Roles
For the purchase and customer data your apps send to RevenueDot Cloud ("Customer Data"), you are the controller and Circo, Inc., which operates RevenueDot, is your processor. Self-hosted RevenueDot involves no processing by us.
What we process
| Data subjects | Users of your apps who make or restore purchases, and your team members |
|---|---|
| Categories of data | App user IDs and aliases, store transaction IDs, product, price, currency, country, purchase and renewal dates, entitlement state, device platform and app version, and any customer attributes you set (for example an email address) |
| Purpose | Validating purchases with Apple and Google, keeping entitlements current, sending your webhooks and integrations, and showing your dashboard |
| Duration | For the life of your project, then deletion within 30 days |
| Special categories | None expected. Do not send health, biometric or similar data as customer attributes. |
Our commitments
- Process Customer Data only on your documented instructions: these terms, your configuration and your API calls.
- Bind our staff and subprocessors to confidentiality.
- Protect data with encryption in transit (TLS) and at rest, access limited to the people who need it, and logged administrative access.
- Tell you without undue delay, and within 72 hours of confirming it, about a personal data breach affecting your Customer Data.
- Help you answer data subject requests and carry out impact assessments, through the API and on request.
- Delete or return Customer Data when your project or account ends, unless the law requires us to keep it.
- Make information available to show compliance, and allow reasonable audits on 30 days' notice.
Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, network, compute and database connectivity | Global network; United States |
We add a subprocessor to this list at least 30 days before it starts processing Customer Data. You can object in that time; if we cannot resolve the objection, you can end the affected service.
International transfers
Where Customer Data from the EEA, UK or Switzerland is transferred to a country without an adequacy decision, the EU Standard Contractual Clauses (and the UK Addendum) apply.
Request the full agreement
Email legal@revenuedot.app with your organization's name.