← Back to RetryPilot

Privacy Policy

Last updated: 20 July 2026

RetryPilot ("we", "us") is operated from New Zealand. This policy explains what data we collect when you use RetryPilot, why we collect it, and how it's protected. RetryPilot is an early-stage product — if anything here is unclear, email us and we'll clarify or fix it.

What we collect

  • Account data: the email address and password you sign up with (passwords are hashed by our authentication provider, Supabase — we never see or store them in plain text).
  • Stripe connection data: a restricted Stripe API key and webhook signing secret you provide so we can detect failed payments on your Stripe account. These are encrypted at rest (AES-256-GCM) before being stored, and are only decrypted in memory when processing a webhook event.
  • Your customers' payment data: when one of your customers' payments fails, Stripe sends us the invoice amount, currency, and the customer's name/email so we can send a recovery reminder on your behalf. We do not receive or store full card numbers — Stripe never sends us that.
  • Usage data: basic operational logs (e.g. which reminder emails were sent and when) so the dashboard can show your recovery stats.

How we use it

Solely to run the service: detecting failed payments on your connected Stripe account, sending recovery emails to your customers on your behalf, showing you a dashboard of results, and billing you for your RetryPilot subscription. We do not sell your data or your customers' data to anyone.

Who we share it with

  • Supabase — hosts our database and handles authentication.
  • Stripe — processes your RetryPilot subscription payment and is the source of your customers' failed-payment events.
  • Resend — delivers the recovery emails sent to your customers.
  • Vercel — hosts the application.

We don't share data with anyone beyond what's needed to run these infrastructure providers above.

Data retention & deletion

We keep your data for as long as your account is active. If you want your account and associated data deleted, email us and we'll remove it within 30 days, except where we're required to keep billing records for tax purposes.

Your rights

You can request a copy of the data we hold about you, ask us to correct it, or ask us to delete it, at any time, by emailing us. If you're in the EU/UK, you have rights under GDPR; if you're elsewhere, we extend the same rights to you regardless.

Cookies

We use only the essential cookies needed to keep you logged in (set by Supabase Auth). We don't use tracking or advertising cookies.

Contact

Questions about this policy or your data — email shaqib1045@gmail.com.