Privacy Policy
Last updated: August 2026
CollectionsCopilot is operated by Cody Burnett, a sole proprietor based in Texas, USA. This policy explains what data the app collects, how it's used, and who it's shared with.
1. What we collect
When you connect your Stripe account via Stripe Connect OAuth, we access:
- Invoice data — amounts, due dates, status, customer names, and customer email addresses
- Payment status information for tracked invoices
- Your Stripe account's display name and email address
We also store an OAuth access token so the app can monitor your invoices on your behalf. This token is encrypted at rest (see Security below). We do not store your Stripe login credentials or your Stripe API keys.
The app sets a single session cookie (session) when you sign in via Stripe. It is HttpOnly, Secure, and SameSite=Lax, and expires after 30 days. We set no other cookies and we do not use analytics scripts, tracking pixels, localStorage, or sessionStorage anywhere in the app or on our marketing site.
2. How we use your data
We use your invoice data only to provide the service:
- Detect overdue invoices
- Draft and send personalized reminder emails to your customers
- Stop reminder sequences when an invoice is paid
- Generate weekly recovery summaries for you
We do not sell your data or your customers' data. We do not use it for advertising, profiling, or any purpose other than the reminder service you signed up for.
3. Third-party services
The app uses the following services, each only when configured:
- Stripe — for OAuth authentication, invoice data access, and subscription billing. Stripe processes data according to its own privacy policy.
- An AI provider (e.g. OpenAI) — drafts reminder emails. The AI receives the customer's name, invoice amount and number, due date, days overdue, escalation stage, and a summary of payment history. The customer's email address is never sent to the AI.
- SendGrid or Resend — delivers the reminder emails. The email provider receives the customer's email address, the email subject, body, and sender address. Either provider is used only when its API key is configured; if neither is set, emails are not sent.
No other third parties receive your data.
4. Data retention
Invoice and reminder data is kept for as long as your account is active. If you cancel your subscription, your data is deleted within 30 days. You can request immediate deletion at any time by contacting us.
5. Security
Stripe OAuth access and refresh tokens are encrypted at rest using AES-256-GCM. The database file is locked to owner-only permissions (chmod 600). All communication between the app and Stripe uses HTTPS.
That said, no online service is completely immune to security risk. If you discover a vulnerability, please notify us immediately.
6. Your rights
You can:
- Disconnect your Stripe account at any time
- Pause or cancel active reminder sequences
- Request a copy of your stored data
- Request correction or deletion of your data
To exercise any of these rights, contact us at the email below. We'll respond within 30 days.
7. Contact
Cody Burnett, sole proprietor — Texas, USA. support@getcollectionscopilot.com