Skip to main content
RecallStream
How it worksSourcesAPIPricingFAQAboutContact
Sign inStart free →
How it worksSourcesAPIPricingFAQAboutContact
Sign inStart free →

Privacy Policy

Last updated: June 23, 2026

RecallStream respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share information about you when you visit our website, create an account, or use the RecallStream service — a cross-agency product-recall feed and webhook API (the "Service").

Sole Proprietor (FOP) Kharchenko Yaroslav Oleksandrovych ("RecallStream", "we", "us", "our"), registered at Komunalna St 16, Hlukhiv, Sumy Oblast, 41400, Ukraine, is the data controller for personal data we process about our customers and website visitors.

When we process your watchlist configurations, webhook endpoint registrations, and recall event history on your behalf in the context of providing the Service, we act as a data processor. See our Data Processing Agreement for details of those processing activities.

This policy applies to all users of recallstream.com, the RecallStream application, and the RecallStream API. It does not apply to third-party websites or services linked from our platform.

Information You Provide

  • Account information: your name, email address, hashed password, time zone, and billing address where required for invoicing.
  • Billing information: payments are processed by Paddle, which acts as our Merchant of Record and is the data controller for the payment transaction. Paddle collects and processes your payment-card or wallet details, billing name, and billing country directly; we never see or store your full card number. From Paddle we receive only a subscription reference, your plan and subscription status, invoice metadata, and (where provided) your billing country for tax purposes. See Paddle's privacy notice for how Paddle handles payment data as an independent controller.
  • Service configuration: the watchlist entries (brand names, supplier names, keywords) you create; the webhook endpoint URLs you register; the API keys you generate (stored as hashed values — the full key is shown only once at creation).
  • Support communications: any messages, attachments, or feedback you send to our support team.

Collected Automatically

  • Usage data: pages visited, features used, API requests made (endpoint, timestamp, response code), events delivered to your webhooks.
  • Device and connection data: IP address, browser type and version, operating system, referring URL, and session duration.
  • Cookies and similar technologies: see our Cookie Policy for a full list.

From Third Parties

We receive subscription and payment-status updates from Paddle (our Merchant of Record) when your billing state changes — for example, when a payment succeeds, a subscription renews, or a chargeback is raised. We do not receive personal data from any social media platform — RecallStream does not connect to social networks.

We process your personal data on the following legal bases under GDPR Article 6:

  • Contract performance (Art. 6(1)(b)): to create and manage your account, provide the recall feed and webhook delivery service, process your subscription, and respond to support requests.
  • Legitimate interests (Art. 6(1)(f)): to improve the Service, detect and prevent abuse and security incidents, send product-related notifications, and maintain security and server logs.
  • Consent (Art. 6(1)(a)): to send marketing emails where you have opted in. Our website analytics (Plausible plus our own first-party event beacon) are cookieless and identifier-free — they store no identifier on your device and process only aggregate usage data — but you can still opt out at any time via the cookie banner. You may withdraw any consent at any time via Settings → Privacy, the cookie banner, or by emailing privacy@recallstream.com.
  • Legal obligation (Art. 6(1)(c)): to comply with applicable laws, respond to lawful requests from authorities, and retain billing records for statutory periods.

We do not sell, rent, or share your personal data for cross-context behavioural advertising. We share data only in the following circumstances:

  • Merchant of Record: Paddle (Paddle.com Market Ltd) is the seller of record for subscriptions and acts as an independent controller for payment data — it is not our subprocessor.
  • Subprocessors: we engage trusted providers to operate the Service: Hetzner (hosting and database backups, Germany), Cloudflare (CDN/DNS), Resend (transactional email), and Plausible (cookieless website analytics). The authoritative, up-to-date list — with each processor's role and location — is maintained in our DPA — Schedule 2. We enter into a GDPR Article 28 data-processing agreement with each subprocessor.
  • Professional advisers: lawyers, accountants, and insurers, under confidentiality obligations.
  • Authorities: when required by law, court order, or to protect the rights, property, or safety of RecallStream, our users, or the public.
  • Business successors: in the event of a merger, acquisition, or sale of assets, your data may transfer to the successor entity, which will be bound by this policy or a materially similar one.

We do not transmit your content or configuration to any third-party social platform. We do not use your watchlist definitions or recall alert history to train machine learning models. We are a read-only consumer of government recall APIs.

RecallStream is operated from Ukraine. If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, your personal data may be transferred to and processed in countries outside those regions, including Ukraine and the United States (via our subprocessors).

Where we transfer personal data from the EEA or UK to countries without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, and the UK International Data Transfer Addendum where applicable. You may request a copy of the relevant transfer mechanism by contacting us at privacy@recallstream.com.

We retain your personal data only as long as necessary for the purposes described in this policy or as required by law:

  • Account record: deleted immediately when you delete your account; residual copies in access-controlled backups are purged within 35 days.
  • Watchlists and recall events: retained until you delete them or close your account.
  • Billing records: retained for 7 years to comply with accounting and tax obligations.
  • Server and security logs: retained for up to 12 months.
  • Backups: purged within 35 days of the applicable data being deleted from our primary systems.

You can export your watchlists, events, and account data at any time from your account settings. The export downloads instantly as a JSON file — there is no waiting period.

Depending on your location, you may have the following rights regarding your personal data:

  • Access: request a copy of the personal data we hold about you.
  • Rectification: ask us to correct inaccurate or incomplete data.
  • Erasure: request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
  • Restriction: ask us to pause processing while a dispute is resolved.
  • Objection: object to processing based on legitimate interests.
  • Portability: receive your data in a structured, machine-readable format.
  • Withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting prior processing.
  • Complain to a supervisory authority: lodge a complaint with a data-protection supervisory authority, in particular in the EU member state of your residence or place of work, or with the UK Information Commissioner's Office (ICO).

To exercise any of these rights, use Settings → Privacy → Manage my data in your account, or email privacy@recallstream.com. We will respond within 30 days. We may ask you to verify your identity before processing your request.

California residents: please see our Do Not Sell or Share page for CCPA/CPRA rights. You also have the right to lodge a complaint with your supervisory authority.

We implement technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include TLS 1.2+ encryption in transit, passwords hashed with Argon2, role-based access controls, EU (Germany) hosting with production access restricted to the operator, and regular security reviews. If a personal-data breach is likely to result in a high risk to your rights, we will notify you and the competent supervisory authority as required by Articles 33–34 GDPR.

API keys (rr_…) are stored as one-way hashes, and webhook signing secrets (whsec_…) are encrypted (AES-256-GCM) at the application layer; neither is ever logged in plaintext. If you believe your account has been compromised, contact us immediately at security@recallstream.com. See our Security page for a full overview.

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact privacy@recallstream.com and we will delete it promptly.

The recall data displayed and delivered through RecallStream is sourced from public government APIs. The originating agencies — the U.S. Food & Drug Administration (openFDA), the U.S. Consumer Product Safety Commission (CPSC), the National Highway Traffic Safety Administration (NHTSA), and the European Commission Safety Gate — each have their own privacy policies governing their publication of recall notices.

US government recall data (openFDA, CPSC, NHTSA) is published as public-domain information. EU Safety Gate data is published under a Creative Commons Attribution 4.0 International (CC BY 4.0) licence.

EU Safety Gate attribution: EU Safety Gate data is sourced from the European Commission Safety Gate (RAPEX) and licensed under Creative Commons Attribution 4.0 International (CC BY 4.0).

Some recall notices may incidentally contain personal data — such as a firm representative's name — that the agency itself chose to publish as part of the official notice. RecallStream normalises and displays this data as received from the agency; we are not the originating controller of it.

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (if you have an account) and by updating the "Last updated" date at the top of this page. Continued use of the Service after changes become effective constitutes acceptance of the revised policy.

If you have questions about this policy or wish to exercise your privacy rights, please contact us:

  • Email: privacy@recallstream.com
  • Post: Sole Proprietor (FOP) Kharchenko Yaroslav Oleksandrovych, Komunalna St 16, Hlukhiv, Sumy Oblast, 41400, Ukraine

For general support enquiries, use support@recallstream.com. We aim to respond to all privacy requests within 30 days.

RecallStream

Cross-agency product-recall intelligence — normalized, near-real-time, developer-friendly.

Sole Proprietor (FOP) Kharchenko Yaroslav Oleksandrovych
Komunalna St 16, Hlukhiv, Sumy Oblast, 41400, Ukraine

Product

  • Pricing
  • API Docs
  • FAQ

Sources

  • openFDA
  • CPSC
  • NHTSA
  • EU Safety Gate
  • FSIS (coming soon)

Company

  • About
  • Contact
  • Security

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Refund Policy
  • Data Sources & Licensing
  • Acceptable Use
  • Do Not Sell / Share
  • Accessibility
  • DPA Overview

© 2026 RecallStream