Privacy Policy

Last updated: August 14, 2026

What we collect

Your account details (email, name, business name, timezone), the invoice and client data you enter or import (client names, emails, amounts, due dates), reminder emails the Service generates for you, and — if you connect a payment integration — the account identifier and invoice metadata it shares. We never see or store your clients' card numbers or your payment-provider credentials.

How we use it

Solely to operate RestPaid: scheduling and sending reminders in your name, showing you dashboards, billing your subscription through Paddle, and sending you service notifications. We do not sell personal data, and we do not use your clients' contact details for anything except the reminders you configured.

Your clients' data

You are the controller of the client information you enter; we process it on your instructions. Clients who receive reminders can reach you directly by replying — replies go to your inbox, not to us.

Service providers

We rely on a small set of processors to run the Service: Supabase (database & authentication), Vercel (hosting), Resend (email delivery), and Paddle (subscription billing, as merchant of record). Each receives only what it needs to perform its function.

Retention and deletion

We keep your data while your account is active. Ask us to delete your account and we will remove your data within 30 days, except records we must keep for legal or accounting reasons.

Security

Data is encrypted in transit, access is scoped per account, and public invoice pages use long, unguessable links that expose only what a payer needs.

Contact

Privacy questions or requests: reply to any RestPaid email or contact the address on our site.