Legal
Privacy Policy
Last updated September 2026
SimpleRecover processes the minimum data needed to recover a failed payment, and nothing else. This page explains exactly what that means.
Who we are
SimpleRecover is operated by Runivox LTD (Runivox Labs), registered at 20 Wenlock Road, London N1 7GU, United Kingdom. We are the controller of your account data and a processor of the customer data we handle on your behalf. Reach us at accounts@runivoxlabs.com.
What we collect from you
Your email address, your name, your product name and sender details, and the Stripe account identifier you connect. Billing for your own subscription is handled by Stripe; we store only the customer and subscription identifiers they return.
What we process about your customers
When one of your subscription invoices fails, Stripe sends us the invoice id, the customer id, the customer's name and email address, the amount and the currency. We store that record so we can email the customer and retry the invoice.
- We never receive, see or store card numbers. Those go directly to Stripe.
- We never access your Stripe balance, payouts or transfers.
- We do not sell, share or enrich customer data, and we run no ad tracking.
Security
Stripe access tokens and restricted keys are encrypted with AES-256-GCM before they reach the database. Card-update links are 192-bit random tokens, scoped to a single invoice, and expire after seven days. All traffic is TLS-encrypted, and row-level security isolates each account's data in Postgres.
Sub-processors
- Stripe: payment processing and connected-account access
- Supabase: database, authentication and hosting of your account data
- Resend: transactional email delivery
- Upstash QStash: delayed job scheduling (message payloads carry only record ids)
- Vercel: application hosting
Retention and deletion
Dunning records are kept while your account is open so your recovery history stays accurate. Disconnecting Stripe stops all processing immediately. Email accounts@runivoxlabs.com and we will delete your account and every associated record within 30 days.
Your rights
You can request access, correction, export or deletion of your data at any time. If you are subject to GDPR or CCPA, we act as a processor for your customer data and as a controller for your own account data.
This document is a starting template written for a solo-founder SaaS. Have a lawyer review it against your jurisdiction, your data-processing agreements and your actual practices before you rely on it.