Skip to main content

Is My Customer Data Secure? (GDPR and Privacy)

N
Written by Nawras Ganim
Updated today

Data security and customer privacy are treated as a core responsibility at Churn.io, not an afterthought. This article summarises how customer data is handled, stored, and protected.

Data encryption

All data transmitted to and from Churn.io is encrypted in transit using TLS 1.2 or higher. Data stored in the Churn.io database is encrypted at rest. Payment card data is never stored by Churn.io. All billing is handled by Stripe, which is PCI DSS Level 1 certified.

What customer data Churn.io stores

When a customer opens your cancel flow, Churn.io records:

  • The customer identifier passed in by your integration (typically a user ID or email)

  • The cancel reason they selected

  • The offer outcome (shown, accepted, or declined)

  • Any feedback text they submitted

  • The session timestamp and duration

Churn.io does not store payment card details, subscription billing information, or any data beyond what is necessary for the cancellation session.

GDPR compliance

Churn.io is built with GDPR compliance in mind:

  • Data is processed only as necessary to deliver the service (lawful basis: legitimate interest and contractual obligation)

  • Customer data is stored on servers within the EU by default

  • A Data Processing Agreement (DPA) is available for customers who require one for compliance purposes. Contact support to request it.

πŸ’‘ Data deletion requests

If a specific customer requests deletion of their data under GDPR or similar legislation, contact our support team with the customer identifier and we will process the deletion request within 30 days.


πŸ’¬ Questions or concerns?

Get help from our support specialists at Churn.io. Click the chat icon at the bottom of your screen to reach us directly.

Did this answer your question?