ChurnShift Privacy Policy
Aug 8, 2025
1. Overview
ChurnShift is committed to protecting the privacy and security of our customers’ data. This Privacy Policy explains how ChurnShift collects, uses, and protects information when our solution is deployed within your own Virtual Private Cloud (VPC).
Because ChurnShift operates entirely within your infrastructure, you retain full control over your data and ChurnShift does not access or store your customer information outside of your environment.
2. Scope of the Policy
This policy applies to:
All instances of ChurnShift software deployed in a customer-managed VPC.
All data processing activities carried out by the ChurnShift solution within that environment.
3. Data Collection and Processing
3.1 Data Processed
ChurnShift processes only the data you choose to provide for churn prediction and analytics purposes. This may include:
Customer profile information (e.g., account details, engagement metrics)
Transactional data (e.g., purchase history, subscription events)
Behavioral data (e.g., product usage logs, interaction patterns)
Note: All processing occurs within your VPC.
3.2 No External Data Transfer
ChurnShift does not export raw customer data outside your environment.
We do not store your data on ChurnShift-managed servers.
Any model training, inference, or analytics are performed locally in your VPC.
4. Access Control
All access to data is governed by your organization’s access policies.
ChurnShift personnel do not have access to your production data unless explicitly authorized for troubleshooting and only under your supervision.
Administrative credentials are controlled solely by you.
5. Security Measures
ChurnShift follows best practices for security, including:
Deployment in isolated, customer-controlled network environments.
Encryption in transit (TLS) and at rest (as configured in your VPC).
Role-based access control (RBAC) and audit logging.
Support for customer-managed encryption keys (CMEK).
6. Data Retention
Since all data resides in your VPC, you control data retention and deletion policies. ChurnShift does not retain or back up customer data in external systems.
7. Compliance and Regulatory Support
ChurnShift can be configured to meet various regulatory requirements, including:
GDPR – Full control of personal data, right to erasure.
CCPA/CPRA – Data remains in customer possession; no sale or sharing.
Industry-specific frameworks (e.g., HIPAA, SOC 2 alignment).
8. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Updated versions will be provided to you prior to implementation.
9. Contact Us
If you have any questions or concerns regarding this Privacy Policy or ChurnShift’s data handling practices, please contact privacy@churnshift.com