Last updated: August 8, 2026
Account information you give us: your name, email address, tax ID, and timezone, used to run your account and invoice you.
Your Stripe integration: a publishable key and a restricted API key you provide when connecting your Stripe account. The restricted key and the webhook signing secret are encrypted at rest. We never see or store your card numbers or bank details — those are handled directly by Stripe.
Your customers' information: to retry failed charges and send dunning emails, we store your end customers' name, email address, Stripe customer ID, and the subscription, invoice, and decline-code data needed to run a case.
Webhook event data: we temporarily store the raw Stripe webhook events for each account, including customer name/email/billing address contained in them. This raw payload is cleared 90 days after receipt — we keep only the event type, status, and Stripe event ID for our audit trail after that.
We use it to detect and classify failed charges, schedule and execute retries, send dunning and reminder emails to your customers, and bill your account a commission on the revenue we actually recover.
We share data with:
Raw webhook payloads are cleared after 90 days. Other account and case data is kept for as long as your account is active, so we can maintain an accurate billing and case history. To request deletion of your account and its data, contact us — see below.
Your Stripe restricted key and webhook secret are encrypted at rest. Regainly's Stripe access is read-only for payment and subscription data — we never intercept or hold your funds directly.
Questions about this policy or your data: [email protected].