legal_

Privacy policy

Last updated: July 15, 2026

Airdun (“Airdun”, “we”, “us”, or “our”) operates the Airdun automated payment-recovery service, including the Airdun app available on the Stripe App Marketplace (the “Service”). This Privacy Policy explains what data we process, why, and the choices and rights you have.

Airdun is operated by Louis Rapp EI, registered at 63 route de Laoureaux, 31590 Lavalette, France.

1. Who this policy is for

Airdun is a business-to-business service. Our direct customers are the businesses that connect their Stripe account to Airdun (the “Merchant”). In doing so, Airdun processes information about the Merchant's own end-customers (the “Customers”) solely to recover failed payments on the Merchant's behalf.

  • For MerchantsAirdun acts as a data controller for account and billing data, and as a data processor for the Customer data it handles on the Merchant's instructions.
  • For Customersthe Merchant remains the data controller; Airdun processes their data only as a processor, under the Merchant's authorization.

2. Data we process

When a Merchant connects Stripe, Airdun accesses only the data needed to detect and recover failed payments, including:

  • Payment and subscription datainvoices, charges, payment attempts, failure reasons and codes, amounts, currency, subscription and plan details.
  • Customer dataname, email, phone number, country, language, billing history and related metadata made available through Stripe.
  • Recovery activitymessages sent, channels used, delivery status, and recovery outcomes generated by Airdun.

We do not collect or store full card numbers, CVCs, or complete bank details. Card data remains within Stripe's secure environment.

As for visitors of our website: airdun.com does not use advertising cookies or third-party trackers.

3. How we use data

Airdun uses this data for a single purpose: detecting failed payments and running a recovery plan on the Merchant's behalf. Specifically, to:

  • open and enrich a recovery case when a payment fails;
  • design and send a personalized, multi-channel recovery plan (email, SMS, WhatsApp, in-app);
  • adapt messages to the Customer's situation, language and timezone;
  • stop the sequence automatically once a payment is recovered;
  • provide the Merchant with performance reporting on their own account.

We do not use this data for advertising, we do not sell it, and we do not use one Merchant's data to benefit another.

Where the GDPR applies, we process this data on the following legal bases: the performance of our contract with the Merchant and, for Customer data, the Merchant's documented instructions as data controller. Where relevant, we also rely on our legitimate interest in operating and securing the Service.

4. Data isolation and confidentiality

Each Merchant's data is logically isolated and accessible only to that Merchant. A Customer's data is never exposed to other Merchants or other Customers. Internal access is restricted to authorized personnel on a strict need-to-know basis, protected by access controls and authentication. Any aggregated insights used to improve the Service are derived without exposing identifiable Merchant or Customer data across accounts.

5. Sharing with third parties

We share data only with the service providers strictly necessary to operate the Service, under contractual confidentiality and data-protection obligations:

  • Stripepayment and subscription data source.
  • Messaging providersto deliver recovery messages: Postmark and Loops (email), Twilio (SMS, WhatsApp).
  • Cloud hostingGoogle Cloud, hosted in the European Union (Paris region).
  • AI message generationAnthropic, used solely to draft recovery message content.
  • Monitoring and analytics toolsused to operate and improve the Service, under the same confidentiality obligations.

We do not sell or rent personal data to anyone.

6. Data security

We protect data using industry-standard measures: encryption in transit and at rest, with an additional layer of application-level encryption for sensitive credentials.

Authentication is delegated to a dedicated identity provider — we never store passwords. Each workspace's data is accessible only to its members: membership is verified server-side on every request, and role-based permissions (owner, administrator, member) determine what actions are allowed.

7. Data retention and deletion

We retain data only as long as needed to provide the Service. If a Merchant disconnects the Airdun app from Stripe or closes their account, we delete the associated Customer and payment data within 30 days, except where retention is required by law (e.g. accounting or tax obligations). Merchants and Customers may also request deletion of their data at any time (see Section 8).

8. Your rights

Depending on your location, you may have the right to access, correct, delete, restrict, or object to the processing of your personal data, and to data portability. Customers should contact the Merchant they interact with; Airdun will support any such request. To exercise your rights or ask a question, contact us at hello@airdun.com.

You also have the right to lodge a complaint with your data protection authority — in France, the CNIL (www.cnil.fr).

9. International transfers

Our data is hosted in the European Union (Google Cloud, Paris region). Where certain providers process data outside the EU, we rely on appropriate safeguards such as Standard Contractual Clauses.

10. Changes to this policy

We may update this policy from time to time. Material changes will be posted on this page with an updated “Last updated” date.

11. Contact

Louis Rapp EI

63 route de Laoureaux, 31590 Lavalette, France

Email: hello@airdun.com