Privacy Policy

Effective date: February 1, 2026

1. Introduction

Unpause (“we”, “us”, or “our”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard information when you use our payment recovery service (“the Service”).

2. Information We Collect

Account Information: When you sign up, we collect your name, email address, and profile picture via Google OAuth. We do not store your Google password.

Stripe Account Data: When you connect your Stripe account via Stripe Connect OAuth, we access invoice data, customer information (names and email addresses), subscription details, and payment event data as needed to provide recovery services. We store your Stripe access token in encrypted form.

Your Customers' Data: We process your customers' names, email addresses, and payment status information solely to send recovery emails on your behalf. We never access or store card numbers, bank account details, or other sensitive payment credentials.

Usage Data: We collect standard usage data including pages visited, features used, and session duration to improve the Service.

3. How We Use Your Information

We use collected information to: provide and operate the recovery service, send payment recovery emails to your customers on your behalf, generate analytics and recovery insights for your dashboard, communicate with you about your account and service updates, and improve and develop new features for the Service.

4. Data Security

We implement industry-standard security measures to protect your data. All sensitive credentials (including Stripe API tokens and Slack webhook URLs) are encrypted at rest using AES-256-CBC encryption. All data transmission uses HTTPS/TLS. We use Stripe's official Connect API and never handle raw card data. Our database is hosted on Neon with encrypted connections and automated backups.

5. Data Sharing

We do not sell, rent, or trade your personal information or your customers' data. We share data only with: Stripe (to access your account data and process retries via their API), our email delivery provider (to send recovery emails on your behalf), and hosting and infrastructure providers (Vercel, Neon) as necessary to operate the Service. All third-party providers are bound by their own privacy policies and data processing agreements.

6. Data Retention

We retain your account data for as long as your account is active. Failed payment records and recovery actions are retained for 12 months to provide historical analytics. When you delete your account or disconnect your Stripe account, we delete all associated data within 30 days. You may request immediate deletion by contacting us.

7. Your Rights

You have the right to: access the personal data we hold about you, request correction of inaccurate data, request deletion of your data, disconnect your Stripe account at any time from the Settings page, export your recovery data, and withdraw consent for data processing (which may require account termination). To exercise any of these rights, contact us at support@unpause.dev.

8. Your Customers' Privacy

We act as a data processor for your customers' information. You remain the data controller. You are responsible for ensuring that your use of recovery emails complies with applicable privacy laws (including GDPR, CCPA, and similar regulations) and that your customers have been appropriately informed about communications they may receive. All recovery emails include an unsubscribe mechanism.

9. Cookies and Tracking

We use essential cookies to maintain your session and authentication state. We may use privacy-friendly analytics (such as Plausible or PostHog) to understand usage patterns. We do not use third-party advertising cookies or trackers. You can control cookie settings through your browser preferences.

10. International Data Transfers

Our Service is hosted in the United States and European Union. If you access the Service from outside these regions, your data may be transferred to and processed in these locations. We ensure appropriate safeguards are in place for any international data transfers.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service. The “Effective date” at the top of this page indicates when this policy was last revised.

12. Contact

If you have questions about this Privacy Policy or our data practices, please contact us at support@unpause.dev.