Privacy Policy

Last updated July 15, 2026

This policy explains what data Recoup, operated by Zrionix Technology, Inc., collects when you use the service, how we use it, and the choices you have. We collect only what we need to recover your failed payments.

What we collect

Account data: your name, email, and workspace details when you sign up.

Square data: on your authorization, we access the failed payments, invoices, subscriptions, customers, and card-on-file references in your connected Square account — only what is needed to run recovery. We never receive or store full card numbers; cards are tokenized by Square.

Usage data: standard logs (IP, browser, timestamps) and product events used to operate, secure, and improve the service.

How we use it

To retry failed charges, send dunning emails, host card-update pages, and show you recovery results — the core function of the service.

To secure the service, prevent abuse, provide support, and comply with legal obligations. We do not sell your data or your customers’ data, and we do not use it for advertising.

Payment card data

Recoup never stores full card numbers. Card details are collected and tokenized directly by Square through its PCI-compliant payment SDK; we only ever handle Square card tokens. Our hosted card-update pages are designed to keep card entry within Square’s scope (PCI SAQ-A).

Sub-processors

We rely on a small set of trusted providers to run the service: Square (payments and card tokenization), Supabase (database and authentication), Vercel (hosting), Inngest (background job scheduling), Resend (transactional and dunning email delivery), and Stripe (billing you for your Recoup subscription).

Each processes data only as needed to provide its part of the service and under its own security and privacy commitments.

Data retention

We keep your data for as long as your account is active and as needed to provide the service. When you disconnect Square or close your account, we stop recovery activity and delete or de-identify your data within a reasonable period, except where we must retain records to meet legal or accounting obligations.

Your choices and rights

You can disconnect Square at any time, which halts all access and recovery activity. You can request a copy of your data or its deletion by contacting us. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA; we honor valid requests under applicable law.

Security

We encrypt sensitive credentials at rest, scope database access with row-level security, and restrict access to production data. No system is perfectly secure, but we work to protect your data and to notify you of material incidents as required by law.

Changes

We may update this policy as the service evolves. Material changes will be posted here with a new “last updated” date.

Questions about this document? Get in touch.