Data Security
Once your integration is sending events, Botsi collects subscription and engagement data to power analytics, retention tracking, and Paywall A/B testing.
What Botsi collects#
From the events your integration sends, plus the store notifications you configured, Botsi tracks in-app activity and subscription lifecycle changes:
- Subscription events: purchases, renewals, cancellations, and trials.
- User behavior: onboarding completion, screen views, and conversion events.
- Device metadata: platform, app version, and
locale. Non-sensitive fields only.
By default no personally identifiable information (PII) is collected. You can send custom events or attach your own user identifiers (see Add Custom Attributes), which is a deliberate choice you make rather than a default you have to turn off.
How data reaches Botsi#
Everything sent to the Botsi API travels over HTTPS with Transport Layer Security (TLS), so it is encrypted in transit. Payloads carry only the metadata a feature needs, which keeps both the exposure and the transfer small.
How Botsi stores and protects it#
Data is encrypted at rest with AES-256 once it arrives.
The infrastructure it lands on complies with SOC 2 Type II.
Internal access follows a least-privilege model: an employee gets access to a given set of data only if their work requires it. Every access event is logged and subject to audit.
Compliance and your control over it#
Botsi's practices align with the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
The part that matters most for your own compliance work: Botsi collects no personal user data by default, and you control what your integration sends. What reaches Botsi is what you chose to send it.