Legal
Privacy Policy
Last updated: August 2, 2026
1. Introduction
This Privacy Policy explains how RecoverFlow ("we," "us," or "our") collects, uses, shares, and protects information when you use our website and Service. We are committed to protecting your privacy and processing your personal data in accordance with applicable laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
2. Information We Collect
- Account information: your name, email address, password (stored securely as a hash), and billing details when you create an account or make a purchase.
- Connection credentials: API keys and tokens for third-party services you connect (Stripe, Twilio, Resend, WhatsApp). These are encrypted at rest and used only to operate the Service.
- Customer data: information about your customers (such as email addresses, phone numbers, and payment status) that you provide or that the Service processes on your behalf to deliver recovery messages.
- Usage data: pages visited, features used, and technical information such as IP address, browser type, and device information.
3. How We Use Information
We use the information we collect to:
- Provide, operate, and maintain the Service;
- Process payments and manage your account;
- Send recovery notifications to your customers as you direct;
- Improve, personalize, and secure the Service;
- Communicate with you about updates, support, and important notices; and
- Comply with legal obligations.
4. Legal Bases for Processing
We process personal data based on your consent (where you provide it), the performance of a contract with you, our legitimate business interests, and compliance with legal obligations. Where we process data on your behalf as a data processor (for example, your customers' contact details), you act as the data controller and are responsible for the lawfulness of that processing.
5. Sharing and Disclosure
We do not sell your personal information. We share information only as needed to provide the Service, including with:
- Payment providers (Paddle): to process transactions and handle billing;
- Infrastructure providers (Vercel, Neon): to host the Service and store data;
- Messaging providers (Twilio, Resend, WhatsApp): to deliver recovery messages;
- Stripe: to create recovery links and manage payment updates you request.
We may also disclose information where required by law, or to protect the rights, property, or safety of our users or the public.
6. Data Security
We implement appropriate technical and organizational measures to protect your data, including encryption of sensitive credentials (AES-256-GCM) at rest, encryption in transit (TLS), verification of incoming webhook signatures, and restricted access to production systems. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Data Retention
We retain account information for as long as your account is active and for a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce our agreements. Customer data processed on your behalf is retained as needed to provide the Service or as you direct. You may request deletion of your data at any time.
8. Cookies and Tracking
We use cookies and similar technologies to keep you logged in, remember preferences, and understand how the Service is used. You can control cookies through your browser settings. We currently do not respond to "do not track" signals.
9. Your Rights
Depending on your location, you may have the right to:
- Access, correct, or delete your personal information;
- Restrict or object to certain processing;
- Receive a copy of your data in a portable format; and
- Withdraw consent at any time where processing is based on consent.
To exercise these rights, contact us at support@hackiom.xyz. We will respond within the timeframe required by applicable law.
10. International Transfers
Your information may be transferred to and processed in countries other than your own, including through our hosting and service providers. We rely on appropriate safeguards, such as standard contractual clauses, to protect transferred data.
11. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will post any changes on this page and update the "Last updated" date. Material changes will be communicated to you through the Service or by email where appropriate.
13. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, contact us at support@hackiom.xyz.