Privacy Policy
Last updated: May 20, 2026
This Privacy Policy explains how Reecog ("we", "us", "our") collects, uses, and shares information when you use our Slack recognition bot and website (the "Services"). It is written to address GDPR requirements for EU users and privacy expectations for US users.
Who we are
Data controller: Reecog. Contact: privacy@reecog.com.
Information we collect
- Account and workspace information from Slack — workspace ID, user IDs, team domain.
- Recognition activity — messages containing recognition syntax, points awarded, value tags, timestamps, and reason text provided by the giving user.
- User point balances — total points, points by company value, daily recognition counts.
- Configuration data — company values list, reward catalog, daily limits, admin settings, GIF preferences.
- Billing information — subscription status, plan tier, billing period, and payment provider references (we do not store payment card details directly).
- Admin audit logs — records of which admin performed what configuration change, including timestamps and action details.
- Contact form submissions — name, work email, company size, message.
- Usage data — to keep the service reliable and improve features.
How we use information
- Provide and operate the Services, including recognition, points, rewards, and admin controls.
- Enforce subscription tiers and workspace access limits.
- Maintain admin audit trails for accountability and compliance.
- Communicate with you about support or product updates.
- Improve security, reliability, and user experience.
Legal bases (GDPR)
- Performance of a contract — to provide the Services you have subscribed to.
- Legitimate interests — service improvement, security, fraud prevention, and analytics.
- Consent — where required for communications or optional features.
Data retention
We retain data as long as needed to provide the Services and comply with legal obligations.
- Recognition data and user records — retained while the workspace has an active installation.
- Audit logs — retained for up to 2 years for compliance purposes.
- Billing records — retained as required by applicable tax and accounting laws.
- On uninstall — when the app is uninstalled from a workspace, all workspace data (user records, configuration, subscriptions, and audit logs) is permanently and automatically deleted.
You may request deletion of your data at any time (see "Your rights" below).
Data deletion
We provide multiple mechanisms for data removal:
- Automatic full purge on uninstall — when you remove Reecog from your Slack workspace, all associated data is permanently deleted, including user records, configuration, subscriptions, and audit logs.
- Individual user deletion — any user can run
/points delete-my-datato permanently delete their personal recognition data from the workspace. This action is irreversible. - Data export — any user can run
/points exportto receive a copy of their personal data in JSON format before deletion (GDPR Article 20, data portability). - Workspace admin requests — workspace admins may contact privacy@reecog.com to request bulk data operations.
Data sharing
We do not sell personal data. We share data only with service providers needed to run the Services:
- Hosting and database — cloud infrastructure providers.
- Giphy — when GIF celebrations are enabled, we send only the company value tag (e.g., "teamwork") to the Giphy API. We never send recognition reason text or user identifiers to Giphy.
- Payment processing — LemonSqueezy handles subscription billing. We share your workspace ID with the payment provider to link subscriptions.
We may disclose information if required by law.
Security
We implement the following security measures:
- Token encryption at rest — Slack bot tokens are encrypted using AES-256-GCM before storage.
- Webhook signature verification — all incoming Slack webhooks and billing webhooks are validated using HMAC-SHA256 signatures.
- Database encryption in transit — SSL/TLS connections are enforced for database communication in production.
- Rate limiting — API endpoints are protected against abuse.
- Replay protection — billing webhook events are deduplicated to prevent replay attacks.
- Parameterized queries — all database queries use parameterized statements to prevent SQL injection.
- Security headers — HTTP security headers (via helmet) are applied to all responses.
No method of transmission or storage is 100% secure. If you become aware of a security vulnerability, please contact privacy@reecog.com immediately.
International transfers
If you are in the EU/UK, your data may be processed in the United States or other countries. Where required, we rely on standard contractual clauses or other lawful transfer mechanisms.
Your rights
Depending on your jurisdiction, you may have the following rights:
- Access — request a copy of data we hold about you (or use
/points export). - Correction — request correction of inaccurate data.
- Deletion — request deletion of your data (or use
/points delete-my-data). - Restriction or objection — restrict or object to certain processing.
- Data portability — receive your data in a structured, machine-readable format.
- Withdraw consent — at any time, where consent is the legal basis.
To exercise these rights, contact privacy@reecog.com or use the in-app commands described above.
US privacy rights
If you are a California resident, you may have rights under the CCPA/CPRA, including the right to access and delete personal information. We do not sell personal information. We do not use personal information for targeted advertising.
Children
Reecog is not intended for children under 16. We do not knowingly collect personal data from children.
Changes
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated "Last updated" date. Continued use of the Services after changes constitutes acceptance.
Contact
For privacy inquiries, contact privacy@reecog.com.