Privacy Policy
Last updated August 2026
Secor recovers failed subscription payments for businesses. Doing that means handling two different sets of people’s information: the business that hires us, and that business’s customers. They are treated differently and both are described below.
Secor is a service of Dact Software LLC, a Georgia limited liability company. “We” and “us” in this policy mean that company. Questions about anything here, including a request to access or delete your data, go to privacy@secor.co.
What we never touch
We do not collect, store, process, or have any access to card numbers, CVV codes, expiry dates, or bank account details. All of that stays with Stripe. Our access to a connected Stripe account is read-only: we can see that a charge failed and why. We cannot create charges, issue refunds, move payouts, or change any setting. If our systems were breached tomorrow, nobody could charge a card with what they found.
If you are a Secor customer
We collect and store:
- Your business name, email address, and Stripe account identifier
- An encrypted, read-only OAuth token for your Stripe account
- Records of what we recovered and what we invoiced you
The OAuth token is encrypted at rest. The encryption key is held separately from the database, so a copy of the database alone is not enough to use it.
If you are a customer of a Secor customer
If a business you buy from uses Secor, and a payment of yours fails, we may hold your name, email address, phone number, the amount, and the reason the payment was declined. We use it for one purpose: telling you that your payment did not go through so you can update your card.
We act as a service provider to that business. They decide what we do with your information; we do not use it for anything of our own. We do not sell it, rent it, or share it with anyone for advertising or marketing. We do not build profiles, and we do not contact you about anything other than the specific failed payment.
Messages we send
We send transactional email and, where the business has your consent, SMS. These messages concern an existing account and are never promotional. Every text includes opt-out instructions; reply STOP and we stop immediately and permanently, across every business using Secor. Message and data rates may apply. Email replies go to the business, not to us.
Phone numbers reach us only from the billing system of the business you deal with. We never buy, append, or scrape them, and we never share them with third parties for marketing.
Who else processes this data
- Stripe — payment data and the connected account. We read from it; the money never passes through us.
- Neon — our database, hosted in the United States.
- Render — application hosting, United States.
- Postmark — sends our email.
- Twilio — sends our SMS.
Each is bound by its own agreement with us. None of them receives data for their own purposes.
How long we keep it
Records of messages sent stay for seven years. That is deliberate: if a customer ever disputes what they received, that log is the only way to answer them accurately. When a business disconnects, we delete their OAuth token immediately and stop all processing, but we retain the historical record for the same reason.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or port your information, and to opt out of its sale — though we do not sell it. If you are a customer of a business that uses Secor, contact that business first; they control the data and we act on their instruction. You can also write to us directly and we will route it correctly.
Security
- Encryption in transit and at rest
- OAuth tokens encrypted with keys stored apart from the database
- Row-level database isolation between customers
- No card data held anywhere in our systems
Children
Secor is a business service and is not directed to anyone under 16. We do not knowingly collect information from children.
Changes
If we change this materially we will email affected customers before it takes effect rather than quietly updating the date at the top.