1. Who we are
RenewKeeper is operated by RemoteWinners.com, which is the data controller for your personal data.
RenewKeeper ("RenewKeeper", "we", "us") is a service operated by "RemoteWinners.com", which is the data controller for the personal data described in this policy. This policy explains what personal data we collect, why we collect it, how we handle it, and the rights you have. It applies to the RenewKeeper application (app.renewkeeper.com) and the RenewKeeper website (renewkeeper.com).
RemoteWinners is a sole trader registered with the UK Information Commissioner's Office (ICO). Our contact address is: RemoteWinners, 27 Old Gloucester Street, London, WC1N 3AX. United Kingdom.
If you have any questions about this policy or your personal data, contact us at privacy@renewkeeper.com.
A few key points, before the detail:
- You sign in with Google, Microsoft, or an email address and password (with optional two-factor authentication). We never see your Google or Microsoft password.
- Your RenewKeeper application data is stored in the European Union (Netherlands).
- We do not sell your personal data, and we do not use it to train AI models.
- RenewKeeper is not a secrets manager. Please do not store passwords, real API keys, or other credentials in the items you track (see Section 2).
2. What data we collect
We collect the information needed to run your account, keep the service secure, and send you the renewal alerts that are the point of RenewKeeper.
The table below sets out the categories of personal data we may collect and who each category may be shared with.
| Type of data | Examples | Who it may be shared with |
|---|---|---|
| Account information | Your name and email address (from your single sign-on provider, or from the details you register with) and your sign-in method. | Google or Microsoft (if you use single sign-on); Mailtrap (to email you). |
| Authentication and security data | A hashed password (email/password accounts only); your two-factor authentication secret and recovery codes if you turn 2FA on; email verification status. | Held by us and our hosting provider; not shared for marketing. |
| Content you add | The items you track: a name, a category, an expiry date, and optionally a renewal URL, a cost, and free-text notes. | Held by us and our hosting provider; not shared. |
| Payment information | Your subscription status. We do not see, receive, or store your card number. | Stripe (which handles your card details directly). |
| Technical data | Limited technical data such as IP address and timestamps, processed to deliver, secure, and monitor the service. | Hosting.com; Sentry; Cloudflare (Turnstile). |
| Website analytics | General usage of the RenewKeeper website (pages viewed and similar). Not collected inside the application. | Google Analytics. |
| Operational notifications | A masked version of your name and email included in our internal service-health alerts (for example, a new sign-up). | Microsoft Teams (internal, to us). |
Important: do not store secrets. RenewKeeper is not a secrets manager. You should never enter passwords, real API keys, private keys, card numbers, or other sensitive credentials into the items you track. The content you add is stored as ordinary application data, not as encrypted secrets, so only record the fact that something expires and when, not the sensitive value itself.
3. How we use your data and our lawful bases
We use your data to run RenewKeeper and keep it secure, and we rely on a specific lawful basis under UK GDPR for each purpose.
- To provide the service (lawful basis: contract). Creating and running your account, letting you organise and track items, sending the expiry and renewal notifications that are the core purpose of RenewKeeper, sending service and account emails (for example, email verification, welcome, billing, and password-related emails), and processing your subscription.
- To keep the service secure and reliable (lawful basis: legitimate interests). Diagnosing errors (Sentry), protecting our sign-in and password-reset forms against bots (Cloudflare Turnstile), rate limiting, and sending ourselves internal service-health notifications that contain only a masked version of your name and email. Our legitimate interest is running a secure and dependable service, and we use minimal, masked data for this where we can.
- To meet legal obligations (lawful basis: legal obligation). For example, keeping the billing and tax records we are required to keep.
- For website analytics (lawful basis: consent, where required). Understanding general usage of the marketing website. You can withdraw consent at any time (see Section 6).
We do not sell your personal data, we do not use it to train AI models, and we do not use your in-app data for advertising.
4. Who we share data with (sub-processors)
We rely on a small number of vetted providers, each of which processes only the data it needs.
- Google and Microsoft: single sign-on. When you sign in this way, they provide your name and email; we never receive your password.
- Stripe: payment processing. Stripe handles your card details directly under its own terms; we do not receive or store your card number (see stripe.com/privacy).
- Mailtrap: sending transactional and notification emails (verification, welcome, billing, expiry alerts, and similar. see mailtrap.io/privacy).
- Cloudflare: the Turnstile anti-bot check on our registration, login, and password-reset forms. It processes minimal challenge-related technical data for bot detection and receives no account content. For details of how Cloudflare handles this data, see the Cloudflare Turnstile Privacy Addendum.
- Sentry: capturing application errors so we can keep the service reliable (see sentry.io/privacy).
- Hosting.com: hosting the application and database in the European Union (Netherlands. see terms.hosting.com/privacy-policy).
- Microsoft Teams: internal operational notifications to us (for example, a new sign-up), which include only a masked version of your name and email and are used solely to monitor the health of the service.
- Google Analytics: usage analytics on the RenewKeeper website only, not inside the application.
We may also disclose personal data if required by law, or in connection with a sale or transfer of the business, in which case this policy would continue to apply to your data.
5. Where your data is stored and international transfers
Your RenewKeeper data is stored in the EU. Where any provider processes data outside the UK or EEA, we rely on the safeguards UK GDPR requires.
Your RenewKeeper application data is stored in the European Union (Netherlands). Some of our providers (for example, Stripe, Google, and Microsoft) may process limited data outside the UK and EEA, including in the United States.
Where personal data is transferred outside the UK or EEA, we rely on the appropriate safeguards required by UK GDPR, for example standard contractual clauses (with the UK Addendum) or transfers to a country the UK recognises as providing an adequate level of protection. We also try to choose providers and settings that reduce international transfers where practical.
6. Cookies and analytics
The website uses a small number of cookies. The application uses only the cookies needed to sign you in.
The RenewKeeper website uses cookies, including for Google Analytics, to understand general site usage. The application itself uses only the cookies necessary to sign you in and keep your session secure.
Essential cookies (which keep you signed in and secure) are always used. Analytics cookies on the website are non-essential; you can refuse or remove them through your browser settings, and refusing some cookies may affect parts of the website.
7. How long we keep your data
We keep your data while your account is active and delete it when you close your account, apart from limited records we must keep.
We keep your personal data for as long as your account is active. If you delete your account, we delete your personal data, apart from limited records we retain for legitimate operational, legal, or audit reasons. These include an internal activity log and any feedback you submitted (which we keep in a form that no longer identifies you where possible), and billing records we are legally required to keep for a set period.
8. Your rights
UK GDPR gives you rights over your personal data, including the right to complain to the ICO.
Under UK GDPR, you have the right to: access your personal data; ask us to correct it; ask us to delete it; object to or restrict certain processing; request a copy of your data (portability); and, where we rely on your consent, withdraw that consent at any time. To exercise any of these, email privacy@renewkeeper.com.
If you are unhappy with how we have handled your personal data, we would like the chance to put it right, so please contact us first. You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator, at ico.org.uk. If you are located in the European Economic Area, you may lodge a complaint with the supervisory authority in your country of residence, place of work, or where the alleged infringement occurred.
9. How we keep your data secure
We use reasonable technical and organisational measures to protect your data.
We use reasonable technical and organisational measures to protect your personal data. Passwords for email/password accounts are stored securely. If you turn on two-factor authentication, the related secret and recovery codes are also held securely. Our application data is hosted in the EU.
No system can be guaranteed completely secure. You also help keep your account safe by protecting your sign-in credentials and by not storing sensitive secrets in the items you track.
10. Children
RenewKeeper is not intended for children.
RenewKeeper is not intended for children. You must be at least 16 years old to use the service.
11. Changes to this policy
We will post any changes here with a new effective date.
We may update this policy from time to time. Changes will be posted on this page with a revised effective date, and where appropriate, we will notify you by email.
12. Contact
Get in touch with any questions about your data.
Questions, comments, or requests about this policy or your personal data should be sent to privacy@renewkeeper.com.
Our postal address is: RemoteWinners, 27 Old Gloucester Street, London, WC1N 3AX. United Kingdom.