Privacy policy
Introduction
Reminder (“we”, “our”, or “us”) operates usereminder.com, a platform that helps businesses follow up on unpaid invoices by sending payment reminder emails on their behalf. This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, and the rights you have over it.
Two groups of people are covered by this policy: our customers (the businesses with a Reminder account) and our customers' invoice recipients (the people whose contact details appear on invoices uploaded to Reminder). If you received a payment reminder sent through our platform, see the section “If you received a reminder email”.
Our role: controller and processor
For account data — the information our customers give us when they sign up and use the platform — Reminder is the data controller.
For invoice and recipient data — the customer names, email addresses, amounts, and documents our customers upload — Reminder acts as a data processor. Our customer remains the controller of that data and decides who receives reminders and when. We process it only on their instructions and under this policy.
Information we collect
Account information
When a business creates an account we collect the account holder's name, work email address, company name, and a password (stored only as a salted hash — we never store plain-text passwords). UAE businesses may also provide a Trade Registration Number (TRN).
Invoice and recipient data
To provide the service, we process the invoice data our customers upload: recipient business names, contact names, email addresses, phone numbers, invoice numbers, amounts, currencies, due dates, and the invoice documents (PDFs) themselves. This data is used solely to send and track payment reminders on the uploading customer's behalf.
Email delivery data
When reminders are sent we record delivery events — sent, delivered, opened, clicked, bounced, complained, unsubscribed — so our customers can see whether their reminders arrived, and so we can stop sending to addresses that opt out or bounce.
Bank account data (optional)
Customers can connect a business bank account through Tink, a licensed open-banking provider, so incoming payments can be matched to invoices. We receive read-only transaction data (dates, amounts, payment references, counterparty names). We never see or store online-banking credentials; access tokens are stored encrypted (AES-256-GCM) and the connection can be revoked at any time.
Payment and billing data
Subscription payments are handled by Stripe. We do not store full card numbers; Stripe shares with us only what we need to manage the subscription (such as plan, billing status, and the last four digits of the card).
Usage and technical data
We automatically collect log and usage information — pages visited, features used, IP address, browser type, and error reports — to keep the platform secure and improve it.
AI-assisted invoice processing
When a customer uploads an invoice PDF, we use Anthropic's Claude API to read the document and extract structured data (invoice number, amounts, dates, recipient details). The document content is sent to Anthropic for this purpose only.
Under our API agreement, Anthropic does not use data submitted through the API to train its models. Extracted data is shown to the uploading customer for review before anything is sent.
How we use personal data
We use the data described above to:
- Send invoice payment reminders on our customers' behalf
- Extract invoice data from uploaded documents
- Match incoming bank payments to open invoices
- Track email delivery and honour unsubscribe requests
- Operate accounts, billing, and customer support
- Secure the platform, prevent abuse, and debug errors
- Comply with legal obligations
We do not sell personal data, and we do not use our customers' invoice or recipient data for advertising or to train AI models.
Legal bases (GDPR)
Where the EU/EEA General Data Protection Regulation applies, we rely on:
- Contract — processing needed to provide the service to our customers (account, invoice, and delivery data)
- Legitimate interests — platform security, fraud prevention, service improvement, and our customers' interest in collecting payment for invoices they have issued
- Legal obligation — tax, accounting, and record-keeping requirements
- Consent — where required, for example optional analytics cookies
Service providers and subprocessors
We use a small number of service providers to run Reminder. Each processes data only to provide their service to us, under a data processing agreement:
- Supabase — database hosting (PostgreSQL, AWS ap-southeast-1, Singapore)
- Vercel — application hosting (functions in Dublin, EU)
- Resend — email delivery for payment reminders
- Anthropic — AI extraction of data from uploaded invoice PDFs
- Amazon Web Services — storage of uploaded invoice documents (S3)
- Tink — open-banking connections for payment matching (EU-licensed)
- Stripe — subscription billing and payment links
- Sentry — error monitoring
Beyond these providers, we disclose personal data only when required by law, to protect our legal rights, or as part of a merger, acquisition, or sale of assets (in which case this policy continues to apply to the transferred data).
International transfers
Our application runs in the EU (Dublin) and our database is hosted in Singapore, with other providers operating in the EU and the United States. Where personal data of EU/EEA residents is transferred outside the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and, for US providers, the EU–US Data Privacy Framework where the provider is certified.
Data security
All data is encrypted in transit (TLS) and at rest. Passwords are hashed with bcrypt. Bank connection tokens are encrypted with AES-256-GCM. Access to production data is limited, and each customer's data is isolated from every other customer's. No method of transmission or storage is completely secure, but we review and improve our safeguards on an ongoing basis, and we will notify affected customers and authorities of a personal data breach where the law requires it.
Data retention
We keep personal data only as long as we need it for the purposes above:
- Account and invoice data — for as long as the account is active. When an account is closed, data is deleted or anonymised within 90 days, except where we must keep records for tax or accounting law.
- Email delivery logs — retained while the account is active to provide reporting and prove compliance with opt-out requests.
- Unsubscribe and suppression records — kept for as long as the account that sent the emails exists, because we need them to make sure an opted-out address is never emailed again.
Customers can delete individual invoices and remove recipients at any time, and can close their account by contacting us — we delete or anonymise the account's data when we close it.
Your rights
Depending on where you live (and in particular under the GDPR), you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Have your data deleted (“right to be forgotten”)
- Restrict or object to certain processing
- Receive your data in a portable format
- Withdraw consent where processing is based on consent
- Complain to your data protection authority — for the Netherlands, the Autoriteit Persoonsgegevens
To exercise any of these rights, email privacy@usereminder.com. We respond within one month. If your data was uploaded by one of our customers, we may refer your request to them (as controller) and will help them respond.
If you received a reminder email
A business you have an invoice with uses Reminder to send its payment follow-ups. That business chose to contact you and provided your details; we sent the email on its behalf.
- Every reminder includes an unsubscribe link. Using it stops all further reminder emails to your address from that business through Reminder, immediately and permanently (unless you resubscribe).
- Questions about the invoice itself — the amount, the goods or services, or a dispute — should go to the business that sent it.
- Questions about how your data is handled on our platform can go to privacy@usereminder.com.
Children
Reminder is a business-to-business service and is not directed at anyone under 18. We do not knowingly collect data from children.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the new version on this page, update the “Last updated” date, and notify account holders by email of any material change before it takes effect.
Contact us
Questions about this Privacy Policy or our data practices: privacy@usereminder.com