Skip to content

Legal

Privacy Policy

Version 0.1 draft · Last updated September 7, 2026

Draft pending counsel review.

This policy is a draft for counsel review. It lists the disclosures Rekoup's Privacy Policy will contain beyond a standard policy.

Data collected from merchants

Account and contact data; bank transaction data (date, amount, description, sender name, account mask) for connected accounts via an aggregator; aggregator access tokens; store order data provided through integrations.

Data collected about merchants' customers

Order reference, amount, and the sender name attached by the customer's bank to a payment; nothing else, and never bank credentials.

Aggregator disclosure

Rekoup uses Plaid Inc. to connect merchant bank accounts; the aggregator's handling of data is governed by its End User Privacy Policy.

Retention

Unmatched raw bank data deleted after 90 days; matched payment records retained for the life of the account and as required by law; access tokens deleted on disconnect.

Your rights

Access, correction, deletion at support@rekoup.app within 30 days; no sale of personal information.

Security

Rekoup encrypts data in transit and at rest, encrypts aggregator tokens again at the application layer, isolates every merchant at the database layer, and requires multi-factor authentication on every system. Read the security page for the full summary.

Advertising partners

On our paid landing page, pricing page, and demo video page, and on the app's signup and plan steps, we use the Meta pixel and Conversions API and Google Ads conversion tracking to measure whether our ads work. The events are: a page view, a video play, a fit-check form sent, a signup started, a trial started, and a subscription started, each with a random event id and, for a form or a trial, a hashed email. We never send what you sell, your store address, or any bank data. Visitors in the EU and the UK never get these tags. Anyone can turn them off for their browser with the link below, which we honor immediately.