Privacy Policy
Effective: June 2025
1. Who we are
Revivopay operates a B2B SaaS platform that helps businesses recover failed subscription payments. References to “we”, “us”, or “our” mean Revivopay. Our contact email is privacy@revivopay.com.
2. Data we collect
- Account data — your name, business email, and authentication credentials (managed by Clerk).
- Payment provider credentials — encrypted API keys and webhook secrets for Stripe or Razorpay.
- Customer payment data — failed payment records synced from your payment provider, including customer email, name, and payment amount.
- Email engagement data — delivery, open, and click events for dunning emails we send on your behalf.
- Usage and log data — request logs, AI prompt/response logs (PII-redacted), cron execution logs, and error traces.
3. How we use your data
- To operate and improve the payment recovery service.
- To send automated dunning emails to your customers on your behalf.
- To generate AI-personalised email content using OpenAI (prompts are PII-redacted before storage).
- To provide dashboard analytics on recovery rates and email performance.
- To comply with legal obligations.
4. Data sharing
We do not sell your data. We share data only with:
- Clerk — authentication and user management.
- Supabase / PostgreSQL — data storage.
- Resend — transactional email delivery.
- OpenAI — AI email personalisation (PII-redacted prompts).
- Stripe / Razorpay — payment provider integrations at your direction.
5. Data retention
Webhook event logs, AI request logs, activity events, and cron logs are automatically deleted after 90 days. Payment records and account data are retained while your account is active. You may request deletion at any time (see Section 7).
6. Your customers' data
You are the data controller for your customers' data. We act as a data processor on your behalf. Each dunning email includes a one-click unsubscribe link. If a recipient unsubscribes, bounces, or marks an email as spam, we automatically suppress further emails to them.
7. Your rights (GDPR / CCPA)
You have the right to access, correct, export, or delete your data. To exercise these rights, email privacy@revivopay.com or use the account deletion option in your dashboard settings. We will respond within 30 days.
8. Security
Payment provider keys are encrypted at rest using AES-256-GCM. All data is transmitted over TLS. We apply rate limiting, HMAC webhook verification, and Content Security Policy headers across the application.
9. Changes to this policy
We will notify you by email if we make material changes to this policy. The effective date above reflects the most recent update.
Questions? Email privacy@revivopay.com