Skip to content

Search the documentation by title, section, or page text.

Data Security

Once your integration is sending events, Botsi collects subscription and engagement data to power analytics, retention tracking, and Paywall A/B testing.

What Botsi collects#

From the events your integration sends, plus the store notifications you configured, Botsi tracks in-app activity and subscription lifecycle changes:

  • Subscription events: purchases, renewals, cancellations, and trials.
  • User behavior: onboarding completion, screen views, and conversion events.
  • Device metadata: platform, app version, and locale. Non-sensitive fields only.

By default no personally identifiable information (PII) is collected. You can send custom events or attach your own user identifiers (see Add Custom Attributes), which is a deliberate choice you make rather than a default you have to turn off.

How data reaches Botsi#

Everything sent to the Botsi API travels over HTTPS with Transport Layer Security (TLS), so it is encrypted in transit. Payloads carry only the metadata a feature needs, which keeps both the exposure and the transfer small.

How Botsi stores and protects it#

Data is encrypted at rest with AES-256 once it arrives.

The infrastructure it lands on complies with SOC 2 Type II.

Internal access follows a least-privilege model: an employee gets access to a given set of data only if their work requires it. Every access event is logged and subject to audit.

Compliance and your control over it#

Botsi's practices align with the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

The part that matters most for your own compliance work: Botsi collects no personal user data by default, and you control what your integration sends. What reaches Botsi is what you chose to send it.