Privacy Policy
Last updated: August 2026
This Privacy Policy explains how YRECURRING LLC ("yRecurring", "we", "us") handles personal data in connection with our billing platform, websites, and APIs (the "Service"). We wrote it to be clear and honest about what we do and do not do.
1. Two roles: controller and processor
We handle personal data in two different roles, and your rights differ depending on which applies.
- As a controller. For the personal data of our own account holders and website visitors, such as the name, email, and company of the person who signs up, billing details for their yRecurring subscription, and support messages, we decide how and why the data is used. This policy governs that data.
- As a processor. When you use the Service, you upload data about your own customers, such as their names, contact details, and billing records ("Customer Data"). We process that data on your behalf and on your instructions, as your processor. Our handling of Customer Data is governed by our Data Processing Addendum. If you are an end-customer of a business that uses yRecurring and you have a request about your data, please contact that business directly, since they control it.
2. What we collect
- Account and profile data: name, work email, company, and role of the people who create and use an account.
- Subscription and billing data for your yRecurring plan: plan, invoices, and payment status. Payments for your plan are handled by a third-party payment gateway; we receive a token and limited details such as card brand and the last four digits, not the full card number.
- Usage and log data: actions taken in the Service, and technical logs such as IP address, browser or client type, and timestamps, used to run, secure, and debug the Service.
- Communications: messages you send us, such as support and sales email.
- Cookies: the essential cookies described in our Cookie Notice, plus optional analytics cookies on the marketing site, which you can decline. We use no advertising cookies.
We do not collect or store full payment card numbers, and we do not knowingly collect data from anyone under 18.
3. How we use data, and our legal bases
We use controller data to provide and secure the Service, to communicate with you about your account, to take payment for your plan, to provide support, to improve the Service, and to comply with law. Where the GDPR or similar laws apply, our legal bases are: performance of our contract with you, our legitimate interests in running and securing the Service, your consent where we ask for it, and compliance with legal obligations.
4. How we share data
We do not sell your personal data, and we do not share it for cross-context behavioral advertising. We share data only with:
- Service providers (subprocessors) that help us run the Service, such as cloud infrastructure, a payment gateway, and email delivery. They are listed on our Subprocessors page and are bound to protect the data.
- Payment and dispute recipients. If a payment to us is disputed, we may share records relevant to the charge with our payment gateway, the card networks, and the card issuer to respond to the dispute. This can include the account holder's name and email, the record of agreement to our terms (including its date and IP address), invoices, and a summary of account activity.
- Legal and safety recipients, where disclosure is required by law or needed to protect rights, safety, or the integrity of the Service.
- A successor in connection with a merger, acquisition, or sale of assets, subject to this policy.
5. International transfers
We may process data in countries other than yours. Where we transfer personal data across borders in a way that triggers legal safeguards, we rely on appropriate mechanisms such as the Standard Contractual Clauses.
6. How long we keep data
We keep controller data for as long as your account is active and as needed to provide the Service, then for a reasonable period afterward to meet legal, accounting, and security needs, after which we delete or anonymize it. Technical logs are kept for a limited period and then removed in the ordinary course. Customer Data is kept and deleted per your instructions and the Data Processing Addendum.
7. Security
We take security seriously and apply administrative, technical, and organizational measures appropriate to the data we handle, including encryption in transit and at rest, tenant isolation, access controls, and an audit trail. No method of storage or transmission is completely secure, so we cannot promise absolute security. You can read more on our Security page.
8. Your rights
Depending on where you live, you may have some or all of the following rights over the personal data we hold as a controller.
If the GDPR or UK GDPR applies to you
You may request access to your data, correction, deletion, restriction of processing, and portability, object to processing based on legitimate interests, and withdraw consent where processing is based on consent. You may also complain to your local data protection supervisory authority.
If you are a California resident (CCPA/CPRA)
You may request to know what personal information we hold, to delete it, and to correct it, and you may exercise these rights without discrimination. We do not sell or share your personal information as those terms are defined by California law, and we do not use sensitive personal information for purposes that require an opt-out.
To exercise any right, write to [email protected]. We will verify your request and respond within the time the law requires. You may use an authorized agent where the law allows.
9. Cookies and analytics
We use essential cookies, described in our Cookie Notice. On the public marketing site we also use Google Analytics to understand which pages are useful. You can decline it through the prompt on the site, and in regions where the law requires prior consent, such as the EEA, the UK, and Switzerland, it sets no cookies unless you agree. Google processes this data on our behalf; IP addresses are truncated. The app itself contains no analytics.
10. Children
The Service is for business use and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has given us data, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. If we make a material change, we will update the date above and, where appropriate, give additional notice.
12. Contact
Controller: YRECURRING LLC, 30 N Gould St # 36102, Sheridan, WY 82801, USA. Privacy questions and requests: [email protected].