Privacy Policy
The short version
We store the minimum data needed to operate Revenue Leak Radar:
- Your email + Clerk auth identifiers (so you can log in).
- Encrypted OAuth tokens for the billing tools you connect.
- Scan results we surface back to you.
- An audit log of recovery actions we attempted on your behalf.
We don't sell your data. We don't share it with third parties beyond the named subprocessors below. You can ask us to delete everything at any time.
1. What we collect
From Clerk (auth): your email address, your name if you provided it to Clerk, and an opaque user ID. We do not store your password.
From integrations you connect: when you grant RLR access via OAuth, we store the access & refresh tokens encrypted at rest using per-record AES-256-GCM. The billing data we read (charges, invoices, subscriptions, customers) is kept only as long as needed to compute and store findings.
From your usage: server logs (IP, user agent, request paths) for debugging and abuse prevention, retained for 30 days.
2. What we don't collect
We don't access cardholder data — Stripe Connect's read-only scope doesn't expose it and we don't ask for it. We don't use trackers, ad pixels, or session recording. We don't use your data to train AI models.
3. How we use it
- To run scans on the integrations you connect and surface findings.
- To execute recovery actions you authorize, with attempt logging.
- To send transactional email (weekly digest, action confirmations).
- To debug, prevent abuse, and improve the service.
4. Subprocessors
We rely on the following services to operate RLR:
- Neon — Postgres hosting (US East).
- Vercel — application hosting + edge.
- Clerk — authentication.
- Inngest — background job orchestration.
- Resend — transactional email delivery.
- Stripe — billing-data integration provider (read access only).
We'll update this list when subprocessors change. Each subprocessor has its own privacy policy governing the data they process for us.
5. Retention
Active accounts: data is retained for the lifetime of the account. Free-audit organizations (no signup) are garbage-collected after 30 days. After account deletion, we purge personal data within 30 days; we may retain aggregated, de-identified statistics indefinitely.
6. Your rights
You can request a copy of your data, correction of inaccuracies, or full deletion by emailing the address below. We respond within 30 days. If you're in the EU/UK we honor GDPR rights; if in California, CCPA rights.
7. Security
Specifics — including tenant isolation, at-rest encryption, and the safety backstop on recovery actions — are documented on /trust and enforced by code & tests in our repository. No system is impenetrable; if you find a vulnerability, please email the address below.
8. Changes
We'll update the "last updated" date when this policy changes. Material changes will be announced in-app or by email at least 14 days before they take effect.
9. Contact
Privacy questions, data requests, or security disclosures: support@revenueleakradar.com.