Last updated: October 2026
Moored is built by Allurance Labs. This policy explains what data we collect as a B2B retention platform — both about you as a founder and about your customers who pass through the exit flow — and the safeguards around it.
Account data: name, email address, and authentication credentials (passwords are stored only as irreversible hashes). Billing configuration: per-project payment gateway API keys, brand color, logo, redirect URLs, survey options, and retention rules. Product analytics: cancellation sessions, selected reasons, offers shown and accepted, and aggregate MRR saved.
When your customer enters the hosted exit flow, we process the minimum necessary to run it: the subscription reference you pass us, the survey answers they give, and the outcome (offer accepted, paused, or cancelled). We do not collect payment card details — those stay with your billing provider. You are the data controller for your customers' data; Moored acts strictly as your processor and uses it only to operate the flow and produce your analytics.
To operate the exit flow and execute the retention actions your rules trigger; to meter sessions and enforce plan limits; to show you analytics and exports; to send transactional email (plan changes, limit warnings, security notices); and to improve reliability and abuse prevention. We do not sell personal data, and we do not train shared models on your data.
Data is shared only as needed to run the service: Neon (managed Postgres hosting), and — at your explicit direction, per retention action — your connected billing provider's API (Stripe, Paddle, Dodo Payments, or Lemon Squeezy). We disclose data to authorities only when legally compelled, and we will notify you unless prohibited.
Gateway API keys are encrypted at rest and never sent to the browser; all traffic is TLS-encrypted in transit. Project data, rules, and logs are strictly isolated per project and account — every query is scoped to your tenant. Access to production data is limited to Allurance Labs operators under least-privilege credentials.
We use a single first-party session cookie to keep you signed in to the dashboard, plus the minimal storage the exit flow needs to prevent duplicate session counting. No advertising trackers, no third-party analytics beacons on the exit flow.
Account and project data is kept while your account is active. Cancellation session logs are retained for 24 months for analytics continuity, then aggregated or deleted. Deleting your account starts deletion of projects, keys, rules, and identifiable logs within 30 days, except where tax or legal obligations require longer retention.
You may access, correct, export, or delete your data at any time from the dashboard or by emailing allurance.business@gmail.com. If you are in the EU/UK, you additionally have the rights to restriction, objection, and portability under GDPR, and the right to lodge a complaint with your supervisory authority. We respond to verifiable requests within 30 days.
Infrastructure currently operates in the regions of our hosting providers (see Sharing above). Where data crosses borders, we rely on appropriate safeguards including standard contractual clauses.
Material changes to this policy will be announced by email at least 14 days before taking effect. Data controller: Allurance Labs — allurance.business@gmail.com.