Privacy

What we collect, why, and what we will never do with it. Last updated August 2026.

Our role

When a business installs Retain, that business is the data controller and we are the data processor. We act only on their documented instructions. Their customers are their customers, and the data describing those customers is theirs, not ours.

What we collect

For each end customer of a business using Retain, we record: a random identifier scoped to that business, the fact that events occurred and when, the type of event, and where a business sends it, the value of a transaction.

We do not collect names, email addresses, physical addresses, phone numbers, payment card details, or any content a person writes, types, uploads or records. There is no field in the schema for any of these.

Identifiers are scoped to a single business. No key links a person across two businesses using Retain, and no such key exists to be created, requested or compelled.

Why we collect it

To measure whether a customer is drifting from their own established pattern, to decide whether an intervention is warranted, and to measure the difference that intervention made against a group deliberately left alone. Aggregate patterns across businesses improve the plays offered to all of them, expressed as counts and medians only.

What we will never do

We will not sell or share customer-level data with any third party. As a processor, doing so would be an unlawful change of purpose, and structurally we hold nothing that would be useful to a buyer. We will not use one business's data to advantage another beyond anonymous aggregate benchmarks. We will not profile individuals outside the business that collected them.

Deletion and access

A business can delete any individual record, or every record it holds with us, through a single API call. Deletion is immediate and complete, with no archived copy retained. Businesses can export their full event history at any time in CSV or JSON.

Sub-processors

Supabase provides database and authentication infrastructure. Netlify provides static hosting. Stripe processes payments where a business uses Retain Checkout; we never hold funds or card data. These are the only third parties with any access to infrastructure holding customer data.

Security

Row level security is applied to every table. The key embedded in a client can write events and read nothing. Administrative keys are never distributed to clients and are rotated on any suspicion of exposure. We do not currently hold SOC 2 certification, and we say so rather than implying otherwise. Our compensating measure is that the client source is published and readable, and the data we hold is described here in full.

Contact

Questions, deletion requests, or a data processing agreement: Jordan.l@hotmail.com. We answer directly, including where the answer is that something does not exist yet.