data processing agreement
what we store, and what we never touch.
A short agreement, in plain language, for what happens when you connect Stripe and your app database to Entitled. This describes the actual data flow, see the security page for the technical constraints that enforce it.
What is processed
Only what is needed to compare who paid against who has access:
- · Stripe customer id and account creation date
- · Customer email address
- · Subscription id, plan / product name, and price id
- · Subscription or access status (active, canceled, trialing, etc.), including whether it is set to cancel at the end of the current period
- · Period end / renewal date
- · Whether the customer's most recent payment was refunded or disputed, worked out from Stripe's charge and dispute status (the charge and dispute records themselves are not kept, only that one word)
- · The columns you mapped in your own app database: customer id, email, the access column, and plan / period end if you mapped them
What is not processed
- · Card numbers or any other payment instrument detail
- · Payment methods (Stripe tokens, bank details)
- · Any column in your database other than the ones you mapped
- · Any Stripe object type outside the read scopes listed on the security page
Where it runs
Everything runs on one server in Frankfurt, Germany (DigitalOcean's fra1 region). The web app, the worker that reads your data, and the database all sit on that machine, inside the EU. Every read of your database comes from 161.35.64.36, so you can restrict access to that single address.
Site analytics
Visits to this site are counted with Umami, running on the same Frankfurt server. No third party receives them, so it is not a subprocessor. It sets no cookies. Before anything is recorded, report ids and the tokens in claim and unsubscribe links are removed from the address, and query strings are dropped. Events carry a name and at most the plan bought, never an email address, a customer id, or anything read from Stripe or your app.
Retention
Each run overwrites the previous read of Stripe and of your app; we don’t keep a history of every past read, only the latest one. An open disagreement is kept for as long as it stays open: a current disagreement is current information, however old it is. Once a finding is resolved, it and the log of events that led to it are deleted after the plan’s history window: there is nothing to delete on the free scan (a single run keeps no history to begin with), 7 days on the audit, and 365 days on Watch. A cleanup runs automatically once a day and removes anything past its window; you never need to trigger it yourself.
Deletion on disconnect
Deleting a report from its page deletes the sealed credentials, the snapshot, and every finding and its history at once, immediately, nothing held back for later. We never held payment methods to begin with, so there is nothing further to purge there.
Subprocessors
Stripe
Source of billing and subscription data, read via a restricted key you create and can revoke.
Resend
Transactional email: the claim link that gets you back to your report, and Watch alerts and weekly summaries.
Polar
Payment processing for the $49 audit and the $99/year Watch subscription. Polar is the merchant of record; we never see card details.
DigitalOcean
Hosting. Runs the web app, the worker that executes scans, and the database, on one server in Frankfurt (fra1), Germany. The worker holds the master decryption key; the web app does not.