Legal
Privacy Policy
CashSDK is a business-to-business platform. We collect what we need to run your workspace, we process End-User purchase data only on your instructions, and we never sell any of it. This policy covers both roles — and the rights you and your users can exercise.
On this page
1. Who we are and what this policy covers#
This Privacy Policy explains how CashSDK (“we”, “us”) handles personal data across cashsdk.com and its subdomains — including the dashboard at app.cashsdk.com and sign-in at auth.cashsdk.com — the CashSDK APIs and SDKs, and our support channels.
We wear two hats. For data about you — visitors, account holders, and workspace members — we are the controller, and this policy is the primary document. For data about your apps' End Users that flows through the platform, we are a processor acting on your instructions; that processing is governed by our Data Processing Addendum at cashsdk.com/dpa, and Section 4 below summarizes it.
If you are an End User of an app that uses CashSDK, the app's developer is responsible for your data — their privacy policy is the one to read, and requests about your data should go to them. Section 4 explains how we help developers honor those requests.
2. Information you provide to us#
- Account and workspace data — your name, email address, workspace name, role, and the settings you configure. Sign-in is passwordless, so we never hold a password for you.
- Billing data — your plan, invoices, and payment method. Card details are collected by our payment processor, Stripe, on Stripe-hosted pages; we never see or store full card numbers.
- Store credentials — keys you provide so the platform can act on your behalf with the app stores (for example App Store Connect API keys or Google Play service-account credentials). These are envelope-encrypted at rest and used only on your instructions.
- Communications — messages you send to support or sales, and anything you submit through forms on our sites.
3. Information we collect automatically#
- Usage and device data — pages viewed, features used, browser and OS type, referring pages, and approximate region derived from your IP address.
- Log data — request logs including IP address, timestamps, user agent, and the identifiers needed to secure the APIs (such as API-key identifiers). Logs are kept for a limited period (see Section 11).
- Diagnostics — error and performance reports from our sites and services (we use Sentry). These are scrubbed of secrets and configured to minimize personal data.
- Cookies and similar technologies — described in our Cookie Policy at cashsdk.com/cookie. Analytics cookies are not set for visitors in the EEA, UK, or Switzerland by default.
4. End-User data we process for our customers#
When your app integrates a CashSDK SDK or you call our APIs, we process purchase and entitlement data about your End Users so the platform can validate transactions, manage subscriptions, and compute your analytics. Typical categories: the user identifiers you assign, store transaction identifiers and signed receipts, product, price, currency and timestamps, subscription and entitlement state, and platform metadata such as OS and SDK version.
We process this data only to provide the Service to you, to secure it, and as required by law — never for advertising, never for profiling for our own purposes, and never for sale. The DPA at cashsdk.com/dpa is the binding contract for this processing, including the subprocessor list, security measures, and deletion commitments.
We generally cannot identify a human being from this data on our own — we hold the identifiers you assign, not the names behind them. If an End User contacts us directly, we will refer them to the relevant developer and support the developer in responding.
5. How we use information#
- Provide and operate the Service — accounts, workspaces, validation, entitlements, paywalls, analytics, and support.
- Billing — metering usage, charging the payment method on file, invoicing, and collections.
- Communications — transactional messages (sign-in codes, receipts, service and security notices) and product updates you can opt out of. Sign-in codes arrive by email because sign-in is passwordless.
- Security and abuse prevention — authenticating requests, rate limiting, and investigating incidents and suspected violations of our Acceptable Use Policy.
- Improvement — understanding, in aggregate, what works and what doesn't, and debugging with scrubbed diagnostics.
- Compliance — meeting legal obligations, enforcing agreements, and establishing or defending legal claims.
We do not sell personal data, we do not run third-party advertising, and we do not use Customer Data to train advertising or marketing models.
6. Legal bases for processing (EEA and UK)#
Where the GDPR or UK GDPR applies to processing we do as a controller, we rely on these legal bases:
| Purpose | Legal basis |
|---|---|
| Providing the Service and support | Performance of a contract (Art. 6(1)(b)) |
| Billing, accounting, and tax records | Legal obligation (Art. 6(1)(c)) and contract |
| Security, abuse prevention, and diagnostics | Legitimate interests (Art. 6(1)(f)) in keeping the Service safe |
| Product updates and marketing email | Legitimate interests, with an opt-out in every message; consent where required |
| Analytics cookies | Consent (Art. 6(1)(a)) — not set in the EEA or UK without it |
| Responding to legal requests | Legal obligation |
7. How we share information#
We share personal data only as described here. We never sell it, and we never share it for cross-context behavioral advertising.
- Subprocessors and service providers — the vendors that run our infrastructure, listed with their roles in Annex 3 of the DPA: hosting, content delivery and network security, payments, transactional email, error monitoring, and website analytics. Each is bound by contract to protect the data and to use it only to provide their service to us.
- App stores and integrations, at your direction — when you connect credentials or enable an integration, we exchange the relevant data with that platform on your behalf (for example, calling Apple and Google APIs to validate transactions, or forwarding events to a webhook you configure).
- Professional advisers — lawyers, accountants, and auditors, under confidentiality, where needed.
- Legal reasons — to comply with law or valid legal process, or to protect the rights, safety, or property of CashSDK, our customers, or the public. Where lawful, we will notify you before disclosing your data in response to a request.
- Business transfers — if we go through a merger, acquisition, or asset sale, data may transfer as part of it; this policy continues to apply, and we will notify you of any successor.
8. Cookies and analytics#
Our Cookie Policy at cashsdk.com/cookie lists every cookie we set and why. The short version: one essential cookie (cashsdk_session) keeps you signed in across CashSDK sites; Google Analytics runs on the marketing site with Consent Mode, has advertising storage disabled everywhere, and sets no analytics cookies for visitors in the EEA, UK, or Switzerland; and payment pages are hosted by Stripe.
9. International data transfers#
We are a US-based service and process data primarily in the United States. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum or Swiss adaptations, as applicable) as incorporated in our DPA, together with supplementary measures such as encryption in transit and at rest. You can request a copy of the relevant transfer mechanism at support@cashsdk.com.
10. Security#
We protect data with encryption in transit (TLS) and at rest, envelope encryption for store credentials, tenant isolation enforced at the database layer, least-privilege internal access, and logging of administrative activity. Annex 2 of the DPA describes our measures in more detail.
No online service can promise perfect security. If you find a vulnerability, tell us at security@cashsdk.com — we read every report. If a breach affects your data, we will notify you as described in the DPA and as the law requires.
11. Data retention#
- Account and workspace data — for the life of the account, plus a short period after closure to handle residual obligations.
- Billing records — for as long as tax and accounting law requires.
- End-User data — per your instructions and the DPA: exportable at any time, deleted from live systems within 90 days after termination, with residual encrypted backups expiring on schedule no later than 180 days after termination.
- Server logs and diagnostics — routinely deleted or de-identified, typically within 90 days.
- Support correspondence — for as long as needed to resolve the matter and improve support.
12. Your rights and choices#
Everyone: you can review and update workspace information in the dashboard, opt out of marketing email using the link in each message, and raise any privacy question at support@cashsdk.com.
EEA, UK, and Switzerland: you may request access, correction, deletion, restriction, and portability, and you may object to processing based on legitimate interests. You may withdraw consent at any time without affecting past processing, and you may lodge a complaint with your supervisory authority — though we'd welcome the chance to resolve concerns first.
California and other US states: you may request to know, access, correct, and delete personal information, with a right to non-discrimination for exercising those rights. We do not sell or share personal information as the CCPA/CPRA defines those terms, and we do not use sensitive personal information beyond providing the Service. Authorized agents may submit requests on your behalf.
We verify requests (usually by confirming control of the account email) and respond within the time the applicable law requires. If the data belongs to a developer's End User, we refer the request as described in Section 4.
13. Children#
Our sites and the Service are business tools, not directed to children, and we do not knowingly collect personal data from anyone under 16. Apps built by our customers have their own audiences and their own policies — obligations for apps directed at children rest with the developer, as our Acceptable Use Policy makes explicit. If you believe a child's data has reached us in error, contact support@cashsdk.com and we will delete it.
14. Changes to this policy#
We will update this policy as the product and the law evolve. Material changes are announced by email or in the dashboard at least 14 days before they take effect; the “Last updated” date above always reflects the current version, and prior versions are available on request.
15. Contact us#
Privacy questions and requests: support@cashsdk.com with the subject “Privacy”, or the form at cashsdk.com/contact. Security reports: security@cashsdk.com.
Questions about our policies? Contact →