reecova

Security & data access

Reecova reads your payment data to find and recover lost revenue. Software that touches revenue data should say precisely what it can and cannot do. This page is that statement.

Read-only, always

Reecova connects through Stripe OAuth with read-only permissions. It can see charges, invoices, subscriptions, and customers. It cannot create charges, issue refunds, or move money. Stripe enforces this at the API level, not us.

The free scan revokes itself

The scanner requests temporary access, reads 90 days of history, computes your report, and then deauthorizes its own connection. Results are kept for 24 hours so you can view your report, then expire.

Tokens are encrypted

OAuth tokens are encrypted at rest. All traffic between your browser, Reecova, and Stripe runs over TLS.

No card numbers, ever

Reecova never receives or stores full card numbers. Stripe returns only metadata: amounts, decline codes, card brand, and last four digits.

You can disconnect any time

One click in Settings disconnects your Stripe account, or revoke Reecova directly from your Stripe dashboard. Either way, access ends immediately.

SOC 2 in progress

SOC 2 compliance work is underway. Until it completes, this page states exactly what we do rather than pointing at a badge.

what the scan reads

chargesfailed, declined, and disputed transactions with decline codes
invoices + subscriptionsbilling gaps and involuntary churn from failed renewals
refundsrevenue lost to disputes and chargebacks
customerscounts and identifiers only, for grouping failures
Run the free leak scan

Questions about data handling? security@reecova.io