grouped or de-identified service measures.

RecoupPay is not built to receive Social Security numbers, government ID images, health data, full payment credentials, or data about children. Please do not submit those items.

2. Where information comes from

We receive information from:

  • you, your organization, and your team members;
  • your API calls, CSV or form uploads, and service settings;
  • Stripe, Square, and other billing providers you choose to connect;
  • email and text providers, including delivery and opt-out events;
  • customers who open a recovery link, choose an action, reply, or ask to stop messages; and
  • browsers, devices, cookies, server logs, and security tools.

3. How we use information

We use personal information to:

  • create and secure accounts, sessions, teams, and API keys;
  • connect billing providers and receive, check, and reconcile their events;
  • open and manage recovery cases, apply the merchant’s journey, and create scoped RecoupPay links and provider actions;
  • send merchant-approved email or text messages and process delivery, reply, consent, opt-out, and suppression events;
  • provide dashboards, exports, cost and recovery measures, billing, and support;
  • prevent duplicate or barred contact, fraud, abuse, unauthorized access, and unsafe payment actions;
  • debug, keep audit records, enforce our terms, protect rights, and meet legal duties; and
  • improve the service with grouped or de-identified information.

We do not use merchant customer data to train a general-purpose AI model. RecoupPay rules may choose the next merchant-set message or hosted action, but RecoupPay does not make credit, employment, housing, insurance, or other decisions that create legal effects for a customer.

4. How we share information

We disclose information only as needed for the uses above. The categories of recipients are:

  • The merchant that supplied the data. Its approved users can view and act on its recovery cases.
  • Payment providers. Stripe, Square, and another provider you connect receive account, transaction, and action data under their own terms and privacy notices.
  • Email and text providers. They receive the sender, recipient, message, links, and routing data needed to send and report a message. Current integrations include Resend for email and, when enabled, Twilio for text.
  • Hosting, database, auth, and security providers. They process the data needed to run, store, back up, secure, and support the service. RecoupPay currently hosts the web service on Vercel.
  • Recipients chosen by the merchant. If a merchant turns them on, its Slack, Discord, or webhook endpoint receives the event data the merchant chose to send.
  • Advisers, authorities, and a new owner. We may disclose data to auditors, counsel, insurers, courts, regulators, law enforcement, or a buyer or successor when needed for a valid legal, safety, or business-transfer purpose.

We do not sell personal information. We do not share it for cross-site behavioral advertising, and we do not use customer data for targeted ads. RecoupPay currently uses no third-party ad or user-behavior analytics provider.

5. Cookies and similar storage

RecoupPay uses needed cookies for sign-in, security, connected-account setup, short-lived recovery sessions, language, theme, and layout choices. We do not currently use advertising cookies. The Cookie Policy lists these tools and how to control them.

A payment provider or security check may use its own cookies when you visit its page or widget. Its policy controls those cookies.

6. How long we keep information

We keep information for as long as needed to provide the service, follow the merchant’s instructions, secure accounts, settle disputes, prove consent and payment events, maintain suppression and audit records, and meet legal, tax, and contract duties. The period varies by record and there is no single fixed deletion schedule.

Closing an account does not at once erase every recovery, consent, suppression, payment-event, backup, or audit record. We delete, anonymize, return, or limit data only after a verified, support-led review; RecoupPay does not currently run an automatic global deletion process. A legal hold, suppression need, backup cycle, audit need, or other duty may limit a request. We may keep grouped or de-identified data that no longer identifies a person.

7. Your choices and privacy rights

Depending on where you live, you may have the right to know, access, correct, delete, or receive a copy of personal information; opt out of sale, targeted advertising, or certain profiling; limit certain sensitive-data use; and appeal a denied request. We will not treat you unfairly for using a privacy right.

For customer recovery data, contact the merchant that sent the message or owns the account first. It decides the request, and RecoupPay will help it respond. You may also email privacy@recouppay.app. State the merchant, contact address or number, and right you wish to use. Do not send payment credentials or government ID unless we ask for a safe way to verify you.

We may verify your identity and authority before acting. An authorized agent may submit a request where law allows it. To appeal a denial, reply within 30 days with “Privacy Appeal” and the reason you think the result should change. We will review it and tell you the outcome and any regulator contact path required by law.

To stop recovery email, use the unsubscribe link or reply with a clear stop request. To stop text messages, reply STOP or use another reasonable way to withdraw consent. A stop request may not bar a message that law permits or requires, but it will stop automated recovery outreach for that address or number as required.

8. Security

We use reasonable steps suited to the data, including access controls, short-lived and scoped links, audit records, transport encryption, and encryption or hashing for designated sensitive fields. Recovery pages use controls that limit caching and outside referrers. No system can promise perfect security. Keep your account and API keys safe and report suspected misuse at security@recouppay.app.

9. United States processing and children

RecoupPay is run from the United States. We and our providers may process information in the United States and other places where they operate, subject to the safeguards required by law and contract.

The service is for businesses and is not meant for anyone under 18. We do not knowingly collect personal information from a child. Contact us if you believe a child gave us information.

10. Changes and contact

We may update this policy as the service or law changes. We will post the new date and give added notice when a change is material. We will ask for consent before a new use when law requires it.

For a privacy request, appeal, or question, email privacy@recouppay.app. RecoupPay is a Hallman Lab service operated by Daniel Hallman in Tennessee, United States.