Privacy Policy
Last updated July 24, 2026
Stay Instead provides a hosted cancellation and retention-offer service that SaaS vendors place in front of their billing flow. This policy explains what data we process, why, and how it is protected. Vendors configure Stay Instead and control the relationship with their own customers; where Stay Instead processes a customer’s data, it does so on the vendor’s behalf.
Data we process
Depending on how a vendor configures Stay Instead, we may process:
- Vendor account data - name, email, authentication data, project settings, and API keys (stored only as one-way hashes).
- Connected Stripe account identifiers - the vendor’s connected account id (for example
acct_…) and granted scopes. We never store a vendor’s Stripe secret keys. - Stripe customer and subscription identifiers - such as customer and subscription ids, plan/price ids, billing interval, currency, and amount, retrieved to evaluate and apply retention offers.
- Cancellation context - the reasons a customer selects and any optional free-text feedback they provide.
- Offer and billing-action records - which offers were presented and accepted, the exact terms consented to, and the status of any resulting billing change.
- Stripe webhook events - signature-verified event envelopes, stripped of known personal fields, used to confirm and reconcile billing actions.
- Customer email - only where a vendor enables an email-verification step in their flow.
- Technical and security logs - request identifiers, timestamps, and safe internal ids used for reliability, fraud prevention, and audit.
Payment data
Stay Instead does not store full payment-card details. Stripe independently processes all payment information as a payment processor. When a retention offer is applied, the change is made through Stripe’s API against the vendor’s connected account.
How we use data
- To provide the cancellation flow and evaluate which vendor-configured retention offers a customer is eligible for.
- To apply a vendor-configured subscription change through Stripe - a discount, a free billing cycle, or a temporary payment pause - only after the customer is shown the exact effect and explicitly accepts it.
- To confirm, reconcile, and audit billing actions using Stripe webhooks and scheduled checks.
- For security, fraud prevention, dispute handling, debugging, and to meet legal obligations.
Automatic subscription changes are available only when a vendor has connected Stripe and enabled them. Otherwise Stay Instead operates in a feedback-only mode and hands the customer back to the vendor’s billing page or Stripe Customer Portal.
Retention
We retain offer, consent, and billing-action records for as long as needed to provide the service and, after that, as required for fraud prevention, dispute resolution, and legal obligations. Consent records are kept as an immutable proof of what a customer agreed to and are not altered by later changes a vendor makes to an offer.
Test and live data
Stay Instead keeps Stripe test and live environments operationally separate. A session created in test mode is bound to test credentials and can never act against live billing, and vice versa.
Sharing and subprocessors
We share data only with the infrastructure providers needed to run the service. See our Subprocessors list. We do not sell personal data.
Your choices and the vendor relationship
If you are a customer of a vendor that uses Stay Instead, the vendor is responsible for your subscription and for answering questions about it. Please contact the vendor directly for requests relating to your subscription. For questions about Stay Instead itself, contact contact@stayinstead.co.
Security
We apply layered technical measures designed to protect the data we process, including: storing session tokens and API keys only as one-way (SHA-256) hashes; keeping Stripe and database secrets on the server only; enforcing row-level access controls so a vendor can reach only their own data; verifying every Stripe webhook signature; and maintaining an append-only audit trail of billing-sensitive actions. No system is perfectly secure, and we describe these measures without implying any specific certification.
Changes and contact
We may update this policy as the product evolves; we will revise the date above when we do. Questions? Email contact@stayinstead.co.
Reviewer note: this policy should be completed with Stay Instead’s legal entity name, registered address, governing jurisdiction, and any region-specific rights (for example GDPR/CCPA) that apply to your operations before publication. These facts are intentionally left blank rather than invented.