Privacy Policy
Last updated: 5 August 2026
This Privacy Policy explains how Recoop (sole trader Noah Bundy, 16 Leachman Way, Petersfield, Hampshire, GU31 4FL, United Kingdom) collects and uses personal data. For UK GDPR purposes, the data controller for our own business data is Recoop; for the customer data we process on behalf of clients, our client is the controller and Recoop is the processor.
1. Data we collect
- From prospects and clients: business name, website, contact name and email, and information you provide when you sign up and during onboarding.
- On behalf of clients (as processor): limited data about the client's customers necessary to recover failed payments, such as customer name, email, the last four digits and expiry status of a card, invoice and payment status. We never receive or store full card numbers; these remain with the payment provider (e.g. Stripe).
2. How we use it
- To provide, operate, and improve the service (identifying and recovering failed payments; sending recovery communications on a client’s behalf).
- To communicate with clients (onboarding, support, billing, reporting).
- For our own limited B2B marketing to prospective business clients, based on legitimate interest, always with the option to opt out.
3. Legal bases (UK GDPR)
Performance of a contract (providing the service); legitimate interests (operating and marketing our business in a proportionate way); and, where required, consent. For customer data processed on behalf of clients, the legal basis is determined by the client as controller.
4. Data processing on behalf of clients (DPA terms)
Where we process a client's customers' personal data:
- We act only on the client’s documented instructions.
- We apply appropriate technical and organisational security measures.
- We do not use the data for our own purposes.
- We assist the client with requests from data subjects and security obligations.
- We use subprocessors (listed below) under equivalent obligations.
- We delete or return the data on termination.
5. Subprocessors and third parties
We use reputable third party providers to run the service, including:
- Stripe: payments and payment data
- Supabase: database
- Vercel and Railway: hosting
- Resend and Zoho: email
- Anthropic: AI processing of text that isn't sensitive
- Cloudflare: network
6. International transfers
Some providers are based outside the UK (including the US and EU). Where personal data is transferred internationally, we rely on appropriate safeguards such as the providers’ standard contractual clauses / data protection frameworks.
7. Retention
We keep client account data for as long as you are a client and as required for legal/accounting purposes. Customer data processed on behalf of clients is retained only as long as needed for recovery and is deleted or returned on termination.
8. Your rights
Under UK GDPR you have rights to access, rectify, erase, restrict, and object to processing of your personal data, and to data portability. To exercise these, contact noah@joinrecoop.com. You also have the right to complain to the UK Information Commissioner’s Office (ico.org.uk).
9. Cookies
Our website uses only essential cookies needed for the site and secure login to function. We do not use advertising cookies.
10. Contact
Privacy questions or requests: noah@joinrecoop.com.