Skip to content

Cha-Ching Privacy Policy

How Cha-Ching handles your information.

Effective October 9, 2026

Cha-Ching collects the minimum information needed to authenticate you, provide subscription access, connect payment sources, show payments, and deliver notifications.

Information we process

  • Your Apple account identifier, name, and email when provided by Sign in with Apple.
  • Your Stripe account identifier, account label, granted permissions, and provider token after you consent.
  • Your Apple subscription identifiers and verified entitlement dates. Cha-Ching does not receive your App Store payment-card details.
  • For supported Stripe alerts: payment and event identifiers, amount, currency, event time, optional billing country, and delivery status. We do not retain the customer's name, email, payment description, or complete webhook payload.
  • For a custom webhook source: its name, private webhook URL credential, field and notification-display mapping, and an arbitrary JSON setup sample of up to 64 KiB supplied by the sender. The sample can contain personal information if the sender includes it. For each active custom payment, we retain the enabled notification display labels and normalized values selected by the user. Custom payments are sender-reported, not independently verified with a payment provider.
  • An APNs device token and app-generated device identifier when you enable notifications.
  • Security and operational data such as session details, request rate limits, and error logs.

How we use and protect information

We use this information only to authenticate you, verify subscription access, display connection and payment history, deliver notifications, provide support, prevent abuse, and operate the service. Cha-Ching's Stripe App has read-only access to event and charge data and cannot create, refund, or change payments. Provider tokens, private custom-webhook credentials, custom setup samples, and the temporary Sign in with Apple revocation credential are encrypted with AES-256-GCM before storage in Cloudflare D1. Active custom webhook payloads are normalized in memory; Cha-Ching retains the mapped payment fields and enabled notification label/value pairs rather than the complete payload. Enabled values are sent to Apple Push Notification service and may be visible on the device lock screen. We do not sell personal information or use it for third-party advertising.

Sharing and retention

We use Apple, Stripe, Cloudflare, and Apple Push Notification service to provide the service. A custom setup sample is replaced when a newer sample arrives and deleted after activation; if setup is not completed, the encrypted sample remains until the custom source or account is deleted. Disconnecting Stripe removes its stored connection and encrypted token but does not erase existing payment history. Account, payment, source, connection, subscription-entitlement, session, and device data remain while your Cha-Ching account is active. Authenticated in-app account deletion removes those records immediately. Unmatched provider-event security records that were never linked to a user may remain for webhook deduplication.

Your choices

You can revoke Stripe access from Cha-Ching or Stripe, pause payment sources, disable payment notifications, and regenerate an exposed custom webhook URL. Delete your account from Settings in the app; deletion also revokes Cha-Ching's Sign in with Apple authorization when Apple provides the required credential. Deleting your Cha-Ching account does not cancel an Apple subscription, so use Apple's Manage Subscription action separately. For access or correction requests, contact Cha-Ching support.