Who is responsible
RevenueDot is operated by Circo, Inc. For this website and for RevenueDot Cloud account data, Circo, Inc. is the controller. For the purchase data your apps send to RevenueDot Cloud, you are the controller and we act as your processor (see the DPA summary). Contact: legal@revenuedot.app.
Self-hosted RevenueDot
When you run RevenueDot on your own servers, we receive no data from it. The self-hosted server has no telemetry and does not contact our servers. It talks only to Apple, Google, your webhook endpoints and any forwarding URL you configure.
This website
- Analytics. We may use Cloudflare Web Analytics to count page views. It sets no cookies, does not use local storage, and does not fingerprint or track visitors across sites. It records the page, referrer, browser type, country and performance timings in aggregate. When it is switched off, no analytics script loads at all.
- Hosting logs. The site is served by Cloudflare, which processes IP addresses and request details to deliver pages and block attacks. We do not use these logs to identify visitors.
- No cookies, no ad trackers. This website sets no cookies and loads no advertising or social-media trackers. Fonts are served from our own domain.
- Email. If you email us, we keep your message and address to reply and to keep a record of the conversation.
RevenueDot Cloud
Account data (we are the controller)
- Your name, work email, hashed password and the projects you belong to, to run your account and sign you in.
- Billing details when paid plans launch, processed by our payment provider; we do not store full card numbers.
- Service logs and security events (IP address, time, action), to secure the Service and investigate abuse.
Customer Data (you are the controller)
The purchase, subscription, receipt and customer data your apps and stores send to the Service, including app user IDs and any attributes you choose to set, such as an email address. We process it only on your instructions, to provide the Service. We never sell it, use it for advertising or combine it across customers. Anonymized, aggregated benchmarks would be offered only if you opt in.
Legal bases (EEA and UK)
- Performing our contract with you: running your account and the Service.
- Legitimate interests: securing the Service, preventing abuse, counting page views without cookies, and answering your messages.
- Legal obligations: tax and accounting records.
Who we share data with
We share personal data only with providers who help us run the Service, under contracts that limit their use of it, and when the law requires. Current providers: Cloudflare, Inc. (hosting, network, database connectivity, web analytics). We list any new provider on the DPA summary before it starts processing Customer Data.
International transfers
Our providers may process data in the United States and other countries. Where the law requires, we rely on the EU Standard Contractual Clauses or an equivalent safeguard.
How long we keep data
- Account data: while your account is open, then up to 30 days.
- Customer Data: while your project exists; deleted within 30 days after you delete the project or close your account.
- Security logs: up to 90 days. Email: as long as needed to handle your request.
Your rights
Depending on where you live, you can ask to access, correct, delete or export your personal data, object to or restrict its processing, and complain to your data protection authority. Email legal@revenuedot.app. If your request is about an app that uses RevenueDot Cloud, we will pass it to that app's developer, who controls that data. We do not sell or share personal data for cross-context advertising.
Children
The Service is for developers and businesses, not children. Apps that use it are responsible for their own users' privacy, including children's.
Changes
We will post changes here and update the date above. For material changes to how we handle Cloud data, we will also email account owners.