Privacy Policy
Effective September 29, 2026
Dunity helps businesses that bill through Stripe recover failed payments. This policy explains what information Dunity handles, why, who else touches it, and what you can ask us to do with it. We’ve kept it in plain language. If anything is unclear, email maxfromdunity@gmail.com and we’ll explain.
Who we are
Dunity is run by an individual based in Bangkok, Thailand, and isn’t a registered company yet. For the information in this policy about you, Dunity is the data controller, and you can reach us at maxfromdunity@gmail.com.
Two kinds of people, two roles
If you run a business and use Dunity, we decide how your account information is used, so we’re its controller. Most of this policy is about you.
If you’re a customer of a business that uses Dunity, for example you got an email about a failed payment, that business decides how your information is used and Dunity only processes it for them. They’re the controller and we’re their processor. The section “Information about your customers” below describes what we handle, but for requests about it, the business you pay is the right place to start.
Information about you
- Account. Clerk handles sign-up and sign-in. It stores your email address and sign-in details. We never see or store your password. We keep the account ID Clerk gives us, and we read your email address when you first check out so Stripe can fill it in for you.
- Billing. Stripe processes your Dunity subscription. Your card details go straight to Stripe and never reach us. We keep your Stripe customer ID and subscription ID, your plan (monthly or yearly) and its price, its status, and the date it ended if you cancel.
- Your settings. Your time zone, retry rules, email wording and reply-to address, alert email address, the Stripe customer IDs you mark as VIP, and your payment-wall settings (your app’s web addresses and accent color). If you connect Slack, we store your Slack webhook address encrypted. We keep only a hash of your payment-wall secret, never the secret itself.
- Your connected Stripe account. Your restricted API key and the webhook signing secret are encrypted in Supabase Vault, never sent back to your browser, and only read by the server process that talks to Stripe. We also keep your publishable key, the ID of the webhook we created, and whether the account is in live or test mode.
- Technical logs. Our hosting providers automatically record things like IP addresses, browser type, pages requested and times, for security and debugging. Our own error logs can include Stripe invoice or customer IDs when something goes wrong.
Information about your customers
When you connect Stripe, Dunity handles the following about your customers, only to run the features you turn on:
- From each failed payment: the invoice ID, the Stripe customer ID, the amount and currency, why it failed, the retry schedule, how many attempts were made, the outcome, and the ID of any win-back credit note.
- Your customer’s email address, which we use to send the emails you’ve set up. We keep a log of each email, including the address, the subject line and whether it was sent successfully.
- For card-expiry reminders, the card brand, last four digits and expiry date, read from Stripe at the moment we write the email and not stored. We keep the payment method ID and the date we sent a reminder so we don’t send it twice.
- On the page where your customer updates their card, the card details go into Stripe’s own secure form. Dunity never receives full card numbers from Stripe or from that page.
- If you install the payment wall, your customer’s browser sends us their Stripe customer ID and your publishable key so we can check whether a payment is overdue, and our hosting provider logs that request like any other. The wall saves one small flag in that browser tab’s session storage when someone dismisses it, and nothing else.
How we use information, and why we’re allowed to
Data protection laws such as the GDPR ask us to name a legal basis for each use. Ours are:
- To provide the service you signed up for: running your account, retries, emails, alerts and dashboard, and billing your plan. The basis is our contract with you.
- To keep Dunity secure and working: preventing abuse, investigating problems and fixing bugs. The basis is our legitimate interest in running a safe, reliable service.
- To meet legal duties, such as keeping billing records for tax. The basis is legal obligation.
- Your customers’ data is processed on your instructions, under the data processing terms in our Terms.
We don’t send marketing emails, we don’t sell or rent personal information, we don’t share it for advertising, and we don’t use your customers’ data to train AI models. Dunity decides when to retry a payment automatically, but only within the rules the business set, and it never decides whether someone owes money.
Cookies and similar technology
Dunity only uses cookies that are needed for it to work. Clerk sets cookies that keep you signed in. Stripe’s scripts, which load on our checkout and card-update pages, set their own cookies to prevent fraud, under Stripe’s privacy policy. We count page visits with Vercel Web Analytics, which sets no cookies and doesn’t identify you. We don’t use advertising or tracking cookies, so there’s nothing to opt out of.
Who we share information with
We share information only with the providers we need to run Dunity. Each one handles it on our behalf, under its own data protection terms:
- Clerk: Sign-in and sessions (United States).
- Stripe: Billing for your Dunity plan, and the source of your connected account’s payment data (United States).
- Supabase: Our database, including encrypted storage for keys and webhook addresses (Seoul, South Korea).
- Vercel: Hosting and the scheduled jobs that run retries and reminders (United States).
- Resend: Delivering the emails Dunity sends to you and your customers (United States).
If you connect Slack, alerts about large failed payments, including the invoice ID, customer ID and amount, go to your own Slack workspace under your agreement with Slack. We may also disclose information if the law requires it, or to protect Dunity, our users or others from fraud or harm.
If Dunity changes hands
If Dunity is ever sold, merged with another business or taken over, your information may move to the new owner as part of that. They’ll have to keep the promises in this policy, and we’ll email you before your information becomes subject to a different one.
International transfers
Dunity is run from Thailand, and our providers store and process data in the United States and South Korea, so your information may leave the country you live in. When it does, we rely on the protections our providers offer for these transfers, such as the European Commission’s standard contractual clauses and, where a provider is certified, the EU-U.S. Data Privacy Framework.
How long we keep information
- Account, settings and billing information: for as long as your account is open.
- When you disconnect Stripe, your restricted key and webhook secret are deleted right away, along with card-expiry reminder records. Your retry and email history stays so you can still see it, until you ask us to delete it or close your account.
- When you close your account, we delete its data, including your customers’ data, within 30 days. Billing records that tax law requires are kept by Stripe, and by us where required, for the period the law sets.
- Technical logs are kept for the short periods our hosting providers set.
To close your account and have its data deleted, email maxfromdunity@gmail.com.
How we protect information
All traffic to Dunity is encrypted with TLS. Stripe keys and Slack webhook addresses are encrypted at rest in Supabase Vault. We ask for a restricted Stripe key, never a full one, and check the signature on every webhook so we only act on events that really came from Stripe. Public endpoints are rate limited. No system is perfectly secure, so we keep only what Dunity needs to work. If a breach affects your information, we’ll tell you and, where the law requires, the regulator.
Your rights
Wherever you live, you can ask us to show you the information we hold about you, correct it, delete it, or send you a copy. You can also object to or ask us to limit how we use it. Email maxfromdunity@gmail.com from the address on your account, and we’ll reply within 30 days. We won’t charge you for this or treat you differently for asking.
- In the EU, EEA or UK, you can also complain to your local data protection authority.
- In Thailand, you have these rights under the Personal Data Protection Act, and you can complain to the Personal Data Protection Committee.
- In California and other US states with privacy laws, you have the right to know, delete and correct your information, and to opt out of its sale or sharing. We don’t sell or share personal information, so there’s nothing to opt out of.
If you’re a customer of a business that uses Dunity, please contact that business first, since they control your information. If you write to us instead, we’ll pass your request to them and help them answer it.
Children
Dunity is a tool for businesses. It isn’t meant for anyone under 16, and we don’t knowingly collect information about children.
Changes to this policy
When we change this policy, we’ll update the date at the top. For a change that matters, we’ll also email you before it takes effect.
Contact
Questions or requests about your information: maxfromdunity@gmail.com.