Legal
Privacy Policy
Last updated: August 26, 2026
What We Collect
Payment Triage information: the payment-health problem you select, your description of the situation, optional website URL, relevant Stripe-message or deadline context, active-dispute context, business name and type, payment model, work email, and whether you can make or share the business decision.
Commercial-offer information: the founder-selected package, recommendation rationale, scope, exclusions, price snapshot, intended business email, offer status, scope-acceptance confirmations, accepted terms and privacy versions, and related timestamps.
Payment information: Stripe Checkout session identifiers, payment status, paid amount, tax amount where reported, currency, payment-intent identifier where available, and verified Checkout event identifiers. Recovra does not receive or store full card numbers through its own Checkout flow; Stripe processes payment credentials.
Secure-case information: case status, account or merchant binding, access state, findings, plans, implementation or testing state, outcome-learning records, and evidence or files you later choose to provide within the secure case boundary.
Account and security information: email address, account or workspace identifiers, authentication and session records, login timestamps, access events, and limited operational or security logs needed to protect the service.
Connected-provider information: if an existing workspace or an accepted future scope uses a separately authorized Stripe connection, Recovra may process the bounded account, dispute, payment, customer, charge, event, or other provider data permitted for that integration and required for the authorized work.
How We Use It
Triage information is used to understand the request, protect the intake from abuse, contact the merchant, and support founder judgment about fit and the smallest responsible next step. Payment Triage does not automatically diagnose the merchant or select a package.
Commercial information is used to prepare and preserve the exact offer, recommendation rationale, accepted scope, price, legal-version confirmations, checkout state, and payment truth for an engagement.
Case and evidence information is used to perform the accepted Payment Health work, preserve provenance, explain findings, coordinate actions, verify implementation where included, and record bounded outcome learning.
Account and operational data is used for authentication, access control, support, security, reliability, auditability, and communication about the service or case.
We do not sell personal data and do not use merchant case data for third-party advertising or cross-site advertising profiles.
Payment Triage Safety
Payment Triage is a public intake and should contain only the minimum relevant business and Stripe context. Do not submit card numbers, passwords, secret API keys, webhook secrets, authentication cookies, or other credentials through the Triage form.
Recovra applies validation, rate limiting, a honeypot control, and checks for card-shaped numbers and common live-secret formats before durable Triage storage. These controls reduce obvious unsafe submissions but cannot guarantee that every sensitive value will be detected.
If more sensitive evidence is reasonably needed later, Recovra should request it through the appropriate secure case or explicitly authorized channel rather than through the public Triage form.
Evidence and Provenance
Recovra may distinguish Merchant Supplied information, Publicly Observed information, Connected Provider Data, Official Guidance, and Recovra-Generated Artifacts so the origin of evidence remains visible.
Findings may also distinguish direct facts, derived facts, interpretations, hypotheses, and unknown information. Recovra does not claim that missing information or private provider logic is known.
Where files or screenshots are accepted, you should provide only material you are authorized to share and should remove unnecessary credentials, card data, personal data, or unrelated sensitive information before uploading whenever possible.
Existing Connected Workspaces
Some existing Recovra workspaces retain a separate Stripe Connect OAuth or Stripe App permission path built for dispute workflows. Payment Triage and the current founder-led Payment Health entry do not require that connection.
When Stripe Connect OAuth is used, Recovra stores encrypted OAuth tokens and uses only the provider data and writes needed for the authorized connected workflow. The separate Stripe App path uses its named permissions rather than the broad Connect read_write scope.
Recovra does not use those connections to move payouts, transfer funds, issue refunds, change bank details, use customer payment methods, or silently expand a merchant's accepted Payment Health scope.
Data Storage and Retention
Recovra currently uses third-party Railway cloud infrastructure in a United States region for production services and the database. Production backups are encrypted before they are written to backup storage.
Commercial and case records may be retained where needed to preserve the accepted agreement, payment and invoice history, security and audit trails, evidence provenance, claims handling, or other documented legal, contractual, or operational purposes.
Selected mutable personal-data fields in legacy dispute records are anonymized only after the dispute is terminal and the applicable retention conditions are met. Immutable evidence provenance, decision history, submission outcomes, and financial-result records may be preserved where deleting them would weaken integrity or audit protections.
Raw monitoring evaluator runs are kept for 30 days. Expired or consumed one-time authentication capabilities and expired sessions are removed after a 30-day operational grace period; currently valid sessions and capabilities are preserved.
The precise legal classification of retained commercial history and the safeguards applicable to international data transfers require appropriate external legal review. This policy does not claim an unverified blanket statutory category or transfer safeguard.
Data Sharing
We do not sell your data and do not share merchant case data with third parties for their marketing.
Data may be processed by providers used to operate Recovra, such as hosting and database infrastructure, Stripe for payment processing and authorized Stripe integrations, and email or communications providers used for account, security, or service messages.
If you consent to analytics, public website usage data is also processed by Google as the analytics provider described in the Cookies section. Analytics consent does not authorize advertising use of merchant case data.
Recovra may also disclose information where reasonably required to comply with applicable law, enforce rights, protect users or the service, investigate abuse, or respond to a valid legal process.
Your Rights
Depending on applicable law and the relevant record, you may request access to personal data, correction of inaccurate personal data, deletion, restriction, objection, or other available data-protection rights.
A deletion request may not require Recovra to erase records that must or may legitimately be retained for legal, contractual, security, claims, fraud-prevention, payment, audit, or integrity purposes. Where deletion is not appropriate, Recovra should explain the applicable boundary when responding to the request.
You can revoke a separately authorized Stripe connection from Stripe. Revocation stops future access through that connection but does not automatically erase records already retained for a legitimate purpose.
Contact support@recovra.de for privacy or data requests.
Cookies
We use essential cookies or equivalent browser storage for authentication, session management, security, and other functions required to operate the service. These functions are not used for advertising.
With your consent, we also use Google Analytics, provided by Google Ireland Limited, to understand how visitors use the public website. Analytics may process information such as pages viewed, referrer, device or browser information, and approximate location derived from network information.
Analytics cookies are set only after you accept them in the cookie banner. If you decline, analytics cookies are not intentionally set by Recovra's consent-controlled analytics path. You can revisit your choice through the Cookie preferences control in the public footer.
We do not use advertising, remarketing, or cross-site behavioral advertising cookies.
Changes
We may update this policy as Recovra evolves. A paid commercial offer records the privacy-policy version accepted for that offer. Material changes affecting an active account or engagement may be communicated by email, workspace notice, or another appropriate channel.
Questions about data handling? Help center →