Effective date: [effective date]
This policy explains how personal data is processed when you visit remindcash.com, use the RemindCash app (app.remindcash.com) or its API, and when businesses use RemindCash to send payment reminders to their customers.
1. Who is responsible
RemindCash is operated by an individual developer (not a company), [postal address] ("RemindCash", "we", "us"). For privacy questions and requests, write to [email protected].
2. Two roles
- Account holders and website visitors. For the data of people who visit the website, sign up, use the app or contact us, we are the controller.
- Customers of our users. When a business uses RemindCash to track receivables and send reminders, the business decides whose data is entered and why. For that data — for example its customers' names, email addresses and phone numbers — the business is the controller and we process it on its behalf as a processor, under the data processing terms in our Terms of Service. If you received a reminder through RemindCash, please contact the business that sent it; we will help it answer your request.
3. What we process
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address, password (stored only as a hash), two-factor authentication secrets and recovery codes (encrypted), passkey public keys, interface language | You |
| Company and team data | Company name, country, time zone, default language, team members, roles and invitations | You or your team |
| Subscription data | Trial start and end, plan, billing period and subscription status; payment confirmations from the payment provider | You and the payment provider |
| Customer contact data (as processor) | Customer name, email address, phone number, preferred language, time zone, contact verification, permission and opt-out records | The business user |
| Receivables and payables | Amounts, currencies, due dates, references, descriptions, recorded payments and status history | The business user |
| Reminder messages | Approved templates, reminder content, delivery attempts and delivery events (accepted, delivered, bounced, complaint) | The service and our email provider |
| API usage | API key names, scopes, expiry and last use; keys are stored only as hashes | You |
| Technical data | IP address, browser type, requested URL and time in server logs; session data | Your device |
| Messages to us | Name, email address, subject and message sent through the contact form | You |
On remindcash.com we use Google Analytics only if you accept analytics cookies; it records pages visited, approximate location derived from the IP address, device and browser information and interactions (Google Analytics does not store full IP addresses). We use no advertising or cross-site tracking tools and do not sell personal data. We never receive or store full payment card numbers: card payments are handled entirely by the payment provider.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the account, workspace, trial and subscription | Performance of a contract (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)) |
| Tracking receivables and sending reminders for business users | The business user's instructions (processor role) |
| Account and security emails (verification, password reset, security notices, invitations, trial and subscription notices) | Performance of a contract |
| Billing, invoicing and tax records for paid plans | Legal obligation (GDPR Art. 6(1)(c); KVKK Art. 5(2)(ç)) |
| Security, abuse prevention, rate limiting and audit logs | Legitimate interests in a secure service (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)) |
| Website usage statistics (Google Analytics) | Your consent (GDPR Art. 6(1)(a); KVKK Art. 5(1) explicit consent), withdrawable via Cookie settings |
| Answering contact-form messages | Legitimate interests / steps before a contract |
| Establishing or defending legal claims | Legitimate interests; KVKK Art. 5(2)(e) |
Reminders are only sent according to schedules and templates the business user has reviewed and approved; we do not make automated decisions that have legal or similarly significant effects on you.
5. Service providers
| Provider | Purpose | Location |
|---|---|---|
| UpCloud | Hosting of the application and database | Frankfurt, Germany (EU) |
| Cloudflare | DNS, content delivery and network security | Global network |
| Resend | Sending account and reminder emails and reporting delivery events | United States |
| Google (Google Analytics) | Website usage statistics, only with consent | Ireland / United States |
| [payment provider] | Processing subscription payments | [payment provider location] |
SMS, WhatsApp and sign-in-with-Google/Apple providers will be added here before any data is shared with them. We may also disclose data where the law requires it.
6. International transfers
Resend and Google process data in the United States and Cloudflare operates globally, so some data leaves Türkiye and the EU. These transfers rely on [transfer safeguard].
7. How long we keep data
- Account, workspace and receivable data: while your trial or subscription is active. When it ends (or after you cancel), the account is read-only for 30 days so you can view and export your data; after that, data is deleted, except data we must keep by law (for example billing records). Deleted data may remain in encrypted backups for up to [backup retention period] until those backups are overwritten.
- Billing records: for the period required by tax law, [tax record retention period].
- Server access logs (including IP addresses) and application error logs: 14 days.
- Google Analytics data: 2 months (the shortest setting Google offers) [confirm data retention is set to 2 months in Google Analytics]; the cookies expire after 2 years or when you withdraw consent.
- Contact-form messages: [contact message retention].
- Automatic expiry: sign-in sessions end after 120 minutes of inactivity, invitation links after 7 days and API keys 30 days after they are issued.
You can delete your user account at any time in Settings → Profile.
8. Your rights
You can ask for access to your data, correction, deletion, restriction, objection, data portability and — where processing is based on consent — withdraw consent. Residents of Türkiye have the rights in Article 11 of Law No. 6698 (see our KVKK information notice, in Turkish). You can also complain to the Turkish Personal Data Protection Authority or, in the EU, to your national supervisory authority.
Send requests to [email protected]. We reply within 30 days at the latest and may first verify your identity.
9. Security
Encrypted connections (TLS); encryption of secrets and sensitive fields at rest; hashed passwords and API keys; two-factor authentication for privileged access; strict separation between companies' data; role-based access; audit logs of administrative actions; and encrypted backups. We will notify affected people and the authorities of personal data breaches as the law requires.
10. Children
RemindCash is a professional service and is not intended for anyone under 18.
11. Changes
We will announce material changes in the app or by email before they take effect.