Privacy Policy
Last updated: September 1, 2026
Venwai ("Venwai", "we", "us") provides a service that monitors your Stripe subscriptions against the access records in your own application and alerts you when the two disagree. This policy explains what data we collect, why, and how it's handled — both for you as an account holder, and for the customer records your account processes through the service.
1. What we collect
| Data | Why we have it |
|---|---|
| Your email address | Account creation, login, and sending you discrepancy/status alerts. |
| Your Stripe restricted key | Stored encrypted (AES-256-GCM). Used only for read-only calls to the Stripe API on your behalf — Venwai cannot charge, refund, or modify anything in your Stripe account. |
| Your client endpoint URL & secret | Stored encrypted. Used to authenticate the periodic request Venwai makes to your app to read who currently has access. |
| Slack webhook URL (optional) | Used only to deliver alerts you've configured. Not used for anything else. |
| Customer/subscription identifiers from your Stripe account and your app | Compared against each other to detect drift. This is data about your customers, processed on your behalf — see Section 4. |
| Basic account activity (login timestamps, poll run history) | Operating the product and helping you debug sync issues. |
We do not use cookies, analytics scripts, or advertising trackers on venwai.com or in the product dashboard. If that changes, this policy — and a proper cookie-consent banner — will be updated first.
2. What we don't do
- We never sell, rent, or share your data with advertisers.
- We never write to your Stripe account or your database — every integration Venwai uses is read-only.
- We don't use your data to train any model or share it with third parties beyond what's needed to run the service (Section 3).
3. Who else touches this data (sub-processors)
| Provider | Purpose |
|---|---|
| Supabase | Database hosting and authentication. |
| Stripe | Read-only API access to your subscription data, at your instruction. |
| Slack | Delivering alerts, only if you've connected a webhook. |
Each of these providers processes data only as needed to deliver the feature you enabled.
4. Payments
Paid plans are not live yet. When they are, card and billing details will be collected and processed directly by Stripe Checkout on Stripe's own domain — Venwai never sees or stores your card number. Billing data is handled under Stripe's own privacy and PCI-DSS compliance framework.
5. Data retention & deletion
We keep your account data for as long as your account is active. Encrypted Stripe keys and endpoint secrets are deleted immediately when you disconnect a project. You can request full account deletion at any time by emailing support@venwai.com — we'll remove your account and associated data within 30 days.
6. Security
- Secrets (Stripe keys, endpoint credentials, webhook URLs) are encrypted at rest with AES-256-GCM.
- All traffic to and from Venwai is encrypted in transit (TLS).
- Access to production data is restricted to the people operating the service.
7. Your rights
Depending on where you're located, you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. To exercise any of these, email support@venwai.com — we'll respond within a reasonable time.
8. Changes to this policy
If we make material changes to this policy, we'll update the date at the top of this page and, where appropriate, notify account holders by email.
9. Contact
Questions about this policy or how your data is handled: support@venwai.com.