Privacy
Collect less. Explain why. Delete on request.
This page says what ChurnRisk reads, what it keeps, who processes it, and how you get it back or make it disappear. Last updated August 8, 2026.
Data we process
Account, billing, connected accounting, selected communication, workflow, audit, and support data are processed only to provide and secure ChurnRisk.
Accounting access is read-only at the permission level. ChurnRisk reads customers, invoices, credit memos, payments, and estimates, and never creates, edits, or deletes a record in your books.
Mailbox access covers only the mailboxes an administrator explicitly authorizes, minus the labels and folders they exclude. From those mailboxes we store the structured signal and a short verbatim quote that proves it, with a link back to the source message where the provider allows it. We do not store a copy of your mailbox.
Purpose and retention
Data supports customer identity, revenue-risk analysis, evidence, approved actions, reporting, and security. Owners control supported retention periods, and expiry runs on a schedule rather than on request. ChurnRisk does not train models on customer data, and customer data is not used to improve any model for any other customer.
Subprocessors and regions
ChurnRisk uses a small set of subprocessors: application hosting, managed PostgreSQL, an email access broker, a voice and messaging provider, and a language model provider for extraction and drafting. Mailbox access is brokered by Unipile, which is hosted in the European Union. The current list, with purposes, regions, and third-party assessment status, is published on the security page and is updated when it changes.
ChurnRisk is built for SOC 2 readiness and does not claim an audit it has not completed. Third-party assessment status shown on the security page belongs to those providers, not to ChurnRisk.
Access, export, and deletion
Authorized Owners and Finance users can export permitted data. Owners can request deletion, which removes derived signals as well as raw records. Audit evidence records that deletion occurred without retaining the deleted content.
Cancelling a subscription does not end your right to export. Export access is preserved for the post-cancellation window recorded in your agreement, and disconnecting a source system never removes the evidence you have already exported. Cancelling never locks you out of your own evidence.
Consent and messaging
Every recipient of a ChurnRisk message is an existing customer of the account holder, and the account holder is the sender of record. Under CASL, the position relied on is implied consent through an existing business relationship, which runs two years from the last transaction. That expiry is tracked per customer, and a customer whose implied consent has lapsed cannot be messaged without an explicit consent record.
Regardless of the consent basis, every commercial message identifies the sender and carries a working unsubscribe mechanism, and opt-outs are honoured within the statutory window. Suppression, quiet hours, and frequency limits are checked immediately before any message is sent. Nothing is sent to a customer without a person on the account holder's team approving it, and a per-channel kill switch stops sending immediately.
ChurnRisk does not sell customer data and does not use it for advertising.
Contact
Privacy requests are handled through the account Owner and the contact channel supplied in the service agreement.