Legal
Security
Last updated: August 15, 2026
Authentication & Authorization
🔐 Restricted API Key Authentication
PayRetrieve uses Stripe's OAuth Connect for secure, read-only access. We never ask for or store your Stripe secret key (sk_...).
What we CAN access (read-only)
- ✓Customer names & emails
- ✓Invoice amounts & status
- ✓Subscription details
- ✓Payment failure reasons
What we CANNOT access
- ✗Card numbers or payment details
- ✗Bank account information
- ✗Create charges or refunds
- ✗Modify account settings
Trust & Transparency Features
See exactly what PayRetrieve can and cannot access in your Stripe Dashboard. Real-time permission breakdown with detailed explanations.
View every Stripe API call PayRetrieve makes. See timestamps, resources accessed, and operation results in real-time.
One-click disconnect terminates all access instantly. Your Restricted API Key is immediately removed from our database.
Restricted API Keys have explicit, minimal permissions. Damage is limited even if a key is compromised.
All stored credentials are encrypted at rest using industry-standard AES-256 encryption with key rotation.
Data Handling
- Stripe data processing. PayRetrieve processes Stripe data on your behalf using read-only Restricted API Keys with minimal required permissions — never your secret key.
- Webhook configuration. With Restricted API Keys (write permission for Webhook Endpoints), PayRetrieve automatically provisions the webhook needed to capture failed-payment events.
- Database encryption. Your data is stored in Neon Postgres with encryption at rest (AES-256) and in transit (TLS 1.3).
- Data retention. Customer data is retained only as long as needed for service operation. Account deletion triggers automatic data removal within 30 days.
- Tenant isolation. Each customer's data is logically isolated with organization-based access controls.
Compliance & Certifications
- GDPR Compliance. PayRetrieve complies with the General Data Protection Regulation for EU customers.
- Data Processing Agreement (DPA). Available upon request for enterprise customers.
- CCPA Ready. Supports California Consumer Privacy Act requirements.
- SOC 2 Type II (Planned). Working towards SOC 2 Type II certification.
Incident Response
- Security monitoring. 24/7 monitoring for unusual access patterns or security events.
- Vulnerability disclosure. Security researchers can report vulnerabilities to security@payretrieve.online.
- Incident notification. We commit to notifying affected customers within 72 hours of confirming a security incident.
- Regular audits. Third-party security audits conducted annually.
Access Controls
- Multi-factor authentication (MFA). Available for all team accounts.
- Role-based access control. Granular permissions for team members.
- Audit logging. All sensitive actions are logged with timestamps and user identifiers.
- Session management. Automatic session expiration after 24 hours of inactivity.
Infrastructure Security
- Hosting: Vercel (SOC 2 Type II compliant)
- Database: Neon (Postgres, HIPAA-ready infrastructure)
- Email delivery: Resend (SOC 2 Type II compliant)
- SMS delivery: Twilio (SOC 2, PCI DSS Level 1)
- Payment processing: Stripe (PCI DSS Level 1 certified)
Subprocessors
PayRetrieve relies on the following third-party subprocessors to operate the Service:
- Stripe — payments processing
- Vercel — hosting
- Neon — database
- Resend — email delivery
- Twilio — SMS delivery
Data Processing Agreement (DPA)
For details on how we process data on your behalf, see our Data Processing Agreement.
GDPR
If you are located in the European Economic Area, you have rights under the General Data Protection Regulation. You can request deletion of your data at any time by contacting us at support@payretrieve.online.
Transparent, Deterministic Core
PayRetrieve's recovery engine is deterministic and rule-based — retries, sequences and notifications run on the exact schedules and templates you configure. Where optional smart features (like billing-contact discovery or message optimization) use a language model, it is clearly labeled in the product, is off by default, and never controls anything without your approval.