Privacy Policy

Service: SalesCentral — central sales backend for iOS in-app purchases (sales-central.org) Provider: SalesCentral ("SalesCentral", "we", "us", "our"), Republic of Armenia Last updated: 30 June 2026 Effective date: 30 June 2026


1. Who this policy is for

SalesCentral is a backend service that other app developers integrate into their iOS apps to handle Apple in-app purchases, subscriptions, premium state, credits, entitlements, push notifications, and analytics. Because of this, two very different groups interact with us, and we treat their data differently:

If you are an End User, the controller responsible for your data is the developer of the app you are using. Please read that app's own privacy policy and direct privacy requests to that developer first; we will support them in responding. The sections below explain what we process on their behalf so you understand the full picture.


2. Data we process about End Users (as processor)

When a Developer integrates our SDK, the app sends us the data below. Almost all of it is optional — the SDK sends what it has, and a Developer chooses which features to enable. We process it solely to provide the service to that Developer.

Account & commerce identifiers

Purchase and entitlement data

Device and technical data

App and locale data

Network and approximate location

Marketing and attribution data

Engagement and analytics data

Push notification data

Developer-defined properties

We do not receive Apple ID credentials, payment card numbers, or full payment instruments — Apple processes the actual payment. We only receive the signed transaction records Apple issues.


3. Data we process about Developers (as controller)


4. Why we process data and our legal bases

For End-User data, the Developer determines the purposes and legal basis as controller; we process only on their documented instructions to:

For our own (controller) processing, our legal bases under the GDPR/UK GDPR (where applicable) are: performance of a contract (operating your account and the service), legitimate interests (security, abuse prevention, service improvement, and — for AI features — generating App Store keyword suggestions and translating notification copy), and legal obligations. Where we rely on legitimate interests, we balance them against your rights.

AI-assisted features

Two optional features use a third-party AI provider (OpenAI). They send only Developer-provided content — App Store metadata (titles, subtitles, keywords) for keyword suggestions, and notification copy for translation. They do not send End-User identifiers, contact details, device data, or purchase records. See the Subprocessors list.


5. How we share data

We do not sell personal data and do not share it for cross-context behavioural advertising. We disclose data only to:


6. International data transfers

SalesCentral operates from the Republic of Armenia and uses subprocessors located in other countries, including the United States (Apple, Cloudflare, OpenAI). Your data may therefore be processed outside your country.

Armenia is a party to Council of Europe Convention 108/108+ and recognises EU/EEA member states as providing adequate protection. For transfers of EU/EEA, UK, or Swiss personal data to Armenia or other countries that are not subject to an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum/IDTA), which are incorporated into our Data Processing Agreement. A copy of the relevant safeguards is available on request to [email protected].


7. Data retention

Specific retention periods: End-User records are kept for the life of the Developer's account and deleted within 90 days after the account is closed or an earlier deletion request is completed; backups are rotated out within 35 days; and request logs are retained for up to 90 days.


8. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of your personal data, to data portability, and to withdraw consent. Under the GDPR/UK GDPR, Armenian Law on the Protection of Personal Data (No. HO-49-N), and the California Consumer Privacy Act (as amended by the CPRA), these include:

How to exercise them. If you are an End User, contact the developer of the app you use — they are the controller — and they will instruct us as needed. If you are a Developer, or you cannot reach the relevant developer, contact us at [email protected] and we will help route or fulfil the request. We may need to verify your identity before acting.


9. Security

We use technical and organisational measures appropriate to the risk, including encryption of data in transit (TLS, terminated at our CDN edge), authenticated and role-scoped access to the admin panel, separated signing secrets for user and admin tokens, hashed operator passwords, and idempotency controls. No system is perfectly secure; we cannot guarantee absolute security. To report a vulnerability or suspected incident, contact [email protected]. Our breach notification commitments to Developers are set out in the DPA.


10. Children

SalesCentral is a developer tool and is not directed to children. Developers are responsible for ensuring their apps comply with children's privacy laws (such as COPPA and the GDPR rules on children's consent) and Apple's requirements, including not enabling IDFA/tracking for child-directed apps. We do not knowingly process children's personal data as a controller. If you believe a child's data has reached us, contact [email protected].


11. Changes to this policy

We may update this policy as the service or the law changes. We will revise the "Last updated" date and, for material changes affecting Developers, provide reasonable notice (for example, in the admin panel or by email). Continued use of the service after an update means you accept the revised policy.


12. Contact

SalesCentral, Republic of Armenia Privacy & data requests: [email protected] General/legal: [email protected] Security: [email protected]