Privacy policy
Last updated 26 July 2026
RetryPilot processes payment metadata belonging to your business and to your customers. This page describes exactly what is collected, why it is needed, and how to get it removed.
Who we are
RetryPilot is operated from Sweden, within the European Union. For data you submit about yourself (your account), we are the data controller. For data about your customers that reaches us through your connected Stripe account, we act as a data processor on your behalf, and you remain the controller.
Contact for any privacy question or request: privacy@retrypilot.com.
What we collect
| Data | Why |
|---|---|
| Your email address and a hashed password | To create and secure your account. Passwords are stored as Argon2 hashes and are never recoverable. |
| Your Stripe account ID and OAuth access token | To read failed invoices and to retry them. The token is encrypted at rest (Fernet / AES-128-CBC with HMAC-SHA256) before being written to the database. |
| Invoice metadata: amount, currency, status, decline reason, attempt count, timestamps | To decide whether and when to retry, and to compute your recovery metrics. |
| Your customers' Stripe customer ID and email address | To send the recovery emails and to attribute a recovery to the right customer. |
| Records of emails sent (recipient, step, timestamp, delivery status) | To avoid sending duplicates and to show you what was sent. |
| Session cookie | To keep you logged in. Strictly necessary — no analytics, advertising or tracking cookies are set. |
What we never collect
- Card numbers, CVCs or expiry dates.The card-update page uses Stripe Elements, so card details travel from your customer's browser directly to Stripe and never reach our servers or logs.
- Bank account or payout details.
- Behavioural tracking, ad pixels, or third-party analytics.
Legal basis
- Contract (Art. 6(1)(b) GDPR) — processing your account data and your connected Stripe data is necessary to provide the service you signed up for.
- Legitimate interest (Art. 6(1)(f)) — security logging and fraud prevention.
- Emails to your customers are sent on your instruction, under your legal basis as the controller of that relationship.
Sub-processors
We use a small number of third parties. Each processes only what is necessary for its function:
| Provider | Purpose | Data shared |
|---|---|---|
| Stripe | Payment processing, retries, card collection, our own billing | Invoice, customer and subscription identifiers |
| Resend | Sending recovery emails | Recipient email address and message content |
| OpenRouter | Generating the written narrative of the leak audit | Aggregate figures only — no customer emails or identifiers |
| Hetzner | Server and database hosting | All of the above, at rest, within the EU |
Where data is stored
On servers located in the European Union. Stripe, Resend and OpenRouter may process data outside the EU under their own transfer mechanisms (Standard Contractual Clauses).
Retention
- Account data: for as long as your account exists.
- Invoice and campaign records: retained while your account is active, so your historical recovery metrics remain accurate.
- Card-update tokens: expire automatically 30 days after creation.
- After account deletion: removed within 30 days, except where we are legally required to keep billing records.
Your rights
Under GDPR you may request access, correction, deletion, restriction, portability, or object to processing. Email privacy@retrypilot.com and we will respond within 30 days. You also have the right to complain to your national supervisory authority — in Sweden, Integritetsskyddsmyndigheten (IMY).
Data processing agreement
Where we process your customers' personal data on your behalf, we do so only on your documented instructions, keep it confidential, apply the technical and organisational measures described on our security page, engage only the sub-processors listed above, assist you with data-subject requests, and delete or return the data when the service ends.
A signed data processing agreement is available on request — email privacy@retrypilot.com.
Changes
If this policy changes materially, we will email account holders before the change takes effect.