Legal
Privacy Policy
Last updated: March 2026 · GDPR-compliant · Churn Technologies FZCO
This Privacy Policy explains how Churn Technologies FZCO ("we," "us," or "our") collects, uses, and protects information about you when you use Churn.io. We are committed to protecting your privacy and handling your data in a transparent and lawful manner.
1. Who We Are
Churn.io is a SaaS platform that helps subscription businesses reduce churn through personalized cancellation flows and retention offers. For GDPR purposes, Churn Technologies FZCO acts as a data controller for data you provide directly to us, and as a data processor for your customers' data shared via integrations. Contact: support@churn.io.
2. What Data We Collect
Account Data
Name, email address, password (hashed), and organization details provided at registration. Also includes account preferences, profile photo, and connected integrations (e.g., Stripe account ID).
Usage Data
How you interact with the Service: pages visited, features used, flows created, session counts, and events such as saves, cancellations, and offer interactions.
Payment Data
Billing is handled by Stripe. We do not store card numbers. We receive and store limited billing metadata: subscription tier, billing cycle, and invoice history.
Cookies & Analytics
Session cookies for authentication, and analytics cookies via PostHog (including session recording). You can opt out by contacting us.
Customer Data
If you connect Stripe, we may receive data about your end-customers (e.g., subscription details, plan names) to power audience targeting. You are responsible for informing your customers via your own privacy policy.
3. How We Use Your Data
- To provide, maintain, and improve the Service
- To process billing, manage subscriptions, and send billing-related communications
- To send transactional emails (account verification, password reset, billing receipts)
- To monitor Service health, debug errors, and detect fraud or abuse
- To analyze usage patterns and improve product functionality
- To communicate about product updates, new features, and support inquiries
We do not sell your personal data to third parties.
4. Legal Basis for Processing (GDPR)
If you are in the EEA or UK, our legal basis for processing your personal data is:
- Contract: Processing necessary to provide the Service under our agreement with you
- Legitimate interests: Improving the Service, detecting fraud, security, and product communications
- Consent: Where you have given explicit consent, such as for optional analytics cookies
- Legal obligation: Where required to comply with applicable law
5. Third-Party Services
We use the following third-party services to operate Churn.io:
7. Data Retention
We retain your data for as long as your account is active. If you delete your account, we delete or anonymize your personal data within 30 days, except where required by law (e.g., billing records retained up to 7 years for tax purposes). Anonymized aggregate analytics data may be retained indefinitely.
8. Your Rights (GDPR)
If you are in the EEA or UK, you have the following rights:
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your personal data ("right to be forgotten")
- Portability: Request your data in a machine-readable format
- Objection: Object to processing based on legitimate interests
- Restriction: Request restriction of processing in certain circumstances
To exercise any right, contact us at support@churn.io. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
9. International Transfers
Some third-party providers may process data outside the EEA. Where this occurs, we ensure appropriate safeguards are in place — including Standard Contractual Clauses (SCCs) approved by the European Commission, or EU-US Data Privacy Framework certification where applicable.
10. Data Security
We implement industry-standard technical and organizational measures including encryption in transit (TLS) and at rest, access controls, and regular security reviews. No method of transmission over the Internet is 100% secure. If you believe your account has been compromised, contact us immediately.
11. Children's Privacy
The Service is not directed to children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently done so, contact us and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by posting a notice on the Service. Your continued use of the Service after that date constitutes acceptance of the changes.
13. Contact / Data Controller
For any questions, concerns, or data requests, contact our data controller:
Churn Technologies FZCO
Dubai Silicon Oasis, IFZA Business Park
DDP, Building A1, United Arab Emirates
Email: support@churn.io