Solely to operate the Service: monitoring disputes, generating response evidence and rebuttal letters, submitting them to Stripe, showing your dashboard, and sending you service emails (dispute alerts, password resets, backups). We do not sell personal data and we do not use your data to advertise to anyone.
Rebuttal letters may be drafted by proprietary AI using the dispute details and the business information you provided. Generating a letter sends that content to a third-party AI infrastructure provider, which processes it under commercial terms that prohibit using it to train models. We do not use your data to train anything ourselves.
We share data with no one else, except where required by law.
One cookie: a signed session cookie that keeps you logged in. No analytics or advertising cookies, no cross-site tracking.
Account, workflow, and dispute data are retained while your account is active, because dispute history informs future cases. Encrypted database backups are kept on a rotating 14-day schedule. When you delete your account (or ask us to), we remove your data from the live database; it ages out of backups within the rotation window.
When we file evidence on your behalf we keep a copy of the case file we submitted, so that what was filed can be established later. It is not published, linked, or shown in your dashboard. There are exactly two ways to read it: request your data from us, which returns the case files as part of your export, or open the copy your payment processor holds on your own account. Deleting your account deletes ours.
All traffic is encrypted in transit (HTTPS). Passwords are hashed with scrypt; API keys are encrypted at rest; sessions are revoked when a password is reset; credential endpoints are rate-limited. No system is perfectly secure — report concerns to the address below.
You can access and update your business data in the dashboard at any time. Email us to request a copy or deletion of your data. Depending on where you operate, you may have additional statutory rights (e.g., GDPR/UK GDPR, CCPA); we will honor verified requests.
If this policy changes materially we will notify you by email or in the dashboard before the change takes effect.
The data controller for the information described above is Takeback LLC, a Kansas limited liability company. Contact us at support@takeback.cc.