Privacy Policy
Last updated: September 12, 2026
This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.
We use Your Personal Data to provide and improve the Service. We collect, use, and disclose Your information as described in this Privacy Policy and, where required by applicable law, only where We have a valid legal basis to do so, including Your consent (where consent is required). This Privacy Policy has been created with the help of the TermsFeed Privacy Policy Generator.
Interpretation and Definitions
Interpretation
The words whose initial letters are capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
Definitions
For the purposes of this Privacy Policy:
- Account means a unique account created for You to access Our Service or parts of Our Service.
- Affiliate means an entity that controls, is controlled by, or is under common control with a party, where "control" means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.
- Application refers to Recoup Hero, the software program provided by the Company.
- Business, for the purpose of CCPA/CPRA, refers to the Company as the legal entity that collects Consumers' personal information and determines the purposes and means of the processing of Consumers' personal information.
- CCPA and/or CPRA refers to the California Consumer Privacy Act (the "CCPA") as amended by the California Privacy Rights Act of 2020 (the "CPRA").
- Company (referred to as either "the Company", "We", "Us" or "Our" in this Privacy Policy) refers to Recoup Hero, Inc., Los Angeles, CA. For the purpose of the GDPR, the Company is the Data Controller.
- Connected Account means any third-party account You link to the Service, including Your Amazon account and any bank or credit card account linked through Plaid.
- Consumer, for the purpose of the CCPA/CPRA, means a natural person who is a California resident.
- Cookies are small files that are placed on Your computer, mobile device or any other device by a website, containing the details of Your browsing history on that website, among its many uses.
- Country/State refers to: California, United States.
- Data Controller, for the purposes of the GDPR, refers to the Company as the legal person which alone or jointly with others determines the purposes and means of the processing of Personal Data.
- Device means any device that can access the Service, such as a computer, a cell phone or a digital tablet.
- Do Not Track (DNT) is a concept that has been promoted by US regulatory authorities for the Internet industry to develop and implement a mechanism for allowing internet users to control the tracking of their online activities across websites.
- GDPR refers to the EU General Data Protection Regulation.
- Personal Data (or "Personal Information") is any information that relates to an identified or identifiable individual. We use "Personal Data" and "Personal Information" interchangeably unless a law uses a specific term.
- Sale, for the purpose of the CCPA/CPRA, means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Consumer's personal information to a third party for monetary or other valuable consideration.
- Service refers to the Application or the Website or both.
- Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used. For the purpose of the GDPR, Service Providers are considered Data Processors.
- Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
- Website refers to Recoup Hero, accessible from https://recouphero.com.
- You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable. Under GDPR, You can be referred to as the Data Subject or as the User as You are the individual using the Service.
Collecting and Using Your Personal Data
Types of Data Collected
Account data
While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. This may include:
- Email address
- First name and last name
- Password (stored only as a salted hash by Our authentication provider)
- If You sign in with Google: Your Google account email address, name and profile picture
- If You request access during an invite-only period: the use case and feature interests You tell Us about
Amazon account data
To read Your order history We sign in to Your Amazon account on Your behalf using an isolated, per-user connection. For this We collect and process:
- Amazon sign-in credentials. Your Amazon email and password, and any one-time verification code You enter. Your password is encrypted with AES-256-GCM before it is stored and is used only to re-establish Your Amazon session when it expires. Verification codes are used once and are not retained. You can remove Your stored credentials at any time by disconnecting Your Amazon account.
- Order history. Orders, items, prices, shipping and delivery status, payment method descriptors (for example the last four digits of a card), returns, refunds, and related order details.
- Gift card and registry activity, where You enable those features.
- Amazon data exports that You choose to upload to Us manually.
Financial account data (Plaid)
When You link a bank or credit card account, You do so through Plaid. Plaid collects Your online banking credentials directly; We never see or store them. From Plaid We receive and store:
- Institution name and account name, type and masked account number (last four digits)
- Transactions: date, amount, merchant/description, pending status and category
- An encrypted access token that lets Us refresh transactions until You unlink the account
Plaid's use of Your information is governed by the Plaid End User Privacy Policy. You may also upload transaction exports (CSV files) instead of, or in addition to, linking through Plaid.
Payment data
If You purchase a Subscription, payment is processed by Stripe. Stripe collects Your card details and billing address directly. We receive and store Your Stripe customer id, subscription status, plan and billing period, and the card brand and last four digits. We do not store Your full card number.
Usage Data
Usage Data is collected automatically when using the Service.
Usage Data may include information such as Your Device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of Our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.
When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device's unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.
We may also collect information that Your browser sends whenever You visit Our Service or when You access the Service by or through a mobile device.
Communications
When You contact Us (for example by email), We keep the correspondence so We can respond and improve support.
Tracking Technologies and Cookies
We use tracking technologies (such as cookies and browser storage) to keep You signed in, remember Your preferences and to understand how the Service is used. The technologies We use may include:
- Cookies or Browser Cookies. A cookie is a small file placed on Your Device. You can instruct Your browser to refuse all Cookies or to indicate when a Cookie is being sent. However, if You do not accept Cookies, You may not be able to use some parts of Our Service.
- Local storage. We use Your browser's local storage to hold Your authentication session and interface preferences (such as theme).
- Web Beacons. Certain sections of Our Service and Our emails may contain small electronic files known as web beacons that permit the Company, for example, to count users who have visited those pages or opened an email and for other related statistics.
Cookies can be "Persistent" or "Session" Cookies. Persistent Cookies remain on Your personal computer or mobile device when You go offline, while Session Cookies are deleted as soon as You close Your web browser.
Where required by law, We use non-essential cookies (that is, Cookies other than the Necessary / Essential Cookies described below) only with Your consent. You can withdraw or change Your consent at any time through Your browser/device settings. Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.
We use both Session and Persistent Cookies for the purposes set out below:
- Necessary / Essential Cookies. Type: Session Cookies. Administered by: Us. Purpose: These Cookies are essential to provide You with services available through the Website and to enable You to use some of its features. They help to authenticate users and prevent fraudulent use of user accounts. Without these Cookies, the services that You have asked for cannot be provided, and We only use these Cookies to provide You with those services.
- Functionality Cookies. Type: Persistent Cookies. Administered by: Us. Purpose: These Cookies allow Us to remember choices You make when You use the Website, such as remembering Your login details or theme preference. The purpose of these Cookies is to provide You with a more personal experience and to avoid You having to re-enter Your preferences every time You use the Website.
- Tracking and Performance Cookies. Type: Persistent Cookies. Administered by: Third-Parties. Purpose: These Cookies are used to track information about traffic to the Website and how users use the Website. The information gathered via these Cookies may directly or indirectly identify You as an individual visitor. This is because the information collected is typically linked to a pseudonymous identifier associated with the device You use to access the Website. We may also use these Cookies to test new pages, features or new functionality of the Website to see how Our users react to them.
Use of Your Personal Data
The Company may use Personal Data for the following purposes:
- To provide and maintain Our Service, including to retrieve Your Amazon orders and financial transactions, match them against each other, and surface missing refunds, discrepancies and return deadlines to You.
- To manage Your Account: to manage Your registration as a user of the Service. The Personal Data You provide can give You access to different functionalities of the Service that are available to You as a registered user.
- For the performance of a contract: the development, compliance and undertaking of the purchase contract for the Subscription You have purchased or of any other contract with Us through the Service.
- To contact You: to contact You by email or other equivalent forms of electronic communication regarding updates or informative communications related to the functionalities, products or contracted services, including security updates, sync results, return-deadline reminders and detected discrepancies, when necessary or reasonable for their implementation.
- To provide You with news, special offers and general information about other goods, services and events which We offer that are similar to those that You have already purchased or enquired about. We send such marketing communications only where permitted by applicable law: where prior consent is required (for example, under the laws applicable in the EEA and the UK), We will send them only with Your consent; otherwise, We may send them until You opt out. You may opt out or withdraw Your consent at any time by using the unsubscribe link in any marketing email We send or by contacting Us.
- To manage Your requests: to attend and manage Your requests to Us.
- To keep the Service secure: to detect, prevent and investigate fraud, abuse and security incidents, and to debug errors.
- For business transfers: We may use Your Personal Data to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Data held by Us about Our Service users is among the assets transferred.
- For other purposes: We may use Your information for other purposes, such as data analysis, identifying usage trends, determining the effectiveness of Our promotional campaigns, and evaluating and improving Our Service, products, services, marketing and Your experience.
We do not use Your Amazon or financial account data for advertising, and We do not sell it. We do not use Your Personal Data to train AI models.
We may share Your Personal Data in the following situations:
- With Service Providers: We may share Your Personal Data with Service Providers to operate the Service, process payments, monitor and analyze the use of Our Service, and to contact You. The Service Providers We use are listed below.
- For business transfers: We may share or transfer Your Personal Data in connection with, or during negotiations of, any merger, sale of Company assets, financing, or acquisition of all or a portion of Our business to another company.
- With Affiliates: We may share Your Personal Data with Our affiliates, in which case We will require those affiliates to honor this Privacy Policy.
- With Your consent: We may disclose Your Personal Data for any other purpose with Your consent.
Categories of Service Providers
We rely on a small number of third-party companies to provide the Service. Each acts as a Service Provider (Data Processor) on Our behalf and is bound by contractual obligations to protect Your data and to use it only to provide its service to Us. The categories are:
| Provider | Purpose | Data involved |
|---|---|---|
| Cloud hosting, database and authentication providers | Storing Your Account and Service data and running the Application | Account data, Amazon order data, transaction data, uploaded files |
| Plaid | Linking bank and credit card accounts and retrieving transactions | Financial institution login (handled by Plaid only), account and transaction data |
| Secure account-connection provider | Isolated, per-user connections used to sign in to Amazon on Your behalf | Amazon session and Your Amazon order history |
| AI processing provider | Extracting structured order details from Your Amazon order information | Text of Your Amazon order information (never credentials or bank data) |
| Google (Sign in with Google) | Optional single sign-on | Google account email, name and profile picture |
| Stripe | Subscription billing | Payment method, billing details, subscription status |
| Product analytics and error-monitoring providers | Understanding how the Service is used and fixing errors | Usage Data, technical error reports and a pseudonymous user id |
| Email delivery provider | Sending transactional email | Email address and the contents of notification emails |
Analytics
We use a third-party product analytics service to monitor and analyze the use of Our Service, including Website traffic, feature usage and, for some sessions, session replays. Analytics events are keyed to a pseudonymous user id, not Your name or email. Session replays mask all form inputs and any text that looks like a currency amount, an email address, an account or order number, or a name, and never record credential forms. You can opt out of analytics tracking by enabling Do Not Track or Global Privacy Control in Your browser, or by contacting Us.
Error monitoring
We use a third-party error-monitoring service to capture application errors so We can fix them. Error reports include technical details about the error, Your browser and Device, and Your pseudonymous user id. The service is configured not to collect personally identifiable information by default.
AI-assisted processing
To turn Your Amazon order information into structured order records, We send the order text to a third-party AI processing provider. Only order content is sent; Your Amazon credentials, bank credentials and financial transactions are never sent to an AI provider. The provider processes this content as Our Service Provider under terms that prohibit using it to train its models.
Payments
We use Stripe for payment processing (e.g. payment processors). We will not store or collect Your payment card details. That information is provided directly to Stripe, whose use of Your personal information is governed by its Privacy Policy. Stripe adheres to the standards set by PCI-DSS as managed by the PCI Security Standards Council. See the Stripe Privacy Policy.
We use a third-party email delivery service to send transactional emails such as sync results, discrepancy alerts, return-deadline reminders and account notices. You can control which notifications You receive in Your Account settings. Marketing emails, if any, always include an unsubscribe link.
Retention of Your Personal Data
The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use Your Personal Data to the extent necessary to comply with Our legal obligations (for example, if We are required to retain Your data to comply with applicable laws), resolve disputes, and enforce Our legal agreements and policies.
Where possible, We apply shorter retention periods and/or reduce identifiability by deleting, aggregating, or anonymizing data. Unless otherwise stated, the retention periods below are maximum periods ("up to") and We may delete or anonymize data sooner when it is no longer needed for the relevant purpose:
- Account, Amazon order and financial transaction data: for as long as Your Account exists. When You delete Your Account it is removed from Our production systems promptly, and from encrypted backups within Our backup rotation period (up to 30 days).
- Amazon credentials and Plaid access tokens: until You disconnect the Connected Account or delete Your Account, at which point they are deleted and, for Plaid, the access token is revoked with Plaid.
- Uploaded files (CSV exports): until You delete them or delete Your Account.
- Billing records: up to 7 years after the transaction, as required by tax and accounting law.
- Support correspondence: up to 24 months from the date the matter is closed.
- Usage Data, analytics and error reports: up to 24 months from collection.
- Server logs (IP addresses, access times): up to 12 months for security monitoring and troubleshooting.
We may retain Personal Data beyond the periods stated above where We are required by law to retain specific data, where data is necessary to establish, exercise, or defend legal claims, where You ask Us to retain specific information, or where data exists in backup systems that are scheduled for routine deletion. When retention periods expire, We securely delete or anonymize Personal Data.
Transfer of Your Personal Data
Your information, including Personal Data, is processed at the Company's operating offices and in any other places where the parties involved in the processing are located. Our infrastructure and Service Providers are primarily located in the United States. This means that this information may be transferred to — and maintained on — computers located outside of Your state, province, country or other governmental jurisdiction where the data protection laws may differ from those of Your jurisdiction.
Where required by applicable law, We will ensure that international transfers of Your Personal Data are subject to appropriate safeguards, such as the European Commission's Standard Contractual Clauses, and, where relevant, supplementary measures. The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy and no transfer of Your Personal Data will take place to an organization or a country unless there are adequate controls in place, including the security of Your data and other personal information.
Delete Your Personal Data
You have the right to delete or request that We assist in deleting the Personal Data that We have collected about You.
You can delete Your Account, including all Connected Accounts and the data retrieved from them, at any time from the Settings section of the Service ("Delete account"). Doing so revokes Our access with Plaid, deletes Your Amazon credentials and connection data, deletes Your uploaded files, and deletes Your Account. You can also disconnect an individual Connected Account, or delete individual uploaded files, without deleting Your Account.
You may also contact Us to request access to, correct, or delete any Personal Data that You have provided to Us. Please note, however, that We may need to retain certain information when We have a legal obligation or lawful basis to do so.
Disclosure of Your Personal Data
Business Transactions
If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.
Law Enforcement
Under certain circumstances, the Company may disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).
Other Legal Requirements
The Company may disclose Your Personal Data in the good-faith belief that such action is necessary to:
- Comply with a legal obligation
- Protect and defend the rights or property of the Company
- Prevent or investigate possible wrongdoing in connection with the Service
- Protect the personal safety of Users of the Service or the public
- Protect against legal liability
Security of Your Personal Data
The security of Your Personal Data is important to Us. Amazon credentials and Plaid access tokens are encrypted at rest with AES-256-GCM, all data is encrypted in transit with TLS, and access to Your data is restricted so that only You (and authorized Company systems) can read it. We never receive Your online banking credentials or full card numbers. Our Data Security page describes these measures in more detail.
Remember, however, that no method of transmission over the Internet, or method of electronic storage, is 100% secure. While We strive to use commercially reasonable means to protect Your Personal Data, We cannot guarantee its absolute security.
GDPR Privacy
Legal Basis for Processing Personal Data under GDPR
We may process Personal Data under the following conditions:
- Consent: You have given Your consent for processing Personal Data for one or more specific purposes, for example when You connect Your Amazon account or link a financial account.
- Performance of a contract: provision of Personal Data is necessary for the performance of an agreement with You and/or for any pre-contractual obligations thereof.
- Legal obligations: processing Personal Data is necessary for compliance with a legal obligation to which the Company is subject.
- Vital interests: processing Personal Data is necessary in order to protect Your vital interests or of another natural person.
- Public interests: processing Personal Data is related to a task that is carried out in the public interest or in the exercise of official authority vested in the Company.
- Legitimate interests: processing Personal Data is necessary for the purposes of the legitimate interests pursued by the Company, such as securing and improving the Service.
In any case, the Company will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.
Your Rights under the GDPR
The Company undertakes to respect the confidentiality of Your Personal Data and to guarantee You can exercise Your rights. You have the right under this Privacy Policy, and by law if You are within the EU, to:
- Request access to Your Personal Data. The right to access, update or delete the information We have on You. Whenever made possible, You can access, update or request deletion of Your Personal Data directly within Your Account settings section.
- Request correction of the Personal Data that We hold about You. You have the right to have any incomplete or inaccurate information We hold about You corrected.
- Object to processing of Your Personal Data. This right exists where We are relying on a legitimate interest as the legal basis for Our processing and there is something about Your particular situation which makes You want to object to Our processing of Your Personal Data on this ground. You also have the right to object where We are processing Your Personal Data for direct marketing purposes.
- Request erasure of Your Personal Data. You have the right to ask Us to delete or remove Personal Data when there is no good reason for Us to continue processing it.
- Request the transfer of Your Personal Data. We will provide to You, or to a third party You have chosen, Your Personal Data in a structured, commonly used, machine-readable format.
- Withdraw Your consent. You have the right to withdraw Your consent on using Your Personal Data. If You withdraw Your consent, We may not be able to provide You with access to certain specific functionalities of the Service.
Exercising of Your GDPR Data Protection Rights
You may exercise Your rights of access, rectification, cancellation and opposition by contacting Us. Please note that We may ask You to verify Your identity before responding to such requests. If You make a request, We will try our best to respond to You as soon as possible, and in any event within one month.
You have the right to complain to a Data Protection Authority about Our collection and use of Your Personal Data. For more information, if You are in the European Economic Area (EEA), please contact Your local data protection authority in the EEA.
CCPA/CPRA Privacy Notice for California Residents
This privacy notice section for California residents supplements the information contained in Our Privacy Policy and it applies solely to all visitors, users, and others who reside in the State of California.
Categories of Personal Information Collected
We collect information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Consumer or Device. The following is a list of categories of personal information which We may collect or may have been collected from California residents within the last twelve (12) months. Please note that the categories and examples provided in the list below are those defined in the CCPA/CPRA. This does not mean that all examples of that category of personal information were in fact collected by Us, but reflects Our good faith belief to the best of Our knowledge that some of that information from the applicable category may be and may have been collected.
- Category A: Identifiers. Examples: a real name, alias, unique personal identifier, online identifier, Internet Protocol address, email address, account name. Collected: Yes.
- Category B: Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)). Examples: a name, address, telephone number, credit card number, debit card number, or any other financial information. Collected: Yes (name, email, masked card/account numbers, and transaction history).
- Category C: Protected classification characteristics under California or federal law. Collected: No.
- Category D: Commercial information. Examples: records of products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies. Collected: Yes (Your Amazon order history and financial transactions, at Your direction).
- Category E: Biometric information. Collected: No.
- Category F: Internet or other similar network activity. Examples: interaction with Our Service. Collected: Yes.
- Category G: Geolocation data. Collected: No (other than coarse location inferred from IP address).
- Category H: Sensory data. Collected: No.
- Category I: Professional or employment-related information. Collected: No.
- Category J: Non-public education information. Collected: No.
- Category K: Inferences drawn from other personal information. Examples: profile reflecting a person's preferences or characteristics. Collected: Yes (limited to product-usage inferences such as plan tier and feature adoption).
- Category L: Sensitive personal information. Examples: account log-in and financial account credentials. Collected: Yes (Amazon sign-in credentials, stored encrypted, and financial account information obtained through Plaid). We use sensitive personal information only to provide the Service You requested and do not use it to infer characteristics about You.
Under CCPA/CPRA, personal information does not include:
- Publicly available information from government records
- Deidentified or aggregated consumer information
- Information excluded from the CCPA/CPRA's scope, such as health or medical information covered by HIPAA and the California Confidentiality of Medical Information Act, and personal information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FCRA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA), and the Driver's Privacy Protection Act of 1994
Sources of Personal Information
We obtain the categories of personal information listed above from the following sources:
- Directly from You. For example, from the forms You complete on Our Service, the credentials You provide, and the files You upload.
- Indirectly from You. For example, from observing Your activity on Our Service.
- Automatically from You. For example, through cookies We or Our Service Providers set on Your Device as You navigate through Our Service.
- From Service Providers and Connected Accounts. For example, order data from Your Amazon account, transaction data from Plaid, billing status from Stripe, and profile data from Google if You sign in with Google.
Use of Personal Information
We may use or disclose personal information We collect for "business purposes" or "commercial purposes" (as defined under the CCPA/CPRA), which may include the purposes described in "Use of Your Personal Data" above, including to provide the Service, to secure it, to respond to Your requests, to process payments, to send notifications, for testing, research and improvement, and as described to You when collecting Your personal information or as otherwise set forth in the CCPA/CPRA.
Disclosure of Personal Information for a Business Purpose
We may use or disclose and may have used or disclosed in the last twelve (12) months the categories of personal information listed above for business or commercial purposes, to the Service Providers listed above. When We disclose personal information for a business purpose, We enter a contract that describes the purpose and requires the recipient to both keep that personal information confidential and not use it for any purpose except performing the contract.
Sale and Sharing of Personal Information
We do not sell Your personal information, and We do not share it for cross-context behavioral advertising. We have not sold or shared personal information of California residents in the preceding twelve (12) months, and We do not sell or share the personal information of Consumers We actually know are less than 16 years of age.
Your Rights under the CCPA/CPRA
The CCPA/CPRA provides California residents with specific rights regarding their personal information. If You are a resident of California, You have the following rights:
- The right to notice. You have the right to be notified which categories of Personal Data are being collected and the purposes for which the Personal Data is being used.
- The right to know/access. You have the right to request that We disclose to You the categories of personal information We collected, the categories of sources, the business or commercial purpose, the categories of third parties with whom We share personal information, and the specific pieces of personal information We collected about You.
- The right to say no to the sale or sharing of Personal Data (opt-out). We do not sell or share personal information, so this right is honored by default. We also treat Global Privacy Control (GPC) signals as a valid opt-out request.
- The right to correct Personal Data. You have the right to correct or rectify any inaccurate personal information about You that We collected.
- The right to limit use and disclosure of sensitive Personal Data. We use sensitive personal information only as necessary to provide the Service You requested.
- The right to delete Personal Data. You have the right to request the deletion of Your Personal Data under certain circumstances, subject to certain exceptions. Once We receive and confirm Your request, We will delete (and direct Our Service Providers to delete) Your personal information from Our records, unless an exception applies. We may deny Your deletion request if retaining the information is necessary for Us or Our Service Providers to complete the transaction for which We collected the personal information, detect security incidents or protect against malicious, deceptive, fraudulent, or illegal activity, debug products, exercise free speech, comply with the California Electronic Communications Privacy Act, enable solely internal uses reasonably aligned with consumer expectations, comply with a legal obligation, or make other internal and lawful uses of that information compatible with the context in which You provided it.
- The right not to be discriminated against. You have the right not to be discriminated against for exercising any of Your consumer's rights, including by denying goods or services, charging different prices or rates, providing a different level or quality of goods or services, or suggesting that You will receive a different price or level of service.
Exercising Your CCPA/CPRA Data Protection Rights
To exercise any of Your rights under the CCPA/CPRA, and if You are a California resident, You can contact Us by email at support@recouphero.com or by using the account controls in the Service. Only You, or a person registered with the California Secretary of State that You authorize to act on Your behalf, may make a verifiable request related to Your personal information. Your request to Us must provide sufficient information that allows Us to reasonably verify You are the person about whom We collected personal information or an authorized representative, and describe Your request with sufficient detail that allows Us to properly understand, evaluate, and respond to it.
We cannot respond to Your request or provide You with the required information if We cannot verify Your identity or authority to make the request and confirm that the personal information relates to You. We will disclose and deliver the required information free of charge within 45 days of receiving Your verifiable request. The time period to provide the required information may be extended once by an additional 45 days when reasonably necessary and with prior notice.
"Do Not Track" Policy as Required by California Online Privacy Protection Act (CalOPPA)
Our Service honors Do Not Track ("DNT") and Global Privacy Control ("GPC") signals. Do Not Track is a preference You can set in Your web browser to inform websites that You do not want to be tracked. When We detect a DNT or GPC signal, We disable non-essential analytics for that browser. You can enable or disable these signals by visiting the Preferences or Settings page of Your web browser.
Children's Privacy
The Service is not directed to, and We do not knowingly collect Personal Information from, anyone under the age of 18. If You are a parent or guardian and You believe Your child has provided Us with Personal Information, please contact Us. If We become aware that We have collected Personal Information from anyone under the age of 18, We will take steps to remove that information from Our servers as soon as reasonably possible.
Some countries and states set a higher age at which an individual can consent to the processing of their own Personal Information. Where We rely on consent as a legal basis and the law applicable to a User sets a higher age, We may require the consent of that User's parent or guardian before We collect and use their Personal Information.
Links to Other Websites
Our Service may contain links to other websites that are not operated by Us. If You click on a third-party link, You will be directed to that third party's site. We strongly advise You to review the Privacy Policy of every site You visit.
We have no control over and assume no responsibility for the content, privacy policies or practices of any third-party sites or services.
Changes to this Privacy Policy
We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page.
We will let You know via email and/or a prominent notice on Our Service, prior to the change becoming effective and update the "Last updated" date at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
Contact Us
If You have any questions about this Privacy Policy, You can contact Us:
- By email: support@recouphero.com
- By visiting the Help & Support page in the Application: https://recouphero.com/help