Data security and customer privacy are treated as a core responsibility at Churn.io, not an afterthought. This article summarises how customer data is handled, stored, and protected.
Data encryption
All data transmitted to and from Churn.io is encrypted in transit using TLS 1.2 or higher. Data stored in the Churn.io database is encrypted at rest. Payment card data is never stored by Churn.io. All billing is handled by Stripe, which is PCI DSS Level 1 certified.
What customer data Churn.io stores
When a customer opens your cancel flow, Churn.io records:
The customer identifier passed in by your integration (typically a user ID or email)
The cancel reason they selected
The offer outcome (shown, accepted, or declined)
Any feedback text they submitted
The session timestamp and duration
Churn.io does not store payment card details, subscription billing information, or any data beyond what is necessary for the cancellation session.
GDPR compliance
Churn.io is built with GDPR compliance in mind:
Data is processed only as necessary to deliver the service (lawful basis: legitimate interest and contractual obligation)
Customer data is stored on servers within the EU by default
A Data Processing Agreement (DPA) is available for customers who require one for compliance purposes. Contact support to request it.
π‘ Data deletion requests
If a specific customer requests deletion of their data under GDPR or similar legislation, contact our support team with the customer identifier and we will process the deletion request within 30 days.
π¬ Questions or concerns?
Get help from our support specialists at Churn.io. Click the chat icon at the bottom of your screen to reach us directly.
