Skip to content
Legal

Privacy Policy

Your transaction and customer data are sensitive. This policy describes what RefundSensor collects, why, and how we keep it protected.

Last updated · June 2026

Product: RefundSensor (refundsensor.com)

Operated by: Vasundhara Infotech LLP

Effective date: 1 June 2026

Last updated: 1 June 2026

1. Introduction

This Privacy Policy explains how Vasundhara Infotech LLP ("RefundSensor", "we", "us", or "our") collects, uses, stores, shares, and protects personal data when you use the RefundSensor website at refundsensor.com and the related software, dashboards, APIs, and services (together, the "Service").

RefundSensor is a business-to-business platform that helps app developers and digital businesses ("Customers") track refund requests for their applications and automate responses to those requests. To do this, the Service connects to platform accounts you authorise (such as Apple App Store Connect) using credentials you provide.

By accessing or using the Service, you confirm that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Service.

This Policy should be read together with our Terms of Use, Cookie Policy.

2. Who we are (Data Controller / Data Fiduciary)

For personal data we process about our own Customers, account holders, and website visitors, the controller (referred to as a "Data Fiduciary" under Indian law) is:

For personal data that flows through the Service about your own end users (for example, the app users who request refunds), you are the controller and we act as your processor.

3. The data we collect

3.1 Information you provide to us

  • Account and identity data: name, business/company name, email address, phone number, job title, billing address, and login credentials.

  • Platform credentials and integration keys: the credentials you provide so the Service can connect to your platform accounts. For Apple integrations this includes your App Store Connect / App Store Server API key (.p8 file), Key ID, and Issuer ID. These keys allow the Service to read subscription, transaction, and refund information from your Apple account and to act on refund-related requests on your behalf.

  • Configuration and content: the rules, templates, automated reply text, and settings you create within the Service.

  • Support and communications: information you share when you contact us by email, chat, or support tickets.

3.2 Information we collect automatically

  • Usage and log data: pages viewed, features used, actions taken, timestamps, referring URLs, and similar diagnostic data.

  • Device and technical data: IP address, browser type, operating system, device identifiers, and language settings.

  • Cookies and similar technologies: as described in our Cookie Policy.

3.3 Information we receive from third parties

  • Platform data: subscription, purchase, transaction, and refund data retrieved from the platforms you connect (for example, the Apple App Store) using the credentials you provide.

  • Payment data: transaction confirmation, subscription status, and limited billing metadata from our payment processor, Razorpay. We do not collect or store your full card number, CVV, or banking credentials - these are handled directly by Razorpay (see Section 6).

3.4 Special note on the Apple .p8 key and platform credentials

Your platform credentials, including the Apple .p8 key, are confidential and sensitive. We handle them as follows:

  • They are encrypted at rest and in transit.

  • Access is strictly restricted to the systems and authorised personnel required to operate the Service.

  • They are not sold, rented, shared, or exposed to any third party, and are not used for any purpose other than operating the Service for you.

  • You can revoke or rotate the key at any time from your Apple account, and you can ask us to delete it (see Section 9).

4. How we use personal data

We use personal data to:

  • create and manage your account and authenticate you;

  • provide, operate, and maintain the Service, including connecting to your platform accounts, tracking refund requests, and sending automated replies you configure;

  • process subscriptions, billing, and payments through Razorpay;

  • provide customer support and respond to your requests;

  • send service, security, and transactional communications (for example, billing notices, downtime alerts, and policy updates);

  • monitor, secure, debug, and improve the Service and prevent fraud or abuse;

  • comply with legal, tax, accounting, and regulatory obligations; and

  • send marketing communications where you have opted in or where otherwise permitted by law (you can opt out at any time).

Where the EU/UK General Data Protection Regulation applies, we rely on the following legal bases:

  • Performance of a contract — to provide the Service you have signed up for.

  • Legitimate interests — to secure, maintain, and improve the Service, prevent fraud, and run our business, provided these interests are not overridden by your rights.

  • Consent — for optional marketing and for non-essential cookies. You may withdraw consent at any time.

  • Legal obligation — to comply with applicable laws (for example, tax and accounting rules).

Under India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025, we process personal data on the basis of your consent or for legitimate uses permitted by the Act. Where we rely on consent, you may withdraw it at any time as easily as it was given.

6. How we share personal data

We do not sell your personal data. We share it only as described below.

6.1 Service providers and sub-processors

We use trusted third parties to operate the Service. These currently include:

Razorpay

Purpose: Payment processing and subscription billing
Location: India

AWS

Purpose: Application hosting and storage
Location: India

A current list of sub-processors is maintained at refundsensor.com and forms part of our Data Processing Agreement. Each provider is bound by contractual confidentiality and data-protection obligations.

6.2 Platform providers

To deliver the Service, we exchange data with the platforms you connect (for example, Apple) using the credentials you authorise. Your use of those platforms is also governed by the platform's own terms and privacy policies.

We may disclose personal data where required by law, court order, or a lawful request from a public authority, or where necessary to protect our rights, safety, property, or that of our users or the public.

6.4 Business transfers

If we are involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction, subject to this Policy.

7. International data transfers

RefundSensor operates globally and our service providers may be located in countries other than your own. Where we transfer personal data internationally, we use appropriate safeguards, such as the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or transfers to jurisdictions recognised as providing adequate protection.

Under the DPDP Act, personal data of individuals in India may be transferred outside India except to any jurisdiction restricted by the Government of India by notification. We monitor such notifications and adjust our transfers accordingly.

8. Data retention

We keep personal data only for as long as necessary for the purposes described in this Policy, including:

  • Account and integration data — for the duration of your subscription and a reasonable period afterwards;

  • Platform credentials (including .p8 keys) — until you disconnect the integration, delete the key, or close your account, after which they are deleted or rendered unusable within a reasonable period;

  • Billing and tax records — for as long as required by applicable tax, accounting, and legal obligations;

  • Logs and diagnostic data — for a limited period needed for security and troubleshooting.

When data is no longer needed, we delete it or irreversibly anonymise it.

9. Your rights

Depending on where you are located, you may have some or all of the following rights:

  • Access the personal data we hold about you;

  • Correct inaccurate or incomplete data;

  • Delete ("erasure" / "right to be forgotten") your data;

  • Restrict or object to certain processing;

  • Portability — receive your data in a structured, machine-readable format;

  • Withdraw consent at any time, where processing is based on consent;

  • Nominate another person to exercise your rights in the event of death or incapacity (under the DPDP Act);

  • Lodge a complaint with your data protection authority (see Section 13) or with the Data Protection Board of India.

If you are a California resident, you also have rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of the "sale" or "sharing" of personal information. We do not sell personal information. We will not discriminate against you for exercising these rights.

To exercise any right, contact us using the details in Section 12. We will respond within the timeframes required by applicable law. We may need to verify your identity before acting on a request.

10. Security

We implement reasonable technical and organisational measures designed to protect personal data, including encryption of credentials at rest and in transit, access controls, network protections, logging, and regular review of our practices. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

If we become aware of a personal data breach, we will notify the relevant supervisory authority and affected individuals where required by applicable law, including the breach-notification duties under the DPDP Rules, 2025 and Article 33/34 of the GDPR.

11. Children

The Service is intended for businesses and is not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

12. Contact us

For any questions, requests, or concerns about this Policy or your personal data:

Email: [email protected] 

13. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date and, where required, notify you by email or through the Service. Your continued use of the Service after the changes take effect constitutes acceptance of the updated Policy.