Privacy
What SubPorter stores, why it stores it, and how Stripe access keys are handled.
Effective 4 September 2026.
SubPorter is operated by Xanthous Tech LLC, a Delaware (United States) company. Contact us at simon@subporter.com.
Information we handle
We store the account information needed for sign-in, including your name, email address, verification records, and basic session records such as IP address and user agent.
For a migration, we store project names, participant roles, Stripe account identifiers, inventory and plan summaries, review decisions, approvals, payment status, and audit events. Migration deliverables may contain Stripe customer, subscription, product, price, and schedule identifiers.
Stripe restricted keys are used only to run the migration steps you authorize. They are encrypted before storage. Stripe Checkout processes your payment details; SubPorter stores the Checkout session identifier, amount, status, and payment date, not your card details.
Where information is processed
Cloudflare hosts SubPorter. Service records are stored in Cloudflare D1, and migration deliverables are stored in Cloudflare R2. Stripe provides Checkout and the Stripe APIs used for your migration.
We share information with these providers only as needed to operate SubPorter, or when required by law. We do not sell personal information.
Analytics
SubPorter uses PostHog to measure page visits and the steps from starting a migration through payment. Before sign-in, PostHog uses an anonymous browser identifier stored without cookies. After sign-in, it uses your internal SubPorter user ID. We respect Do Not Track and disable session recordings. We do not send Stripe keys, customer data, project names, email addresses, or migration contents to PostHog.
Retention
Encrypted Stripe keys are deleted seven days after a project is completed. For an incomplete project, they are deleted after 30 days of inactivity.
Other account, project, payment, summary, artifact, and audit records are kept as needed to provide the service and preserve the migration record. To request access, correction, or deletion, contact simon@subporter.com. Some records may need to be retained for legal, security, or payment purposes.
Changes
We may update this notice as SubPorter changes. The effective date above shows the latest revision.