Revised July 2026
This Privacy Policy explains what data PayPigeon (operated at https://paypigeon.io) collects, why, and how it’s handled — both for businesses that use PayPigeon (“Customers”) and for the end customers those businesses invoice (“Recipients”).
From Customers (business accounts):
From Recipients (a Customer’s own customers):
Recipient data is provided to us by our Customers, who are responsible for having a lawful basis to share and contact that data — see our Terms of Service.
We do not sell personal data, and we do not use Recipient data for advertising.
Data is shared with the following processors, solely to operate the Service:
Reminder SMS include opt-out instructions, and opt-out requests are honored immediately and permanently for that phone number. Reminder emails include a functional reply channel; Recipients may also contact the Customer directly to request their data not be used for reminders.
We retain account and invoice data for as long as an account is active, and for a limited period after closure as needed for legal, tax, and dispute-resolution purposes. Customers can request deletion of their business data by contacting us.
Depending on your jurisdiction, you may have rights to access, correct, export, or delete personal data we hold about you, or to object to certain processing. To exercise these rights, contact us at the address below — Recipients should also feel free to contact the business that invoiced them directly.
Data is encrypted in transit (TLS) and at rest. Access to business data is enforced by row-level security scoped to each business’s own members. Inbound webhooks are signature-verified.
We may update this policy from time to time; material changes will be reflected by updating the date above.
Privacy questions or data requests: info@paypigeon.io