Skip to main content

Privacy Policy

Effective date: April 11, 2026  ·  Last updated: August 12, 2026

PayNudge (“we”, “us”, or “our”) operates the PayNudge service available at paynudge.xyz. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our service. By using PayNudge, you agree to the collection and use of information in accordance with this policy.

This policy is written to comply with the General Data Protection Regulation (GDPR), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and the California Consumer Privacy Act (CCPA) where applicable.

1. Roles: Controller and Processor

When you use PayNudge to send reminders to your clients, you (the business user) are the data controller — you determine the purpose and means of processing your clients' personal data. PayNudge acts as a data processor on your behalf, processing that data only as necessary to provide the service you have requested.

As the controller, you are responsible for ensuring you have a lawful basis to collect and use your clients' contact information, and for complying with applicable privacy laws when sending automated communications to them.

2. Information We Collect

2a. Information you provide directly

  • Account information: name, business name, email address, password (stored hashed)
  • Business settings: reply-to email, custom reminder message templates

2b. Information synced from your integrations

When you connect QuickBooks Online, Square, Jobber, or Stripe, we access:

  • Invoice data: invoice numbers, amounts, due dates, statuses
  • Customer data: names, email addresses, phone numbers (where available)
  • Account identifiers: provider account/realm IDs for API calls

We do not access bank account numbers, payment card details, payroll data, tax filings, or any data beyond what is necessary to identify overdue invoices and contact the relevant customer.

2c. Usage data

  • Log data: IP address, browser type, pages visited, timestamps
  • Analytics events: feature usage, clicks, session duration (via PostHog) — collected anonymously and without cookies until you accept analytics cookies; see Section 10 for exactly what is recorded in each state
  • Error reports: stack traces, error context (via Sentry)

3. How We Use Your Information

  • To provide the service: sync invoices, identify overdue amounts, and send automated payment reminder emails to your clients on your behalf; SMS reminders are generated as one-tap drafts that you send from your own phone
  • To manage your account and respond to support requests
  • To send service notifications (e.g. billing confirmations, feature updates)
  • To improve the service through aggregated, anonymised usage analytics
  • To monitor for errors and maintain service reliability
  • To comply with legal obligations

We do not sell your data or your clients' data to third parties. We do not use your clients' contact information for any purpose other than sending reminders on your behalf.

4. Integration Access Scope

When you connect an accounting or business platform, PayNudge requests the minimum permissions necessary:

  • QuickBooks Online: Read access to invoices and customers
  • Square: Read access to invoices and customers
  • Jobber: Read access to invoices and clients
  • Stripe: Read access to invoices and customers via Stripe Connect

Access tokens are stored encrypted and used only to sync data and operate the reminder service. You can disconnect any integration at any time from your Settings page, which permanently deletes the stored tokens so PayNudge can no longer access your account. To also revoke the authorization on the provider’s side, use the connected-apps settings in QuickBooks, Square, Jobber, or Stripe.

5. Sub-Processors and Third Parties

We use the following sub-processors to deliver the service. Each is contractually bound to process data only as directed and to maintain appropriate security standards:

Sub-processorPurposeLocation
SupabaseDatabase and authenticationUSA (AWS)
VercelApplication hosting; cookieless traffic and performance measurementUSA
ResendTransactional email deliveryUSA
StripePayment processing and billingUSA
PostHogProduct analytics — anonymous and cookieless until you accept (see Section 10)USA / EU
SentryError monitoringUSA
Intuit (QuickBooks)Integration data syncUSA
SquareIntegration data syncUSA
JobberIntegration data syncCanada / USA

This list may be updated as the service evolves. Material changes to our sub-processors will be reflected in an updated version of this policy with a new effective date.

6. Data Retention and Deletion

  • Active accounts: Data is retained for as long as your account is active, subject to the reminder-history limits below
  • After cancellation: Your account data is retained for 30 days after cancellation to allow for reactivation, then permanently deleted
  • Synced data: Invoice and customer data synced from integrations is deleted within 30 days of account deletion or integration disconnection
  • Reminder wording: The subject line and message text of each reminder we send are deleted 12 months after it was sent. Reminder wording is generated from your templates, so this removes a stored copy rather than the ability to see what a reminder said.
  • Reminder records: The record of the send itself — the recipient address, which reminder in the sequence it was, the date, and whether it was delivered, bounced, opened or reported as spam — is kept for 36 months from the send date and then deleted. This is the shorter of what anti-spam law expects us to be able to evidence and how long a complaint can be raised, and it is what lets us show that a given reminder was legitimate.
  • Opt-out records: Never expire on their own. See Section 7.

6a. Deleting your account

You can delete your account yourself, without asking us. Sign in, open Settings, and use Delete this account at the bottom of the page. You will be asked to type a confirmation phrase, and only the account owner can do it.

Deletion is scheduled 7 days out, not immediate, and we do that on purpose: your invoice records are what you chase payment with, and there is no way for you to restore them yourself if the request was a mistake. Your account carries on working normally during those 7 days, and you can cancel from the same page at any point before the date shown there. We email you when a deletion is scheduled, so you find out even if you were not the person who requested it.

On the scheduled date the following are permanently erased from our live systems: your clients and their contact details, your invoices, your full reminder history, your business settings and email templates, your do-not-send list, any connected-integration records and access tokens, and your organisation record itself.

Two things are deliberately not covered by that automated step, and we would rather say so than imply otherwise:

  • Your sign-in record — your email address and hashed password held by our authentication provider — is removed by us separately, by hand, shortly afterwards. You lose all access to the account and to every record above on the scheduled date regardless, because the account it belonged to no longer exists.
  • A minimal record that the deletion happened is kept, because a deletion we cannot evidence is not much use to you if you are ever asked to demonstrate it (see our Data Processing Addendum). It contains only: the internal random identifier of the deleted account, the internal random identifier of the person who requested it, the date requested and the date executed, a count of how many records in each category were removed, and a keyed one-way fingerprint of the requesting email address so we can match a later enquiry without keeping the address itself. It contains no business name, no client name, no email address in readable form, no invoice, and no message content.

About backups. Deletion removes your data from our live systems on the scheduled date. Our database provider also holds its own encrypted infrastructure backups on its own rotation; those age out automatically, we do not control their schedule, and we do not use them to restore a deleted account. If we ever had to restore a backup after a disaster, we would re-run any deletion that had already been executed.

You can also still just email us at hello@paynudge.xyz and we will do it for you.

7. Opt-Out and Unsubscribe (Your Clients' Rights)

Your clients — the individuals who receive automated payment reminders — have the following opt-out rights:

  • Email opt-out: Every automated reminder email includes an unsubscribe link. Clicking it immediately stops all future email reminders from that business. The opt-out is permanent until the business user reverses it.
  • SMS opt-out: SMS reminders are one-tap drafts the business sends from its own phone. Clients can reply “STOP” directly to the business at any time; the business honours the request and can mark the client as opted out in PayNudge so no further SMS drafts are generated.
  • Direct request: Clients may contact the business directly to request that reminders be stopped. Business users can opt out a client from that client’s page in their PayNudge account.

Opt-out records are retained for audit purposes to demonstrate compliance with anti-spam laws. We honour all opt-outs within 10 business days of receipt at the latest, though automated opt-outs take effect immediately.

To be precise about how that interacts with the retention limits in Section 6: opt-out and bounce records have no expiry and are never removed by our routine data clean-up. An opt-out list that expired would eventually let us email somebody who had already asked us to stop, which is the exact outcome it exists to prevent. Opt-out records are held against the email address rather than against a client record, so deleting and re-adding a client — or re-importing them from QuickBooks, Square, Jobber or Stripe — does not undo an unsubscribe. They are removed only when the business user deletes their whole account, which is an explicit instruction from the controller to erase everything.

8. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate data
  • Deletion: Delete your data (“right to be forgotten”). Available to business users directly in Settings — see Section 6a.
  • Portability: Your data in a machine-readable format. Available to business users directly in Settings — see below.
  • Restriction: Request that we restrict processing of your data
  • Objection: Object to processing based on legitimate interests
  • Opt-out of sale: We do not sell personal data. No opt-out is required.

8a. Downloading your data

If you are a business user, you do not need to ask us and you do not need to wait. Sign in, open Settings, and use Download your data. You can download, as many times as you like:

  • Your clients, with contact details, notes, and who has asked to stop receiving reminders (CSV)
  • Your invoices, with amounts, dates, status and reminder counts (CSV)
  • Your full reminder history, with recipient, date and delivery outcome (CSV)
  • Your business profile, settings, email templates and do-not-send list (CSV)
  • All of the above in a single JSON file, for moving to another system

The CSV files open directly in Excel, Numbers or Google Sheets. Two things are deliberately excluded, and the download says so on its own first page: reminder wording older than 12 months, which has already been deleted under Section 6; and the access tokens for your connected accounting apps, because those are credentials rather than personal data and a downloaded file is the wrong place for them.

To exercise any right that is not self-serve, or if you are one of our business users’ clients rather than a business user yourself, contact us at hello@paynudge.xyz. We will respond within 30 days.

9. Security

We implement industry-standard security measures to protect your data, including encryption in transit (TLS) and encryption at rest for all stored data. Access to production systems is restricted to authorised personnel. Integration tokens are stored encrypted and never exposed in client-side code.

No method of transmission over the internet or electronic storage is 100% secure. While we use commercially reasonable measures to protect your data, we cannot guarantee absolute security.

10. Cookies, Analytics, and Your Choices

10a. Essential cookies

When you sign in, we set a session cookie that keeps you logged in and protects the sign-in process. It is required for the service to function, so it is not covered by the cookie banner. Signing out clears it.

10b. Before you answer the cookie banner

Until you choose, our analytics provider’s software is not loaded in your browser at all. No analytics cookie is set, nothing is written to your browser’s local storage or session storage, and your browser makes no connection of any kind to our analytics provider — not even to look up its address.

What we do record is a short, fixed list of events sent to PayNudge’s own servers and forwarded from there. The identifier that groups those events into a single visit is a random value created fresh in the page’s memory. It is never written to your device, so it carries across pages as you browse and is destroyed the moment you reload or close the tab. We forward these events with profile creation switched off, so no profile exists for you inside our analytics provider’s systems — which means what is recorded before you answer cannot be joined to you afterwards, by us or by them.

What is recorded in that mode:

  • Pages viewed and pages left
  • A fixed list of named product events such as “signup started” or “tool generate success”, whose properties are limited to non-personal values such as a step name, a method, or a count
  • The site that referred you

Because the provider’s software is not running, there is in this mode no automatic capture of your clicks or form interactions, and no collection of your browser, device type, screen size, or campaign (utm_*) parameters.

Page addresses are stripped of their query string and fragment before being sent. A visit to /unsubscribe?token=abc is recorded only as /unsubscribe, so tokens, magic links, and anything else carried in a URL never reach our analytics provider.

Because these events are relayed by our servers rather than sent from your browser, your IP address is not passed on to our analytics provider; it is explicitly discarded rather than recorded, so no approximate location is derived from it in this mode. Our own servers receive your IP address as an unavoidable part of serving any web page, exactly as they do for every page you load.

10c. If you accept

Accepting is what loads PostHog into your browser, for the first time. From then on it stores identifiers in your browser’s local storage and in a first-party cookie (both named ph_<project key>_posthog) so that repeat visits are recognised as the same person, and it records the clicks, form interactions and device details described above that the anonymous mode does not. Your answer itself is stored in local storage as pn_cookie_consent. What was recorded before you accepted stays anonymous: the earlier in-memory visit identifier is discarded rather than joined to your new one, so accepting is not retroactive. Once you are signed in, your activity is linked to your PayNudge account’s internal identifier — a randomly generated UUID — and, where relevant, your organisation’s UUID. We never attach your name, email address, business name, or any of your clients’ details to analytics events.

To be precise rather than reassuring: that account identifier does not identify you on its own, but because we can match it back to your account it is pseudonymous personal data under the GDPR, not anonymous data. We treat it as personal data throughout this policy, including for the access and deletion rights described in Section 8.

10d. If you decline

Analytics stop entirely. No further events are captured — not from your browser, and not through our own servers either — and PostHog is never loaded on any page you visit from then on, so your browser makes no request to our analytics provider at all. Anything PostHog had previously stored is deleted immediately, and re-checked on every later page load: the ph_<project key>_posthog local storage entry, its matching cookie, the session-storage entry alongside them, and PostHog’s own opt-out record are all removed, and the link to your account identifier is discarded. Exactly one record remains in local storage, and only so that your refusal survives a page reload: pn_cookie_consent set to declined.

10e. Changing your mind

“Cookie preferences”in the footer of every page reopens the banner, so you can withdraw consent — or grant it — at any time, as easily as you gave it. The change takes effect immediately, without a page reload.

10f. Session recording is disabled

PayNudge does not record your screen, your mouse movement, or your keystrokes. Session replay is switched off in every environment, whether or not you accept analytics cookies.

10g. Other measurement

Our host, Vercel, provides aggregate traffic and page-performance measurement that does not use cookies. Because it stores no identifier on your device, it runs regardless of your analytics choice.

11. Children's Privacy

PayNudge is a business tool not intended for use by persons under 18. We do not knowingly collect personal data from minors.

12. International Transfers

Your data may be processed in countries outside your own, including the United States and Canada. Where we transfer personal data from the European Economic Area, we ensure appropriate safeguards are in place in accordance with GDPR requirements.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by updating the effective date at the top of this page. Continued use of the service after changes are posted constitutes your acceptance of the updated policy.

14. Governing Law

This Privacy Policy is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, without regard to conflict of law principles.

15. Contact Us

For privacy inquiries, data requests, or questions about this policy:

PayNudge (operated by Pavneet Singh, Ontario, Canada)
Email: hello@paynudge.xyz

For data processing agreements (GDPR Article 28), see our Data Processing Addendum.