Privacy Policy

Last updated: July 2026

Revenue Recovery Labs ("RRLabs", "we", "us", or "our") provides an enterprise AI platform that helps subscription and eCommerce businesses recover failed payments and reduce involuntary churn. This Privacy Policy explains what personal data we process, why we process it, how long we keep it, who we share it with, and the rights available to individuals under the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and other applicable privacy laws.

This policy applies to our public websites (including https://www.rrlabs.online), the RRLabs application, our APIs, and any related services (together, the "Services"). Where we process personal data on behalf of our customers, we act as a processor (or "service provider" under the CCPA); where we determine the purposes and means of processing (for example, our own account, billing, and website data), we act as a controller.

1. Data we process

We collect and process the following categories of personal data:

  • Account data — name, work email, workspace and organization information, authentication identifiers, role, and preferences you set in the product.
  • Billing metadata — plan, billing frequency, subscription state, transaction identifiers, tax information required by our Merchant of Record, and invoice references. Payment card details are never seen or stored by RRLabs.
  • End-customer data — contact information (such as name, email, phone, and language preference) and event data (such as decline reasons, amounts, retry outcomes, and message delivery status) provided by our customers so we can generate and send recovery communications on their behalf.
  • Product usage — logs, IP address, device and browser type, session identifiers, and diagnostic events used to secure and improve the Services.
  • Support and communications — messages you send to us and metadata about those interactions.

2. Purposes and lawful bases

  • Providing the Services — performance of contract with our customer.
  • Payment recovery messaging — legitimate interests of our customer in recovering owed sums and preserving their customer relationship, executed under a data processing agreement.
  • Billing, tax, and fraud prevention — compliance with legal obligations and our legitimate interests.
  • Security, monitoring, and abuse prevention — legitimate interests in keeping the platform safe and reliable.
  • Marketing communications — consent, or legitimate interests where permitted by applicable law (including PECR and CAN-SPAM). You may opt out at any time.

3. Merchant of Record and payments

Our Merchant of Record for online subscription purchases is Lemon Squeezy. Lemon Squeezy processes payments, calculates and remits applicable sales taxes and VAT, issues invoices and receipts, and handles related compliance obligations. When you purchase a plan, Lemon Squeezy acts as an independent controller for the payment transaction and is responsible for the collection and processing of your payment information under its own privacy notice. RRLabs receives limited billing metadata (such as subscription identifiers, plan, status, and amounts) but does not receive or store full payment card numbers.

4. Sharing and sub-processors

We share personal data only with vetted sub-processors that support the Services under written contracts, including: cloud hosting and database infrastructure, email delivery, WhatsApp Business messaging, error monitoring, product analytics, and payment processing (Lemon Squeezy). A current list of sub-processors is available on request via [email protected].

5. International transfers

Personal data may be transferred to and processed in countries other than your own, including the United States and the United Kingdom. Where required, transfers are protected by the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or equivalent safeguards.

6. Retention

We retain account and billing data for as long as your workspace is active and for a reasonable period afterwards to meet legal, tax, and accounting obligations. End-customer contact and event data is retained only for the duration of the recovery cycle configured by our customer, plus a short buffer for reconciliation and audit, after which it is deleted or anonymized.

7. Your rights

Subject to applicable law, you have the right to access, correct, delete, restrict, or object to our processing of your personal data, to data portability, and to withdraw consent. California residents have additional rights under the CCPA/CPRA, including the right to know, delete, correct, and limit the use of sensitive personal information. We do not sell personal data and do not share personal data for cross-context behavioral advertising. To exercise any of these rights, email [email protected]. If you are an end-customer of one of our customers, we will forward your request to the relevant customer, who is the controller of your data.

8. Security

We apply administrative, technical, and organizational safeguards designed to protect personal data, including encryption in transit and at rest, tenant isolation via row-level security, least-privilege access, audit logging, and continuous monitoring. Learn more on our Security page.

9. Children

The Services are not directed to children under 16, and we do not knowingly collect personal data from children.

10. Changes

We may update this Privacy Policy from time to time. Material changes will be communicated through the Services or by email. The "Last updated" date at the top of this page always reflects the most recent version.

11. Contact

Questions or complaints? Contact us at [email protected]. EU and UK individuals also have the right to lodge a complaint with a supervisory authority in their country of residence.