Privacy Policy

A graphical banner image of a person using a laptop computer, with a padlock icon on the screen.

Last Updated: 19th March 2026
Effective Date: 1st January 2026

Company Information

SaaSi Hub LLC
Leander, Texas, United States
Website: https://www.saasihub.com

The “Plain English” Summary (TL;DR)

This section provides a simplified overview of how SaaSi Hub handles your data and is intended to help you quickly understand our privacy practices. The full Privacy Policy below contains the complete details.

Full details about how we process and protect data are explained in the sections below.

Introduction

SaaSi Hub (“SaaSi Hub LLC”, “we,” “us,” or “our”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and safeguard personal information when you use our website, platform, and related services.

This policy applies to information collected through the SaaSi Hub website, our software platform, and any communication between you and our organisation. It outlines the types of data we may collect, how that data is used, and the rights you have regarding your personal information.

We handle personal data in accordance with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR), the EU GDPR, the Data Protection Act 2018, and applicable United States privacy laws such as the California Consumer Privacy Act (CCPA/CPRA) and similar state privacy laws where applicable. Our aim is to ensure transparency in how information is processed while maintaining the highest standards of data protection and security.

By using our services or accessing our website, you acknowledge that you have read and understood this Privacy Policy.

1. Data Controller and Data Processor Roles

This section explains details about when SaaSi Hub acts as a Data Controller and when it acts as a Data Processor.

1.1 When and What SaaSi Hub Acts As

For your account information (your name, billing details): We are the Data Controller.
For your company’s data in our platform: We are the Data Processor.

We process this data solely on your behalf to supply the service.

1.2 Managed Service Providers and Third Party Administrators

In some cases, organisations may access the SaaSi Hub platform through a Managed Service Provider (MSP), consultant, or other authorised third party administrator.

Where a Managed Service Provider uses the platform on behalf of a client organisation, the client organisation remains the Data Controller for the personal data processed within the platform. SaaSi Hub acts as a Data Processor on behalf of the relevant organisation in accordance with the SaaSi Hub Data Processing Addendum and applicable data protection laws.

Managed Service Providers are responsible for ensuring that they have obtained appropriate authority from the organisation they represent to access and process data through the platform.

SaaSi Hub does not control how a Managed Service Provider manages or accesses data within the platform and is not responsible for operational decisions made by MSPs on behalf of their clients.

2. Information We Collect

In order to provide and improve the SaaSi Hub platform, we may collect certain information when you use our website, create an account, or interact with our services. The types of data collected depend on how you use the platform and the features you access.

2.1 Account Information

When you create an account or register to use SaaSi Hub, we may collect basic account information required to provide access to the platform. This may include:

This information allows us to create and manage your account and provide access to the SaaSi Hub platform.

2.2 Platform Usage Data

When you use the SaaSi Hub platform, we may collect information relating to how the service is used. This helps us maintain system performance and improve functionality.

This may include:

This information is used solely to operate, maintain, and improve the platform.

2.3 Integration Data

If you connect third party HR and SaaS tools to the platform, SaaSi Hub may collect certain data from those integrations in order to provide its monitoring and analytics features.

Depending on the integration, this may include:

Examples of the data we collect from third-party integrations you authorize to provide our services (detecting “Zombie Subscriptions” and facilitating offboarding) include:

Employee Directory Data (via HRIS)

Source: Integrations like BambooHR, Workday, Gusto.

Data Points: Employee Names, Email Addresses, Department, Job Title, Employment Status (Active/Terminated), Termination Dates.

Important: When capturing employee email addresses, we do not access email content.

Identity & Access Data (via IT Providers)

Source: Integrations like Google Workspace, Microsoft 365, Okta.

Data Points: User Accounts, License Assignments, Last Login Time/Date, Account Status (Active/Suspended).

Important: When capturing employee workspaces and/or drives we do not access drive files.

Financial & Usage Data

Source: Integrations like QuickBooks, Xero, or Manual Entry.

Data Points: Vendor names, transaction amounts, transaction dates (to identify SaaS spend).

2.4 Employee Data Provided by Customers

We process personal data relating to employees or contractors of our customers where such data is provided to us in connection with the use of the Service.

This data is intended to be limited to business-related information, such as work-issued email addresses and organisational details. Customers are responsible for ensuring that any personal data they provide is accurate, relevant, and limited to what is necessary for business purposes.

2.5 Billing and Payment Information

If you subscribe to a paid plan, certain billing information may be collected to process payments and manage subscriptions.

This may include:

Payment card information is processed securely by our third party payment providers and is not viewable or stored directly within the SaaSi Hub platform.

2.6 Communications and Support Data

If you contact us for support or enquiries, we may collect information provided during those interactions. This may include:

This information is used to respond to enquiries and improve customer support.

2.7 Live Chat and AI Assisted Support

SaaSi Hub may provide live chat or automated support features on its website or within the platform. These services may use AI assisted technologies to help respond to enquiries and provide guidance to users.

When you interact with our live chat system, we may collect information such as:

Chat conversations may be processed by automated systems and may also be reviewed by authorised SaaSi Hub personnel for the purposes of responding to enquiries, improving customer support, and maintaining service quality.

Where live chat services are provided through a third party platform, that provider may process chat data on our behalf in accordance with appropriate data protection safeguards.

2.8 Website and Technical Information

When you visit our website, certain technical information may be collected automatically to ensure the website functions properly and to analyse usage.

This may include:

Further information about how we use cookies is provided in our Cookie Policy.

2.9 Information We Do Not Intentionally Collect

SaaSi Hub does not intentionally collect sensitive personal data unless it is necessary to provide the service or required by law.

SaaSi Hub is a business-to-business (B2B) platform intended for use by adults and corporate entities. We do not knowingly collect personal information from children under the age of 16. If we become aware that we have inadvertently collected such data, we will take immediate steps to delete it.

3. How We Use Your Data

SaaSi Hub uses the information collected through our website and platform solely for the purpose of operating, maintaining, and improving our services. We process data in a responsible and transparent manner and only use it where necessary to deliver the functionality of the platform.

The information we collect may be used for the following purposes:

3.1 Subscription Discovery

SaaSi Hub analyses software licence and user information obtained through connected integrations in order to identify subscriptions that may no longer be required. This includes matching active software licences against employee status information to highlight licences assigned to employees who have left the organisation. These are sometimes referred to as “zombie subscriptions” and represent a common source of unnecessary SaaS spending.

3.2 Business Use of Employee Data

We process employee data solely for the purpose of providing the Service to our customers, including SaaS subscription tracking, cost analysis, and account management.

We expect customers to provide employee data in a professional context and not to include personal email addresses or unrelated personal information unless they have a valid lawful basis to do so under applicable data protection laws.

3.3 Cost Analytics and Reporting

We use collected data to generate insights into SaaS usage and expenditure. This allows organisations to view their software costs in one central dashboard and identify areas where savings may be possible. Analytics may include spend analysis, licence usage patterns, renewal monitoring, and estimated cost optimisation opportunities.

3.4 Offboarding Management

The platform uses integration data to support employee offboarding processes. When a user is identified as having left an organisation, SaaSi Hub can generate recommended actions, checklists, and guidance to help administrators review and remove access from connected software platforms.

3.5 Security and Access Monitoring

SaaSi Hub may use platform data to identify potential security risks related to user access. For example, the system may detect instances where an account associated with a former employee remains active in connected software tools. These insights help organisations reduce access related risks and maintain better control over their SaaS environments.

3.6 Platform Operation and Improvement

Information may also be used to maintain system performance, monitor platform reliability, and improve the functionality of the service. This includes analysing usage trends, diagnosing technical issues, and enhancing the overall user experience.

3.7 Customer Support and Communication

If you contact us for support or assistance, we may use the information provided to respond to enquiries, investigate issues, and provide technical guidance. Communication records may also be used to improve the quality of our support services.

Support communications may include interactions through email, support forms, or live chat systems, including AI assisted support tools used to respond to enquiries and improve the quality of customer support.

4. Legal Basis for Processing

SaaSi Hub processes personal data in accordance with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. These regulations require organisations to identify a lawful basis for processing personal information.

Where SaaSi Hub acts as a data processor on behalf of a customer organisation, the customer is responsible for determining the legal basis for processing the personal data stored within the platform.

Depending on how the platform is used, SaaSi Hub may rely on one or more of the following legal bases for processing data.

4.1 Performance of a Contract

Much of the data processed by SaaSi Hub is necessary to provide the services requested by our customers. This includes creating and managing accounts, enabling access to the platform, processing integrations with third party software tools, and generating analytics and reporting within the dashboard.

Without processing this information, we would not be able to deliver the core functionality of the SaaSi Hub platform.

4.2 Legitimate Interests

We may process certain information where it is necessary for our legitimate business interests, provided that these interests are not overridden by the rights and freedoms of individuals.

Examples of legitimate interests may include:

When relying on legitimate interests, we take appropriate steps to ensure that personal data is handled responsibly and with minimal impact on individual privacy.

4.3 Legal Obligations

In some cases, we may be required to process or retain certain information in order to comply with legal or regulatory obligations. For example, financial transaction records may be retained to meet accounting and tax compliance requirements.

4.4 Consent

Where required by law, we may rely on user consent for certain types of data processing. This may include optional communications, marketing activities, or the use of certain cookies on our website.

Where consent is relied upon, individuals have the right to withdraw their consent at any time.

5. Data Storage & Security

SaaSi Hub takes the security of customer data seriously and implements a range of technical and organisational safeguards to protect information processed through the platform. These measures are designed to ensure that data remains secure, confidential, and protected against unauthorised access, alteration, or loss.

5.1 Infrastructure and Hosting

SaaSi Hub’s internal platform is hosted on Google Cloud infrastructure, benefiting from Google’s enterprise grade physical and network security systems. Google Cloud data centres provide advanced protections including controlled facility access, continuous monitoring, and resilient network architecture.

All data transmitted between your browser, connected SaaS applications, and the SaaSi Hub platform is encrypted using modern transport layer security protocols (TLS 1.2 or higher).

Our public facing website is hosted separately with an ISO27001 certified secure hosting provider. This environment includes advanced network protections such as high capacity DDoS mitigation, secure SSL encryption, and real time monitoring against malware, suspicious uploads, and other security threats.

5.2 Data Storage and Encryption

Customer data stored within the SaaSi Hub platform is protected using strong encryption standards.

Sensitive data, including integration tokens and relevant user information retrieved from connected SaaS tools, is encrypted at rest using AES-256 encryption. All data transmitted between systems is encrypted in transit using TLS/SSL protocols to protect against interception.

Database storage volumes and backups are also encrypted using industry standard encryption mechanisms.

5.3 Data Residency

Customer data is primarily stored in secure cloud infrastructure located in the United States (US East) and the European Union (EU West). These locations are selected to ensure reliability, performance, and security while maintaining appropriate data protection safeguards.

5.4 Authentication and Integration Security

Where available, SaaSi Hub uses OAuth 2.0 authentication for connecting third party SaaS integrations such as Google Workspace or Slack. This method allows users to securely authorise access without sharing their account passwords with our platform.

If an integration does not support OAuth 2.0 authentication, alternative secure authentication methods may be used. 

SaaSi Hub does not view, store, or retain customer passwords used to access third party services. The platform requests only the minimum permissions necessary to retrieve information required for licence monitoring, user status tracking, and analytics within the SaaSi Hub dashboard.

Customers can revoke SaaSi Hub’s access to any connected SaaS platform at any time through their respective SaaS provider’s administration console.

5.5 Access Control

Access to customer data within the SaaSi Hub platform is strictly limited to internal, authorised personnel who require it for operational support, maintenance, or security purposes. Internal access controls are designed to ensure that only appropriate individuals can access specific systems or data.

5.6 Payment Security

All payment transactions are processed through Stripe, a PCI DSS Level 1 certified payment service provider. Stripe handles all payment card processing directly, meaning SaaSi Hub does not store, process, or have access to credit card or debit card details submitted through our billing system.

5.7 Vulnerability Management

We maintain ongoing monitoring and vulnerability management processes to ensure the platform remains secure. This includes automated scanning of software dependencies and infrastructure components to detect potential vulnerabilities.

Where vulnerabilities are identified, updates and patches are applied promptly to maintain the integrity and security of the platform.

5.8 Data Breach Response

In the event of a data security incident affecting customer data, SaaSi Hub will investigate promptly and notify affected customers or organisations without undue delay and, where required by applicable law, within legally required timeframes (including 72 hours where GDPR applies).

6. Data Sharing

SaaSi Hub does not sell, trade, or rent personal data to third parties. Information collected through our platform is used solely to operate and improve our services.

In order to provide the SaaSi Hub platform, certain information may be processed by trusted third party service providers that support the operation, security, and functionality of our services. These providers only process data on our behalf and in accordance with appropriate contractual safeguards.

6.1 Cloud Hosting

SaaSi Hub’s platform infrastructure is hosted using Google Cloud services. Google Cloud provides secure data storage, network infrastructure, and computing resources required to operate the platform.

Customer data processed through the platform may be stored within Google Cloud data centres located in approved regions. Google Cloud operates under strict security and compliance frameworks designed to protect customer information.

6.2 International Data Transfers

As SaaSi Hub operates globally and uses trusted cloud infrastructure and service providers to operate the platform, customer data may be processed or stored in data centres located outside the United Kingdom or the European Economic Area (EEA), including in the United States.

As mentioned in section 5.3, heading ‘Data Residency’:
Customer data is primarily stored in secure cloud infrastructure located in the United States (US East) and the European Union (EU West). These locations are selected to ensure reliability, performance, and security while maintaining appropriate data protection safeguards.”

Where personal data is transferred internationally, we take appropriate steps to ensure that it remains protected in accordance with applicable data protection laws. This may include the use of contractual safeguards with our service providers and reliance on recognised data protection frameworks where available.

All third party providers used by SaaSi Hub are required to maintain appropriate security and privacy protections for the data they process on our behalf.

6.3 Payment Processing

Payments for SaaSi Hub subscriptions are processed by Stripe, a PCI DSS Level 1 certified payment service provider. Stripe securely handles payment transactions and billing information on our behalf.

SaaSi Hub does not store or have access to customers’ full credit or debit card details. All payment information is processed directly by Stripe through secure encrypted connections.

6.4 Service Providers and Subprocessors

SaaSi Hub may engage additional trusted service providers to support areas such as infrastructure management, security monitoring, customer support, or communications. Where third parties are used, they are required to process data only for the purposes necessary to deliver the service and must implement appropriate data protection safeguards.

A list of key subprocessors used by SaaSi Hub is available at: https://www.saasihub.com/subprocessors

6.5 Legal Requirements

In limited circumstances, SaaSi Hub may disclose information where required to comply with applicable laws, regulations, or legal processes. This may include responding to lawful requests from government authorities, regulatory bodies, or courts.

6.6 Data Protection Commitments

Any third party service providers engaged by SaaSi Hub are required to maintain appropriate security measures and process data in accordance with applicable data protection regulations. We take reasonable steps to ensure that customer data remains protected when shared with authorised partners.

6.7 Business Transfers

If SaaSi Hub undergoes a merger, acquisition, corporate restructuring, or sale of assets, customer data may be transferred as part of that transaction, subject to the same privacy commitments outlined in this Privacy Policy.

7. Your Data Protection Rights

SaaSi Hub respects the rights individuals have over their personal data. We aim to operate in accordance with applicable data protection regulations, including the UK General Data Protection Regulation (UK GDPR), the EU GDPR, and other applicable international privacy frameworks such as the California Consumer Privacy Act (CCPA) where relevant.

Depending on your location and the nature of the data processed, you may have the following rights regarding your personal information.

7.1 Right to Access

You have the right to request confirmation of whether we process personal data relating to you and to request a copy of the information we hold. This may include data associated with your account, platform usage, or other interactions with our services.

7.2 Right to Rectification

If you believe that the information we hold about you is inaccurate or incomplete, you have the right to request that it be corrected or updated.

7.3 Right to Erasure (“Right to be Forgotten”)

You have the right to request the deletion of personal data relating to you or your organisation. Where a valid request is received, we will review and process the request in accordance with applicable data protection laws.

Upon account cancellation, customers may request that we permanently delete all synced company data stored within the SaaSi Hub platform. Please note that once deletion has been completed, this action is permanent and cannot be reversed. All platform data, integrations, and associated records will be removed from active systems.

Certain information may still be retained where required for legal or regulatory obligations, such as maintaining billing records for tax and accounting purposes.

7.4 Right to Data Portability

Customers may export their reports and platform data directly from the dashboard at any time.

7.5 Right to Restrict Processing

In certain circumstances, you may request that we temporarily restrict the processing of your personal data while a request or concern is being reviewed.

7.6 Right to Object

You may object to certain types of data processing where we rely on legitimate interests as the legal basis for processing.

7.7 Right to Lodge a Complaint

If you believe that your data protection rights have been violated, you have the right to lodge a complaint with your local data protection authority.

In the United Kingdom, the supervisory authority is the Information Commissioner’s Office (ICO). SaaSi Hub LLC is registered with the Information Commissioner’s Office under registration reference: ZC089944.

7.8 Additional Rights for US Residents

Residents of certain US states, including California, may have additional privacy rights under applicable state privacy laws. These rights may include the ability to request access to personal information collected about them, request deletion of certain data, or request information about how personal data is shared.

Where applicable, SaaSi Hub will respond to such requests in accordance with relevant US privacy regulations.

8. Data Retention and Deletion

8.1 Data Retention

SaaSi Hub follows structured data retention policies designed to balance operational requirements with data protection principles.

Account related data is retained for the duration of the active subscription and may be retained for a limited period of up to 12 months after a subscription has ended for operational or legal purposes.

Billing and transaction records may be retained for up to seven years in order to comply with tax and accounting obligations.

Customer support communications and technical logs may be retained for a limited period after a subscription ends in order to maintain system security, resolve disputes, and improve platform functionality.

Accounts with no active subscription may remain accessible for up to 12 months to allow customers to reactivate their account. After this dormant period, access will be disabled and associated account data will be scheduled for deletion from active systems. Customers are advised to export any required reports before their subscription ends.

8.2 Backup Data

For disaster recovery purposes, encrypted backups of system data may be retained for a limited period. Backup systems are automatically overwritten on a rolling basis, meaning deleted data may temporarily remain within backup archives until those backups expire.

Backup data is retained solely for recovery purposes and is not used for operational processing.

8.3 Third Party Integration Services In Our Platform

SaaSi Hub integrates with third party SaaS tools within our platform. Data retrieved through integrations is stored only as required to provide platform functionality. Customers remain responsible for managing their data within those external platforms. Deleting data from SaaSi Hub does not automatically remove information stored within third party integration services.

8.4 Exercising Your Rights

If you wish to exercise any of the rights described above, or have questions regarding how your data is handled, you may contact us at: privacy@saasihub.com

9. Cookies and Tracking Technologies

SaaSi Hub uses cookies and similar tracking technologies on our website to ensure that it functions correctly, improves user experience, and to understand how visitors interact with our site.

Cookies are small text files that are stored on your device when you visit a website. They allow websites to recognise your browser, remember certain preferences, and collect information about how visitors use the site.

9.1 How We Use Cookies

We use cookies for several purposes, including:

Cookies may be either session cookies, which expire when you close your browser, or persistent cookies, which remain on your device for a limited period.

9.2 Cookie Consent and Preferences

When you first visit our website, you will be presented with a cookie consent notice that allows you to choose whether to accept or decline certain categories of cookies.

Our cookie management tool allows you to:

You may change your cookie preferences at any time by accessing the cookie settings available on our website. This allows you to review or withdraw your consent for non essential cookies.

9.3 Analytics and Performance Tracking Services
9.3.1 Google Analytics

SaaSi Hub uses Google Analytics, a web analytics service provided by Google, to help us understand how visitors interact with our website.

Google Analytics uses cookies to collect information such as:

This information helps us analyse website performance, identify areas for improvement, and understand how visitors discover and use our services.

Google Analytics may use anonymised IP addresses where configured. The data collected through Google Analytics is aggregated and used for statistical analysis only. We do not use this information to personally identify individual visitors.

Google may process this information on servers located outside your country of residence. Further information about how Google processes data can be found in Google’s Privacy Policy.

9.4 Website Security and Performance Services

SaaSi Hub uses appropriate technologies and service providers to support website performance, reliability, and security. These measures are designed to help protect the website from malicious traffic, unauthorised access, and other security threats.

In order to provide these protections, certain technical information about visitors to our website may be processed. This may include IP addresses, browser information, and basic request data. This information is used solely for security, performance monitoring, and traffic management purposes.

We may also use strictly necessary cookies or similar technologies to support the secure operation of the website. These cookies help distinguish between legitimate users and automated or malicious activity and do not collect personal information for marketing purposes.

These services may be provided by third party providers acting on our behalf. Further information about the third party providers we use can be found on our Subprocessors page.

9.5 Changes to Cookie Usage

We may update our use of cookies and tracking technologies from time to time as our website and services evolve. Any significant changes will be reflected in this policy.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, operational practices, or legal requirements.

When updates are made, the revised version will be published on this page and the “Last Updated” date will be amended accordingly. Where changes are significant, we may also notify users through the platform or via email.

We encourage users to review this policy periodically to stay informed about how their information is protected.

11. Contact Us

If you have questions about this Privacy Policy or how SaaSi Hub handles personal data, you may contact us at: privacy@saasihub.com