Privacy policy

Last updated 26 July 2026

RetryPilot processes payment metadata belonging to your business and to your customers. This page describes exactly what is collected, why it is needed, and how to get it removed.

Who we are

RetryPilot is operated from Sweden, within the European Union. For data you submit about yourself (your account), we are the data controller. For data about your customers that reaches us through your connected Stripe account, we act as a data processor on your behalf, and you remain the controller.

Contact for any privacy question or request: privacy@retrypilot.com.

What we collect

DataWhy
Your email address and a hashed passwordTo create and secure your account. Passwords are stored as Argon2 hashes and are never recoverable.
Your Stripe account ID and OAuth access tokenTo read failed invoices and to retry them. The token is encrypted at rest (Fernet / AES-128-CBC with HMAC-SHA256) before being written to the database.
Invoice metadata: amount, currency, status, decline reason, attempt count, timestampsTo decide whether and when to retry, and to compute your recovery metrics.
Your customers' Stripe customer ID and email addressTo send the recovery emails and to attribute a recovery to the right customer.
Records of emails sent (recipient, step, timestamp, delivery status)To avoid sending duplicates and to show you what was sent.
Session cookieTo keep you logged in. Strictly necessary — no analytics, advertising or tracking cookies are set.

What we never collect

  • Card numbers, CVCs or expiry dates.The card-update page uses Stripe Elements, so card details travel from your customer's browser directly to Stripe and never reach our servers or logs.
  • Bank account or payout details.
  • Behavioural tracking, ad pixels, or third-party analytics.

Legal basis

  • Contract (Art. 6(1)(b) GDPR) — processing your account data and your connected Stripe data is necessary to provide the service you signed up for.
  • Legitimate interest (Art. 6(1)(f)) — security logging and fraud prevention.
  • Emails to your customers are sent on your instruction, under your legal basis as the controller of that relationship.

Sub-processors

We use a small number of third parties. Each processes only what is necessary for its function:

ProviderPurposeData shared
StripePayment processing, retries, card collection, our own billingInvoice, customer and subscription identifiers
ResendSending recovery emailsRecipient email address and message content
OpenRouterGenerating the written narrative of the leak auditAggregate figures only — no customer emails or identifiers
HetznerServer and database hostingAll of the above, at rest, within the EU

Where data is stored

On servers located in the European Union. Stripe, Resend and OpenRouter may process data outside the EU under their own transfer mechanisms (Standard Contractual Clauses).

Retention

  • Account data: for as long as your account exists.
  • Invoice and campaign records: retained while your account is active, so your historical recovery metrics remain accurate.
  • Card-update tokens: expire automatically 30 days after creation.
  • After account deletion: removed within 30 days, except where we are legally required to keep billing records.

Your rights

Under GDPR you may request access, correction, deletion, restriction, portability, or object to processing. Email privacy@retrypilot.com and we will respond within 30 days. You also have the right to complain to your national supervisory authority — in Sweden, Integritetsskyddsmyndigheten (IMY).

Data processing agreement

Where we process your customers' personal data on your behalf, we do so only on your documented instructions, keep it confidential, apply the technical and organisational measures described on our security page, engage only the sub-processors listed above, assist you with data-subject requests, and delete or return the data when the service ends.

A signed data processing agreement is available on request — email privacy@retrypilot.com.

Changes

If this policy changes materially, we will email account holders before the change takes effect.