Ir para o conteúdo
Jurídico

Privacy Policy

Your transaction and customer data are sensitive. This policy describes what RefundSensor collects, why, and how we keep it protected.

Última atualização · June 2026

Product: RefundSensor (refundsensor.com)
Operated by: VASUNDHARA SOLUTIONS LAB LLP
Effective date: 1 June 2026
Last updated: 1 June 2026

1. Introduction

This Privacy Policy explains how Vasundhara Solutions Lab LLP ("RefundSensor", "we", "us", or "our") collects, uses, stores, shares, and protects personal data when you use the RefundSensor website at refundsensor.com and the related software, dashboards, APIs, and services (together, the "Service").

RefundSensor is a business-to-business platform that helps app developers and digital businesses ("Customers") track refund requests for their applications and automatically respond to those requests. To do this, the Service connects to the app-store accounts you authorise — currently Apple App Store Connect and Google Play — using credentials you provide.

By accessing or using the Service, you confirm that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Service.

This Policy should be read together with our Terms of Use and Cookie Policy.

2. Who we are (Data Controller / Data Fiduciary)

For personal data we process about our own Customers, account holders, and website visitors, the controller (referred to as a "Data Fiduciary" under Indian law) is Vasundhara Solutions Lab LLP, India. You can reach us at [email protected].

For personal data that flows through the Service about your own end users (for example, the app users associated with a refund request), you are the controller and we act as your processor, as described in our Data Processing Agreement.

3. The data we collect

3.1 Information you provide to us

  • Account and identity data: your name, sign-in email address, and — for organisation accounts — your company name, company website, and business type. We do not require a phone number or job title to use the Service.

  • Authentication: RefundSensor accounts are passwordless. You sign in with a one-time code sent to your email, or through a supported single sign-on provider (Google, Apple, Facebook, Microsoft, or GitHub). We do not store a password for your account. When you use single sign-on, we receive only your verified email address (and a stable account identifier) from that provider.

  • Platform credentials and integration keys: the credentials you provide so the Service can connect to your app-store accounts.

    • Apple: your App Store Connect / App Store Server API key (.p8 file), Key ID, Issuer ID, and shared secret. These allow the Service to read subscription, transaction, and refund information from your Apple account and to submit refund-related (consumption) responses to Apple on your behalf.

    • Google Play: the Google credentials you authorise so the Service can access your Play Console financial data and receive real-time developer notifications (RTDN). Depending on how you connect, this is either a Google service-account key (JSON) you upload, together with your app package name, or — in our managed setup — access you grant to our service account in Play Console, with notifications routed to a topic we provide (in which case no key is stored for your account).

  • Configuration and content: the apps you connect, team members you invite, notification preferences, and other settings you create within the Service.

  • Support communications: information you share when you contact us by email or through the contact form on our website.

3.2 Information we collect automatically

  • Usage and log data: pages viewed, features used, actions taken, timestamps, and similar diagnostic data.

  • Device and technical data: IP address, browser type, operating system, and language settings.

  • Cookies and similar technologies: as described in our Cookie Policy. We use strictly necessary session cookies and, within the application, Microsoft Clarity product analytics. We do not use third-party advertising or retargeting cookies.

3.3 Information we receive from third parties

  • Platform data: subscription, purchase, transaction, and refund data retrieved from the app stores you connect (the Apple App Store and Google Play) using the credentials you provide. This includes Apple App Store Server Notifications and Google Play real-time developer notifications (such as voided-purchase, refund, and subscription events), and the fuller purchase details we retrieve from Apple's and Google's developer APIs to process them.

  • Payment data: subscription status and limited billing metadata (such as plan, amount, currency, and country) from our payment provider, Paddle. Paddle acts as the Merchant of Record and handles checkout, card details, billing address, and tax directly on its own infrastructure. We do not collect or store your full card number, CVV, or banking credentials.

3.4 Special note on platform credentials (Apple .p8 keys and Google service-account keys)

Your platform credentials — including the Apple .p8 key and any Google service-account key — are confidential and sensitive. We handle them as follows:

  • They are encrypted at rest (AES-256-GCM) and in transit (TLS).

  • Access is strictly restricted to the systems and authorised personnel required to operate the Service.

  • They are not sold, rented, shared, or exposed to any third party, and are not used for any purpose other than operating the Service for you.

  • You can revoke or rotate the credential at any time from your Apple or Google account, and you can remove it yourself by disconnecting the app or integration in your dashboard, or ask us to delete it (see Section 8).

4. How we use personal data

We use personal data to:

  • create and manage your account and authenticate you;

  • provide, operate, and maintain the Service, including connecting to your Apple App Store and Google Play accounts, tracking refund and voided-purchase requests, and submitting the consumption responses you have configured;

  • process subscriptions and billing through Paddle;

  • provide customer support and respond to your requests;

  • send service, security, and transactional communications (for example, billing notices, refund-activity summaries you have opted into, and policy updates);

  • monitor, secure, debug, and improve the Service and prevent fraud or abuse;

  • comply with legal, tax, accounting, and regulatory obligations; and

  • send marketing communications where you have opted in or where otherwise permitted by law (you can opt out at any time).

We do not sell your personal data, and we do not use your data to train third-party machine-learning models.

Where the EU/UK General Data Protection Regulation applies, we rely on the following legal bases:

  • Performance of a contract — to provide the Service you have signed up for.

  • Legitimate interests — to secure, maintain, and improve the Service, prevent fraud, and run our business, provided these interests are not overridden by your rights.

  • Consent — for optional marketing and for non-essential cookies/analytics. You may withdraw consent at any time.

  • Legal obligation — to comply with applicable laws (for example, tax and accounting rules).

Under India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025, we process personal data on the basis of your consent or for legitimate uses permitted by the Act. Where we rely on consent, you may withdraw it at any time as easily as it was given.

6. How we share personal data

We do not sell your personal data. We share it only as described below.

6.1 Service providers and sub-processors

We use trusted third parties to operate the Service. These currently include:

Provider

Purpose

Location

Paddle

Payment processing and subscription billing (Merchant of Record)

United Kingdom / United States

Amazon Web Services (AWS)

Application hosting, database, and storage

India (Mumbai, ap-south-1)

Google Cloud Platform (Pub/Sub)

Receiving Google Play real-time developer notifications (RTDN)

United States / regional

Email delivery (SMTP) provider

Sending transactional and notification emails

Varies by provider

Microsoft Clarity

In-app product analytics (usage and session insights)

United States

A current list of sub-processors is maintained as part of our Data Processing Agreement. Each provider is bound by contractual confidentiality and data-protection obligations.

6.2 Platform and identity providers

To deliver the Service, we exchange data with the app stores you connect — Apple (App Store Connect / App Store Server API) and Google (Google Play Developer API and Google Cloud Pub/Sub for real-time notifications) — using the credentials you authorise. If you sign in using single sign-on, we also verify your identity with the provider you choose (Google, Apple, Facebook, Microsoft, or GitHub). Your use of those platforms is governed by their own terms and privacy policies.

We may disclose personal data where required by law, court order, or a lawful request from a public authority, or where necessary to protect our rights, safety, or property, or that of our users or the public.

6.4 Business transfers

If we are involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction, subject to this Policy.

7. Data retention

We keep personal data only for as long as necessary for the purposes described in this Policy, including:

  • Account and integration data — for the duration of your account and a reasonable period afterwards;

  • Platform credentials (Apple .p8 keys and Google service-account keys) — until you disconnect the integration, delete the credential, or close your account, after which they are deleted or rendered unusable within a reasonable period;

  • Refund, transaction, and consumption-response records — retained while your account is active so you have an auditable history of the refund and voided-purchase activity and the responses submitted to Apple and Google; removing a connected app deletes that app's records;

  • Billing and tax records — for as long as required by applicable tax, accounting, and legal obligations;

  • Logs and diagnostic data — for a limited period needed for security and troubleshooting.

When data is no longer needed, we delete it or irreversibly anonymise it. See our Data Deletion page for how to remove your data.

8. Your rights

Depending on where you are located, you may have some or all of the following rights:

  • Access the personal data we hold about you;

  • Correct inaccurate or incomplete data;

  • Delete ("erasure" / "right to be forgotten") your data;

  • Restrict or object to certain processing;

  • Portability — receive your data in a structured, machine-readable format;

  • Withdraw consent at any time, where processing is based on consent;

  • Nominate another person to exercise your rights in the event of death or incapacity (under the DPDP Act);

  • Lodge a complaint with your data protection authority (see Section 11) or with the Data Protection Board of India.

Much of your data can be managed or deleted directly from your dashboard (editing your profile, disconnecting an app, or deleting your account). If you are a California resident, you also have rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of the "sale" or "sharing" of personal information. We do not sell personal information, and we will not discriminate against you for exercising these rights.

To exercise any right, contact us using the details in Section 11. We will respond within the timeframes required by applicable law. We may need to verify your identity before acting on a request.

9. Security

We implement reasonable technical and organisational measures designed to protect personal data, including encryption of credentials and secrets at rest (AES-256-GCM) and in transit (TLS), least-privilege access controls, audit logging, network protections, and regular review of our practices. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

If we become aware of a personal data breach, we will notify the relevant supervisory authority and affected individuals where required by applicable law, including the breach-notification duties under the DPDP Rules, 2025 and Articles 33–34 of the GDPR.

10. Children

The Service is intended for businesses and is not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

11. Contact us

For any questions, requests, or concerns about this Policy or your personal data, email us at [email protected].

12. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date and, where required, notify you by email or through the Service. Your continued use of the Service after the changes take effect constitutes acceptance of the updated Policy.