You must have ended up here because you care about your and your users’ privacy. That’s great.
The lawyers make us write a bunch of fancy words in our official policy but its worth laying out in more plain language what our policy on data privacy is.
There are two different kinds of data we touch: your personal data as the developer and the data of your customers who use your app that uses RevenueCat. We have different policies for each and it’s worth breaking down:
Your Personal Data
Your Revenue and Customer Data
Your customer data, which would, by association, include information about your business, are under a completely different set of policies. In GDPR terms, we are a “processor” here. This data is probably why you are here in the first place. Two important points:
We will never share information about your app outside of RevenueCat
The data about your revenue and your users stays within RevenueCat. We do utilize some 3rd party services for hosting, such as AWS, but that data is encrypted and unavailable to those providers.
We will never send identifiable information about your users to 3rd parties without your consent
With the exception of opt-in integrations, we won’t send information about your subscribers to any 3rd parties. We don’t want the liability of any downstream processors having issues and compromising your data. We want to keep it with us, where we can have some control over its security.
We will never sell your data
We’re in the business of making money off of you making money. We have no interest in trying to turn a 2nd order profit by fencing information about your business. We may, at some point, utilize aggregate data to provide insights in our app (i.e. “your app is 20% below average for churn”), but it would not be possible to extract any meaningful information about your business from that.
Last update: January 24th, 2019
This policy (together with our terms of service and any other documents referred to in it) sets out:
- Information we collect about you
- Cookies and other technologies
- How we use your information
- Our promotional updates and communications
- Who we give your information to
- Where we store your information
- How we protect your information
- How long we keep your information
- Your rights
- Changes to this policy
- Contact us
Our site may, from time to time, contain links to external sites. We are not responsible for the privacy policies or the content of such sites.
Information we collect about you
We will collect and process the following personal data from you:
- Information you give us
- This is information about you that you give us by filling in forms on our site or by corresponding with us by phone, e-mail or otherwise. It includes information you provide when you register to use our site, subscribe to our service, search for a product, in discussion boards or other social media functions on or via our site, enter a competition, promotion or survey, submit a query, providing information at trade shows or sponsored events and when you report a problem with our site.
- The information you give us may include your name, address, e-mail address and phone number, financial and credit card information, personal description and photograph, login and password details.
- It may also include employment details if you send us a CV, resumé or other details of your employment history in connection with an advertised job vacancy or a general inquiry regarding employment opportunities with us.
Information we collect about you from your use of our site
- Technical information
- Technical information may include the Internet protocol (IP) address used to connect your computer to the Internet, your login information, browser type and version, time zone setting, operating system and platform;
- Information about your visit
- Information about your visit may include the full Uniform Resource Locators (URL), clickstream to, through and from our site (including date and time), page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), methods used to browse away from the page, and any phone number used to call our customer service number or social media handle used to connect with our customer service team.
- IP Location data
- Location data – IP addresses are collected and location is inferred based on IP location.
- Information collected from platform activities
Information we receive from other sources
This is information we receive about you:
- If you use any of the other websites or apps we operate or the other services we provide.
- From third parties we work with.
- In this case we will have informed you when we collected that data and if we intend to share your data internally and combine it with data collected on this site. We will also have told you for what purpose we will share and combine your data. We are working closely with third parties (including, for example, business partners, sub-contractors in technical, payment and delivery services, advertising networks, analytics providers, and search information providers).
Cookies and other technologies
How we use your information
- Information you give to us:
- We will use this information in our legitimate interests, where we have considered these are not overridden by your rights:
- To administer our site and for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes.
- To keep our site safe and secure.
- For measuring or understanding the effectiveness of advertising we serve to you and others, and to deliver relevant advertising to you.
- To improve our site to ensure that content is presented in the most effective manner for you and for your computer.
- To allow you to participate in interactive features of our service, when you choose to do so.
- Information we receive from other sources
- We may combine this information with information you give to us and information we collect about you in our legitimate interests (where we have considered that these are not overridden by your rights). We will use this information and the combined information for the purposes set out above (depending on the types of information we receive).
Our promotional updates and communications
Where permitted in our legitimate interest or with your prior consent where required by law, we will use your personal information for marketing analysis and to provide you with promotional update communications by email about our products and services. You can object to further marketing at any time by checking and updating your contact details within your account, or selecting the “unsubscribe” link at the end of all our marketing and promotional update communications to you, or by submitting your email address here.
Who we give your information to
We may give your information to:
- Any member of our group, which means our subsidiaries, our ultimate holding company and its subsidiaries, who support our processing of personal data under this policy. If any of these parties are using your information for direct marketing purposes, we will only transfer the information to them for that purpose with your prior consent.
- Selected third parties may include:
- Organizations who process your personal data on our behalf and in accordance with our instructions and applicable law. This includes organizations supporting the services we offer through the site, in particular organizations providing website and data hosting services, providing fulfillment services, distributing any communications we send, supporting or updating marketing lists, and facilitating feedback on our services. These organizations (which may include third party suppliers, agents, sub-contractors and/or other companies in the RevenueCat group of companies) will only use your information to the extent necessary to perform their support functions.
- Analytics and search engine providers that assist us in the improvement and optimization of our site and subject to the cookie section of this policy (this will not identify you as an individual).
- Payment processing providers who provide secure payment processing services. (Your payment card details are not shared with us by the provider.)
- We will disclose your personal information to third parties:
- If RevenueCat or substantially all of its assets are acquired by a third party, in which case personal data held by it about its customers will be one of the transferred assets.
Where we store your information
The data that we collect from you will be stored securely on Amazon Web Services (“AWS”) in the USA.
The site may, from time to time, make chat rooms, message boards, news groups and/or other public forums available to its users. Any information that is disclosed in these areas becomes public information and you should exercise caution when using these and avoid posting any personal information
The site is intended for use only by persons who are at least 16 years of age. By using the site, you confirm to us that you meet this requirement. If you are under the age of 18, you confirm you have received permission from your parent or guardian before using this site or sending us personal information.
How we protect your information
Security is one of our biggest priorities at RevenueCat. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorized access.
- All application data is secured in transit using TLS.
- Any payment transactions will be encrypted using SSL.
- RevenueCat audits changes to the application throughout the development lifecycle: architecture reviews are performed as well as stringent automated and manual code review processes.
- RevenueCat monitors application servers, infrastructure, and the RevenueCat network environment to detect potential abuse.
- RevenueCat uses Amazon Web Services (“AWS”) to persistently store Customer data and does not host Customer data on its premises. AWS is a leading cloud provider, and holds industry best security certifications, such as SOC2 and ISO 27001. Customer data sent to RevenueCat from around the world is sent to AWS data centers located in the United States.
How long we keep your information
We retain personal data during any period in which you have expressed an interest in our products and services, for as long as you have an account with us in order to meet our contractual obligations to you, and for six years after that to identify any issues and resolve any legal proceedings. We may also retain aggregate information beyond this time for research purposes and to help us develop and improve our services. You cannot be identified from aggregate information retained or used for these purposes.
EU Citizen rights under GDPR
- You have the right under certain circumstances:
- to be provided with a copy of your personal data held by us.
- to request the rectification or erasure of your personal data held by us.
- to request that we restrict the processing of your personal data (while we verify or investigate your concerns with this information, for example).
- to object to the further processing of your personal data, including the right to object to marketing.
- to request that your provided personal data be moved to a third party.
- You may opt out at any time from allowing further access by us to your location data by emailing email@example.com.
- Your right to withdraw consent:
- Where the processing of your personal information by us is based on consent, you have the right to withdraw that consent without detriment at any time by going here.
You can also exercise the rights listed above at any time by contacting us at firstname.lastname@example.org.
We would appreciate the opportunity to directly address any GDPR issues you may have. Please contact us at email@example.com. You do, however, have the right to approach your local data protection authority, (see http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.html for data protection authorities in the EU).
Data processed on behalf of our Customers
Customer agreements are in place with each RevenueCat customer. These agreements cover data transfers to third parties that may occur as part of RevenueCat’s provision of its services to the customer.
See also our data processing addendum.
Changes to this policy
Kleiner Ring 15a