Legal

Privacy Policy

What we collect, why we collect it, and the choices you have — for platform users, funnel visitors, and end users of partner apps.

Last updated: July 26, 2026

1. Who we are

inTandm (“inTandm”, “we”, “us”) operates a partnership platform at intandm.io that connects subscription-app developers with content creators and runs the attribution, revenue-share accounting, invoicing, and payouts those partnerships depend on.

This policy explains what personal data we collect, why we collect it, and the choices you have. For personal data covered by this policy (other than the end-user event data described in section 6, where the app developer is the controller), the data controller is inTandm. It covers three groups of people: platform users (creators, developers, and their team members with inTandm accounts), funnel visitors (people who open a creator’s link or landing page), and end users of partner apps (subscribers whose purchase events we process on a developer’s behalf).

2. Data we collect

Account and application data. When you apply for or hold an inTandm account we collect your name, email address, sign-in credentials, and the information you submit in your creator or developer application — such as your channels and audience details (creators) or your company, app, and store-listing details (developers).

Partnership and financial data. To run revenue sharing we maintain contracts and their terms, an append-only ledger of attributed payments, earnings, reversals, and adjustments, invoices issued to developers, and payout records for creators. Creator payouts are processed by Stripe; Stripe collects your payout and identity-verification details directly under its own privacy policy, and we store only the references we need to run payouts.

Attribution and funnel data. When someone opens a creator link or landing page we mint a random touch token and record the campaign, code, and offer it belongs to, a coarse platform classification (iOS, Android, or web) parsed from the browser’s user-agent family, salted hashes used for fraud prevention, and basic funnel telemetry such as which call-to-action was clicked. We do not use device fingerprinting, and we do not build cross-site profiles.

End-user purchase events. Developers connect their RevenueCat integration so that subscription events (purchases, renewals, refunds, transfers) reach inTandm. These events carry pseudonymous app-user identifiers and transaction details — product, price, currency, store, and timestamps. We do not receive end users’ payment-card numbers, and we process this data as a service provider to the developer (see section 6).

Support and correspondence. Messages you send us, and records of application review and account decisions.

3. How we use data

  • To operate the platform: attribute subscriptions to creator touches, compute earnings, issue invoices, and run payouts.
  • To review applications and verify that creators and developers meet our acceptance criteria.
  • To prevent fraud and abuse: detecting self-referral, code sharing abuse, and anomalous attribution patterns, and maintaining audit logs of sensitive actions.
  • To communicate with you about your account, partnerships, earnings, and changes to the service.
  • To comply with legal obligations, including tax, accounting, and financial-records requirements.
  • To improve the product, using aggregated or de-identified usage data.

5. Cookies

We use a small set of first-party cookies. We do not use third-party advertising cookies or cross-site trackers.

  • Session cookie — keeps you signed in to your inTandm account. Essential; deleted when the session ends or you sign out.
  • it_tt — set when you arrive on an app’s landing page through a creator link. It stores the random touch token so a later purchase on that device can be credited to the creator. It lasts up to 90 days, is first-party to the landing domain, and contains no personal details — only the random token.
  • it_sandbox_mode — remembers a dashboard preference (viewing sandbox test data) for signed-in users. Lasts up to 180 days.

You can delete or block cookies in your browser settings. Blocking the session cookie prevents sign-in; blocking it_tt only affects whether a creator is credited for a referral.

6. Data we process on behalf of developers

Subscription events from a developer’s app reach us through the developer’s own integrations (such as RevenueCat and app-store install referrers). For that end-user event data, the developer is the data controller and inTandm acts as a processor / service provider: we use it only to attribute purchases, compute the revenue-share ledger, and detect fraud — never for advertising or to contact end users.

End users who have questions about how a partner app handles their data should contact that app’s developer; each app’s landing page links to the developer’s own privacy policy.

7. When we share data

We share personal data only as needed to run the service:

  • Between partners. Creators and developers in an active partnership see the information the partnership requires — for example, a developer sees which creator a subscription is attributed to, and a creator sees per-app performance and earnings. Neither side sees the other’s payout or banking details.
  • Service providers. Payment and payout processing (Stripe), subscription-event infrastructure (RevenueCat, on the developer’s behalf), cloud hosting, and email delivery. Providers may use the data only to provide their service to us.
  • Legal. When required by law, to enforce our terms, or to protect the rights, safety, or property of inTandm, our users, or others.
  • Business transfers. As part of a merger, acquisition, or sale of assets, subject to this policy.

We do not sell personal data.

8. How long we keep data

Financial records — the earnings ledger, invoices, and payout history — are append-only by design and are retained for as long as required for accounting, tax, and audit purposes. Attribution records are kept for the life of the attribution they support plus the period needed for fraud review. Account data is kept while your account is active and for a limited period afterwards; application data for unsuccessful applications is kept only as long as needed to administer the decision.

9. Security

We protect personal data with encryption in transit, access controls, audit logging of sensitive operations, and salted hashing of identifiers used for fraud prevention. No system is perfectly secure, but we design for least access: payout credentials live with Stripe, and end-user identifiers stay pseudonymous inside our systems.

10. Your rights

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. You can exercise these rights by contacting us at [email protected]. We will not discriminate against you for exercising them.

Note that some data cannot be deleted while we have a legal duty to keep it — most notably financial records in the ledger — and requests about end-user data from a partner app are forwarded to, or should be made directly to, that app’s developer as the data controller.

11. International transfers

We operate globally, and data may be processed in countries other than the one you live in. Where required, we rely on appropriate safeguards such as standard contractual clauses with our service providers.

12. Children

inTandm accounts are for adults running a business — you must be at least 18 to create one. We do not knowingly collect personal data from children; if you believe a child has provided us data, contact us and we will delete it.

13. Changes to this policy

We may update this policy as the service evolves. We will post the updated version here with a new “last updated” date, and for material changes we will notify account holders by email or in the dashboard before the change takes effect.

14. Contact

Privacy questions and requests: [email protected]. General support: [email protected].