Legal

Privacy Policy

Last updated: 7 July 2026

This policy explains what personal data UntilPaid collects, why, and what rights you have over it. It’s written to meet the GDPR, the UK GDPR, and the Czech Act No. 110/2019 Coll. on the Processing of Personal Data. We’ve kept it as plain as we can.

The person responsible for your data (the “data controller” for the purposes of this policy) is Jonas Vondracek, an individual established in the Czech Republic. [Add your IČO here once you have a trade licence or company registration.] Because we are established in the EU (the Czech Republic), an Article 27 EU representative is not required. We have not appointed a UK representative at this stage; we will revisit this if usage from the UK grows.

1. Two hats: controller and processor

It matters which role we’re playing:

2. What we collect

Data you give us or that comes from Stripe

Data we generate

Your clients’ data (as processor)

To do its job the service also handles your clients’ names, email addresses, phone numbers, and invoice details, read from Stripe. We process that only to run your follow-ups. See the DPA.

3. Why we use it, and our legal basis

Under the GDPR we need a lawful basis for each use. Here’s ours:

What we doLegal basis
Provide the service, run your account, and take paymentPerformance of our contract with you
Keep the service secure, prevent abuse, and troubleshootOur legitimate interests in running a safe, reliable service
Send you essential service messages (e.g. a failed-reminder alert, security notices)Performance of our contract / legitimate interests
Improve the product and understand how it’s usedLegitimate interests (balanced against your privacy)
Send you marketing (if we ever do)Your consent, which you can withdraw at any time
Comply with legal, tax, and accounting obligationsLegal obligation

Where we rely on legitimate interests, we’ve weighed them against your rights, and you can object (see Your rights).

4. Cookies

We keep this simple: we only use cookies that are necessary for the app to work. We don’t use advertising or cross-site tracking cookies.

NamePurposeType
lic_sessionKeeps you signed in after you connect StripeEssential · ~30 days
lic_csrfProtects against cross-site request forgeryEssential · ~30 days
lic_themeRemembers light/dark preference (stored in your browser)Preference

Because these are strictly necessary (or a preference you set), they don’t require a consent banner under the EU ePrivacy rules as implemented in the Czech Republic by Act No. 127/2005 Coll., on Electronic Communications (which requires consent only for cookies that aren’t strictly necessary). You can clear them in your browser at any time, though signing in won’t work without the session cookie.

5. Who we share it with

We don’t sell your data. We share it only with the service providers we need to run UntilPaid, and only for that purpose. Each is bound by a contract to protect it.

ProviderWhat for
StripeReading your invoice and customer data (via Stripe Connect)
PolarSelling and billing paid plans as merchant of record; collecting and remitting VAT/sales tax
PostmarkSending reminder emails and receiving bounce/complaint notices
TwilioSending reminder SMS and handling opt-outs
RailwayHosting the application, database, and job queue
PostHogProduct analytics and error reporting (EU Cloud, hosted in Germany; cookieless on our website — nothing is stored on your device, and we scrub email addresses and phone numbers before anything is sent)

We may also disclose data if the law requires it, to protect our rights or someone’s safety, or as part of a merger or sale of the business (in which case we’ll tell you).

6. International transfers

Some of our providers process data in the United States — Stripe, Polar, Postmark, Twilio, and (depending on the deployment region) Railway. When personal data is transferred outside the EEA/UK, we rely on an appropriate safeguard: the EU–U.S. Data Privacy Framework where the provider is certified under it, and otherwise the European Commission’s Standard Contractual Clauses (with the UK addendum) — so your data keeps an equivalent level of protection. You can ask us for details.

7. How long we keep it

8. How we protect it

We take security seriously and use measures appropriate to the risk, including: encryption in transit (HTTPS); encryption at rest for the sensitive secrets we store (such as connection tokens and provider credentials); signed, verifiable webhooks; access controls and least-privilege access to production systems; and validated, origin-checked requests to guard against forgery. No system is perfectly secure, but we work to keep the risk low, and we’ll notify you and the relevant authority of a personal-data breach where the law requires.

9. Your rights

If the GDPR or UK GDPR applies to you, you have the right to:

To exercise any of these, email [email protected]. We’ll respond within the time the law allows (usually one month). You won’t be charged, and we won’t treat you differently for asking. If you’re unhappy with how we’ve handled your data, you can complain to your local data-protection authority — for us, the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, ÚOOÚ, uoou.gov.cz) — but we’d appreciate the chance to put things right first.

If you’re one of our customers’ clients and want your data changed or removed, please contact that business (the controller). We’ll help them act on your request.

10. Children

The service is for businesses, not for children. We don’t knowingly collect data from anyone under 16. If you believe a child has given us data, contact us and we’ll delete it.

11. Changes

We may update this policy as the service or the law changes. We’ll post the new version here and update the date at the top; if a change is significant, we’ll tell you directly.

12. Contact

For any privacy question, email [email protected]. The controller is Jonas Vondracek, Czech Republic. We have not appointed a Data Protection Officer, as one is not required for processing on this scale.