Privacy policy

Last updated 9 September 2026

churnbrake shows a cancellation flow to the customers of the businesses that use it. That means two very different kinds of people are involved: the businesses who sign up, and their subscribers who meet the flow. This page says what is held on each, and why.

Who we are

churnbrake is published by Jovan Panetie, RCS de Dijon, SIREN 849268958, 5 Rue Castelnau, 21000 Dijon, France. For anything on this page, write to jovan@churnbrake.com or call +33 7 44 26 89 61.

For the businesses who sign up, we are the data controller. For their subscribers — everyone who is shown a cancellation flow — the business is the controller and we act as their processor. If you met churnbrake while cancelling something, the company you were cancelling is who to ask first, and we will help them answer.

Businesses who sign up

When you create a churnbrake account we store:

  • Your email address. There is no password — signing in is a code sent to that address — so there is no password hash to leak either.
  • Your organisation name, and the public App ID and signing secret your integration uses. The secret is encrypted at rest with a key held outside the database.
  • If you connect Stripe: the account id and the OAuth tokens, both encrypted at rest. We never see or store card details.
  • The cancellation flow you write: your questions, your offers and their wording.

Your subscribers

When somebody is shown a flow, one session is recorded. It holds:

  • Their Stripe customer id and subscription id — identifiers issued by Stripe, not names or email addresses. churnbrake never receives their name, their address or their payment details.
  • Which reason they chose, and any free-text comment they wrote.
  • Which offer they were shown, and whether they took it.
  • A one-way hash of their IP address, and their browser's user-agent string. The address itself is never written down; the hash exists to spot abuse and cannot be turned back into an address.

The free-text box is the one place a subscriber can type anything at all, including something identifying, because it is a free-text box. It goes to the business they were cancelling and nowhere else.

What we do not do

  • No advertising, no profiling, no selling anything to anybody.
  • No third-party analytics or tracking scripts inside the cancellation flow. It sets no cookies of its own.
  • No use of your subscribers' data to build anything of our own across accounts.

Who else touches it

Three processors, and nothing beyond them:

  • Hostinger — the server this runs on.
  • Resend — sends the sign-in code to businesses. It never emails subscribers.
  • Stripe — when a business connects their account, an accepted offer is applied there. Stripe is the controller of their own data as a payment provider.

How long it is kept

  • Account data: for as long as the account exists, and deleted with it.
  • Session and event records: kept while the account exists, because they are what the business bought — the record of why their customers left. A business can ask for any of it to be deleted at any time.
  • Sign-in codes: ten minutes, hashed, then gone.

Your rights

Under the GDPR you may ask for a copy of your data, its correction, or its deletion, and you may object to how it is handled. Write to jovan@churnbrake.com. If you are a subscriber rather than a customer of ours, ask the business whose flow you saw — they hold the relationship, and we act on their instruction. You may also complain to the CNIL.

Changes

If this page changes in a way that affects what is collected or who it reaches, account holders are told by email before it takes effect. The date at the top is the only version marker there is.