Skip to main content
Recurr is pre-scale, so compliance review should be direct about what is formalized today and what is handled by architecture and vendor posture.

Payment compliance

Recurr runs on the customer’s payment rail. Stripe is the default rail and owns the payment processing environment for Stripe transactions. Paddle can be scoped where merchant-of-record coverage is needed. Recurr does not ask customers to route card data through Recurr-owned card-processing infrastructure.

Store-policy posture

The default migration path uses out-of-app communication and web checkout. The app binary is not changed for the migration path. See Apple policy posture and Google Play policy posture.

Privacy and data

Recurr processes subscriber and subscription data needed for migration, Oikos motions, reporting, and support. The DPA documents processing purposes, subprocessors, retention, and deletion.

SOC 2 and formal assurance

If formal certifications are not yet complete, Recurr provides the current security posture, subprocessor list, architecture overview, and DPA for customer review. Recurr docs are product and operating documentation. Customers should rely on their own legal, tax, and compliance advisors for jurisdiction-specific obligations.