Anti-Spam Policy

Effective July 28, 2026 · Last updated July 28, 2026

Payment Recovery System sends email under your brand, to your customers. This policy sets out what you may send and to whom. It is incorporated into the Terms of Service and the Acceptable Use Policy.
CAN-SPAMExisting customers only0.1% complaint ceiling

1. Why This Policy Exists

Recovery email is sent from shared sending infrastructure. One customer mailing a purchased list does not only harm that customer — it degrades the sending reputation of the IP ranges and domains every other customer relies on, and legitimate dunning email starts landing in spam folders across the platform.

So the thresholds in this policy are enforced technically, not just contractually. They are not a formality.


2. Who You May Email

You may use the Service to email a person only where all of the following are true:

  • The person is a customer of yours with a payment relationship on the Stripe account you have connected;
  • The message relates to a specific failed charge, at-risk charge, upcoming renewal, or expiring payment method on that account;
  • The person gave you their email address in the course of that relationship;
  • The person has not unsubscribed from your recovery messages or otherwise asked you to stop.

This is a narrow permission by design. Dunning email works because it is transactional in character and expected by the recipient. The moment it becomes general marketing it loses both its deliverability and its legal footing.


3. Who You May Not Email

You must never use the Service to email:

  • Purchased, rented, leased, appended, scraped, or harvested addresses;
  • Addresses from a list you acquired with a business, unless you have verified the underlying permission;
  • Role addresses harvested from websites (info@, sales@) that are not your customer’s billing contact;
  • Anyone who has unsubscribed, marked your mail as spam, or issued a GDPR objection;
  • Anyone with no failed or at-risk payment on your connected account — the Service is not a newsletter tool;
  • Recipients of general promotional, cross-sell, upsell, or announcement campaigns dressed as recovery email.

Uploading a list that did not originate from your connected Stripe account is a material breach and grounds for immediate suspension.


4. CAN-SPAM Requirements

The CAN-SPAM Act (15 U.S.C. §§ 7701–7713) applies to commercial email sent to U.S. recipients. Penalties run to five figures per message, and both the sender and the party whose product is promoted can be liable. Every message you send through the Service must:

  • Use accurate header information — a real “From” name, domain, and reply-to;
  • Use a subject line that is not deceptive about the message’s contents;
  • Identify the message as an advertisement where it is one (transactional dunning messages whose primary purpose is the failed transaction are generally exempt from this specific requirement — but the exemption is lost if you bundle promotional content);
  • Include your valid physical postal address. This is not optional and there is no exemption for small senders;
  • Provide a clear, functioning opt-out mechanism;
  • Honour opt-outs within 10 business days (the Service honours them immediately).

Configure your business name and postal address in Settings → Brand before your first campaign. Templates that omit the address footer will not pass our pre-send validation.

Florida additionally prohibits falsified email headers and deceptive subject lines under the Florida Electronic Mail Communications Act, Fla. Stat. § 668.60.


5. GDPR, CASL & Other Regimes

If you email recipients outside the United States, stricter rules usually apply and they are your responsibility to meet:

  • EU / EEA & UK.Under the ePrivacy Directive and PECR, email to an existing customer about a similar product generally relies on the soft opt-in, and dunning email about the customer’s own subscription is squarely within it. You must still identify yourself, offer opt-out in every message, and have a lawful basis under Article 6 — normally contract performance or legitimate interests.
  • Canada. CASL requires express or implied consent. An existing business relationship provides implied consent for a limited window; billing messages about a live subscription generally qualify. Penalties are severe — verify before sending to Canadian recipients.
  • Australia. The Spam Act 2003 requires consent, sender identification, and a functional unsubscribe facility.

Where you are the controller for these recipients, our role is limited to processing on your instructions under the Data Processing Agreement.


6. Unsubscribe Handling

The Service handles opt-outs for you, and you must not defeat it:

  • Every recovery email carries a one-click unsubscribe link;
  • A List-Unsubscribe header with one-click POST support is set, as Gmail and Yahoo bulk-sender requirements now demand;
  • Unsubscribes take effect immediately — no confirmation step, no delay;
  • Suppression is permanent and applies across all your campaigns;
  • Re-uploading a suppressed address does not resurrect it.

You must not remove, obscure, or disable the unsubscribe link, require a login to unsubscribe, or charge a fee. If a customer asks you directly to stop, honour it whether or not they clicked the link.

Genuinely transactional messages — a receipt, or a legally required notice about an account — are not suppressed by an unsubscribe from marketing. Recovery email sits close to that line; when in doubt, treat the unsubscribe as binding.


7. Deliverability Thresholds

These are the limits at which we intervene. They reflect mailbox-provider expectations, not arbitrary preference — Gmail and Yahoo both publish a 0.3% complaint rate as the level at which delivery is materially affected, and we act well before that.

MetricWarningThrottle / suspend
Spam complaint rate0.08%0.1%
Hard bounce rate3%5%
Spam-trap hitsAny2 in 30 days
Unsubscribe rate2%5%

Rates are measured over a rolling 30-day window with a minimum volume of 500 messages, so a small sample cannot trip a threshold. Where sending is throttled we will tell you which metric triggered it and what to change.


8. Sender Authentication

If you send from your own domain, you must publish valid SPF and DKIM records, and we strongly recommend a DMARC policy of at least p=none with reporting, moving to quarantine once aligned. Gmail and Yahoo require SPF, DKIM, DMARC alignment, and one-click unsubscribe from bulk senders; mail that fails these is rejected outright, not delivered to spam.

If you configure custom SMTP, you are responsible for the reputation and authentication of that infrastructure. The thresholds in Section 7 still apply to the events we can observe.


9. Monitoring & Enforcement

We monitor aggregate bounce, complaint, and trap metrics per account. We do not read the content of your recovery emails except where investigating a specific abuse report, a deliverability incident, or a legal requirement.

Enforcement follows the escalation table in the Acceptable Use Policy: warning, then feature restriction, then suspension. Sending to a purchased list, or deliberately defeating the unsubscribe mechanism, skips straight to suspension.


10. Who Is Liable

You are the sender. The messages carry your brand, your sender identity, and your postal address, and you decide who receives them. You are responsible for compliance with CAN-SPAM, the GDPR, CASL, and every other law applicable to your recipients, and you indemnify us against claims arising from your sending under Section 11 of the Terms.

We provide the tooling to make compliance the default — automatic suppression, one-click unsubscribe, list-unsubscribe headers, address-footer validation — but tooling is not a legal opinion, and using the Service is not a defence.


11. Report Spam

If you received an unwanted email sent through the Service, report it and we will act. Include the full message headers where you can — they identify the sending account.

Payment Recovery System — Abuse

Report abuse: abuse@paymentrecoverysystem.com

We acknowledge reports within 2 business days and investigate every one. To stop mail from a specific sender, use the unsubscribe link in the message — that takes effect immediately.