Skip to content

Privacy Policy

What Stopee does with the subscription, billing and letter data in your dashboard, who else sees it, how long we keep it and what you can demand.

1. Stopee is the controller of your data

https://www.stopee.com is published by Stopee Solutions Limited (C 114787), whose registered office is at . That company is the data controller for every piece of personal data described here.

Anything you want to ask, correct or contest goes to [email protected].

This page sets out what Stopee does with your personal data, where it goes and what you can require of us. Three sets of rules govern it:

  • Regulation (EU) 2016/679 (GDPR), for users located in the European Union;
  • Law No. 78-17 as amended (Data Protection Act), for France;
  • the Personal Data Protection Law (PDPL) applicable in Malta.

2. What we see when you add a subscription and cancel it

Only what the dashboard, the letters and the billing actually need. Five groups:

Who you are
Surname, first name, email address, phone number, country and the postal address we print on the cancellation letter as the sender, so the merchant can identify the account being closed.
Your account
Username, encrypted password, subscription history and invoices.
Your card
The card number and the banking data behind it are handled solely by our payment provider, Stripe. Stopee never has access to them.
What you do in the dashboard
The documents you upload, the templates you create, the sender and recipient addresses on each letter, your sending history and the tracking that comes back as proof.
Technical traces
IP address, device type, browser, server logs, plus analytical and security cookies.

Card and banking details travel from the payment form straight to Stripe and are never stored on our side.


3. Why we hold it, and what entitles us to

Your data is processed for these purposes and no others:

  • supplying the service, meaning the drafting, printing and dispatch of your cancellation letters;
  • running your customer account and billing you;
  • preventing fraud and securing payments;
  • answering you when you contact support;
  • improving the site and measuring how the service performs;
  • meeting legal obligations on invoicing, anti-money laundering and accounting records;
  • sending you administrative or contractual messages about the service;
  • handling requests to exercise rights under the GDPR and the PDPL.

Each rests on one of four legal bases: performance of the contract, for use of the service, order processing and billing; your consent, for account creation, cookies and marketing; a legal obligation, for invoices and record keeping; our legitimate interest, for fraud prevention and improving the service.


4. Who else touches it

Stopee neither sells nor rents personal data. It is passed on in four situations only:

  • to technical suppliers responsible for hosting, routing, printing and customer support;
  • to the payment provider, Stripe;
  • to carriers and postal operators, so that the letter can actually be delivered;
  • to an administrative or judicial authority, where the law compels us.

Every subprocessor is held to strict confidentiality and security commitments in writing.

The processors we rely on

  • Stripe Payments Europe Ltd. for payment processing;
  • OVHcloud (OVH SAS) for hosting;
  • Google LLC for audience measurement (GA4);
  • the postal service, for printing and posting your letters;
  • OpenAI and equivalent AI APIs, which draft the wording of a letter and retain no personal data once the text is returned.

We use Stripe for payment, analytics, and other business services. Stripe collects identifying information about the devices that connect to its services. Stripe uses this information to operate and improve the services it provides to us, including for fraud detection. You can learn more about Stripe and read its privacy policy at https://stripe.com/privacy.


5. Where it sits, and when it crosses a border

Your data lives on secured OVHcloud (OVH SAS) servers inside the European Union, in Lithuania and the Netherlands.

Backups, technical operation and support work may take place in Malta, which means a transfer there. Every such transfer is covered by the European Commission's Standard Contractual Clauses under Article 46 of the GDPR and the equivalent PDPL safeguards, so the level of protection follows the data.


6. How long we keep each thing

Nothing is kept longer than the purpose it was collected for requires.

CategoryMaximum duration
Account datafor as long as the account is open, then 3 years after deletion
Billing data10 years, to satisfy accounting obligations
Data on letters sentthe length of the subscription, then 6 months
Technical data and logs12 months
Analytical cookies13 months at the outside

The documents and files you uploaded are erased automatically when the subscription ends or the account is closed.


7. How it is protected

Stopee applies technical and organisational measures meeting international standards: SSL/TLS encryption, hashed passwords, firewalling, activity logging, separated environments, tightly restricted access rights and internal security audits.


8. Some cookies you can refuse, one set you cannot

The site uses three kinds of cookie:

  • technical cookies, without which the service does not work;
  • analytical cookies (Google Analytics 4), which measure audience;
  • functional cookies, which remember your language and preferences.

You control them from the consent banner or your browser settings. Refuse the technical ones and the service stops being reachable.


9. What you can demand, and how fast you get it

Under the GDPR and the PDPL you hold the following rights:

  • to obtain a copy of your data;
  • to have it corrected;
  • to have it erased, the so-called right to be forgotten;
  • to have its processing restricted;
  • to object to processing;
  • to receive it in a portable form and export it;
  • to leave instructions on what happens to it after your death (EU only).

Send the request to [email protected]. You will have an answer within 30 days at the latest. We may ask for an identity document first, because releasing an account's history to the wrong person cannot be undone.


10. If you think we have got it wrong

Start with [email protected], which takes both questions about this policy and requests to exercise your rights.

If our answer does not satisfy you and you are in the European Union, you may complain to the data protection authority of your own country, without needing our agreement.


11. When this policy changes

Stopee may amend this policy at any time. The version that binds us is the one published on the site on the day you read it. Where a change is substantial, you will be told by email or through a notice in your customer account.