Privacy Policy
Effective date: March 9, 2026
1. Introduction
Reecova ("Company," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Reecova platform, website at reecova.io, APIs, and related services (collectively, the "Service").
By using the Service, you consent to the data practices described in this policy. If you do not agree with this policy, please do not use the Service.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, and authentication credentials when you create an account (managed through our authentication provider, Clerk)
- Organization Information: Company name and organizational details
- Communication Data: Information you provide when contacting us for support or feedback
- Preferences: Alert settings, notification preferences, and dashboard configurations
2.2 Payment Processor Data
When you connect your payment processor account (e.g., Stripe) to the Service, we access and process:
- Transaction Data: Payment amounts, dates, statuses (succeeded, failed, refunded), currency, and failure codes
- Customer Data: Your customers' Stripe customer IDs, email addresses (if available through Stripe), and subscription information
- Subscription Data: Plan details, billing intervals, subscription statuses, and cancellation information
- Invoice Data: Invoice amounts, payment statuses, and associated metadata
- Dispute Data: Chargeback and dispute details
Important: We do not store or have access to your customers' full credit card numbers, bank account numbers, or other raw payment credentials. All payment processing occurs through your connected payment processor.
2.3 Automatically Collected Information
- Usage Data: Pages visited, features used, actions taken within the Service
- Device Information: Browser type, operating system, device identifiers
- Log Data: IP addresses, access times, referring URLs, and error logs
- Performance Data: Application performance metrics collected through our error monitoring service (Sentry)
3. How We Use Your Information
We use the collected information for the following purposes:
- Provide the Service: Analyze payment data, detect failed payments, identify revenue leaks, generate recovery recommendations, and execute automated retries and dunning campaigns
- Analytics and Insights: Generate dashboards, reports, trend analysis, risk scores, and AI-powered insights about your revenue health
- Notifications: Send alerts about payment failures, recovery opportunities, and weekly digest reports via email and in-app notifications
- Service Improvement: Improve our algorithms, features, and user experience based on aggregated and anonymized usage patterns
- Security: Detect and prevent fraud, unauthorized access, and other security threats
- Communication: Respond to your inquiries, provide support, and send service-related notices
- Legal Compliance: Comply with applicable laws, regulations, and legal processes
4. AI and Machine Learning
The Service uses artificial intelligence and machine learning to:
- Predict optimal retry timing for failed payments
- Score customer churn risk
- Generate revenue insights and recommendations
- Identify patterns in payment failure data
AI models are trained on aggregated and anonymized data patterns. Your individual payment data is processed to generate your specific insights but is not used to train models that serve other customers without anonymization.
5. Data Sharing and Disclosure
We do not sell your personal information or your customers' data. We may share information in the following circumstances:
5.1 Service Providers
We use trusted third-party services to operate the Service:
- Clerk: Authentication and user management
- Neon: Database hosting (PostgreSQL)
- Upstash: Redis caching and task queue management
- Railway: Backend application hosting
- Vercel: Frontend application hosting
- Resend: Transactional email delivery
- Sentry: Error monitoring and performance tracking
- Anthropic: AI-powered insight generation (processes anonymized data only)
These providers are contractually obligated to protect your information and may only use it to provide services to us.
5.2 Legal Requirements
We may disclose your information if required to do so by law or in response to valid legal process, including:
- Court orders, subpoenas, or legal proceedings
- Requests from law enforcement or government agencies
- To protect the rights, property, or safety of Reecova, our users, or the public
5.3 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of the transaction. We will notify you of any such change and any choices you may have regarding your information.
6. Data Security
We implement commercially reasonable technical and organizational measures to protect your data, including:
- Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS/SSL
- Encryption at Rest: Sensitive credentials (such as payment processor tokens) are encrypted using industry-standard encryption (Fernet/AES-128-CBC)
- Access Controls: Role-based access controls and authentication requirements for all data access
- Infrastructure Security: Our hosting providers (Railway, Vercel, Neon) maintain SOC 2 compliant infrastructure
- Monitoring: Continuous error monitoring and security logging through Sentry
Despite our efforts, no security measures are perfect or impenetrable. We cannot guarantee the absolute security of your information.
7. Data Retention
We retain your data as follows:
- Account Data: Retained for the duration of your account and deleted or anonymized within 30 days of account termination
- Payment Transaction Data: Retained for the duration of your account to provide historical analytics and trend analysis
- Log Data: Retained for up to 90 days for security and debugging purposes
- Aggregated Analytics: Anonymized and aggregated data may be retained indefinitely for service improvement
You may request deletion of your data at any time by contacting us. We will process deletion requests within 30 days, subject to any legal retention requirements.
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data
- Portability: Request your data in a structured, machine-readable format
- Restriction: Request that we restrict processing of your data in certain circumstances
- Objection: Object to our processing of your data for certain purposes
- Withdraw Consent: Withdraw your consent at any time where we rely on consent for processing
To exercise any of these rights, please contact us at privacy@reecova.io. We will respond to your request within 30 days.
9. International Data Transfers
Your data may be processed and stored in the United States or other countries where our service providers operate. By using the Service, you consent to the transfer of your information to countries outside your country of residence, which may have different data protection laws.
Where required by applicable law, we ensure appropriate safeguards are in place for international data transfers, such as Standard Contractual Clauses or equivalent mechanisms.
10. GDPR Compliance (EEA Users)
If you are located in the European Economic Area (EEA), the following additional provisions apply:
- Legal Basis: We process your data based on: (a) your consent; (b) the necessity to perform our contract with you; (c) our legitimate interests in operating and improving the Service; or (d) compliance with legal obligations
- Data Protection Officer: You may contact our data protection team at privacy@reecova.io
- Supervisory Authority: You have the right to lodge a complaint with your local data protection authority
11. CCPA Compliance (California Users)
If you are a California resident, under the California Consumer Privacy Act (CCPA) you have the right to:
- Know what personal information we collect, use, and disclose
- Request deletion of your personal information
- Opt out of the sale of personal information (note: we do not sell personal information)
- Non-discrimination for exercising your privacy rights
To exercise your CCPA rights, contact us at privacy@reecova.io or use our data management tools within the Service.
12. Cookies and Tracking
We use essential cookies and similar technologies necessary for the Service to function, including:
- Authentication Cookies: To maintain your logged-in session (managed by Clerk)
- Security Cookies: To prevent cross-site request forgery and other security threats
- Preference Cookies: To remember your settings and preferences
We do not use third-party advertising or tracking cookies. You can control cookies through your browser settings, but disabling essential cookies may affect the functionality of the Service.
13. Children's Privacy
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information promptly.
14. Third-Party Links
The Service may contain links to third-party websites or services, including your payment processor's dashboard. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you interact with.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on the Service and updating the "Effective date" above. For changes that materially affect your rights, we will provide at least 30 days' notice.
Your continued use of the Service after changes become effective constitutes your acceptance of the updated policy.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Reecova
Email: privacy@reecova.io
Website: reecova.io
For data protection inquiries specifically, please email privacy@reecova.io with the subject line "Data Protection Inquiry."