Controller and processing roles
ZAYEN DIGITAL acts as controller for MRR Pilot account data, workspace administration, MRR Pilot subscription billing administration, product analytics, feedback, support and security records. For some customer Stripe-derived revenue data, MRR Pilot may process data on behalf of the workspace/customer to provide the requested revenue analysis.
Data categories
- Account: name, email, Clerk identifier, role and account status.
- Workspace: workspace name, membership and onboarding answers.
- Connected Stripe revenue data: customer identifiers, imported names/emails, products, prices, subscriptions, invoices, statuses, amounts and billing intervals.
- Revenue intelligence: MetricSnapshots, RevenueActions, risk scores, upgrade opportunities, action statuses and recovered-revenue observations.
- AI data: server-created summarized context, relevant metrics/actions/customer context; never Stripe credentials, API keys or encryption keys.
- Product analytics: anonymous session ID, page paths, timestamps, landing page, referrer, UTM fields and user-agent hash where enabled.
- Feedback/support: category, severity, message, page, contact permission and optional screenshot URL.
Purposes and legal bases
Processing supports service delivery, account security, billing administration, support, product improvement, revenue analytics and applicable legal obligations. Legal bases may include contract performance, legitimate interests, legal obligations and consent where required, including for certain analytics choices.
AI and OpenAI
MRR Pilot builds a minimized revenue context server-side. Stripe credentials, Stripe tokens, API keys and encryption keys are not sent in AI prompts. Relevant metrics, actions and limited customer/action context may be included where necessary to answer a workspace question.
Service providers and transfers
- Vercel — Application hosting, deployment, server and runtime infrastructure. Data: Application requests, operational logs and deployment/runtime data. Transfer note: Provider infrastructure may involve processing outside France or the EEA depending on account and routing configuration.
- Supabase — PostgreSQL database infrastructure. Data: Application database records including accounts, workspace data, imported revenue records, actions, feedback and analytics records. Transfer note: The production database region should be confirmed in the Supabase project settings before broad commercial scale.
- Clerk — Authentication and account identity services. Data: Authentication identifiers, account emails, names and security session data. Transfer note: Provider processing may involve international transfers according to the provider's own data-processing terms.
- Stripe — MRR Pilot subscription payment processing and optional connected Stripe revenue-data access. Data: Payment/subscription administration data for MRR Pilot billing, plus Stripe-derived revenue records when a workspace connects Stripe. Transfer note: Stripe payment processing and connected-account data flows are governed by Stripe's applicable terms and data-processing documentation.
- OpenAI — AI-powered revenue analysis and Ask Your Revenue answers. Data: Minimized server-created revenue context, metrics and relevant action/customer context needed to answer a workspace question. Transfer note: AI context may be processed outside France or the EEA according to the provider's applicable terms.
The production Supabase database region should be confirmed in the admin launch checklist before broad commercial scale.
Retention criteria
- Account records are retained while the account is active and for as long as needed for security, billing, support, legal or legitimate operational purposes after closure.
- Workspace configuration and onboarding records are retained while the workspace exists or as needed to administer the service.
- Imported Stripe-derived revenue records are retained while the workspace uses MRR Pilot and until deletion is requested or operationally required, subject to billing, audit and legal needs.
- Revenue Actions, statuses and recovered-revenue observations are retained to provide action history and product value unless the workspace data is deleted.
- Visitor sessions, page views and product events are retained for product analytics and beta operations using criteria based on usefulness, security and legal obligations.
- Feedback and support messages are retained while needed to respond, improve the beta and maintain an operational history.
- Audit logs are retained as long as needed for security, abuse prevention, account administration and legal protection.
- Retention automation should be reviewed before broad commercial scale; some requests may currently require manual operational handling.
Your rights
Data subjects may request access, correction, deletion, restriction, objection, portability where applicable and withdrawal of consent where processing relies on consent. You may also lodge a complaint with the CNIL.
Contact: support@mrrpilot.app