RetainerMeter / Legal / Web Privacy Notice

Effective 24 August 2026

RetainerMeter Web privacy notice

Controller and contact. RetainerMeter Web is operated by Hernan Morales, a sole trader trading as RetainerMeter. Privacy questions and rights requests can be sent to hello@retainermeter.com.

1. Edition boundary

Desktop is local-first and normally keeps consultant content on the user's device. Web is a separate cloud-hosted edition. Desktop and Web datasets do not synchronize.

2. Data used to operate Web

The service processes verified email, account and consent timestamps, hashed authentication/session values, subscription and payment status, approved pilot reservation and check-in status, Desktop-link state, lifecycle dates, and security/operational events. Workspace content includes consultant settings, a normalized logo, clients, weekly time rows, and immutable invoice snapshots.

3. Purposes and lawful bases

Data is used to authenticate the account, provide and secure the workspace, calculate lifecycle access, create and reconcile subscriptions, produce exports, link an eligible Desktop licence, send necessary lifecycle messages, investigate failures, prevent abuse, meet legal obligations, and respond to requests. Processing needed to provide the account, workspace, exports, billing, and requested support is based on performing the service contract. Billing, tax, fraud-prevention, security, and required records are processed where necessary for legal obligations or legitimate interests. Optional campaign analytics and marketing messages are processed only with consent, which can be withdrawn through the available control or unsubscribe route without affecting the service.

4. Product measurement

Operational milestone records may note timestamps and counts such as verified account, first completed setup, invoice preview, export, checkout, payment, renewal, cancellation, or refund. They do not contain client names, notes, hours, invoice text, logos, or other workspace content. A named reader offer uses a limited offer identifier on the verified account to preserve the advertised benefit and count resulting signups. General campaign attribution is attached only after consent through the existing first-party mechanism; missing attribution remains unknown. RetainerMeter does not join visitors by raw IP address, fingerprinting, or probabilistic identity.

5. Service providers

Cloudflare provides edge, Worker, and database infrastructure; Resend delivers authentication and lifecycle email and, only after a user's confirmed action, processes saved recipients and an attached invoice PDF for delivery; Lemon Squeezy acts as merchant of record for subscription checkout, tax, and payment processing. RetainerMeter does not keep an invoice-file archive for emailed PDFs, although the email provider processes and may retain message data under its own terms. The current service-provider list and change process are in the subprocessor notice. Providers may process technical information under their own terms and security practices.

6. Storage, security, and transfers

Web uses a separate customer database configured in the EU. Sessions store only a token hash server-side. Security measures include secure HttpOnly cookies, CSRF and Origin checks, rate controls, input limits, revision conflicts, content escaping, and restricted operational logging. Cloud encryption is provider-managed; RetainerMeter does not claim end-to-end encryption. Cloudflare, Resend, Lemon Squeezy, and other operational providers may process information in locations outside the EU under their own terms and applicable transfer safeguards. RetainerMeter does not promise EU-only processing.

7. Retention and deletion

The workspace lifecycle and separate business-record retention domains are described in the retention schedule. A verified self-service deletion request offers a final backup and removes active workspace/authentication data within 24 hours. Payment, tax, fraud-prevention, consent, and necessary audit records may need a different justified period.

8. Customer and data-subject rights

Depending on applicable law, individuals may request access, correction, deletion, restriction, portability, or objection to processing, and may withdraw consent where processing relies on consent. Send a request to hello@retainermeter.com; reasonable information may be requested to verify identity. Where a customer is the controller of client content, requests about that content may need to be directed to that customer. Individuals may also complain to their applicable data-protection supervisory authority.

9. Contact

Privacy questions and rights requests: hello@retainermeter.com.