Privacy Policy
Last updated July 18, 2026
Contents
- 1. WHAT INFORMATION DO WE COLLECT?
- 2. HOW DO WE PROCESS YOUR INFORMATION?
- 3. WHAT LEGAL BASES DO WE RELY ON?
- 4. WHEN AND WITH WHOM DO WE SHARE YOUR INFORMATION?
- 5. DO WE USE ARTIFICIAL INTELLIGENCE?
- 6. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?
- 7. HOW LONG DO WE KEEP YOUR INFORMATION?
- 8. HOW DO WE KEEP YOUR INFORMATION SAFE?
- 9. DO WE COLLECT INFORMATION FROM MINORS?
- 10. WHAT ARE YOUR PRIVACY RIGHTS?
- 11. CONTROLS FOR DO-NOT-TRACK FEATURES
- 12. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
- 13. DO WE MAKE UPDATES TO THIS NOTICE?
- 14. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
- 15. HOW CAN YOU REVIEW, UPDATE, OR DELETE YOUR DATA?
This notice describes how Foxhound ("we," "us," "our") collects, uses, and shares information when a merchant connects a Stripe account and when that merchant's customers interact with recovery emails and hosted pages Foxhound sends on the merchant's behalf.
Summary of key points
This summary covers the key points from our Privacy Policy below. Use the contents list above to jump to the full detail on any topic.
- What information do we collect? Merchant Stripe data (invoices, subscriptions, disputes, customer records) through a Stripe OAuth connection, plus first-party engagement signals we generate ourselves, whether a recovery email was opened or clicked, never a third-party tracking vendor.
- Do we use artificial intelligence? Yes, to draft recovery email copy and dispute evidence. Dispute evidence always requires a human on the merchant's team to review and approve before it reaches Stripe.
- Who do we share information with? Only the infrastructure providers that run the Services: Stripe, Cloudflare, and Anthropic. We do not sell personal information or share it for anyone else's marketing.
- How long do we keep information? Engagement events and email sends for 180 days, webhook and AI call logs for 90 days, billing records for as long as the account stays active.
- How do we keep information safe? Stripe access is limited to a short list of actions, no card numbers are stored, and sensitive tokens are encrypted at rest with AES-256.
- What are your rights? Merchants can review and update account data in Settings, and can request deletion by contacting us. A merchant's customers should contact that merchant directly.
- Is information transferred internationally? Foxhound is a US company under US jurisdiction; Cloudflare Workers may process a request at an edge location outside the US as ordinary delivery, but our data stores and governing law are US-based.
1. WHAT INFORMATION DO WE COLLECT?
From merchants: account and contact information, and the Stripe data your OAuth connection grants us access to, invoices, subscriptions, disputes, and customer records needed to run recovery sequences and dispute drafts.
From merchants' customers: information Stripe already has about a failed payment (name, email, decline reason), plus first-party engagement signals we generate ourselves, whether a recovery email was opened or a link in it was clicked, recorded through our own tracking routes rather than a third-party vendor.
2. HOW DO WE PROCESS YOUR INFORMATION?
We process information to run recovery sequences (silent retries, then email sequences), draft dispute evidence for human review and approval, compute MRR and churn analytics, bill matured recoveries, and operate the product generally (authentication, support, fraud prevention).
3. WHAT LEGAL BASES DO WE RELY ON?
We process merchant data under contract, to provide the Services the merchant signed up for. We process a merchant's customer data as a processor acting on the merchant's instructions; the merchant, not Foxhound, is the data controller for their own customers and is responsible for having an appropriate legal basis and privacy notice of their own.
4. WHEN AND WITH WHOM DO WE SHARE YOUR INFORMATION?
We share data with the infrastructure providers that run the Services: Stripe (payments and Connect), Cloudflare (hosting, database, and email delivery), and Anthropic (drafting recovery email copy and dispute evidence, see the AI section below). We do not sell personal information, and we do not share merchant or customer data with anyone for their own marketing purposes.
5. DO WE USE ARTIFICIAL INTELLIGENCE?
Yes. Foxhound uses AI models to draft recovery email copy and dispute evidence. Recovery copy passes an automated quality check before it sends. Dispute evidence always requires a human on the merchant's team to review and approve it before it is submitted to Stripe, there is no automatic submission path. AI drafting uses the decline or dispute data needed to write the draft; it is not used to build advertising profiles.
6. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?
Foxhound is a US company operating under US jurisdiction. The Services run on Cloudflare Workers, a global network, so requests may be processed at an edge location outside the United States as part of ordinary delivery, but the company itself, its data stores, and its governing law are US-based.
7. HOW LONG DO WE KEEP YOUR INFORMATION?
We keep raw engagement events (opens and clicks) and email send records for 180 days, then delete them. Webhook event logs and AI call records are kept for 90 days. Billing records (invoices, line items, the evidence ledger) are kept for as long as the account is active, since they are the record of what was billed and why.
8. HOW DO WE KEEP YOUR INFORMATION SAFE?
The Stripe OAuth connection carries read and write scope, because retrying a failed invoice is a write. Foxhound uses the write half for three things and no others: retrying payment on an invoice that has already failed, setting a customer default payment method after that customer updates their card, and submitting dispute evidence once someone on your team has approved it. It never changes prices, products, or subscription plans, never creates a charge outside an invoice you already issued, and never reaches your payouts or bank account. Foxhound never stores card numbers. Sensitive tokens are encrypted at rest with AES-256. Access to production data is limited to what the Services need to run.
9. DO WE COLLECT INFORMATION FROM MINORS?
The Services are intended for business use and are not directed at anyone under 18. We do not knowingly collect information from minors.
10. WHAT ARE YOUR PRIVACY RIGHTS?
Merchants can review and update their account data from Settings at any time. Deletion is by request rather than self-serve: contact us and we will confirm what will be deleted and what we are required to keep. Section 15 sets out that process. A merchant's customers should contact that merchant directly, Foxhound processes their data on the merchant's instructions and is not the right party to field an end-customer request directly.
11. CONTROLS FOR DO-NOT-TRACK FEATURES
There is no uniform standard for Do-Not-Track signals yet, so the Services do not currently respond to them differently.
12. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
Depending on your state, you may have rights to access, correct, or delete personal information we hold about you, or to opt out of certain processing. Contact us at support@foxhoundapp.com to make a request; we will respond consistent with applicable state law.
13. DO WE MAKE UPDATES TO THIS NOTICE?
Yes. We will update this notice as needed to stay compliant with relevant laws, and we will update the date at the top of this page when we do.
14. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
Email support@foxhoundapp.com. See also our Terms of Service.
15. HOW CAN YOU REVIEW, UPDATE, OR DELETE YOUR DATA?
Merchants can review and update account information from Settings at any time. To request deletion of an account and its associated data, email support@foxhoundapp.com; we will confirm what will be deleted and what, if anything, we are required to retain (for example, billing records tied to fees already charged).