1. Overview
This Privacy Policy explains how MemberBay (memberbay.io) collects, uses, stores, and discloses personal data when you use our service.
MemberBay is operated by: UNIPERSONAL KHRESTENKOV DANIIL Barroso 3605, 3, Buceo, Montevideo, Uruguay, 11400 RUT: 220740740013 Contact: [email protected]
2. Information We Collect
We collect information you provide directly to us, including your name, company name, email address, billing details, and account credentials.
We also collect business and operational data made available through your connected ServiceTitan tenant, which may include customer records, membership data, invoices, and workflow activity needed to provide the service.
We automatically collect limited technical information such as log data, browser type, device information, IP address, pages visited, and event timestamps for security, troubleshooting, and product improvement.
3. How We Use Information
We use personal and business data to:
- provide, maintain, and secure MemberBay;
- authenticate users and manage accounts;
- sync and display ServiceTitan data inside the product;
- process billing and subscription management;
- communicate about support, product updates, and important account notices;
- analyze usage patterns to improve performance and features;
- comply with legal obligations and enforce our Terms of Service.
4. Legal Bases for Processing
Where applicable under laws such as the GDPR, we process personal data based on one or more of the following legal bases:
- performance of a contract;
- legitimate interests in operating, securing, and improving the service;
- compliance with legal obligations;
- consent, where consent is specifically required.
5. ServiceTitan Data and Customer Information
If you connect MemberBay to ServiceTitan, you authorize us to access and process relevant ServiceTitan data strictly for delivering the service you requested.
To the extent MemberBay processes personal data contained in your ServiceTitan account on your behalf, you are the Data Controller and MemberBay acts as a Data Processor. You are responsible for ensuring you have the necessary rights and notices in place for the underlying customer data, and you represent and warrant to MemberBay that such rights are in place.
6. Sharing of Information
We do not sell personal data.
We may share data with trusted service providers and subprocessors that help us operate MemberBay. A current list of subprocessors is maintained below. We may also disclose information if required by law, to protect rights and safety, or in connection with a merger, acquisition, or asset sale.
Current Subprocessors
- Vercel — hosting and infrastructure
- Supabase — database and authentication
- Lemon Squeezy — payment processing
- Anthropic — AI-powered features (customer summaries, retention insights); data sent is scoped to the feature and no full-tenant data is exported
- ServiceTitan — integration and data sync
We will update this list when adding new subprocessors and, where required by law, will notify affected customers in advance.
7. Payments
Subscription payments are processed by Lemon Squeezy or other authorized payment providers. We do not store full payment card details on our own servers. Payment information is handled according to the payment provider's own privacy and security practices.
8. Data Retention
We retain account, billing, and operational data for as long as reasonably necessary to provide the service, comply with legal obligations, resolve disputes, and enforce agreements. As a general guide:
- Account and operational data: retained while the account is active and for up to 90 days after termination.
- Billing records: retained for up to 7 years to meet applicable tax and accounting obligations.
- Security and audit logs: retained for up to 12 months.
After account termination, we may retain limited records for legal, tax, fraud-prevention, backup, and audit purposes. If you request a data export after termination, we will handle that request in accordance with our Terms of Service within 30 days.
9. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal data against unauthorized access, loss, misuse, or disclosure. These measures include:
- Encryption of data in transit (TLS 1.2+) and sensitive credentials at rest (AES-256 via Fernet)
- Row-level security (RLS) policies enforcing multi-tenant data isolation at the database level
- Audit logging of authentication events, API key rotations, and sensitive data access
- Regular dependency updates and vulnerability scanning
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a data breach affecting your personal data, we will notify you and any applicable supervisory authority as required by law.
For a full description of the ServiceTitan scopes we request, the scopes we explicitly do not request, the Chrome extension's permissions and data flow, and our incident response process, see the Security page.
10. International Data Transfers
Your data may be processed in countries other than your own, including countries where our hosting providers or subprocessors operate. Our primary infrastructure is hosted in the United States (Vercel, Supabase) and the European Union.
Where required by law, we implement appropriate safeguards for cross-border transfers of personal data, including Standard Contractual Clauses (SCCs) approved by the European Commission or other legally recognized transfer mechanisms. You may request a copy of the applicable SCCs by contacting [email protected].
11. Your Rights
Depending on your location and applicable law, you may have the following rights regarding your personal data:
Under the GDPR (EU/EEA residents):
- Right of access (Art. 15) — obtain a copy of your personal data
- Right to rectification (Art. 16) — correct inaccurate data
- Right to erasure (Art. 17) — request deletion of your data
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20) — receive your data in a structured, commonly used, machine-readable format (JSON or CSV)
- Right to object (Art. 21) — object to processing based on legitimate interests
- Right to lodge a complaint with a supervisory authority (Art. 77) — you may file a complaint with your local data protection authority if you believe your rights have been violated
Under the CCPA/CPRA (California residents):
- Right to know what personal information we collect, use, and disclose
- Right to delete your personal information
- Right to opt-out of the sale or sharing of personal information — MemberBay does not sell or share personal information for cross-context behavioral advertising
- Right to non-discrimination for exercising your privacy rights
Data Processing Agreement (DPA): If you process personal data of EU/EEA data subjects through MemberBay, a DPA is available upon request at [email protected].
To exercise any of these rights, contact [email protected]. We will respond to verified requests within 30 days (GDPR) or 45 days (CCPA). We may need to verify your identity before fulfilling a request. Data exports are provided in JSON or CSV format.
12. Cookies and Analytics
MemberBay uses the following technologies to keep you signed in, remember preferences, understand product usage, and improve performance:
- Session cookies — required for authentication and keeping you logged in. These are first-party cookies and cannot be disabled without breaking the service.
- Product analytics — we use Plausible Analytics (privacy-friendly, no cross-site tracking, no personal data sent to third parties) to understand feature usage and improve the product.
We do not use advertising cookies or third-party tracking pixels. You can control session cookies through your browser settings, though some features will not function if you disable them.
13. Chrome Extension (MemberBay Pulse)
MemberBay Pulse is a Chrome browser extension that displays membership data from MemberBay's API as an overlay on ServiceTitan pages.
Data the extension collects:
- Authentication token — stored locally in Chrome's encrypted session storage to keep you signed in. Cleared when all Chrome windows are closed or when you sign out.
- Cached membership data — stats and at-risk membership counts are cached in Chrome's local storage to reduce API calls and improve loading speed.
- UI preferences — overlay toggle, sync interval, and theme preference are stored in Chrome's local storage.
Data the extension does NOT collect:
- The extension does not read, scrape, extract, or collect any data from ServiceTitan pages. It only reads the page URL to determine which customer you are viewing, then fetches that customer's data from MemberBay's own API.
- The extension does not access browser history, bookmarks, tabs, cookies, or any data outside of ServiceTitan pages and memberbay.io.
- No data is sent to third parties. All communication is between the extension and MemberBay's API (api.memberbay.io).
Browser permissions and their purpose:
storage— stores authentication tokens and UI preferences locally in Chrome.alarms— runs a periodic background sync (every few minutes) to keep at-risk data up to date.go.servicetitan.com— the content script runs only on ServiceTitan pages to display the membership overlay.*.memberbay.io— communicates with MemberBay's API and handles sign-in from the website.
Removal: uninstalling the extension removes all locally stored data. You can also sign out from the extension at any time to clear authentication tokens without uninstalling.
14. Children's Privacy
MemberBay is intended for business use and is not directed to children under 16, or such other minimum age as required by applicable law. We do not knowingly collect personal data from children.
15. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date and notify you by email at least 30 days before the changes take effect. Continued use of the service after changes take effect constitutes your acceptance of the updated policy.
16. Contact
For privacy questions, requests, or complaints, contact:
UNIPERSONAL KHRESTENKOV DANIIL
Barroso 3605, 3, Buceo, Montevideo, Uruguay, 11400
