Privacy Policy
Effective July 14, 2026
This policy explains what Churnmend (“we,” “us”) collects, how we use it, and the choices you have. Churnmend serves businesses (“founders”) that bill their customers through Stripe. Two roles matter here: for founder account data we are the controller; for the personal information of a founder's customers we are a processor/service provider acting on the founder's instructions.
1. What we collect
From founders (account holders):
- Account email and login credentials (passwords are hashed by our auth provider — we never see them).
- Business name and physical mailing address (used in recovery emails, as required by anti-spam law).
- Stripe connection identifiers and access tokens. Tokens are encrypted at rest (AES-256-GCM) and are removed when you disconnect.
- If you join our mailing list: your email address.
About founders' customers (processed on the founder's behalf):
- For each failed payment: the customer's name and email, invoice amount and currency, the card decline code, and Stripe invoice/customer/subscription identifiers.
- For the cancel-flow widget: Stripe customer and subscription identifiers, the customer's email, an estimate of the subscription's monthly value, and an event log of the session (offers shown, accepted, declined).
- Unsubscribe requests, so we never email that customer again.
We never receive or store card numbers or bank details — payment credentials stay with Stripe. We also collect standard technical data needed to run and protect the service (such as IP-based rate-limit counters and server logs).
2. How we use it
- To provide the service: retry failed invoices, send recovery emails on the founder's behalf, show and apply cancel-flow offers, and display results in the founder's dashboard.
- To secure the service: authentication, abuse prevention, rate limiting, and audit logs.
- To communicate with founders about their account.
- To improve the service using aggregate, de-identified information.
We do not sell personal information and we do not use it for third-party advertising.
3. AI processing
Recovery emails may be personalized using an AI model provided by Anthropic. The model receives the founder's approved template and limited context about the failed payment (such as first name, amount, and decline reason). Outputs are validated before sending, and anything that fails validation falls back to the approved template. Our AI provider processes this data to provide the service to us and, per its API terms, does not train its models on it.
4. Who we share it with (subprocessors)
- Stripe — payments infrastructure and Connect authorization.
- Supabase — database and authentication hosting.
- Vercel — application hosting.
- Resend — email delivery.
- Anthropic — AI text generation as described above.
We may also disclose information if required by law, or as part of a merger or acquisition (in which case this policy continues to apply to previously collected data).
5. Cookies
The app uses essential cookies only — the session cookie that keeps a founder signed in. There are no advertising or cross-site tracking cookies.
6. Security
Data is encrypted in transit (TLS). Stripe tokens and widget secrets are encrypted at rest. Database access is locked down so that browsers can only read their own account's rows, all money-state writes go through controlled server paths, and key audit records are append-only. No system is perfectly secure, but the service is designed so the most sensitive actions are structurally impossible (for example, the code contains no path that can create a new charge).
7. Retention
Founder account data is kept while the account is active. Payment-recovery and cancel-flow records are kept while needed to provide the service and for bookkeeping and audit purposes, then deleted or de-identified. Unsubscribe records are kept as long as necessary to honor the request. You can ask us to delete your account data at any time (see below); we may retain what the law requires us to keep.
8. Your choices and rights
- Founders: you can access and update business info in the dashboard, disconnect Stripe at any time, and email us to request a copy or deletion of your data.
- Customers of founders: every recovery email has a one-click unsubscribe. For access or deletion of your data, contact the business that bills you — we will assist them as their processor. You can also email us and we will route the request.
- Depending on where you live (for example California or the EU), you may have rights to access, correct, delete, or port personal information, and to non-discrimination for exercising them. Email us and we will honor applicable rights.
9. Where data is processed
Our infrastructure is hosted in the United States.
10. Children
The service is for businesses and is not directed to anyone under 16.
11. Changes
We may update this policy from time to time. Material changes will be announced by email or in the dashboard before they take effect.
12. Contact
Privacy questions or requests: support@churnmend.com.