Legal
Privacy Policy
What MemberCue actually stores, why, and who else is involved. This describes the real behaviour of the product.
Last updated: 2026-09-27
What this covers
This policy explains what personal data MemberCue handles when you use the product, why we handle it, and who we share it with. It describes the behaviour of the service as built.
Account information
When you create an account we store your name, your email address, a securely hashed password, and your workspace settings such as workspace name, currency and timezone. We never store your password in a readable form.
Imported member and customer data
You can import a CSV of member activity. MemberCue stores the rows you import, which typically include member identifiers such as a name or email, activity dates, and a retention status we derive from them, along with any notes you add. You control what you upload; we process it to provide the retention workflow you asked for.
Activity, contact and outreach records
We store the actions you take in the product: which members you mark as contacted, follow-up and snooze state, and the dates involved. These records are what make the weekly review and the observed recovery rate meaningful.
Billing information
Payments are handled by Lemon Squeezy. We do not receive or store your full card details. We store identifiers and status returned by our billing provider — such as a customer or subscription reference, your plan and billing interval, subscription status, and the period end — so we can apply the correct entitlements.
Transactional email
We send transactional email such as password resets, email verification and security notices. Delivery is handled by our email provider, which processes the recipient address and the message content needed to deliver it.
AI drafting
If AI drafting is enabled, requesting a draft sends limited single-member context to our AI provider so it can write the message: the member first name, the community name, days since last activity, join date, previous activity, last contacted date, and any internal note on that member. It does not send your full CSV, your member list, aggregate counts, or the community database.
Security and operational logs
We record operational logs so we can run and secure the service, including authentication events, rate-limit events, billing webhook outcomes, and error categories. Logs are written with sensitive values redacted: passwords, reset and verification tokens, API keys, authorisation headers, session cookies and database connection strings are never written to logs.
Cookies and sessions
MemberCue uses a single first-party session cookie to keep you signed in. It is HTTP-only, so scripts on the page cannot read it, and it is marked SameSite to limit cross-site sending. It is set with Secure when the app is served over HTTPS. We do not use it for advertising, and we do not run third-party advertising or analytics trackers.
Why we process this data
To provide the retention workflow you signed up for; to authenticate you and keep your workspace secure; to take payment and manage your subscription; to send the transactional email the product depends on; to diagnose faults and prevent abuse; to measure, first-party and internally, whether workspace owners reach and repeat the core workflow so we can improve the product, using only the records already described on this page and never shared with third parties; and to meet our legal obligations.
Storage and security
Data is stored in a managed PostgreSQL database and accessed over an encrypted connection. Passwords are hashed with scrypt. Sessions use HTTP-only cookies, and access is scoped to your workspace so one workspace cannot read another. Data in transit is encrypted. No system is perfectly secure, so we do not offer an absolute guarantee.
How long we keep data
We keep your workspace data while your account is active. If your trial ends or you cancel, the workspace becomes read-only and your data is retained so you can subscribe again or export it. When you delete your account, the data is removed as described below.
Deleting your account and data
You can delete your account yourself from the danger zone in Settings. Deleting your profile removes your workspace and its members, imports, templates and events, and signs you out. This is immediate and cannot be undone. You can export your member data as CSV before deleting.
Privacy requests
For a copy of your data, a correction, or a deletion request you cannot make yourself, contact us using the address below. Export is available in-product at any time from Settings.
Changes to this policy
If our data practices change, we will update this page and revise the date at the top. Significant changes will be announced in the product.
Service providers
We use a small number of providers to run the service. Each processes data only as needed for the purpose shown.
- Render — Application hosting — runs the MemberCue web application.
- Neon — Managed PostgreSQL database — stores your workspace data.
- Upstash — Managed rate-limiting store — protects sign-in and other endpoints from abuse.
- Lemon Squeezy — Payments and Merchant of Record — processes subscriptions and applicable taxes.
- Resend — Transactional email — delivers password resets, verification and security notices.
- OpenAI — AI drafting (when enabled) — receives limited single-member context to write an outreach draft. Never your full CSV or member list.
Contact
Support and privacy requests: support@membercue.app