Churn.io

Legal

Privacy Policy

Last updated: March 2026 · GDPR-compliant · Churn Technologies FZCO

This Privacy Policy explains how Churn Technologies FZCO ("we," "us," or "our") collects, uses, and protects information about you when you use Churn.io. We are committed to protecting your privacy and handling your data in a transparent and lawful manner.

1. Who We Are

Churn.io is a SaaS platform that helps subscription businesses reduce churn through personalized cancellation flows and retention offers. For GDPR purposes, Churn Technologies FZCO acts as a data controller for data you provide directly to us, and as a data processor for your customers' data shared via integrations. Contact: support@churn.io.

2. What Data We Collect

Account Data

Name, email address, password (hashed), and organization details provided at registration. Also includes account preferences, profile photo, and connected integrations (e.g., Stripe account ID).

Usage Data

How you interact with the Service: pages visited, features used, flows created, session counts, and events such as saves, cancellations, and offer interactions.

Payment Data

Billing is handled by Stripe. We do not store card numbers. We receive and store limited billing metadata: subscription tier, billing cycle, and invoice history.

Cookies & Analytics

Session cookies for authentication, and analytics cookies via PostHog (including session recording). You can opt out by contacting us.

Customer Data

If you connect Stripe, we may receive data about your end-customers (e.g., subscription details, plan names) to power audience targeting. You are responsible for informing your customers via your own privacy policy.

3. How We Use Your Data

  • To provide, maintain, and improve the Service
  • To process billing, manage subscriptions, and send billing-related communications
  • To send transactional emails (account verification, password reset, billing receipts)
  • To monitor Service health, debug errors, and detect fraud or abuse
  • To analyze usage patterns and improve product functionality
  • To communicate about product updates, new features, and support inquiries

We do not sell your personal data to third parties.

5. Third-Party Services

We use the following third-party services to operate Churn.io:

StripePayment processing. Acts as independent data controller for payment data.
SupabaseDatabase hosting and authentication. EU storage (eu-central-1).
PostHogProduct analytics and session recording.
SentryError monitoring. May include limited user context in error reports.
IntercomCustomer support chat. Receives name, email, and conversation history.
SMTP2GOTransactional email delivery.
CloudflareCDN, DDoS protection, and DNS. Network traffic passes through Cloudflare.

6. Cookies and Tracking

  • Essential cookies: Required for authentication and session management. Cannot be disabled.
  • Analytics cookies: Used by PostHog to understand how you use the Service. Optional.

You can disable non-essential cookies in your browser settings. This may affect Service functionality.

7. Data Retention

We retain your data for as long as your account is active. If you delete your account, we delete or anonymize your personal data within 30 days, except where required by law (e.g., billing records retained up to 7 years for tax purposes). Anonymized aggregate analytics data may be retained indefinitely.

8. Your Rights (GDPR)

If you are in the EEA or UK, you have the following rights:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Request correction of inaccurate or incomplete data
  • Erasure: Request deletion of your personal data ("right to be forgotten")
  • Portability: Request your data in a machine-readable format
  • Objection: Object to processing based on legitimate interests
  • Restriction: Request restriction of processing in certain circumstances

To exercise any right, contact us at support@churn.io. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

9. International Transfers

Some third-party providers may process data outside the EEA. Where this occurs, we ensure appropriate safeguards are in place — including Standard Contractual Clauses (SCCs) approved by the European Commission, or EU-US Data Privacy Framework certification where applicable.

10. Data Security

We implement industry-standard technical and organizational measures including encryption in transit (TLS) and at rest, access controls, and regular security reviews. No method of transmission over the Internet is 100% secure. If you believe your account has been compromised, contact us immediately.

11. Children's Privacy

The Service is not directed to children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently done so, contact us and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by posting a notice on the Service. Your continued use of the Service after that date constitutes acceptance of the changes.

13. Contact / Data Controller

For any questions, concerns, or data requests, contact our data controller:

Churn Technologies FZCO

Dubai Silicon Oasis, IFZA Business Park

DDP, Building A1, United Arab Emirates

Email: support@churn.io