PaymentReminder

PaymentReminder Privacy Policy

Last updated: August 3, 2026

1. Scope of this policy

PaymentReminder helps freelancers and small teams import accounts-receivable information, organize invoice follow-up, and send payment reminders from a Gmail or Google Workspace account they connect. This Privacy Policy explains how the official PaymentReminder hosted service (the “Service,” “we,” “us,” or “our”) collects, uses, stores, and shares information.

2. Information we collect

Account and contact information

We collect the email address used to sign in, your name, your PaymentReminder account name, reminder settings, and information you include when contacting us for support.

Invoice and customer information

When you connect Xero, we receive and store information needed to provide the Service. This can include connected-account identifiers, customer names and email addresses, invoice identifiers and numbers, invoice dates and due dates, amounts, currencies, payment status, invoice links, provider records, and synchronization or webhook events. You may also add customer contacts and assign them to invoice groups directly in PaymentReminder.

Google user data

When you connect Gmail, PaymentReminder requests your email address and the gmail.send permission. We store Google's stable account identifier, the connected email address, granted scopes, connection state, token expiry, and the encrypted OAuth access and refresh tokens Google provides. The tokens allow scheduled jobs to send reminders after you leave the Service.

The gmail.send permission lets PaymentReminder send email from the connected account. PaymentReminder does not request permission to read the connected mailbox and does not inspect or import mailbox content, labels, or read state.

When a reminder is due, PaymentReminder generates the recipient, sender, subject, and message body from your settings and invoice data and transmits that message to Google for delivery. We store the generated message content in the delivery ledger, including the sender, recipients, subject, and message body, alongside the invoice, reminder stage, date, status, provider message identifier, and any delivery error.

Technical information and cookies

We process ordinary technical information needed to operate and protect the Service, such as IP address, browser or device information, request times, and application logs. We use necessary cookies for sign-in sessions, pending authentication, security, and your selected time zone. PaymentReminder does not use these cookies for cross-site advertising.

3. How we use information

We use information to:

  • create and secure accounts and send one-time signup and sign-in codes;
  • connect, synchronize, and display invoice data from Xero;
  • organize customers by payment history and apply the reminder schedules you configure;
  • generate and send invoice reminders through the Gmail account you authorize;
  • show reminder history;
  • operate, troubleshoot, secure, and improve the Service; and
  • respond to support requests and comply with legal obligations.

We do not sell personal information or Google user data. We do not use Google user data for advertising, and we do not use it to train general-purpose artificial intelligence or machine learning models.

4. How we share information

We disclose information only as needed for the following purposes:

  • Connected services. We exchange account and invoice information with Xero when you ask us to synchronize it. We send reminder recipients and message content to Google through the Gmail API when you enable delivery.
  • Service providers. We may use hosting, database, email-delivery, monitoring, and security providers that process information for us under appropriate contractual and confidentiality obligations.
  • Legal and safety reasons. We may disclose information when reasonably necessary to comply with law or a valid legal request, investigate abuse, protect users, or defend the rights and security of PaymentReminder and others.
  • Business changes. Information may be transferred as part of a merger, financing, acquisition, reorganization, or sale of assets, subject to applicable law and the commitments in this policy.

Google and Xero process information under their own terms and privacy policies. We do not control messages after Google delivers them to sender or recipient mailboxes.

5. Google API Services User Data Policy

PaymentReminder’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular:

  • Google user data is used only to provide or improve the user-facing Gmail reminder feature.
  • We request only the Google permissions needed for that feature.
  • We do not sell Google user data or use it for advertising.
  • We do not transfer Google user data except to provide the feature you requested, with your consent; for security purposes; to comply with law; or as otherwise permitted by Google’s Limited Use requirements.
  • Humans do not read Google user data unless we have your affirmative agreement for support or security, doing so is necessary to comply with law, or the data has been aggregated and anonymized for permitted internal operations.

6. Data security

The official hosted Service uses HTTPS in production, access controls, and operational safeguards designed to protect information. OAuth access and refresh tokens for Gmail and Xero are encrypted before they are stored in the database, with encryption keys kept separately from database records. No security measure is perfect, and we cannot guarantee absolute security.

Independent operators are responsible for securing their own PaymentReminder installation, database, encryption keys, backups, mail service, and network configuration.

7. Retention, disconnection, and deletion

We retain account and invoice information while your account is active and for as long as reasonably needed to provide the Service, maintain security and business records, resolve disputes, or meet legal obligations. Retention periods may differ by category and context.

Disconnecting Gmail removes the stored Gmail access and refresh tokens, clears the stable Google identity from the active connection, and disables automatic reminders. Historical reminder delivery records, including outbound provider identifiers and connection snapshots, may remain so that the account has an accurate operational and audit history. You can also revoke access from your Google Account permissions. Revocation prevents future sending but does not recall messages already delivered through Gmail.

You may request account or personal-information deletion by contacting us. Some information may remain temporarily in backups or be retained where required for security, fraud prevention, legal compliance, or the establishment or defense of legal claims.

8. Your choices and rights

You can update reminder settings, disconnect connected services, and manage Gmail permission through your Google Account. Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of personal information, or object to certain processing. Contact us to make a request. We may need to verify your identity before acting.

9. Changes to this policy

We may update this policy as the Service or legal requirements change. We will update the date above and provide additional notice when a change is material and applicable law requires it.

10. Contact us

For privacy questions or requests, email [email protected].

Please also read the PaymentReminder Terms of Service.

Privacy Policy · Terms of Service