Privacy Policy
Service: SalesCentral — central sales backend for iOS in-app purchases (sales-central.org) Provider: SalesCentral ("SalesCentral", "we", "us", "our"), Republic of Armenia Last updated: 30 June 2026 Effective date: 30 June 2026
1. Who this policy is for
SalesCentral is a backend service that other app developers integrate into their iOS apps to handle Apple in-app purchases, subscriptions, premium state, credits, entitlements, push notifications, and analytics. Because of this, two very different groups interact with us, and we treat their data differently:
- Developers (our customers / "Operators"). The businesses and individuals who register an app with us, integrate our SDK, and use the admin panel. For data about Developers and their accounts, SalesCentral is the data controller, and this policy describes how we handle it.
- End Users. The people who use a Developer's iOS app. Their data reaches us only because a Developer chose to integrate SalesCentral. For End-User data, the Developer is the data controller and SalesCentral acts as a data processor, processing that data only on the Developer's documented instructions under our Data Processing Agreement.
If you are an End User, the controller responsible for your data is the developer of the app you are using. Please read that app's own privacy policy and direct privacy requests to that developer first; we will support them in responding. The sections below explain what we process on their behalf so you understand the full picture.
2. Data we process about End Users (as processor)
When a Developer integrates our SDK, the app sends us the data below. Almost all of it is optional — the SDK sends what it has, and a Developer chooses which features to enable. We process it solely to provide the service to that Developer.
Account & commerce identifiers
- An internal user identifier we generate (a random UUID).
- A client-generated identifier the SDK stores on the device (a random UUID), used to re-link a user after an offline first launch or a lost response.
- Apple transaction identifiers (including the original transaction ID) used to recognise restores and renewals.
Purchase and entitlement data
- Purchase events (initial buys, renewals, restores, refunds, revocations, expirations), product identifiers, prices, currency, and trial status.
- Subscription state, premium tier and expiry, feature unlocks, entitlements.
- Credit balances and an append-only credit ledger, retention/streak reward state, and lifetime purchase/refund totals.
Device and technical data
- Device model and family, OS name and version, screen dimensions and scale, total memory, low-power-mode and simulator flags, and (rarely) a user-supplied device name.
App and locale data
- App version and build, SDK version, first-launch time, and App Store storefront.
- Locale, language, region, time zone, and currency.
Network and approximate location
- Connection type and mobile carrier (as reported by the app).
- Approximate location (country, and where available region/city) that we derive server-side from the request IP address using an edge header (e.g. Cloudflare's
CF-IPCountry) or a GeoIP database. We never trust a client's claimed location. The IP address itself is processed transiently to derive this location and for security, rate-limiting, and logging; we do not build an end-user profile from raw IP addresses.
Marketing and attribution data
- The advertising identifier (IDFA) only when the user has granted App Tracking Transparency permission (it is empty or zeroed otherwise), the vendor identifier (IDFV), the ATT authorization status, attribution source, campaign, and UTM parameters/referrer the app provides.
Engagement and analytics data
- Session counts and durations, custom in-app events and their properties, and sticky A/B experiment assignments.
Push notification data
- Push device tokens (APNs/FCM) and the notification authorization status, used to deliver notifications a Developer sends.
Developer-defined properties
- Arbitrary key/value properties a Developer's app chooses to set on a user (for example a plan intent — or, if the Developer decides to send them, a name or email address). SalesCentral does not require these fields and does not ask for them; what appears here is entirely controlled by the Developer. Developers are responsible for having a lawful basis and the necessary notices/consents for anything they send, and for not sending special categories of data.
We do not receive Apple ID credentials, payment card numbers, or full payment instruments — Apple processes the actual payment. We only receive the signed transaction records Apple issues.
3. Data we process about Developers (as controller)
- Account data: operator username, a securely hashed password, role, and session tokens.
- App configuration: app names, bundle identifiers, and the Apple credentials you provide so we can operate the service for you — App Store Server API keys (
.p8private key, key ID, issuer ID), APNs keys, and any legacy shared secret. These are stored to verify purchases and send notifications on your behalf; treat them as the sensitive credentials they are. - Usage and operational data: request logs (method, path, timestamp, and the originating IP after proxy resolution), and configuration you create (products, paywalls, remote config, experiments, ASO catalog, push rules).
- Billing data: if your plan is paid, the plan associated with your account and the billing contact details you provide for invoicing. We do not store full payment-card numbers.
4. Why we process data and our legal bases
For End-User data, the Developer determines the purposes and legal basis as controller; we process only on their documented instructions to:
- verify Apple receipts and notifications and maintain premium, entitlement, and credit state;
- deliver push notifications the Developer triggers;
- provide analytics, dashboards, and experiment/paywall functionality to the Developer;
- detect, prevent, and investigate fraud, abuse, and security incidents; and
- keep the service reliable (idempotency, deduplication, debugging).
For our own (controller) processing, our legal bases under the GDPR/UK GDPR (where applicable) are: performance of a contract (operating your account and the service), legitimate interests (security, abuse prevention, service improvement, and — for AI features — generating App Store keyword suggestions and translating notification copy), and legal obligations. Where we rely on legitimate interests, we balance them against your rights.
AI-assisted features
Two optional features use a third-party AI provider (OpenAI). They send only Developer-provided content — App Store metadata (titles, subtitles, keywords) for keyword suggestions, and notification copy for translation. They do not send End-User identifiers, contact details, device data, or purchase records. See the Subprocessors list.
5. How we share data
We do not sell personal data and do not share it for cross-context behavioural advertising. We disclose data only to:
- Subprocessors who help us run the service, under contract and only as needed — currently Apple, Cloudflare, OpenAI, and our hosting/infrastructure provider. The current list, with purposes and locations, is maintained at Subprocessors.
- The relevant Developer, who can access data about their own End Users through the admin panel and API.
- Authorities or other parties where required by law, to enforce our terms, or to protect the rights, safety, and security of users, the public, or SalesCentral.
- A successor in a merger, acquisition, or asset sale, subject to this policy and applicable law.
6. International data transfers
SalesCentral operates from the Republic of Armenia and uses subprocessors located in other countries, including the United States (Apple, Cloudflare, OpenAI). Your data may therefore be processed outside your country.
Armenia is a party to Council of Europe Convention 108/108+ and recognises EU/EEA member states as providing adequate protection. For transfers of EU/EEA, UK, or Swiss personal data to Armenia or other countries that are not subject to an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum/IDTA), which are incorporated into our Data Processing Agreement. A copy of the relevant safeguards is available on request to [email protected].
7. Data retention
- End-User data is retained for as long as the Developer's account is active and they instruct us to keep it, and is then deleted or returned in line with the DPA. Many records are first soft-deleted (hidden and excluded from processing) and then purged.
- Operator account and configuration data is retained while the account is active and for a reasonable period afterwards to meet legal, accounting, and security obligations.
- Logs are retained for a limited operational period and then rotated out.
Specific retention periods: End-User records are kept for the life of the Developer's account and deleted within 90 days after the account is closed or an earlier deletion request is completed; backups are rotated out within 35 days; and request logs are retained for up to 90 days.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of your personal data, to data portability, and to withdraw consent. Under the GDPR/UK GDPR, Armenian Law on the Protection of Personal Data (No. HO-49-N), and the California Consumer Privacy Act (as amended by the CPRA), these include:
- GDPR/UK GDPR: access, rectification, erasure, restriction, portability, objection, and the right to lodge a complaint with a supervisory authority.
- CCPA/CPRA (California): the rights to know, delete, and correct, and to opt out of sale/sharing — note that we do not sell or share personal information as those terms are defined. We do not discriminate against you for exercising your rights.
- Armenia (PDPL): the rights to information about, access to, correction of, and blocking/destruction of your personal data, overseen by the Personal Data Protection Agency within the Ministry of Justice.
How to exercise them. If you are an End User, contact the developer of the app you use — they are the controller — and they will instruct us as needed. If you are a Developer, or you cannot reach the relevant developer, contact us at [email protected] and we will help route or fulfil the request. We may need to verify your identity before acting.
9. Security
We use technical and organisational measures appropriate to the risk, including encryption of data in transit (TLS, terminated at our CDN edge), authenticated and role-scoped access to the admin panel, separated signing secrets for user and admin tokens, hashed operator passwords, and idempotency controls. No system is perfectly secure; we cannot guarantee absolute security. To report a vulnerability or suspected incident, contact [email protected]. Our breach notification commitments to Developers are set out in the DPA.
10. Children
SalesCentral is a developer tool and is not directed to children. Developers are responsible for ensuring their apps comply with children's privacy laws (such as COPPA and the GDPR rules on children's consent) and Apple's requirements, including not enabling IDFA/tracking for child-directed apps. We do not knowingly process children's personal data as a controller. If you believe a child's data has reached us, contact [email protected].
11. Changes to this policy
We may update this policy as the service or the law changes. We will revise the "Last updated" date and, for material changes affecting Developers, provide reasonable notice (for example, in the admin panel or by email). Continued use of the service after an update means you accept the revised policy.
12. Contact
SalesCentral, Republic of Armenia Privacy & data requests: [email protected] General/legal: [email protected] Security: [email protected]