SubTru LLC Privacy Policy
Effective date: August 25, 2026
This Privacy Policy explains how SubTru LLC ("SubTru," "we," "us," or "our") collects, uses, and discloses personal information when you visit https://subtru.com, create or use an account, use the SubTru subscription backend, or communicate with us (collectively, the "Services").
1. Who we are
SubTru LLC is a Virginia limited liability company.
For privacy questions or requests, contact [email protected].
2. When SubTru is a controller or processor
We act as a controller when we determine how and why to process account, billing, website, support, advertising, and service-usage information.
Our business customers also submit personal information for us to process on their behalf, including information about their subscribers ("Customer Data"). For Customer Data, the customer generally acts as controller and SubTru acts as processor. Our processing of Customer Data is governed by our Data Processing Addendum and agreement with that customer. If a SubTru customer submitted your information, direct requests concerning that information to the customer.
3. Information we collect
Depending on how you use the Services, we collect:
- Account and organization information: email address, authentication and account identifiers, organization and project names, roles, memberships, invitations, and account preferences.
- Social sign-in information: if you choose to sign in with Google or GitHub, the provider supplies SubTru and our managed authentication provider with information needed to authenticate you. Depending on the provider and your account settings, this may include your name, email address, profile image, provider name, provider account identifier, and authentication and identity-linking metadata. We request only basic identity, profile, and email access. We do not request access to GitHub repositories or to other Google account services such as Gmail, Drive, contacts, or calendars.
- SubTru billing information: plan, trial, subscription, invoice, payment status, billing interval, and payment-processor customer identifiers. Our payment processor handles complete payment-card details; SubTru does not receive complete card numbers.
- Customer Data: customer-defined subscriber identifiers; supported payment and app-store provider subscription and event identifiers; product and price identifiers; subscription status and billing dates; webhook event types, timestamps, processing results, and error information; and information used to configure and authenticate provider integrations. Customers should use opaque subscriber identifiers and not place names, email addresses, or other directly identifying information in subscriber identifiers.
- Service, device, and log information: IP address, approximate country, browser and device type, operating system, referring URL, request and response metadata, timestamps, diagnostic information, and actions taken in the Services.
- Product analytics: page views, referring pages, UTM campaign parameters, account identifiers, organization and project identifiers, product events, feature usage, billing conversions, and performance information.
- Session replay: masked recordings of interactions with the website. We configure replay to exclude form inputs and designated customer-specific content.
- Advertising and attribution information: advertising and measurement partners receive information such as cookie and conversion identifiers, IP address, user agent, page visits, referring and campaign information, conversion events, and hashed contact identifiers for eligible advertising measurement and attribution.
- Communications: support requests, feedback, and other messages you send us.
We collect information directly from you, automatically from your browser or device, from Google or GitHub when you choose the corresponding social sign-in option, from our customers when they use the Services, from customer-directed payment and app-store providers, and from our service providers.
4. How we use information
We use personal information to:
- provide, operate, secure, and maintain the Services
- authenticate users, create or link account identities, and administer accounts, organizations, projects, and permissions
- receive, verify, deduplicate, order, normalize, and report subscription events
- process SubTru billing, trials, renewals, cancellations, and payments
- provide support and service communications
- monitor performance, diagnose errors, and prevent fraud and abuse
- understand and improve the Services
- measure advertising and attribute visits and conversions
- comply with law and enforce our agreements; and
- establish, exercise, or defend legal claims.
We do not use Customer Data about our customers' subscribers for advertising. We use information received through Google or GitHub social sign-in to authenticate you, create or link your SubTru account, secure the Services, and administer access. We do not use provider access tokens to access unrelated Google or GitHub services.
5. Legal bases for European processing
Where European data-protection law applies, we rely on:
- Contract when processing is necessary to provide the Services or take requested steps before entering a contract.
- Legitimate interests in operating, securing, supporting, measuring, and improving the Services, where those interests are not overridden by your rights.
- Legal obligations when processing is required to comply with law.
- Consent where applicable law requires consent. You may withdraw consent without affecting processing that occurred before withdrawal.
For Customer Data processed on behalf of a customer, the customer determines the applicable legal basis.
6. How we disclose information
We disclose personal information to:
- Infrastructure and service providers that provide website and API hosting, request geolocation, authentication, transactional email delivery, data storage, analytics and session replay, logs and telemetry, and payment processing.
- Third-party identity providers when you choose social sign-in. Google or GitHub processes your authentication request under its own terms and privacy policy and sends basic identity information to our managed authentication provider for use by SubTru. See the Google Privacy Policy and GitHub Privacy Statement.
- Customer-directed payment and app-store providers when necessary to process the customer's subscription integrations.
- Advertising and measurement partners for eligible advertising measurement, attribution, audience matching, and campaign optimization.
- Professional advisers, such as lawyers, accountants, auditors, and insurers.
- Authorities and other parties for legal and safety reasons, when we reasonably believe disclosure is legally required or necessary to protect rights, safety, or the Services.
- Transaction participants, in connection with a financing, merger, acquisition, reorganization, bankruptcy, or sale of all or part of our business, subject to appropriate confidentiality protections.
Our current subprocessors and their processing locations are listed at https://subtru.com/subprocessors.
We do not sell personal information for money. Our disclosure of information to advertising and measurement partners may be considered "sharing," a "sale," or targeted advertising under some United States state privacy laws. You may opt out by emailing [email protected]. We also honor Global Privacy Control signals for this advertising activity.
7. Cookies, analytics, replay, and advertising
We use cookies and similar technologies for authentication, security, account functionality, analytics, replay, advertising measurement, and attribution.
- Necessary authentication and security technologies operate wherever the Services are available.
- Browser-based product analytics, masked session replay, advertising pixels, and similar browser measurement technologies operate only when geolocation identifies a visitor as outside the EU, EEA, and United Kingdom. They remain disabled when geolocation is missing or invalid.
- Advertising measurement also remains disabled when a visitor has opted out or sends a recognized Global Privacy Control signal. Server-side advertising conversions follow the same advertising eligibility and opt-out rules.
- Our first-party advertising click-attribution cookie expires after 90 days unless it is deleted sooner through browser controls.
- Server-side product and lifecycle analytics operate independently from these browser measurement and advertising controls.
SubTru does not respond to browser "Do Not Track" signals because there is no generally accepted standard for interpreting them. We honor Global Privacy Control as described above.
8. International transfers
SubTru is based in the United States. We and our service providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws than your country.
Where required, we use recognized safeguards such as adequacy decisions, the European Commission's Standard Contractual Clauses, and the UK International Data Transfer Addendum. Contact [email protected] for information about applicable safeguards.
9. Retention
We retain personal information only as long as reasonably necessary for the purposes described in this policy. The period depends on the type of information, the length of the customer relationship, user choices, security and fraud-prevention needs, legal requirements, and applicable limitation periods.
In general, we retain account information while an account is active; Customer Data as described in the applicable agreement and Data Processing Addendum; and billing, security, and operational records for the periods needed to meet the purposes above. Backups are deleted when overwritten in the ordinary backup cycle. We may retain information longer where required by law or reasonably necessary for security, dispute resolution, or legal claims.
10. Security
We use administrative, technical, and organizational safeguards designed to protect personal information. These include access controls, encryption in transit, encryption of stored provider credentials and webhook secrets, tenant-scoped authorization, monitoring, and incident-response procedures. No method of transmission or storage is completely secure.
11. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information; restrict or object to processing; withdraw consent; opt out of certain targeted advertising, sale, sharing, or profiling; appeal a denied request; or complain to a data-protection authority.
Submit a request to [email protected]. We may need to verify your identity and authority. Authorized agents may submit requests where permitted by law. You will not be discriminated against for exercising a privacy right.
If we process the information for a customer, we may direct your request to that customer.
12. Children
The Services are intended for businesses and are not directed to anyone under 18. We do not knowingly permit anyone under 18 to create a SubTru account. Customers are responsible for obtaining any authorization required before submitting information about children as Customer Data.
13. Changes to this policy
We may update this policy from time to time. We will post the updated version and change the effective date above. If changes are material, we will provide notice by email or through the Services where required.
14. Contact us
SubTru LLC