Privacy Policy
Last updated: August 20, 2026
Who we are
DisputeStack is a tool that helps merchants prepare structured responses to Stripe payment disputes. The data controller is [to be completed by the operator], [to be completed by the operator]. For any privacy question or request, contact [to be completed by the operator].
Data we collect
We collect only what the product needs to work:
- Account data: your name, email address, and authentication credentials (managed by our authentication provider — we never store your password in plain text).
- Billing data: subscription status, plan, and payment details, processed by Stripe. We do not store full card numbers.
- Dispute content you enter:the details you type into a dispute packet. This can include a customer's email address, charge amounts, payment references, and your notes. You control what you enter.
- Usage data: the packets you generate and save, and basic counts used to enforce your plan limits.
How we use your data
- To provide the service: generate, save, and export your dispute packets.
- To generate a response draft, we send the dispute details you enter to OpenAI.
- To bill your subscription and enforce plan limits.
- To secure the service, prevent abuse, and meet legal obligations.
We do not sell your personal data, and we do not use it for advertising.
Third parties that process your data (subprocessors)
We rely on the following subprocessors. Each only receives the data it needs for its function.
| Provider | Purpose | Data handled |
|---|---|---|
| Supabase | Authentication, application database (Postgres), file/data storage | Account details, dispute packets, billing status, usage |
| Stripe | Subscription billing and payment processing for DisputeStack plans | Email, billing/payment details, subscription status |
| OpenAI | Generating the dispute response draft from the details you enter | The dispute details you submit for a packet (may include a customer email and charge details you enter) |
| Vercel | Application hosting and delivery | Request metadata; no dispute content stored at rest by the host |
Where your data is stored
Application data is stored in a managed Postgres database (Supabase). The application is hosted on Vercel. Specific hosting regions depend on your deployment configuration; confirm your project's region with the operator at [to be completed by the operator]. International transfers, where they occur, rely on the providers' standard contractual clauses.
How long we keep it
We keep your account and packet data for as long as your account is active. You can request deletion of your account and associated data at any time (see your rights below). Billing records may be retained as required for tax and accounting purposes.
Your rights
Depending on where you live (for example under GDPR or CCPA), you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. To exercise any of these, contact [to be completed by the operator]. You can also delete your account from within the app, which removes your account and packet data.
Changes to this policy
We may update this policy. Material changes will be reflected in the “last updated” date above, and where appropriate we will notify you.
This document does not constitute legal advice, and DisputeStack does not guarantee the outcome of any dispute.