Legal
Privacy Policy
Last updated: September 15, 2026
This policy explains what D613 Labs ("we", "us") collects when you use the D613 Pay website, the free D613 Pay WordPress plugin, and the paid Auto-Verify service — and what we do with it. The short version: the free plugin sends us nothing unless you opt in to anonymous install statistics; Auto-Verify reads only the mailbox you connect, keeps only what it needs to confirm payments, and never sees card numbers or moves money.
1. The website (d613pay.d613labs.com)
Our web server keeps standard access logs (IP address, browser type, pages requested, timestamps) for security and troubleshooting, retained for up to 90 days. The site does not use advertising or cross-site tracking cookies. The account portal sets a session cookie so you stay signed in.
2. The free plugin
The free plugin runs entirely on your own website. It does not contact our servers to take or confirm payments. Customer and order data stay in your WordPress database and are never sent to us.
Optional install statistics. After activation the plugin asks once whether it may send anonymous usage statistics. If you decline, nothing is ever sent. If you allow it, the plugin sends a request to https://paycloud.d613labs.com/v1/telemetry/ping once on opt-in and then weekly, containing:
- a one-way hash of your site URL (we cannot recover the URL from it);
- the plugin version and WordPress/WooCommerce versions;
- which payment rails (Zelle, Venmo, PayPal, Cash App) are enabled and whether Auto-Verify is active.
No personal data, customer data or order data is included. We use these counts to understand how many stores use the plugin and which versions to support.
3. Auto-Verify: what we collect
Account and billing. When you start a trial we collect your name, email address and the store URL(s) you connect. Payment details are collected and stored by Stripe, our billing provider; we receive only a customer reference, the last four digits and expiry of your card, and your billing history. We never see your full card number.
License and pairing keys. The connector plugin on your store sends us its license key so we know which subscription it belongs to.
Mailbox connection. To read your payment alerts you give us the IMAP host, username and an app password (not your main account password) for the mailbox where your bank or payment app sends alerts. Credentials are encrypted at rest with a key held separately from the database and are used only to connect to that mailbox.
Email content. We connect to the mailbox in read-only mode and scan incoming messages for payment alerts from your bank, Zelle, Venmo, PayPal or Cash App. Messages that are not payment alerts are skipped and not stored. For each alert we keep the fields needed to confirm and audit a payment: sender, subject, date, amount, the memo/note text, the sender's name as shown by the payment app, and cryptographic authentication results (DKIM/DMARC). We do not read, store or use any other mail in the mailbox.
Order data from your store. Your store sends us the details needed to match alerts: order identifiers and numbers, order totals, the expected memo, and order status. It does not send us your customers' addresses, phone numbers or payment credentials.
Parser generation. If your bank is not already supported, Auto-Verify builds a custom parser from sample alert emails. When you enable auto-detection or paste samples, those sample messages are sent to an AI model hosted for us on Microsoft Azure to identify the email's structure. The samples are used only to build and test your parser; you review the result before it goes live.
Support. If you email us, we keep the correspondence so we can help you and refer back to it.
4. How we use it
- To provide the service: detect payment alerts, match them to orders, and tell your store which orders are paid.
- To keep an audit trail of every match and every order status change, so you and we can see exactly why an order was confirmed.
- To bill you, send receipts and service emails (trial ending, payment failed, unmatched-payment digests), and respond to support requests.
- To secure and improve the service, including investigating abuse and fixing parsers when a bank changes its email format.
We do not sell personal data, use it for advertising, or share it with anyone except the providers below.
5. Who we share it with
- Stripe — subscription billing (privacy policy).
- Microsoft Azure — hosting for the Auto-Verify service and its database, and the Azure OpenAI Service used for parser generation. Microsoft does not use data sent to Azure OpenAI to train its models (privacy statement).
- Microsoft 365 — delivery of transactional email from us to you.
- Law enforcement or regulators, only where we are legally required to.
- A successor business, if D613 Labs is acquired or merges — you will be notified.
6. Retention and deletion
- Mailbox credentials are deleted immediately when you disconnect a mailbox or your subscription ends.
- Stored payment-alert records and match audit logs are kept while your subscription is active and for 90 days afterwards, then deleted.
- Account and billing records are kept for as long as required by tax and accounting law (typically 7 years).
- You can request deletion of your account and all associated data at any time by emailing support@d613labs.com; we complete deletion within 30 days, except for records we must keep by law.
7. Security
All connections — between your store and us, between us and your mailbox, and to our website — use TLS. Mailbox credentials are encrypted at rest. Every alert is verified with DKIM/DMARC before it is trusted. Every action is idempotent and audit-logged, and your own store re-validates each proposed match before any order changes. Access to production systems is limited to D613 Labs staff who need it. No system is perfectly secure; if we become aware of a breach affecting your data we will notify you without undue delay.
8. Your rights
Depending on where you live you may have the right to access, correct, export, restrict or delete personal data we hold about you, and to object to certain processing. Email support@d613labs.com and we will respond within 30 days. If you are in the EU/UK, D613 Labs is the data controller for account data and a processor acting on your instructions for mailbox and order data; you may also complain to your local supervisory authority.
9. Your customers' data
You are the controller of your customers' data. The free plugin keeps it on your site. With Auto-Verify, the only customer-related information we receive is what appears in a payment alert (typically the payer's name as shown by the payment app and the memo they typed) and the order number and amount. Please make sure your own privacy policy tells your customers that you use an automated service to confirm payments.
10. Children
D613 Pay is a business tool and is not directed at children under 16. We do not knowingly collect their data.
11. Changes
We will post any changes here and update the date at the top. For material changes we will also email your account address before they take effect.
12. Contact
D613 Labs · support@d613labs.com · d613labs.com