Legal
Privacy Policy
Last updated: August 30, 2026
This Privacy Policy explains how Stropia ("we", "us", or "our") collects, uses, shares, and protects information when you use our AI collections copilot (the "Service"). By using the Service, you agree to the practices described in this policy.
1. Information we collect
We collect information you provide directly to us, information we gather automatically when you use the Service, and information from third parties you connect to the Service.
- Account information: your name, email address, and password (stored securely as a hashed credential).
- Business data: the information you enter into the Service, such as client details, invoices, quotes, products, expenses, payment plans, and reminder settings.
- Payment information: when you subscribe, billing is processed by Stripe. We never see or store your full card number; Stripe handles and stores payment credentials on our behalf.
- Usage data: technical data such as IP address, browser type, device information, and how you interact with the Service.
- Connected-account data: when you connect integrations such as Stripe, Airtable, or QuickBooks, we access the data required to provide the integration (for example, invoices and customer records).
2. How we use your information
We use the information we collect to operate, maintain, and improve the Service, including:
- Creating and managing your account and sending you transactional communications.
- Generating AI-written payment reminders that are tone-matched to your communication style, and calculating payment-risk scores.
- Scheduling and sending reminder emails, and generating secure payment links for your invoices.
- Processing payments and subscriptions through Stripe, and reconciling invoice payments.
- Syncing data with integrations you connect, such as Airtable and QuickBooks.
- Detecting, preventing, and responding to fraud, abuse, and security incidents.
- Improving the Service through analysis of aggregated, non-identifying usage patterns.
3. AI-generated content
To draft payment reminders and assess payment risk, we send the minimal necessary invoice facts (amounts, due dates, client names, and your prior message history) to an AI provider (DeepSeek, accessed through the Vercel AI SDK).
AI output is always validated against the source data before it can be queued or sent, and sending reminders is human-approved by default — automated sending is only enabled when you explicitly opt in.
AI models do not have access to your account credentials or payment card data.
4. How we share your information
We do not sell your personal information. We share data only with the service providers required to run the Service, and only to the extent needed:
- Vercel — hosting and serving the Service.
- Neon (PostgreSQL) — database storage of your account and business data.
- Stripe — payment processing and subscription billing.
- Amazon SES and React Email — sending reminder and transactional emails.
- DeepSeek (via the Vercel AI SDK) — generating AI reminder drafts.
- Inngest — background jobs that schedule and deliver reminders.
- Connected integrations (for example, Airtable or QuickBooks) — only when you authorize the connection and only for the data the integration requires.
We never share your data with third parties for their own marketing purposes, and we never sell personal information.
5. Data retention
We retain your data for as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. If you delete your account, we delete or anonymize your business data within a reasonable period, except where we are required to retain it by law.
6. Data security
We take reasonable technical and organizational measures to protect your information, including encryption in transit, secure authentication, and least-privilege access to stored data. Payments are processed and stored by Stripe, which is PCI-DSS compliant. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Your rights and choices
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can update much of your account and business data directly in the Service.
- Access and correction: review and update your account information in Settings.
- Export: request a copy of the business data we hold about you.
- Deletion: delete your account and request removal of your data.
- Object or restrict: request that we limit how we process your data.
8. Cookies and similar technologies
We use cookies and similar technologies to keep you signed in, remember your preferences, and understand how the Service is used. You can control cookies through your browser settings; disabling them may affect parts of the Service.
9. Children's privacy
The Service is not directed to individuals under the age of 16, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
10. International data transfers
Your information may be processed and stored in countries other than your own, including through our hosting and service providers. Where required, we rely on appropriate safeguards to protect your data.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
12. Contact us
If you have questions about this Privacy Policy or how we handle your data, contact us at:
- Email: hello@stropia.com