Privacy policy
Last updated: July 15, 2026
Airdun (“Airdun”, “we”, “us”, or “our”) operates the Airdun automated payment-recovery service, including the Airdun app available on the Stripe App Marketplace (the “Service”). This Privacy Policy explains what data we process, why, and the choices and rights you have.
Airdun is operated by Louis Rapp EI, registered at 63 route de Laoureaux, 31590 Lavalette, France.
1. Who this policy is for
Airdun is a business-to-business service. Our direct customers are the businesses that connect their Stripe account to Airdun (the “Merchant”). In doing so, Airdun processes information about the Merchant's own end-customers (the “Customers”) solely to recover failed payments on the Merchant's behalf.
- For Merchants — Airdun acts as a data controller for account and billing data, and as a data processor for the Customer data it handles on the Merchant's instructions.
- For Customers — the Merchant remains the data controller; Airdun processes their data only as a processor, under the Merchant's authorization.
2. Data we process
When a Merchant connects Stripe, Airdun accesses only the data needed to detect and recover failed payments, including:
- Payment and subscription data — invoices, charges, payment attempts, failure reasons and codes, amounts, currency, subscription and plan details.
- Customer data — name, email, phone number, country, language, billing history and related metadata made available through Stripe.
- Recovery activity — messages sent, channels used, delivery status, and recovery outcomes generated by Airdun.
We do not collect or store full card numbers, CVCs, or complete bank details. Card data remains within Stripe's secure environment.
As for visitors of our website: airdun.com does not use advertising cookies or third-party trackers.
3. How we use data
Airdun uses this data for a single purpose: detecting failed payments and running a recovery plan on the Merchant's behalf. Specifically, to:
- open and enrich a recovery case when a payment fails;
- design and send a personalized, multi-channel recovery plan (email, SMS, WhatsApp, in-app);
- adapt messages to the Customer's situation, language and timezone;
- stop the sequence automatically once a payment is recovered;
- provide the Merchant with performance reporting on their own account.
We do not use this data for advertising, we do not sell it, and we do not use one Merchant's data to benefit another.
Where the GDPR applies, we process this data on the following legal bases: the performance of our contract with the Merchant and, for Customer data, the Merchant's documented instructions as data controller. Where relevant, we also rely on our legitimate interest in operating and securing the Service.
4. Data isolation and confidentiality
Each Merchant's data is logically isolated and accessible only to that Merchant. A Customer's data is never exposed to other Merchants or other Customers. Internal access is restricted to authorized personnel on a strict need-to-know basis, protected by access controls and authentication. Any aggregated insights used to improve the Service are derived without exposing identifiable Merchant or Customer data across accounts.
5. Sharing with third parties
We share data only with the service providers strictly necessary to operate the Service, under contractual confidentiality and data-protection obligations:
- Stripe — payment and subscription data source.
- Messaging providers — to deliver recovery messages: Postmark and Loops (email), Twilio (SMS, WhatsApp).
- Cloud hosting — Google Cloud, hosted in the European Union (Paris region).
- AI message generation — Anthropic, used solely to draft recovery message content.
- Monitoring and analytics tools — used to operate and improve the Service, under the same confidentiality obligations.
We do not sell or rent personal data to anyone.
6. Data security
We protect data using industry-standard measures: encryption in transit and at rest, with an additional layer of application-level encryption for sensitive credentials.
Authentication is delegated to a dedicated identity provider — we never store passwords. Each workspace's data is accessible only to its members: membership is verified server-side on every request, and role-based permissions (owner, administrator, member) determine what actions are allowed.
7. Data retention and deletion
We retain data only as long as needed to provide the Service. If a Merchant disconnects the Airdun app from Stripe or closes their account, we delete the associated Customer and payment data within 30 days, except where retention is required by law (e.g. accounting or tax obligations). Merchants and Customers may also request deletion of their data at any time (see Section 8).
8. Your rights
Depending on your location, you may have the right to access, correct, delete, restrict, or object to the processing of your personal data, and to data portability. Customers should contact the Merchant they interact with; Airdun will support any such request. To exercise your rights or ask a question, contact us at hello@airdun.com.
You also have the right to lodge a complaint with your data protection authority — in France, the CNIL (www.cnil.fr).
9. International transfers
Our data is hosted in the European Union (Google Cloud, Paris region). Where certain providers process data outside the EU, we rely on appropriate safeguards such as Standard Contractual Clauses.
10. Changes to this policy
We may update this policy from time to time. Material changes will be posted on this page with an updated “Last updated” date.
11. Contact
Louis Rapp EI
63 route de Laoureaux, 31590 Lavalette, France
Email: hello@airdun.com