Skip to content
Back to home

Acceptable Use and Security

RevFence's acceptable use rules and general security approach.

RevFence is a software service offered to businesses to manage subscription cancellation and customer retention processes. So that the service can run reliably, steadily and safely for all customers, RevFence must not be used in a way that harms the law, the rights of third parties or the security of the service.

This policy sets out RevFence’s acceptable use rules and its general approach to security. Customers who use RevFence, and the users who access the service through their account, must comply with these rules.

This policy forms part of our Terms of Service and applies together with them.

01Acceptable use of the service

RevFence may be used only for activities that are lawful, legitimate and consistent with the purposes of the service.

The Customer is responsible for operations carried out through its account and for the users it gives access to its account acting in accordance with this policy.

The cancellation flows created through RevFence, the offers presented, the information collected and the subscription operations carried out must comply with applicable law, the Customer’s own contracts and the statements the Customer makes to its customers.

The Customer must hold all rights, permissions and legal bases necessary to use RevFence and to process the data it transfers to the service.

02Prohibited uses

RevFence may not be used for the following purposes or in a way that produces the following results:

  • Violating applicable laws, regulations or binding legal obligations
  • Committing fraud, deception, impersonation or misleading commercial practices
  • Carrying out unauthorized subscription, payment or account operations without a person’s consent or knowledge
  • Misleading customers about cancellation rights, subscription terms, prices or offers presented
  • Making a cancellation unreasonably difficult, hiding it or unlawfully blocking it
  • Using deceptive interfaces, manipulative designs or unfair commercial practices
  • Carrying out unauthorized discounts, credits, plan changes or subscription operations
  • Collecting, using or sharing personal data without a valid legal basis
  • Violating privacy, consumer protection, electronic communications or marketing rules
  • Infringing intellectual property, privacy, personality or other third-party rights
  • Processing harmful, unlawful, threatening or abusive content
  • Engaging in spam, phishing, malicious redirection or unsolicited commercial communication
  • Abusing or damaging RevFence or third-party systems

This list is not limited to covering every inappropriate use of the service. Even if an activity is not expressly listed, RevFence may intervene in activities that pose a serious risk to the security and rights of other customers or third parties.

03System and network security

Activities that could endanger the security, integrity or availability of RevFence or any system connected to RevFence are not permitted.

The following are prohibited:

  • Attempting to gain unauthorized access to an account, system, network, data or service component
  • Attempting to access data or accounts belonging to another Customer
  • Bypassing authentication, authorization or access controls
  • Disabling, defeating or evading security measures
  • Carrying out security scanning, penetration testing or automated vulnerability research without RevFence’s written permission
  • Attempting to obtain the source code of the service or to decode its protected components
  • Transmitting viruses, malware, harmful code or disruptive content to the service
  • Carrying out a denial-of-service attack or preventing the normal operation of the service
  • Placing excessive load on the infrastructure, APIs or integrations by generating unusual traffic
  • Attempting to exceed rate limits, usage quotas or technical restrictions
  • Sending forged requests, misleading technical data or altered webhook messages
  • Altering or hiding security logs, transaction history or audit trails
  • Abusing an identified vulnerability or increasing risk by disclosing it to others

People who wish to examine the security of RevFence in good faith must contact us before carrying out any test and obtain explicit written permission.

04Account and access security

The Customer must give access to its RevFence account only to people it has authorized. User accounts should be personal to the individual wherever possible, and sign-in details should not be shared among several people.

Customers are expected to:

  • Use strong and unique passwords,
  • Keep sign-in details and access links confidential,
  • Review user roles and account permissions regularly,
  • Remove permissions of users who no longer need access,
  • Connect integrations only with trusted and authorized accounts,
  • Report suspicious or unauthorized account activity to us without delay

These expectations apply to the Customer and to every user acting under its account.

If you suspect that an account, credential or connected integration is being used without authorization, you should contact us at hello@revfence.com.

05Use of APIs and integrations

APIs, webhooks and third-party integrations provided by RevFence may be used only for the stated technical purposes and within the permissions granted.

The Customer must:

  • Use integrations only with systems and accounts it is authorized to access,
  • Store access keys, tokens and other credentials securely,
  • Not share these details in public repositories, in client-side code or with unauthorized people,
  • Revoke or renew credentials that are no longer needed or that are suspected to have been exposed,
  • Comply with published technical limits and usage quotas for API use,
  • Use data obtained from integrations only for authorized purposes.

Operations carried out through an integration are executed according to the rules the Customer sets within RevFence and the permissions it grants. Checking the accuracy of those rules and the commercial and legal compliance of the operations carried out is the Customer’s responsibility.

06Protection of Customer Data

The Customer should transfer to RevFence only the data necessary to provide the service. Personal data that is unrelated to the purpose of the service or for which there is no sufficient legal basis for processing should not be transferred to RevFence.

In particular, unless the relevant area of the service is expressly designed for this purpose, the following data should not be sent to RevFence:

  • Payment card numbers
  • CVV/CVC security codes
  • Financial account passwords or secret access credentials
  • Copies of government-issued identity documents
  • Health data
  • Biometric data
  • Sensitive personal data relating to children
  • Other sensitive information subject to special legal protection

The Customer is responsible for providing its own customers with the necessary privacy notices and for having a valid legal basis for the personal data it processes through RevFence.

The rights and obligations of the parties regarding the processing of Customer Data are set out separately in our Data Processing Agreement.

07RevFence’s approach to security

RevFence applies technical and organizational measures appropriate to the structure of the service and the risks involved to protect the service and the data it processes against unauthorized access, alteration, disclosure, loss or misuse.

Depending on the relevant component of the service, these measures may include:

  • Encryption of data in transit
  • Secure authentication mechanisms
  • Role- and permission-based access controls
  • Separation of customer environments
  • Secure storage of passwords and access credentials
  • API and webhook security controls
  • Verification of webhook signatures
  • Rate limiting controls
  • Protection against repeated operations
  • Keeping security and audit logs
  • Monitoring of suspicious or unusual activity
  • Restricting access to production systems
  • Protective controls against replay attacks

The measures applied may be reviewed according to the development of the service, the technology used, the nature of the data processed and changing security risks.

No internet-based service can guarantee absolute security. The measures RevFence applies do not constitute a guarantee that all security incidents or unauthorized access will be prevented in every circumstance.

08Reporting security incidents

If you detect a vulnerability, unauthorized access or suspicious activity that could affect RevFence or Customer Data, you must report it without delay to hello@revfence.com.

Where possible, it is helpful to include the following in your report:

  • A short and clear description of the problem
  • The service or system component you think is affected
  • The date and time you observed the problem
  • Steps that could help reproduce the problem
  • Relevant technical logs or screenshots, if any
  • Information that lets us contact you securely

Security issues should be given to RevFence to review and take the necessary measures before they are made public or shared with third parties. Abusing a vulnerability, accessing data unnecessarily or disrupting the availability of the service is not considered good-faith security research.

09Monitoring and review

RevFence may review account activity, technical logs, usage levels and system events to protect the security, integrity and availability of the service.

These reviews may be carried out for the following purposes:

  • Detecting security incidents and unauthorized access
  • Preventing fraud or misuse of the service
  • Investigating and fixing technical issues
  • Enforcing usage limits and technical quotas
  • Assessing whether this policy and the Terms of Service have been breached
  • Complying with legal obligations and protecting our rights

Personal data is processed in this context in accordance with our Privacy Policy and, where applicable, our Data Processing Agreement.

10Measures that may be applied in case of a breach

If we reasonably determine that this policy has been breached or that a serious risk to the security of the service has arisen, we may take appropriate measures according to the nature of the breach and the risk it creates.

These measures may include:

  • Requesting an explanation or corrective action from the Customer
  • Asking for certain content, configurations or integrations to be removed
  • Temporarily restricting a risky operation, integration or feature
  • Revoking certain access credentials or asking for them to be renewed
  • Suspending access to the account or to certain parts of the service
  • Restricting access without prior notice where there is an urgent security risk
  • Terminating the account or the agreement in accordance with the Terms of Service
  • Cooperating with competent authorities where legally required

Where circumstances permit, we will try to inform the Customer concerned about the issue and give a reasonable opportunity to remedy the breach. However, we may not give prior notice where immediate action is needed to protect the security of the service, other customers or third parties.

11Customer responsibilities

The security measures RevFence applies do not remove the Customer’s responsibility to protect its own systems and accounts.

The Customer is in particular responsible for:

  • Ensuring the data it transfers to RevFence is obtained lawfully,
  • Granting appropriate access permissions to its users,
  • The security of its own devices, systems and networks,
  • Protecting Stripe and other connected accounts,
  • The accuracy of the cancellation flows, rules and offers it configures,
  • Its users acting in accordance with this policy,
  • Reporting unauthorized access or security suspicions without delay

These responsibilities rest with the Customer.

Configuring the security features provided by RevFence correctly and enabling the available security options is also the Customer’s responsibility.

12Changes to this policy

We may update this policy from time to time to reflect changes in our services, security practices, the technologies we use or our legal obligations.

When we make significant changes, we may also notify you through channels such as the website, an in-account notice or email, as appropriate.

The current policy is published on this page and the “Last updated” date at the top of the page is changed.

13Contact

If you have questions about this policy, the acceptable use rules or the security of RevFence, you can use the contact details at the end of this page.

Contact details

Company:
SWAN TECHNOLOGIES LTD
Address:
Suite 10400 5 Brayford Square, London, United Kingdom, E1 0SG
Country:
United Kingdom
Email:
hello@revfence.com

Last updated: 19 September 2026