Privacy Policy
Last updated: January 2025
Introduction
At LetterSettle, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our payment reminder letter services.
We are committed to protecting your personal data and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR), UK GDPR, California Consumer Privacy Act (CCPA), and other regional privacy regulations.
By using LetterSettle, you agree to the collection and use of information in accordance with this policy.
Data Controller
LetterSettle is the data controller responsible for your personal data. For any questions or concerns about how we handle your data, please contact us at:
- Email: privacy@lettersettle.com
- Support: support@lettersettle.com
Information We Collect
Personal Information
When you register or use our services, we collect:
- Account Information: Name, email address, phone number, company name
- Billing Information: Payment card details (processed securely by Stripe), billing address
- Business Information: Company registration details, business address, industry type
- Authentication Data: Password (encrypted), authentication tokens
Letter Content Data
- Debtor information (names, addresses, contact details)
- Invoice details and amounts owed
- Letter content and customizations
- Communication records and delivery confirmations
Automatically Collected Information
- Usage Data: Pages visited, features used, time spent on platform, interaction patterns
- Device Information: IP address, browser type and version, device type, operating system
- Location Data: Country/region based on IP address for currency display and service localization
- Cookies and Tracking: Session cookies, preference cookies, analytics cookies
Third-Party Information
- Information from payment processors (transaction status, payment verification)
- Authentication providers if you use social login
- Email delivery status from our communication partner
How We Use Your Data
We use your personal data for the following purposes:
Service Delivery
- Generate and customize payment reminder letters
- Deliver letters via email
- Provide delivery confirmations and tracking
- Process payments and manage subscriptions
- Authenticate and verify your identity
Customer Support
- Respond to your inquiries and support requests
- Troubleshoot technical issues
- Provide guidance on using our services
Service Improvement
- Analyze usage patterns to improve our platform
- Develop new features and services
- Conduct research and analytics
- Test and optimize user experience
Legal and Security
- Comply with legal obligations and regulations
- Prevent fraud and abuse
- Enforce our terms and conditions
- Protect our rights and the rights of our users
Marketing (With Your Consent)
- Send promotional emails about new features or services
- Provide personalized recommendations
- Share industry insights and best practices
- You can opt-out of marketing communications at any time
Legal Basis for Processing (GDPR)
Under GDPR, we process your personal data based on the following legal grounds:
- Contract Performance: Processing necessary to provide our services to you
- Legitimate Interests: Improving our services, preventing fraud, ensuring security
- Legal Obligation: Complying with tax laws, financial regulations, and legal requests
- Consent: Marketing communications and optional features (you can withdraw consent at any time)
Data Storage & Security
Where We Store Your Data
- Data is stored on secure servers provided by Supabase (hosted on AWS)
- Payment data is processed and stored by Stripe in compliance with PCI-DSS
- Backup data is stored in multiple geographic locations for redundancy
Security Measures
- Encryption: All data transmitted is encrypted using SSL/TLS (256-bit encryption)
- Access Controls: Role-based access controls and authentication requirements
- Password Protection: Passwords are hashed using industry-standard algorithms
- Regular Audits: Security assessments and vulnerability testing
- Monitoring: 24/7 system monitoring for suspicious activity
Data Retention
- Account data: Retained while your account is active
- Letter data: Retained for 7 years for legal and accounting purposes
- Payment records: Retained as required by financial regulations (typically 7 years)
- Analytics data: Aggregated and anonymized after 2 years
- You can request deletion of your data subject to legal retention requirements
Data Sharing & Third Parties
We do not sell your personal data. We may share your data with:
Service Providers
- Supabase: Database hosting and authentication (AWS infrastructure)
- Stripe: Payment processing (PCI-DSS compliant)
- Email Provider: Letter delivery service
- Analytics Tools: Usage analytics and performance monitoring
All service providers are contractually bound to protect your data and use it only for specified purposes.
Legal Requirements
We may disclose your data when required by law, such as:
- Responding to court orders or legal processes
- Complying with regulatory investigations
- Protecting our legal rights or the rights of others
- Preventing fraud or criminal activity
International Data Transfers
Your data may be transferred to and processed in countries outside your own. We ensure appropriate safeguards are in place, including:
- EU Standard Contractual Clauses for transfers outside the EEA
- Adequacy decisions by the European Commission
- Privacy Shield frameworks (where applicable)
Your Data Protection Rights
Under GDPR and other privacy laws, you have the following rights:
Right to Access
Request a copy of the personal data we hold about you
Right to Rectification
Request correction of inaccurate or incomplete data
Right to Erasure ("Right to be Forgotten")
Request deletion of your data (subject to legal retention requirements)
Right to Restrict Processing
Request limitation of how we process your data
Right to Data Portability
Receive your data in a structured, commonly used format
Right to Object
Object to processing based on legitimate interests or for direct marketing
Right to Withdraw Consent
Withdraw consent for processing where consent was the legal basis
Right to Lodge a Complaint
File a complaint with your local data protection authority:
- UK: Information Commissioner's Office (ICO)
- EU: Your national data protection authority
- US: Federal Trade Commission (FTC) or state attorney general
How to Exercise Your Rights
To exercise any of these rights, contact us at privacy@lettersettle.com. We will respond to your request within 30 days. You may need to verify your identity before we process your request.
Cookies & Tracking Technologies
We use cookies and similar tracking technologies to improve your experience:
Essential Cookies
Required for the website to function (authentication, security, preferences)
Analytics Cookies
Help us understand how users interact with our website
Functional Cookies
Remember your preferences (language, currency, country selection)
You can control cookies through your browser settings. Note that disabling certain cookies may affect website functionality.
Children's Privacy
LetterSettle is not intended for children under 18 years of age. We do not knowingly collect personal data from children. If we discover that we have collected data from a child, we will delete it immediately. If you believe a child has provided us with personal data, please contact us at privacy@lettersettle.com.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the updated policy on our website with a new "Last Updated" date
- Sending you an email notification (for significant changes)
- Displaying a prominent notice on our platform
Your continued use of LetterSettle after changes take effect constitutes acceptance of the updated policy.
Contact Us About Privacy
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices:
- Privacy Email: privacy@lettersettle.com
- General Support: support@lettersettle.com
- Response Time: Within 30 days for data subject requests
For EU/UK data subjects, you also have the right to lodge a complaint with your local supervisory authority.