Privacy Policy
Last updated: July 19, 2026
EntitleHub ("EntitleHub", "we", "us") provides an entitlement and subscription-management platform for app developers. This policy explains what we collect, why, and your choices. It covers entitlehub.com, the dashboard, and our APIs.
Who the data belongs to
EntitleHub acts in two roles. For our account holders (developers who sign up), we are a data controller of their account information. For the end-user and transaction data a developer sends us to track entitlements, we are a data processoracting on that developer's instructions, that data belongs to the developer, and we handle it only to provide the service.
What we collect
- Account data: name, email, hashed password, and security settings (2FA, passkeys) of developers who register.
- App & catalog data, the entitlements, products, mappings, and API keys a developer configures.
- Transaction & entitlement data, the app-user identifiers, purchase/receipt metadata, and grants a developer's app or backend reports to us so we can resolve entitlements. We do not collect payment card numbers; purchases are processed by the app stores (Apple, Google, Stripe).
- Connected-service data, when a developer connects a third-party service (e.g. QuickBooks Online, an app-store account), we store the tokens/credentials needed to provide that integration, encrypted.
- Operational data: logs, IP addresses, and usage needed to run, secure, and debug the service.
How we use it
- To provide the service: validate receipts, resolve entitlements, deliver webhooks, produce analytics and accounting reports.
- To operate the connected integrations a developer enables (for example, reading a developer's QuickBooks company to write revenue journal entries they request, or reading store financial reports they authorize).
- To secure accounts, prevent abuse, and comply with law.
We do not sell personal information, and we do not use developer transaction data to build advertising profiles.
Sharing
We share data only with: infrastructure sub-processors that host and run the service; the third-party services a developer explicitly connects (e.g. QuickBooks Online / Intuit, app stores); and where required by law. Integrations are used solely to deliver the feature the developer turned on.
Retention & security
We keep data for as long as an account is active or as needed to provide the service, then delete or anonymize it. Secrets (API keys, integration tokens, credentials) are stored hashed or encrypted. Access is restricted and audited.
Your choices
- Developers can disconnect any integration at any time from the dashboard, which revokes stored tokens.
- Developers can delete their account and associated data by contacting us.
- End users should direct data requests to the developer whose app they use, as that developer controls the data; we will assist the developer as their processor.
Contact
Questions about this policy: [email protected].
See also our Terms of Service.
