Revenue State Guard
Protection
Activity
Needs attention
Setup
Help
Privacy
How it worksPrivacyStoring data outside KitSupport

Privacy

Last updated 9 September 2026

Revenue State Guard (RSG) connects a Stripe account to a Kit account so that people who have already paid stop receiving payment reminder emails. To do that it has to hold a small amount of information about your customers. This page says exactly what, why, and for how long.

RSG is operated by Orumio. Contact: masanori.iwata@orumio.com.

What RSG stores

  • —Your Kit account ID and name, and the ID of the connected Stripe account.
  • —Access credentials for both accounts, encrypted at rest with a key held separately from the database.
  • —For each customer RSG has matched: their Stripe customer ID, their Kit subscriber ID, and the email address the two were matched on.
  • —For each of your products and each matched customer: the state RSG worked out, the reason in plain words, and the Stripe object IDs the decision rests on.
  • —Invoice IDs and times of payment failures RSG observed, because a paid invoice no longer shows that it once failed.
  • —A record of every change RSG made in Kit, why, and what Kit said when RSG read it back.
  • —The exclusion settings on the sequences you asked RSG to protect — the IDs in them, not the content of any email.
  • —The IDs of webhook deliveries received, to avoid acting on the same event twice.

What RSG does not store

RSG never asks Stripe for permission to move money, and it never stores card numbers, card brands, the last four digits, billing addresses, phone numbers or customer names. It does not store the content of your emails, your subscribers' custom field values, or your purchase history. When a webhook arrives, RSG keeps the identifiers it needs to look the object up and discards the rest of the payload; it then reads the current object from Stripe rather than trusting what was delivered.

RSG never creates a Kit subscriber, never changes anyone's subscription status or consent, and never writes to your Kit purchase history.

How long it is kept

  • —Webhook delivery records: 30 days.
  • —Read-back receipts and verification evidence: 90 days. The record of what RSG actually changed stays visible in Activity for as long as your account exists.
  • —Everything else: for as long as RSG is protecting your account.
  • —After you disconnect: RSG stops immediately and deletes your data within 30 days. A deletion marker is kept so that queued work or a restored backup cannot bring a deleted account back. See what RSG stores and why.

Who else sees it

Nobody. RSG does not sell data, does not share it with advertisers, and uses no third-party analytics that receive customer information. Usage measurement is stored in RSG's own database and records what kind of thing happened, never who it happened to.

RSG runs on Vercel (hosting) and Neon (database), and communicates with Stripe and Kit on your behalf. Payment for RSG itself is handled by Stripe on a separate Stripe account from the one you connect — the account RSG reads your revenue from and the account that bills you are deliberately not the same one, and neither can reach the other.

Your control

  • —Pause at any time from the Protection page. RSG stops making changes immediately and leaves everything already in Kit exactly as it is.
  • —Disconnect at any time from Setup. RSG removes the one tag it added to your sequence exclusion settings, deletes its webhook, and erases your data within 30 days.
  • —Disconnecting never removes tags from your subscribers. Stripping your segmentation on the way out would do more damage than leaving it.
  • —To ask what RSG holds about you, or to have it deleted sooner, email masanori.iwata@orumio.com.

Changes to this page

If what RSG stores changes, this page changes with it and the date above moves. RSG will not quietly widen what it collects.