Data Processing Agreement (Art. 28 GDPR)
Version dated 2026-10-05
between the App Provider that connects RevenueCat to RevReach (the “Controller”) and Luca Martini, Planeggerstraße 57c, 82110 Germering (the “Processor”). This agreement becomes part of the Terms of Service when RevenueCat is connected.
1. Subject matter and duration
The Processor processes personal data of the users of the Controller's app in order to attribute purchases to Creator partnerships and to calculate and bill revenue shares. This agreement applies for as long as the Controller has connected RevenueCat to the Platform and thereafter until all data has been deleted in accordance with clause 9.
2. Type of data and data subjects
| Data subjects | Users of the Controller's app who make a purchase or start a trial |
|---|---|
| Data | Pseudonymous app user IDs and aliases (from RevenueCat), creator code entered, product, price, currency, tax and commission portion, store, country, timestamps, transaction IDs, event type |
| Not processed | Names, email addresses, payment data, device or advertising IDs of the app users (unless the Controller uses them as the app user ID, which should be avoided) |
| Purpose | Attribution to Creator partnerships, calculation and billing of the revenue share, anonymous metrics (daily counters) |
3. Instructions
The Processor processes the data only on documented instructions from the Controller. These instructions result from this agreement, the Terms of Service and the settings on the Platform. If the Processor considers an instruction to be unlawful, it informs the Controller without undue delay.
4. Confidentiality
Persons who have access to the data are bound to confidentiality. Creators do not receive any personal data of the app users, only aggregated figures.
5. Security
The Processor implements the technical and organisational measures pursuant to Art. 32 GDPR described in Annex 2 and adapts them to the state of the art.
6. Sub-processors
The Controller approves the sub-processors listed in Annex 1. The Processor informs the Controller of any intended changes by email at least 30 days in advance; the Controller may object for good cause under data protection law and, in this case, disconnect the connection. Sub-processors are contractually bound to the same level of protection.
7. Assistance
The Processor assists the Controller with requests from data subjects, with data protection impact assessments and with the notification of breaches. It reports personal data breaches without undue delay, where possible within 48 hours of becoming aware of them.
8. Evidence and audits
The Processor provides the Controller with the information necessary to demonstrate compliance and allows audits after reasonable advance notice, usually by providing documentation and certificates of the sub-processors.
9. Deletion
Once the connection has been disconnected, the Processor deletes the data as soon as it is no longer required for billing claims that have already arisen. The Processor retains data that forms the basis of accounting records in restricted form for the duration of the statutory retention periods; this corresponds to an instruction from the Controller.
Annex 1: Sub-processors
| Provider | Service | Location |
|---|---|---|
| Supabase, Inc. (USA) | Database, sign-in and file storage | US region (Ohio); transfer based on the standard contractual clauses in Supabase's data processing agreement |
| Netlify, Inc. (USA) | Delivery of the website and execution of server functions | Delivery via servers distributed worldwide, server functions in the USA; transfers based on the standard contractual clauses in Netlify's data processing agreement |
Annex 2: Technical and organisational measures
- Encrypted transmission (TLS) for all connections, including webhooks from RevenueCat.
- Authentication of every webhook with a secret token per app, optionally with an additional HMAC signature.
- Database in the EU; row-level access control (Row Level Security); clients only have read access to released rows.
- Secrets (API keys, tokens) additionally encrypted with AES-256-GCM.
- Immutable booking journal and logging of security-relevant actions.
- Purchases are only stored if a creator code is attributed; otherwise, only anonymous daily counters are kept.
- Daily backups at the database provider; access to production data only for authorised administrators with strong passwords and, where available, two-factor authentication.
Suggested wording for your privacy policy
If you enter a creator's code in our app, we transmit your pseudonymous user ID, the code and information about your purchases to Luca Martini (RevReach) via our subscription service provider RevenueCat so that the creator can receive a share of the revenue. RevReach processes this data on our behalf (Art. 28 GDPR). The legal basis is our legitimate interest in remunerating our partners (Art. 6(1)(f) GDPR). Names, email addresses and payment data are not transmitted.