Security & data access
Reecova reads your payment data to find and recover lost revenue. Software that touches revenue data should say precisely what it can and cannot do. This page is that statement.
Read-only, always
Reecova connects through Stripe OAuth with read-only permissions. It can see charges, invoices, subscriptions, and customers. It cannot create charges, issue refunds, or move money. Stripe enforces this at the API level, not us.
The free scan revokes itself
The scanner requests temporary access, reads 90 days of history, computes your report, and then deauthorizes its own connection. Results are kept for 24 hours so you can view your report, then expire.
Tokens are encrypted
OAuth tokens are encrypted at rest. All traffic between your browser, Reecova, and Stripe runs over TLS.
No card numbers, ever
Reecova never receives or stores full card numbers. Stripe returns only metadata: amounts, decline codes, card brand, and last four digits.
You can disconnect any time
One click in Settings disconnects your Stripe account, or revoke Reecova directly from your Stripe dashboard. Either way, access ends immediately.
SOC 2 in progress
SOC 2 compliance work is underway. Until it completes, this page states exactly what we do rather than pointing at a badge.
what the scan reads
Questions about data handling? security@reecova.io