Skip to content
Back to home

Privacy Policy

How RevFence collects, uses, stores and protects personal data.

This Privacy Policy explains how SWAN TECHNOLOGIES LTD (“RevFence”, “we” or “our”) collects, uses, stores and protects personal data when you visit our website, create a RevFence account or use our services.

By using RevFence, you acknowledge that you have read and understood this Privacy Policy.

01Who we are

RevFence is operated by SWAN TECHNOLOGIES LTD (Suite 10400 5 Brayford Square, London, United Kingdom, E1 0SG).

For questions and requests about privacy, personal data or this policy, you can contact us at hello@revfence.com.

02Personal data we collect

The personal data we collect may vary depending on how you interact with RevFence and how you use the service.

Account information

When you create a RevFence account or manage your existing account, we may collect the following:

  • First and last name
  • Email address
  • Company or organization name
  • Account sign-in and authentication details
  • User role and account permissions
  • Account and subscription status

Subscription and billing information

When you subscribe to a paid RevFence plan, we may process information about your subscription, the plan you chose, your usage entitlements and your billing status.

Payment card details are processed by our payment service provider. Unless expressly stated otherwise, card numbers, CVV/CVC codes and similar card details are not stored by RevFence.

Product and usage information

To understand how you use RevFence, provide the service and resolve technical issues, we may process the following:

  • Projects and configuration settings
  • Customer retention offers and rules
  • Cancellation sessions
  • Cancellation reasons
  • Whether offers were accepted or declined
  • Session and application states
  • Usage volume and quota information
  • Audit logs
  • Error, performance and diagnostic information

Customer Data processed through the service

When you use RevFence to manage your own customers’ subscription cancellation processes, we may process personal data that you send to us or that is transferred through the integrations you use.

Depending on how the service is configured, this data may include:

  • Customer and subscription identifiers
  • Email addresses
  • Subscription information
  • Plan information
  • Billing-related information
  • Cancellation reasons
  • Other information needed to run the configured cancellation and customer retention flow

Where RevFence processes this data on your behalf, you are generally the data controller and RevFence acts as the data processor.

The details of processing Customer Data on your behalf are set out in our Data Processing Agreement.

03How we use personal data

Depending on the nature of the data and how you use RevFence, we may use personal data for the following purposes:

  • To provide and operate the RevFence service
  • To create and manage user accounts
  • To verify users’ identity
  • To manage subscriptions, usage entitlements and billing processes
  • To provide customer support and respond to requests
  • To run cancellation and customer retention flows
  • To apply the rules and offers configured by the Customer
  • To carry out authorized Stripe operations and verify their results
  • To keep security and audit logs
  • To detect and prevent fraud, abuse and security incidents
  • To monitor the performance, reliability and availability of the service
  • To detect, investigate and fix errors and technical issues
  • To send operational notices about the service
  • To comply with our legal obligations
  • To enforce our agreements and protect our legal rights

RevFence does not independently decide which commercial offer should be presented to your customers. Retention rules and offers are determined and configured by the RevFence Customer who uses the service.

04Our legal bases for processing personal data

Where required by applicable data protection law, we process personal data on one or more of the following legal bases:

  • Performance of a contract: Where processing is necessary to provide the RevFence service, manage your account or carry out operations you request.
  • Legitimate interests: Where processing is necessary to operate our service, ensure security, monitor performance, prevent abuse and protect our legal rights, provided this does not override your rights and freedoms.
  • Legal obligation: Where we need to process personal data to comply with an applicable legal obligation.
  • Consent: Where we rely on your consent for a specific processing activity.

Where we process your personal data based on your consent, you may withdraw it at any time under applicable law. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

05Stripe and payment services

RevFence works with Stripe to provide payment, subscription and billing functions.

Depending on the integration you use and the service configuration, RevFence may receive or process information about Stripe customers, subscriptions, invoices, payment statuses and other billing events needed for the service to work.

Stripe processes personal data independently in accordance with its own terms of service and privacy practices.

Where the standard Stripe Connect integration is used, RevFence does not request or store your Stripe secret API key.

Where RevFence carries out an authorized operation in your Stripe account, that operation is executed through the relevant Stripe integration and according to the rules you configure within RevFence.

06Service providers and subprocessors

To deliver RevFence, we may work with trusted third parties that provide infrastructure, hosting, email, payment, analytics, monitoring, security and other technical services.

These service providers may access personal data only to the extent required by the services they provide to us and process it in line with the relevant contracts and applicable data protection obligations.

The current service providers and subprocessors we use to process personal data are published on our Subprocessors page.

We may also share personal data in the following cases:

  • Where sharing is necessary to comply with a legal obligation
  • Where a valid request is received from a competent public authority, regulator or court
  • Where sharing is necessary to protect the rights and safety of RevFence, our users or third parties
  • Where sharing takes place in connection with a merger, sale of the company, restructuring, financing or a related business transaction

In such cases we take the measures necessary to protect personal data under applicable law.

07International data transfers

RevFence and its service providers may process personal data in countries outside the country where you or your customers are located.

Where applicable law requires additional safeguards for international data transfers, we use accepted transfer mechanisms to carry out the transfer lawfully.

Depending on the circumstances, these mechanisms may include contractual safeguards or other appropriate transfer methods recognized by applicable data protection law.

08How long we keep personal data

We keep personal data for as long as is reasonably necessary for the purposes described in this policy.

In determining the retention period, we may consider the following:

  • Providing the service and managing the account
  • Keeping subscription, billing and transaction records
  • Meeting legal, financial and regulatory obligations
  • Resolving disputes
  • Enforcing our agreements and protecting our legal rights
  • Keeping security, fraud prevention and audit logs
  • The nature, volume and sensitivity of the data
  • Risks that may arise from unauthorized use or disclosure

When personal data is no longer needed, it may be deleted, anonymized or, where there is a valid legal or legitimate retention requirement, kept securely with restricted access.

Specific retention and deletion obligations for data processed on behalf of a Customer may also be set out in our Data Processing Agreement.

09Data security

We apply technical and organizational measures appropriate to the structure of the service and the risks involved to protect personal data against unauthorized access, alteration, disclosure, loss or destruction.

Depending on the nature of the data and the relevant service component, these measures may include:

  • Encryption of data in transit
  • Secure authentication mechanisms
  • Role- and permission-based access controls
  • Separation of customer environments
  • Rate limiting controls
  • Security and anomalous traffic monitoring
  • Keeping audit and transaction logs
  • Protection of credentials and access keys
  • Verification of webhook signatures
  • Protection against replay attacks
  • Restricting and controlling access to production systems

No internet-based service can be guaranteed to be completely secure. We do, however, review our security measures in light of technological developments, operational needs and the risks we encounter.

If you believe you have found a security issue affecting RevFence, you can contact us at hello@revfence.com.

10Cookies and similar technologies

Our website and service may use cookies or similar technologies to provide core functions, maintain sessions, ensure security and understand how the service is used.

The cookies used may fall into the following categories according to their purposes:

  • Cookies required for the service to work
  • Authentication and session cookies
  • Security cookies
  • Cookies that remember preferences
  • Analytics technologies that help us understand service use and performance

Where applicable law requires it, we obtain your consent before using non-essential cookies or similar technologies.

You can manage your cookie preferences through your browser settings and, where offered, through RevFence’s cookie controls. Disabling some cookies may cause parts of the website or service not to work as expected.

11Your privacy rights

Depending on where you are located and the applicable data protection law, you may have certain rights over your personal data.

These rights may include:

  • Accessing your personal data
  • Asking for inaccurate or incomplete personal data to be corrected
  • Requesting deletion of your personal data
  • Asking for restriction of processing
  • Objecting to certain processing activities
  • Receiving your data in a portable format, where applicable
  • Withdrawing consent where processing is based on consent
  • Lodging a complaint with a competent data protection authority

These rights are not absolute. Whether we can fulfil a request depends on the nature of the request, the role RevFence has in relation to the data and applicable law. To assess your request, we may ask for additional information to verify your identity.

If you use RevFence through an organization, that organization may be the data controller of the personal data processed through your account. In that case, you should first send your request to the organization that provides you with the service or manages the RevFence account.

You can send requests about personal data for which RevFence is directly the data controller to hello@revfence.com.

12Marketing and service communications

We may contact you about your account, subscription, security notices, support requests, billing operations or important changes to the service. Some of these notices may be necessary for the service to be provided.

Where we send marketing communications, we obtain your prior consent to the extent required by applicable law or rely on another valid legal basis.

You can stop receiving marketing emails by using the unsubscribe link in them. Opting out of marketing communications does not prevent you from receiving necessary operational notices about your account or the service you use.

13Children’s privacy

RevFence is a software service for businesses and is not designed for use by children.

We do not knowingly collect personal data from children where this is prohibited by applicable law. If you believe a child has provided personal data to us inappropriately, you can contact us so that we can investigate and take the necessary steps.

14Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our services, the technologies we use, our business practices or our legal obligations.

When we make significant changes, depending on the circumstances and applicable law, we may also notify you through appropriate channels such as the website, an in-account notice or email.

The current policy is published on this page and the “Last updated” date at the top of the page is changed.

15Contact

If you have questions, requests or concerns about this Privacy Policy, your personal data or your privacy rights, you can use the contact details at the end of this page.

Contact details

Company:
SWAN TECHNOLOGIES LTD
Address:
Suite 10400 5 Brayford Square, London, United Kingdom, E1 0SG
Country:
United Kingdom
Email:
hello@revfence.com

Last updated: 19 September 2026