Skip to content
retentix
  • Product
  • How it works
  • Pricing
  • FAQ
Log in Get started

Legal

Privacy Policy

Last updated: 25 July 2026

This policy explains what personal data retentix handles, why, and what you can do about it. It is deliberately specific: where we say we do not do something, we do not do it.

Who we are. Osman Nuri Uluhan, a sole proprietor established in Turkey, trading as retentix. Registered address: Hurma Mah., Royal Homes Sitesi, 252. Sokak, B Blok No: 41, Konyaaltı / Antalya, Turkey. Contact: [email protected].

1. Two different situations

retentix serves two kinds of people, and your rights depend on which one you are.

If you have a retentix account — you are a Founder. We are the controller of your account data and this policy governs it directly.

If you reached a cancel flow page — you are a Subscriber of a business that uses retentix. That business decides what happens on that page and what is recorded about you. They are the controller; we only store and process the record on their behalf. If you want your data accessed, corrected, or deleted, contact that business first. You can also write to us and we will pass the request on and tell you we have done so, but we cannot act on their data without their instruction.

Read section 8 if you are a Subscriber — it is written for you.

2. What we collect

From Founders:

  • email address, and authentication credentials (stored hashed, handled by Supabase Auth)
  • plan tier and billing status
  • product names, slugs, and the monthly revenue value you enter for each product
  • your branding settings, including the powered-by preference
  • the cancellation reasons, offers, and offer copy you configure
  • support correspondence you send us

From cancel flow pages (Subscriber Data):

  • a session identifier
  • which cancellation reason was selected
  • which offer was shown, its parameters, and whether it was accepted
  • the customer reference supplied by the Founder — intended to be a pseudonymous identifier such as a billing-system customer ID
  • timestamps and the associated product

We do not collect at all: card numbers, bank details, or any payment instrument; special-category data such as health, religion, ethnicity, or sexual orientation; biometric data; precise geolocation; browsing history or cross-site behavioural data. We do not buy data about you from anyone.

We ask Founders not to place names, email addresses, or other directly identifying data in the customer reference field. If a Founder does so anyway, that data reaches us without our asking; the Founder remains the controller of it and we handle it under this policy and our contract with them.

3. Why we process it, and on what legal basis

PurposeBasis (GDPR)
Creating your account and letting you sign inPerformance of a contract
Providing the panel, flow pages, exports, and notificationsPerformance of a contract
Taking payment and applying your plan entitlementsPerformance of a contract
Answering your support requestsPerformance of a contract
Keeping the service secure, preventing abuse and fraudLegitimate interests
Diagnosing errors and maintaining reliabilityLegitimate interests
Complying with tax, accounting, and other legal obligationsLegal obligation

Subscriber Data is processed on the instructions of the Founder who configured the flow. Their own privacy notice, not ours, tells you the basis they rely on.

We do not use your data for advertising and we do not use it to train machine learning models.

4. Who we share it with

We use a small number of service providers. Each processes data only to provide its part of the service, under a contract that restricts it to that purpose.

ProviderWhat it doesWhere
SupabaseAuthentication and databaseFrankfurt, Germany (eu-central-1)
CloudflareSite hosting, edge compute, DNS, email routingGlobal edge network
ResendTransactional email to FoundersUnited States
Lemon Squeezy (a Stripe company)Merchant of Record: payments, invoicing, taxUnited States

We will update this table before adding a provider, not afterwards.

Beyond these, we disclose data only where the law requires it, or in connection with a sale or reorganisation of the business — in which case this policy continues to apply to data already collected until it is replaced by one that is no less protective.

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

5. Where your data is stored and moved

Our primary database is in Frankfurt, Germany, inside the European Economic Area. Founder account records and Subscriber Data are stored there.

Some processing necessarily happens outside the EEA. Resend and Lemon Squeezy operate from the United States. Cloudflare operates a global edge network, so a request may be served from a location near you. We are established in Turkey and access the service from there.

Where personal data leaves the EEA, we rely on the data protection terms of the provider concerned, which incorporate the European Commission's Standard Contractual Clauses. We ask each provider to commit to safeguards equivalent to those in this policy, and we do not use a provider that will not. Copies of the relevant terms can be requested from us.

If you would like to know exactly which provider handles which part of your data and on what basis, write to [email protected] and we will tell you.

6. How long we keep it

DataRetention
Cancel flow events (Subscriber Data)24 months from the event, then deleted
Founder account and configuration dataFor as long as your account is open
Support correspondence24 months
Invoices and tax recordsHeld by Lemon Squeezy as Merchant of Record, for the period their statutory obligations require

When you close your account we delete your account and configuration data from our active systems. Backups are overwritten on their normal rotation cycle, after which the data is gone from those too.

We deliberately do not say "as long as necessary" without a number. A retention period you cannot audit is not a retention period.

7. Cookies

We use only what the service needs to work: a session cookie so you stay signed in, and security-related storage.

We run no third-party analytics, no advertising pixels, and no cross-site tracking. That is why you do not see a cookie banner here — there is nothing to consent to. If that ever changes, this page changes first, before the tool ships.

Cancel flow pages set no tracking cookies. The session identifier recorded there identifies the flow visit, not you across the web.

8. If you reached a cancel flow page

You clicked cancel on a subscription, and the business you subscribe to used retentix to build the page you saw.

What was recorded: which reason you selected, which offer you were shown, whether you accepted it, the time, and a reference code that business uses to identify your account with them. We were not told your name or your email address unless that business chose to put it in the reference field, which we ask them not to do.

Your choice on that page is an agreement between you and that business. retentix does not apply discounts, pauses, or downgrades to your subscription — that business does. If an offer you accepted was not applied, contact them.

To access or delete what was recorded, contact the business. If you cannot reach them, write to [email protected] with the reference and we will identify the account and pass your request on.

9. Your rights

Depending on where you live, you may have the right to know what data we hold, to get a copy, to have it corrected or deleted, to restrict or object to processing, to data portability, and not to be subject to solely automated decisions with legal effect. We do not make automated decisions of that kind.

Where we rely on consent, you can withdraw it at any time; that does not affect processing that already happened.

To exercise any of these, email [email protected]. We will respond within the time the applicable law allows — one month under the GDPR, thirty days under Turkish law — and we may need to verify who you are first, using only the information needed to do so. We do not charge for this and we will not treat you worse for asking.

If you are in the EEA, the UK, or Switzerland, you may also complain to your national data protection authority. If you are in Turkey, you may apply to us under Article 11 of Law No. 6698 and then complain to the Personal Data Protection Authority (KVKK).

10. Security

Data in transit is encrypted. Access to production data is limited to what is needed to operate and support the service. Database access is governed by row-level security so an account can only reach its own rows, and export routes are gated server-side rather than in the browser. Passwords are hashed by our authentication provider and we never see them.

No system is perfectly secure, and we will not pretend otherwise. If a breach affects your data we will tell you and the relevant authority as the law requires.

11. Children

retentix is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe we have, write to [email protected] and we will delete it.

12. Changes

We will update this policy when what we do changes. The "Last updated" date at the top always reflects the current version, and we will tell Founders by email before material changes take effect.

13. Contact

Osman Nuri Uluhan, trading as retentix
Hurma Mah., Royal Homes Sitesi, 252. Sokak, B Blok No: 41, Konyaaltı / Antalya, Turkey
[email protected]
retentix

Keep customers before they leave.

Product

  • Overview
  • How it works
  • Pricing
  • FAQ

Legal

  • Terms
  • Privacy
  • Refunds

Contact

  • [email protected]

© 2026 retentix. All rights reserved.