Legal
Privacy Policy
Last updated August 13, 2025
Overview
Kusmol operates a payment failure recovery network. To do this, we process information about failed payment attempts on behalf of our business customers (“Merchants”) in order to classify the failure and recommend an appropriate recovery path. This policy explains what we process, why, and how it is protected.
What we process
Depending on how a Merchant integrates with Kusmol, we may process:
- Payment metadata related to a transaction attempt — such as failure or decline codes, payment rail, issuer region, and attempt history. Kusmol does not require or store full card numbers, CVV codes, or other primary account numbers.
- Contextual signals surrounding a failed attempt that are relevant to classifying the failure (for example, timing, retry count, or authentication status).
- Technical and account information from Merchants integrating with our API, including API credentials and usage logs.
Kusmol is not a payment processor and does not hold or move funds. Sensitive cardholder data is handled by our Merchants’ underlying, licensed payment processors — not by Kusmol directly.
AI processing
Kusmol uses machine learning models to classify why a payment failed and to recommend a recovery action and confidence level. These models are trained and evaluated on failure-pattern data rather than on the sensitive contents of any individual payment instrument. Classification outputs (such as failure class, confidence, and recommended action) may be logged in order to improve the accuracy of future classifications.
Automated classification is a decision-support signal for Merchants and their systems. Merchants remain responsible for how recovery recommendations are acted upon.
Third-party processors and providers
Kusmol integrates with third-party payment processors, issuing banks, and infrastructure providers in order to receive failure signals and route recovery actions. Each of these parties processes data under their own privacy and security terms, in addition to any agreement between Kusmol and the Merchant.
Security
We apply encryption in transit and at rest, access controls scoped to least privilege, and audit logging across systems that handle payment-failure data. No system is completely immune to risk, and we continually review our practices as our infrastructure evolves.
Data retention
Failure and classification data is retained for as long as reasonably necessary to provide the service, improve classification accuracy, and meet legal or contractual obligations, after which it is deleted or anonymized.
Your rights
If Kusmol processes personal data about you as part of a Merchant’s use of our service, you may have rights to access, correct, or request deletion of that data, subject to applicable law. Requests should generally be directed to the Merchant you transacted with, who can coordinate with us as needed.
Changes to this policy
We may update this policy as our product and practices evolve. We will update the date at the top of this page when changes are made.
Contact
Questions about this policy can be sent to privacy@kusmol.com.