Privacy Policy

Revenue Recovery Labs processes billing failure data on behalf of our customers. This policy explains exactly what we receive, why we hold it and how long we keep it.

Last updated 6 September 2026

1. Data we receive

  • Read-only webhook payloads from your billing provider (Stripe, Lemon Squeezy, Paddle, Shopify, Chargebee).
  • Decline codes and processor failure reasons.
  • Invoice and subscription values, currency and retry history.
  • End-customer email addresses and phone numbers, used strictly for recovery sequencing.
  • Account data you give us directly: your email, workspace name and white-label branding.

2. Data we never store

Zero credit card or raw PCI data stored. AES-256-GCM encryption at rest.

We never receive or persist primary account numbers, CVV codes, expiry dates, bank credentials or full card fingerprints. Billing connections are read-only: RRLabs cannot move money, issue refunds or modify a subscription.

3. Why we process it

  • To detect a failed payment and place it in a recovery cadence.
  • To generate and dispatch recovery messages over email, SMS and WhatsApp.
  • To time retries against the specific bank decline code.
  • To produce recovery reporting and dollar-level attribution for your workspace.

Our lawful basis under GDPR is legitimate interest (recovering a payment the end-customer already authorised) and performance of a contract with our customer, who acts as data controller. RRLabs acts as a data processor.

4. Sub-processors

  • Meta WhatsApp Cloud API — WhatsApp message delivery (customer's own sender under BYOK).
  • OpenAI — primary recovery copy generation.
  • DeepSeek — fallback recovery copy generation.
  • Resend — transactional and recovery email delivery.
  • Supabase — database, authentication and storage hosting.

5. Retention and deletion

Failure events and message logs are retained for the life of the workspace plus 30 days. You can request permanent deletion of a tenant's failure history, logs and billing keys at any time through our data deletion page or by emailing support@rrlabs.online. Deletion completes within 30 days.

6. Your rights

Data subjects may request access, correction, export, restriction or erasure. Requests arriving directly to RRLabs are forwarded to the relevant workspace owner (the controller). Contact support@rrlabs.online for anything covered by GDPR, UK GDPR or CCPA.

7. International transfers and security

Data is processed in the EU and US regions of our infrastructure providers under standard contractual clauses. Access is limited to named personnel, all traffic is TLS 1.2+ in transit, and secrets are encrypted with AES-256-GCM at rest.