← Back to PayPigeon

Privacy Policy

Revised July 2026

This Privacy Policy explains what data PayPigeon (operated at https://paypigeon.io) collects, why, and how it’s handled — both for businesses that use PayPigeon (“Customers”) and for the end customers those businesses invoice (“Recipients”).

1. Data we collect

From Customers (business accounts):

  • Account info: name, email, business name, phone, country, timezone.
  • Billing info: handled directly by Stripe — we store a Stripe customer/subscription ID, not card numbers.
  • Content you upload or forward: invoices, customer lists, message template edits.
  • Usage data: login events, feature usage, and support communications.

From Recipients (a Customer’s own customers):

  • Contact details a Customer provides about them: name, email, phone.
  • Invoice and payment details relevant to reminders sent to them.
  • Delivery and engagement metadata for messages (sent/delivered/opened/replied), and any reply content they send back.

Recipient data is provided to us by our Customers, who are responsible for having a lawful basis to share and contact that data — see our Terms of Service.

2. How we use data

  • To operate the Service: scheduling and sending reminders, processing payments, and rendering the dashboard.
  • To detect and prevent abuse, fraud, and violations of our Terms.
  • To communicate with Customers about their account, billing, and support requests.
  • To improve the Service (aggregated/anonymized usage analysis only — never sold).

We do not sell personal data, and we do not use Recipient data for advertising.

3. Sub-processors we use

Data is shared with the following processors, solely to operate the Service:

  • Supabase — database, authentication.
  • Stripe — subscription billing and, where enabled, invoice payment processing.
  • Telnyx — SMS delivery.
  • Resend — transactional and reminder email delivery.
  • Anthropic (Claude API) — extracting invoice fields from forwarded emails, photos, or PDFs a Customer submits.
  • Vercel — application hosting.

4. SMS & email consent

Reminder SMS include opt-out instructions, and opt-out requests are honored immediately and permanently for that phone number. Reminder emails include a functional reply channel; Recipients may also contact the Customer directly to request their data not be used for reminders.

5. Data retention

We retain account and invoice data for as long as an account is active, and for a limited period after closure as needed for legal, tax, and dispute-resolution purposes. Customers can request deletion of their business data by contacting us.

6. Your rights

Depending on your jurisdiction, you may have rights to access, correct, export, or delete personal data we hold about you, or to object to certain processing. To exercise these rights, contact us at the address below — Recipients should also feel free to contact the business that invoiced them directly.

7. Security

Data is encrypted in transit (TLS) and at rest. Access to business data is enforced by row-level security scoped to each business’s own members. Inbound webhooks are signature-verified.

8. Changes to this policy

We may update this policy from time to time; material changes will be reflected by updating the date above.

9. Contact

Privacy questions or data requests: info@paypigeon.io

Privacy Policy — PayPigeon