Legal
Privacy Policy
This policy explains how Retriq collects, uses and protects information when you use our website and our failed-payment recovery service.
Last updated
1. Who we are
Retriq is software that helps businesses using Stripe find, work and track failed subscription payments. A business connects the Stripe account it already bills on, and Retriq identifies invoices that failed, explains why they failed, coordinates the follow-up with the customer, and reports what was recovered.
Retriq is an independent product. It is not operated, owned or endorsed by Stripe. It integrates with Stripe through Stripe’s published app and API platform.
In this policy, Retriq, we and us mean the service described here. Retriq is the service described in this Privacy Policy; if you need to identify the operating entity for a formal request, contact us at privacy@retriq.io and we will confirm it in writing.
Who this policy covers
This policy describes two different relationships, and it is worth separating them:
- Retriq account holders. The people at a business who sign up for Retriq, connect a Stripe account and use the dashboard. We decide how their account information is handled, and this policy describes that directly.
- Customers of a connected business. The people whose subscription payments failed. Their information reaches Retriq because the business they pay chose to connect Stripe to Retriq. In most cases that business decides why and how its own customer information is used, and Retriq handles it to provide the service to that business.
If you are a customer of a business that uses Retriq and you want your information accessed, corrected or deleted, the fastest route is to contact that business directly, because it controls the Stripe account the information comes from. You can also contact us at privacy@retriq.io and we will help where we are able to.
2. Information we collect
Account information
When you create a Retriq account we collect your email address and, if you provide one, your name. Accounts are created and authenticated through our authentication provider; your password is handled by that provider and Retriq does not store or have access to it. We also store the name of your workspace and any business details you enter in settings, such as a business name, a reply-to address and a support address used in recovery emails.
Stripe connection details
When you connect a Stripe account we store the identifier of that Stripe account, the business name and account email Stripe reports, the account country and default currency, whether the account is in live or test mode, and the times the connection was made, synchronised and, if applicable, disconnected. We also store the access and refresh credentials Stripe issues, encrypted at rest.
Failed-payment and recovery information
To work a recovery, Retriq stores a record for each failed subscription invoice in a connected account. That record can include:
- Stripe identifiers for the invoice, customer, subscription and payment attempt
- The customer’s name and email address as held in Stripe
- The amount due, the amount still outstanding and the currency
- When the payment first failed, when it last failed, how many attempts have been made, and when Stripe has scheduled its next attempt
- The failure and decline information Stripe returned, and the category Retriq assigned to it
- The status of the recovery, the invoice status, a link to the Stripe-hosted invoice, and whether and when the invoice was paid
- A timeline of what happened on the case, such as when a failure was classified, an email was scheduled or sent, or a case was closed
Communications
For each recovery email, we store the recipient address, which message was used, its status, when it was scheduled and sent, the identifier returned by our email provider, and any delivery error. If you email us for support, we keep that correspondence so we can answer it.
Technical information
Our servers write structured logs so we can operate and debug the service. Those logs are written to redact anything that looks like a credential and to mask email addresses. Our hosting and infrastructure providers may separately record standard request information, such as IP addresses and timestamps, as part of running and protecting the service.
Retriq does not use analytics products, advertising technology, session recording or third-party tracking. There is no such software in the application.
3. Information we access through Stripe
Retriq is distributed as a Stripe App. Connecting is an explicit, reviewable step: you are shown what Retriq is asking for and you authorise it in Stripe. Retriq can only ever access what those permissions allow, and you can withdraw them at any time.
Retriq requests access to the following, and nothing else:
- Invoices — to detect subscription invoices whose payment failed, and to see when they are later paid.
- Payment attempts — to read the decline reason behind a failed invoice payment.
- Customer records — to identify the customer to contact about a failed payment, including their name and email address.
- Subscriptions — to confirm a failed invoice belongs to a subscription before acting on it.
- Events — to receive payment failure and payment success notifications as they happen.
Retriq’s Stripe access is read-only
Every permission listed above is a read permission. Retriq holds no write access to your Stripe account. It cannot charge a card, refund a payment, retry an invoice, or create, change or cancel an invoice, subscription, customer or price. It cannot alter your Stripe billing configuration. Stripe owns every payment attempt; where a retry happens, it is Stripe’s own retry, which Retriq reads and works around rather than triggers.
Retriq does not receive or store card numbers, expiry dates, CVC values or any other full payment-card credentials. Card data stays with Stripe and never reaches Retriq’s systems.
Disconnecting
You can disconnect Stripe from your Retriq settings at any time. Doing so deletes the stored Stripe credentials, which is what actually ends Retriq’s access, and cancels any recovery emails that were scheduled but not yet sent. Recovery records already created are kept so your history and reporting remain intact; see Data retention below if you want them removed.
Stripe processes information under its own terms. See the Stripe Privacy Policy.
4. How we use information
We use the information described above to:
- Provide, operate and maintain Retriq
- Create your account, sign you in and verify your email
- Connect your Stripe account and keep the recovery data in Retriq in step with it
- Identify failed subscription payments and work out why they failed
- Open and manage recovery cases, and apply the recovery rules configured for your workspace
- Send recovery emails to the affected customers on your behalf, and record whether they were delivered
- Show you recovery status, timelines, revenue at risk and revenue recovered
- Keep the service secure and reliable, investigate faults, and prevent abuse
- Respond to your support requests
- Meet legal obligations that apply to us
We do not sell personal information. We do not use your information, or your customers’ information, for behavioural advertising, and we do not share it with advertising networks.
5. Legal bases for processing
If you are in the European Economic Area or the United Kingdom, we rely on the following general bases, depending on what is being processed and why:
- Performance of a contract — where processing is necessary to give you the Retriq service you signed up for, such as running your account and working your recovery cases.
- Legitimate interests — where processing is necessary to keep the service secure and working, to prevent misuse, and to support and improve it, balanced against your rights.
- Legal obligation — where we are required to process information to comply with a law that applies to us.
- Consent — where we ask for it specifically. You can withdraw consent at any time, which does not affect processing that already happened.
Where a connected business decides why and how its own customers’ information is used, that business is responsible for identifying the basis for that processing.
7. Data retention
We keep personal information for as long as it is reasonably needed for the purposes described in this policy. In practice we judge that against:
- Whether your account and Stripe connection are still active
- Whether the recovery history is still needed for your reporting, for support, or to resolve a dispute
- Security and abuse-prevention needs
- Legal, tax and accounting obligations that apply to us
Two specifics worth stating plainly. Disconnecting Stripe deletes the stored Stripe credentials immediately and cancels scheduled recovery emails, but it does not delete recovery records already created. Retriq does not currently offer a self-service button that deletes an account and all of its data.
If you want your account and its data deleted, email us at privacy@retriq.io and we will action the request and confirm when it is done.
8. Security
We use technical and organisational measures designed to protect information, including:
- Stripe credentials encrypted at rest with authenticated encryption, and never returned to the browser
- Encrypted connections (HTTPS) for traffic to the service
- Database-level access rules that isolate each workspace, so one customer’s data cannot be read from another’s account
- Verification of the signature on every incoming Stripe webhook before it is processed
- Secrets held server-side only, and logging that redacts credentials and masks email addresses
No service can guarantee absolute security. If you believe your account has been compromised, or you have found a security issue in Retriq, please contact us at privacy@retriq.io.
9. International data transfers
Retriq and the service providers listed above operate internationally. Your information, and information about your customers, may be stored or processed in a country other than the one you live in, and the data-protection laws there may differ from your own.
Where a transfer of this kind requires a specific safeguard under applicable law, we take steps to put an appropriate one in place. If you need detail on the safeguards that apply to a particular transfer, contact us at privacy@retriq.io.
10. Your privacy rights
Depending on where you live and the law that applies to you, you may have some or all of the following rights over your personal information:
- Access a copy of the information we hold about you
- Have inaccurate information corrected
- Have information deleted
- Restrict or object to certain processing
- Receive information in a portable format
- Withdraw consent, where our processing is based on consent
- Complain to your local data-protection or privacy authority
These rights are not absolute and some are qualified by law, so there are situations where we may not be able to act on a request in full. If that happens we will explain why.
To make a request, email privacy@retriq.io. We may need to verify who you are before we act, which protects you as much as us.
If your request concerns information that reached Retriq because a business you pay connected its Stripe account, please also contact that business. It controls the Stripe records the information comes from, and in most cases it is the party able to resolve the request fully.
12. Children’s privacy
Retriq is a business service. It is not directed to children and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us at privacy@retriq.io and we will delete it.
13. Changes to this policy
We may update this Privacy Policy as Retriq changes or as the law requires. The current version is always the one published on this page, and the “Last updated” date at the top of the page shows when it last changed. If a change materially affects how we handle your information, we will take reasonable steps to bring it to your attention.
14. Contact us
For any question about this policy, or to make a privacy request, email privacy@retriq.io.
If you are contacting us about information relating to a payment you made to a business that uses Retriq, please tell us the name of that business so we can route your request correctly.