Effective October 2, 2026 · Last updated October 2, 2026
This policy explains what [Your company legal name] ("we") collects when you use RecoupOS (the "Service"), why, and the choices you have. The short version: we collect what we need to run your account and bill you, we process the files you upload only to produce your reports, we don't sell data, and you can export or delete it.
1. Who this covers
This policy applies to visitors of our website and to people who use the Service through a customer organization (administrators and team members). If your employer set up the account, your employer controls the organization's data and decides who has access; contact them for questions about their choices.
2. What we collect
Information you give us
Account details: name, email address, password (stored only as a one-way hash), username, role, and the company name you sign up with.
Organization settings: your company name, logos, store names, license numbers and store aliases.
Uploaded files and the data in them: point-of-sale and brand-funding exports, defective-product logs and similar spreadsheets. These typically contain store names, product names, package or METRC identifiers, quantities, prices, discount amounts, dates and vendor or brand names. They should not contain customer personal information; please remove any columns with consumer names, contact details or IDs before uploading.
Records you create: reports, credit ledger entries, notes, vendor profiles and settings.
Support messages you send us.
Billing information
Payments are handled by Stripe. Your card details are entered on Stripe's secure checkout and stored by Stripe, not by us. We receive and keep your Stripe customer and subscription identifiers, plan, billing status, trial and renewal dates, and the last four digits / card brand that Stripe shows us for display. Stripe's handling of your information is described in Stripe's Privacy Policy.
Collected automatically
Session cookie: a strictly necessary cookie that keeps you signed in. We do not use advertising or cross-site tracking cookies.
Server logs: IP address, browser type, pages requested, timestamps and error details, kept for security and troubleshooting.
Browser storage: some tools remember small conveniences (for example a license number you edited) in your own browser. That data never leaves your device.
We do not collect precise location, biometric or financial-account information, and we do not knowingly collect information from anyone under 18.
3. How we use it
To provide the Service: read your uploads, generate reports, keep your ledger, show your branding on printouts, and let your team collaborate.
To run your account: sign-in, invitations, password resets, plan limits.
To bill you and manage trials, renewals, failed payments and cancellations.
To support you when you ask for help.
To keep the Service secure, prevent abuse, and fix problems.
To send service messages (trial ending, payment issues, important changes). We do not send marketing email unless you opt in, and you can opt out of any marketing at any time.
To improve the Service using aggregated, de-identified usage information that cannot be tied back to a customer.
We do not sell your information, use your uploaded data to train models, or use one customer's data to benefit another.
4. Who we share it with
Service providers who help us run the Service, under contracts that limit what they may do: our hosting and database provider (Render), our payment processor (Stripe), and our email provider for service messages. They process data on our instructions only.
Your own organization: administrators and members of your organization can see the data in it, according to their role.
Legal and safety: if required by law, subpoena or court order, or to protect the rights, safety or property of our customers, the public or us.
Business transfers: if we are involved in a merger, acquisition or sale of assets, your information may transfer to the successor, who must honor this policy.
We never share your data with your vendors or other customers. Reports go only where you send them.
5. Security
We use industry-standard measures: encrypted connections (HTTPS) for all traffic, hashed passwords, per-organization isolation of data in the database, role-based access, and least-privilege access for our staff. Card data never touches our servers. No system is perfectly secure; if we learn of a breach affecting your data we will notify affected administrators without undue delay and as required by law.
6. Retention
Active accounts: we keep your data for as long as your organization uses the Service.
After your subscription ends: your data is retained for 90 days so you can resubscribe or request an export, then may be permanently deleted.
On request: an administrator can ask us to delete the organization and its data sooner.
Billing records are kept as long as tax and accounting laws require (generally 7 years).
Server logs are kept for a limited period (typically 30–90 days).
Backups are rotated on a schedule; deleted data may persist in backups for a short period before being overwritten.
7. Your choices and rights
Access and export: you can view your data in the app and export reports and ledger entries at any time.
Correction: update your profile, organization and stores in Settings.
Deletion: remove users, stores and reports in the app, or ask us to delete your organization entirely.
Marketing: opt out via the link in any marketing email or by contacting us.
Depending on where you live (for example California, or the EU/UK), you may have additional rights such as portability, restriction, objection, and the right not to be discriminated against for exercising them. We honor these requests from the account holder or a verified representative. We do not "sell" or "share" personal information as those terms are defined in California law.
To exercise any right, email [support email] from an administrator address. We will respond within 30 days.
8. Where data is stored
Our servers and database are located in the United States. If you use the Service from elsewhere, you understand that your information is transferred to and processed in the United States.
9. Chrome extension (RecoupOS Receiving)
The optional RecoupOS Receiving browser extension adds a "Check in" button to Metrc's Licensed Transfers page and a price button to Dutchie receiving screens. It runs only on metrc.com, dutchie.com and your RecoupOS account's domain.
What it reads: when you click "Check in", the manifest number, shipper and the list of packages (tags, product names, categories, quantities) on the Metrc manifest you clicked. On Dutchie receiving screens, the package tags shown on the page, so it can look up what you previously paid.
Where it sends it: only to your own RecoupOS account, using the session you are already signed in with. Nothing is sent anywhere else, and nothing is read from pages other than those two sites.
What it stores on your computer: the RecoupOS server address you chose in the extension popup. No browsing history, no analytics, no advertising identifiers.
When it is paused: if you are signed out, your subscription is inactive, or the Receiving add-on is not on your plan, the extension's buttons are disabled and it makes no requests other than checking your sign-in status.
Removing the extension from Chrome deletes its stored settings. Data already checked into RecoupOS is covered by the rest of this policy.
10. Children
The Service is for businesses and is not directed to children. We do not knowingly collect information from anyone under 18; if you believe we have, contact us and we will delete it.
11. Changes to this policy
We may update this policy. For material changes we will notify administrators by email or in the app at least 14 days before they take effect, and we will always show the effective date at the top of this page.
12. Contact
[Your company legal name] [mailing address] [support email]