Privacy Policy

Last updated: August 7, 2026

1. Overview

This Privacy Policy explains what information Latchpay ("we," "us," or "our") collects, how we use it, and the choices you have. It applies to everyone who uses Latchpay's website and dashboard (the "Service").

Latchpay collects two categories of data: information you give us directly as an Account Holder, and failed-payment information we process on your behalf from your connected Stripe account. Each is described below.

2. Information you provide directly

  • Account information — the email address and password you use to sign up, handled by our authentication provider, Supabase.
  • Stripe connection — when you link your Stripe account, we store your Stripe account ID and connection status so we know which account to read events from. We never receive or store your Stripe API keys.
  • Subscription status — if you subscribe to a paid plan, Paddle (our billing provider) shares your subscription status and renewal date with us so we can grant access to the Service.

3. Information we process on your behalf

When Stripe reports a failed payment on your connected account, we receive and store a record of that event, which may include your customer's email address, the payment amount and currency, the failure reason, and the related invoice ID. This information is used only to:

  • Display failed-payment records in your dashboard;
  • Send an automated recovery email to your customer asking them to update their payment method.

We act as a data processor with respect to this information — you, as the Account Holder, are the data controller for your own customers' data.

4. How we use information

We use the information described above to:

  • Operate and maintain the Service, including authentication and the dashboard;
  • Detect failed payments and send recovery emails on your behalf;
  • Process subscription billing and grant access to paid features;
  • Respond to support requests and communicate service-related updates;
  • Maintain the security and integrity of the Service.

We do not sell personal information, and we do not use it for advertising.

5. Third-party service providers

The Service relies on the following providers to function. Each processes a limited slice of data necessary for its role:

  • Stripe — payment event data and account linking (Stripe Connect OAuth).
  • Paddle — subscription billing, invoicing, and tax handling, as merchant of record for Latchpay subscriptions.
  • Supabase — user authentication and database storage for account and failed-payment records.
  • Resend — delivery of transactional recovery emails to your customers.

6. Data retention

We retain account and failed-payment data for as long as your account is active, or as needed to provide the Service. If you delete your account, we delete or anonymize your data within a reasonable period, except where we are required to retain it for legal, tax, or fraud-prevention purposes.

7. Data security

We use industry-standard measures to protect data in transit and at rest, including encrypted connections, scoped API access, and webhook signature verification on all incoming Stripe and Paddle events. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete the personal information we hold about you. You can exercise most of these rights directly from your account, or by contacting us at the email below.

9. Cookies and session data

Latchpay uses only the essential cookies required to keep you signed in, set by our authentication provider, Supabase. We do not use tracking or advertising cookies.

10. Children's privacy

The Service is intended for business use and is not directed at children. We do not knowingly collect personal information from anyone under 16.

11. International data transfers

Our service providers may process and store data in countries other than your own. Where required, we rely on appropriate safeguards, such as standard contractual clauses, to protect data transferred internationally.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above. See also our Terms of Service.

13. Contact us

Questions about this Privacy Policy or your data can be sent to support@latchpay.com.