Privacy Policy
Last updated July 15, 2026
This policy explains what data Recoup, operated by Zrionix Technology, Inc., collects when you use the service, how we use it, and the choices you have. We collect only what we need to recover your failed payments.
What we collect
Account data: your name, email, and workspace details when you sign up.
Square data: on your authorization, we access the failed payments, invoices, subscriptions, customers, and card-on-file references in your connected Square account — only what is needed to run recovery. We never receive or store full card numbers; cards are tokenized by Square.
Usage data: standard logs (IP, browser, timestamps) and product events used to operate, secure, and improve the service.
How we use it
To retry failed charges, send dunning emails, host card-update pages, and show you recovery results — the core function of the service.
To secure the service, prevent abuse, provide support, and comply with legal obligations. We do not sell your data or your customers’ data, and we do not use it for advertising.
Payment card data
Recoup never stores full card numbers. Card details are collected and tokenized directly by Square through its PCI-compliant payment SDK; we only ever handle Square card tokens. Our hosted card-update pages are designed to keep card entry within Square’s scope (PCI SAQ-A).
Sub-processors
We rely on a small set of trusted providers to run the service: Square (payments and card tokenization), Supabase (database and authentication), Vercel (hosting), Inngest (background job scheduling), Resend (transactional and dunning email delivery), and Stripe (billing you for your Recoup subscription).
Each processes data only as needed to provide its part of the service and under its own security and privacy commitments.
Data retention
We keep your data for as long as your account is active and as needed to provide the service. When you disconnect Square or close your account, we stop recovery activity and delete or de-identify your data within a reasonable period, except where we must retain records to meet legal or accounting obligations.
Your choices and rights
You can disconnect Square at any time, which halts all access and recovery activity. You can request a copy of your data or its deletion by contacting us. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA; we honor valid requests under applicable law.
Security
We encrypt sensitive credentials at rest, scope database access with row-level security, and restrict access to production data. No system is perfectly secure, but we work to protect your data and to notify you of material incidents as required by law.
Changes
We may update this policy as the service evolves. Material changes will be posted here with a new “last updated” date.
Questions about this document? Get in touch.