Legal
Privacy Policy
Last updated: 29 July 2026
Reclaim is a payment recovery product built by BuildNest Studio. This policy explains what information we collect when you use Reclaim, why we collect it, who we share it with, and the choices you have. It covers two different groups of people: businesses who sign up to use Reclaim (“account holders”), and the customers of those businesses who receive recovery messages (“end customers”).
1. Information we collect from account holders
When you sign up and use Reclaim, we collect:
- Account details — your name and email address, via our authentication provider, Auth0.
- Company information — the business/company name you provide during onboarding.
- Your Paystack secret key — provided by you so Reclaim can read your transaction history. This key is encrypted (AES-256-GCM) before it is stored, and is never exposed to your browser or any other user. We never see or store full card numbers.
2. Information we process about your customers
To detect and follow up on failed payments, Reclaim reads transaction data from your connected Paystack account. This can include your customers' email addresses, phone numbers, transaction amounts, and payment failure reasons. We do not collect this information directly from your customers — it comes from your Paystack account, because you have asked Reclaim to act on your behalf to recover these payments.
We use this information only to send a recovery SMS (a message notifying the customer that their payment failed, with a link to complete it) and to record whether that message was sent successfully. We do not use it for any other purpose, and we do not share it with anyone other than the SMS provider needed to deliver the message (see below).
3. How we use information
- To operate your account and authenticate you when you log in.
- To connect to your Paystack account and analyze failed transactions.
- To generate a fresh payment link and send a recovery SMS to your customer.
- To show you a history of recovery attempts in your dashboard.
- To respond if you contact us for support.
We do not sell personal data, and we do not use it for advertising.
4. Who we share information with
We use a small number of third-party services to run Reclaim. Each only receives the data it needs to do its job:
- Auth0 — authentication (login, session management).
- Supabase — our database, storing account, connection, and recovery-attempt records.
- Paystack — your own connected payment account, which we read from using the key you provide.
- Africa's Talking — delivers the recovery SMS to your customer's phone number.
- Vercel — hosts the Reclaim application.
We do not sell or share data with anyone beyond what's needed to provide the service described above.
5. Cookies
Reclaim uses one essential session cookie, set by Auth0, to keep you logged in. We do not currently use analytics or advertising cookies.
6. Data retention
We keep account and recovery-attempt data for as long as your account is active, so you can see your recovery history. If you close your account, we delete your Paystack connection and company information; recovery-attempt records may be retained for a limited period afterward for accounting and dispute purposes, then deleted.
7. Your rights
If you are an account holder, you can request access to, correction of, or deletion of your data at any time by emailing us below. If you are an end customer who received a recovery SMS and want your information removed from our systems, you can also contact us — we will pass on deletion requests to the relevant account holder as needed, since the underlying transaction data belongs to their Paystack account.
8. Changes to this policy
We may update this policy as Reclaim changes. We'll update the “Last updated” date above when we do.
9. Contact us
Questions about this policy, or requests about your data? Email hello@buildneststudio.com.