Privacy Policy

Last updated July 30, 2026

Download signed PDF

What SteadyStreamPay processes

SSP is an installed Stripe application. With your authorization, it reads failed-charge metadata from your Stripe account — decline codes, charge amounts, subscription identifiers, customer email addresses, and card expiry months. This data is processed solely to recover revenue on your behalf.

No raw card data, ever

SSP never receives, requests, or stores primary account numbers (PANs), CVCs, or full card details. Card credentials remain inside Stripe's vault at all times. Recovery links hand the customer directly to a Stripe-hosted update page, which keeps SSP within PCI SAQ-A scope.

Credentials and encryption

Your Stripe connection is held in the Stripe Secret Store. All data in transit is protected with 256-bit TLS, and all data at rest is encrypted by our infrastructure provider.

How recovery messages are generated

Outbound recovery emails are written from the brand voice instructions you configure in the SSP dashboard, combined with the non-sensitive transaction context above. Message content is retained only as long as needed to report on recovery outcomes.

Retention and deletion

Recovery event records are retained for the life of your SSP installation so your dashboard metrics remain accurate. Uninstalling SSP from your Stripe account revokes our access and schedules deletion of associated records.

Sharing

SSP does not sell data. Transaction data is shared only with the infrastructure and message-delivery providers required to operate the service, and with Stripe itself for billing the performance fee.

Contact

Questions about this policy or a data request can be sent to privacy@steadystreampay.com.