Draft — this document still contains unfilled placeholders and has not been reviewed by a lawyer. Do not rely on it. Fill in src/lib/legal.ts to remove this banner.

Privacy Policy

How ChurnLens handles personal data — both for the founders who use it and for the customers who receive an exit survey.

Last updated: [EFFECTIVE DATE]

1. Who we are

ChurnLens is operated by [LEGAL ENTITY NAME], [ENTITY TYPE AND REGISTRATION NUMBER], of [FULL POSTAL ADDRESS] ("ChurnLens", "we", "us").

For privacy questions or to exercise your rights, contact privacy@churnlens.com.

ChurnLens is subject to South Africa's Protection of Personal Information Act (POPIA). Our designated Information Officer is [INFORMATION OFFICER NAME], reachable at the address above.

2. Who this policy is for

ChurnLens sits between two different groups of people, and the law treats them differently. Find yourself below.

If you signed up for ChurnLens — you are our customer. We decide how your account data is handled, so we are the "controller" for it. Sections 3, 5 and 6 apply to you.

If you received an exit survey email — you cancelled a subscription with a business that uses ChurnLens. That business decides to send the survey and what it asks; they are the "controller". We only act on their instructions, so we are their "processor". Sections 4 and 7 apply to you, and you should direct most requests to that business rather than to us.

3. Data we collect about our customers

When a founder signs up and connects their Stripe account, we store:

  • Email address — used to sign you in and to send the weekly digest. We do not store passwords; sign-in is by emailed magic link only.
  • Your Stripe restricted API key and webhook signing secret — encrypted at rest with AES-256-GCM. Used only to read cancellation events and to look up the cancelling customer.
  • Survey customisation — the display name, logo URL and any custom cancellation reasons you configure.
  • A session cookie — a signed identifier that keeps you logged in. See section 9.
  • Sign-in tokens — stored only as a one-way hash, valid for 15 minutes, single-use, and deleted shortly after expiry.

4. Data we process about churned customers

When a customer cancels a subscription with a business using ChurnLens, that business's Stripe account notifies us and we process, on their instructions:

  • Email address and name, as held in that business's Stripe account
  • The Stripe subscription identifier and the value of the cancelled subscription
  • The cancellation reason selected, and any free-text answers given
  • Whether the recipient has opted out of further survey emails

We did not obtain this information from you directly — we received it from the business you cancelled with. We use it for one purpose only: to deliver that business's exit survey and report the results back to them. We never sell it, never use it for our own marketing, and never combine it across businesses.

Free-text answers. Your written answer to "can you tell us a bit more?" is sent to OpenAI to group similar responses into themes. OpenAI does not use data submitted through its API to train its models, and deletes it after a short abuse-monitoring period. Your answer to "what would bring you back?" is not sent to OpenAI.

5. Why we process it, and our legal basis

  • To provide the service to our customers — performance of our contract with them.
  • To send exit surveys to churned customers — the legitimate interests of the business you cancelled with, in understanding why customers leave. That business is responsible for establishing this basis; see section 7 for your right to object.
  • To secure the service and prevent abuse — our legitimate interest in operating the service safely.
  • To meet legal obligations — where we are required to retain or disclose information.

Under POPIA, our justification for processing our own customers' account data is section 11(1)(b) (performance of our contract with them) and section 11(1)(f) (our legitimate interests in operating and securing the service). For churned customers, the business that connected its Stripe account to ChurnLens is the "responsible party" under POPIA — it decides that surveys are sent and what they ask — and we are its "operator", processing that data only on its instructions. This mirrors the controller/processor split described in section 2 above.

6. Who we share data with

We do not sell personal data. We share it only with the service providers below, each bound to process it only on our instructions:

ProviderPurposeLocation
RailwayApplication hosting and PostgreSQL databaseUnited States
ResendTransactional email deliveryUnited States
OpenAIClustering free-text survey answers into themes (GPT-4o-mini)United States
PolarSubscription billing for ChurnLens accounts (merchant of record)United States

Stripe is not on this list. We never send data to Stripe. We read cancellation events from our customer's own Stripe account using a restricted key they provide. Stripe's handling of that data is governed by their agreement with that business.

Polar receives account data only. Polar is the merchant of record for ChurnLens subscriptions, so it processes the account holder's name, email address and billing details. It never receives exit-survey data — no churned customer's name, email address or free-text answer is disclosed to it. That is why Polar does not appear in the sub-processor table of our Data Processing Agreement, which covers only the data we process on our customers' behalf.

We may also disclose data where required by law, or to a successor entity in a merger or acquisition, in which case this policy continues to apply.

7. International transfers

Our providers are located in the United States. Where personal data of individuals in the UK or European Economic Area is transferred there, the transfer relies on the UK International Data Transfer Addendum or the European Commission's Standard Contractual Clauses, as incorporated into our agreements with each provider.

Where the transfer instead concerns personal data subject to POPIA, it relies on section 72(1)(a): each of the sub-processors listed in section 6 is bound by a written agreement obliging it to provide a level of protection to that data that is at least equivalent to what POPIA itself requires.

8. How long we keep it

Retention here is enforced by a job that runs in our infrastructure every day, without a human triggering it — not a policy we merely intend to honour.

  • Customer account data — for as long as the account is open. A founder can request deletion at any time from Settings; we disconnect Stripe and stop surveys immediately, and a daily job permanently erases the account 30 days after the request.
  • Survey responses — a daily job deletes any survey response older than 24 months from collection. A response is also deleted sooner if the business that collected it closes its account (see above) or asks us to delete it directly.
  • Opt-out records — kept for as long as the business you opted out of has an account with us, so the suppression keeps being honoured. Once that business closes its account, the opt-out record is erased with it by the same daily job. If that business later opens a new account, you would need to opt out again.
  • Sign-in tokens — deleted by the same daily job shortly after they expire.

9. Cookies

We set one cookie, churnlens_org_id, which keeps you signed in. It is cryptographically signed, marked HttpOnly and Secure, and contains no personal data beyond an account identifier. It is strictly necessary to operate the service, so we do not ask for consent to set it.

We use no analytics, advertising, or third-party tracking cookies. The exit survey pages set no cookies at all.

10. Security

  • Stripe API keys and webhook secrets are encrypted at rest with AES-256-GCM.
  • Sign-in tokens are stored only as one-way hashes, expire in 15 minutes, and cannot be reused.
  • Session cookies are cryptographically signed and rejected if tampered with.
  • Survey links are signed and expire after 7 days.
  • Incoming Stripe webhooks are verified against a per-account signing secret.
  • Data is transmitted over TLS.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify the relevant supervisory authority and affected individuals as required by law.

11. Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, and to object to processing based on legitimate interests. Under POPIA section 11(3), you specifically have the right to object, on reasonable grounds, to processing of your personal data, and to object at any time to processing for the purpose of direct marketing.

If you received an exit survey — the business you cancelled with controls your data. Contact them first. If you contact us instead, we will pass your request to them and assist them in responding; we are not permitted to delete their data on our own initiative.

To stop receiving survey emails immediately, use the unsubscribe link at the bottom of the email. That takes effect at once and requires no account.

If you are a ChurnLens customer, email privacy@churnlens.com and we will respond within one month. You also have the right to complain to your local data protection authority, or, for matters we are responsible for under POPIA, to lodge a complaint with the Information Regulator (South Africa).

12. Children

ChurnLens is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe we have, contact us and we will delete it.

13. Changes

We may update this policy. Material changes will be notified by email to account holders at least 14 days before taking effect. The date at the top always reflects the current version.