Data Lifecyle

Data Collected

Refiner may process the following types of data:

  • User identifiers (e.g. user ID, email address)
  • User traits (e.g. plan, role, custom attributes)
  • Events (user actions, if tracked)
  • Survey responses (including free-text feedback)

We recommend only sending data that is necessary for your use case. Avoid sending sensitive personal data unless absolutely required.

Data Residency

Your personal data, your imported user data, as well as data we collect on your behalf from your users, is safely stored in our AWS cloud in the EU-WEST-1 (Ireland) data center. The physical data residency of your user data is in Europe at all times.

By default, your user data stays within our data center at all times won’t be sent to any third party sub-processors (see Sub-Processors section below).

We might send data about our customers (your name, company, email, …) to third party providers, such as our CRM or email sending solution. We are committed to anonymize personal data as much as possible in that case.

We don’t store any payment information and don’t process payments on our own infrastructure. We are using Stripe and Chargebee for all payment related matters. Stripe and Chargebee are both PCI compliant services.

Data Retention

By default, user data is retained in your account environment for as long as you maintain an active paid subscription, unless you delete it or configure shorter retention settings.

You can control retention in several ways:

  • Delete individual user records
  • Delete or purge an environment
  • Configure automatic deletion of old user profiles after a period of inactivity
  • Export data you need to keep outside Refiner

You are responsible for choosing retention settings that match your own legal, regulatory, and business requirements. We recommend regularly reviewing stored data, deleting data that is no longer needed, and exporting or backing up data that you need to retain long-term.

Refiner is not intended to be used as long-term archival or backup storage.

When you cancel your subscription, your data may remain available for export for a limited retrieval period of up to 180 calendar days. After that period, it may be permanently deleted from our systems in accordance with our Terms of Service and Data Processing Agreement.

Sub-processors

By default, no user data is shared with third party sub-processors other than our hosting provider AWS Europe.

Refiner uses a limited number of trusted sub-processors to operate and deliver the service, such as infrastructure and payment providers. These vendors are carefully selected and bound by strict data protection and security requirements.

If you choose to use our Notification features, user data will be shared with our email service provider Customer.io. If you choose to use IP address based geo targeting, we’ll send anonymized IP addresses to our IP geocoding provider.

A full list of our sub-processors can be found in our GDPR Data Processing Agreement template.

Third-Party Integrations

Refiner can send data to third-party tools (e.g. Slack, CRM systems, data warehouses).

When using integrations:

  • Ensure those tools meet your compliance requirements
  • Understand what data is being shared and why
  • Update your privacy policy accordingly

AI Data Processing

Our AI-powered features (AI Translations and AI Tagging) are designed with the same strict data protection principles that apply to the rest of our platform. We use AWS Bedrock to process AI requests within our secure infrastructure, ensuring that customer data does not leave our controlled environment and is not used to train external models.

Was this helpful? Let us know with a quick a vote